Social Engineering Flashcards
Broad range of malicious activities accomplished through human interaction. Any attempt to manipulate users to reveal confidential information or perform actions detrimental to a system’s security.
Social Engineering
A social engineering attack where the malicious actor communicates with the victim from a supposedly reputable source to lure the victim into divulging sensitive information
Phishing
Uses the same technology and techniques but is a more targeted version of phising
Spear phishing
Focused on key executives within an organization or other key leaders, executives, and managers in the company
Whaling
The text message service component on cellphones, smartphones, tablets, and other mobile devices
A form of text messaging that also allows pictures, sounds, or videos to be sent
Smishing –
Short Message Service (SMS)
Multimedia Messaging Service (MMS)
Occurs when the message is being communicated to the target using the voice functions of a telephone
Vishing
Occurs when an attacker takes over a high-level executive’s email account and orders employees to conduct tasks
Business Email Compromise (BEC)
Tricks users into divulging private information by redirecting a victim to a website controlled by the attacker or pen tester
Pharming
The abuse of the electronic messaging systems, most commonly through email
Spam
The act of pretending to be someone else in order to gain access or gather information
Impersonation
A fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communication
Evil Twin (Rogue Access Point)
Type of evil twin attack that exploits the behavior of Wi-Fi devices due to a lack of access point authentication protocols being implemented
Karma Attack
A list of the SSIDs of any access points the device has previously connected to and will automatically connect to when those networks are in range
PNL (Preferred Network List)
A web page that the user of a public-access network is obligated to view and interact with before access is granted
Captive Portal