Social Engineering Flashcards
Spear Phishing
targeted phishing
Whaling/Whale Phishing
Phishing that target executive level to get wire transfers etc
Smishing
Phishing over SMS
Vishing
Phishing over the phone
SPAM
Large quantities of unsolicited advertising over email
SPIM
Spam sent over Text
Dumpster Diving
Removing sensitive info from literal trash cans
Shoulder Surfing
Looking over someones shoulder - Privacy screens, masked passwords
Pharming
redirecting to malicious site
How to mitigate Shoulder Surfing
privacy screens. masked passwords, multiple asterisks per keystroke
Tailgating Mitigations
Cameras to monitor doors, key card access.
Pharming examples
DNS Cache Poisoning, Host File Injection,
Hoax
Someone pretends to be an IT person or fellow coworker. Seem legitimate.
Prepending
Adding mentions to tweets/social media to make them seem more personal or to get broader audience, higher engagement.
Watering Hole Attack
Uses less secure websites or ones a particular target is likely to visit to plant malware and infect users.