Social Engineering Techniques Flashcards
Phishing
social engineering technique where attacker tricks user into responding to something (ex. email) to instance a malware-based attack
Smishing
phishing via text message
Vishing
phishing via phone calls
Spam
unwanted and unsolicited digital mail sent out in bulk
Spim
spam over instant messaging
Spear Phishing
targeted phishing
Dumpster Diving
act of going through the garbage at an organization in order to find sensitive information that could possibly compromise a network and its resources
Shoulder Surfing
act of looking over a persons shoulder to gather sensitive information from an individuals device/desk (can include looking through windows w/ binoculars)
Pharming
the use of malicious code to direct victims to spoofed websites in an attempt to steal their credentials and data
Tailgating
following closely behind someone to gain unauthorized access to a physical building or location
Eliciting Information
the act of casual conversation to extract information from a victim w/out giving the impression that they are being interrogated
Whaling
targeting a higher up w/ a phishing attack (ex. CEO)
Prepending
?
Identity Fraud
the act of stealing someones identity and pretending to be them
Invoice Scams
scams over the phone that attempt to gain sensitive/personal information