Social engineering Flashcards
Define Social engineering
Art of convincing people to reveal confidential information
Steps of social engineering
Research - Gather info on target org
Select target - Choose indiv target
build Relationship - Earn target trust
Exploit - Extract information from target
What is the term for Stealing someone’s information to pose as that person?
Identity theft
What foss tool can perform credential harvesting and attacks like website attack vectors, mass mailer attack, sms spoofing, QRCode generator, WAP attack…
Social-Engineer Toolkit (SET)
What is the term for pretending to be someone else to learn needed information
Impersonation aka masquerading
What is the term for secretly listening to other peoples communication without consent.
Eavesdropping
What is the term for observing victims when they’re using devices such as ATMs, computers, kiosks…
Shoulder surfing
What is the term for collecting information from the target’s trash bins
Dumpster diving
What is the method that is initiated by the victim that’s tricked into contacting the attacker herself where an attacker poses as an authority figure usually by creating a problem then offering a solution.
Reverse social engineering
What is the term for convincing authorized personnel to let attacker into a secured area which differs from tailgating as it includes consent of the personal.
Piggybacking
Gaining access to restricted areas by following another person where the countermeasure is using man traps as because they only allow single person at a time.
Tailgating
Use of the telephone to perform the attack (voice and phishing)
Vishing
Attack where the attacker sends a link to a malicious website to collect information.
E.g. someone calls, asks to fill a form, and says it’s a company survey and it’ll help company a lot.
Phishing
A very targeted attack on a high value victim called “Whale” (big fish).
Usually targets high-level executives
Whaling
Using specialized phishing content for a specific person or group of people.
Generate higher response rate as it’s more personalized
Spear Phishing