Social Engineering Techniques Flashcards
What is Phishing?
Hacker getting user to provide their secure information (usually through fake email links)
What is Smishing?
Type of Phishing that uses SMS messages
What is Vishing?
Type as Phishing but uses VOICE / VOIP
What is Spear Phishing?
Type of phishing where the hacker attacks a specific person/ user
What is Whaling?
Type of spear phishing where the hacker goes against a the highest possible target (CEO, CIO, CFO, ect….) to get more sensitive data
How do you fight Phishing?
primarily done through user training to identify fake emails and URLs and not to provide any sensitive data
What is web ripper?
Software that allows user to download entire websites, usually used by hackers to create phishing websites
What is Shoulder Surfing and how do you fight it?
Hacker looking over a users shoulder to steal data. You fight it by user training and providing ways to limit viewing angles (privacy screens)
What is dumpster Diving and how do you fight it?
Hackers going through an organizations trash to find sensitive information. You fight it by either the shredding or preferably burning documents.
What is the main concept of social engeenering?
To gather data directly from users
What different techniques do social engeers employ use to get data out of users
Authority, Intimidation, Consensus, Scarcity, Familiarity, Trust, and Urgency
What is Authority relating to Social Engineering?
When a hacker tries to get information out of user by trying to get users to think they have the Authority to get it (EX. Someone pretending to be in IT, HR, or Accounting).
What is Intimidation relating to Social Engineering?
When a hacker scares users into giving them data
What is Consensus relating to Social Engineering?
When a hacker tries to convince users to give data by using herd mentality
What is Scarcity relating to Social Engineering?
When a hacker tries to convince users to give data by saying something is scarce or in limited supply
What is Familiarity relating to Social Engineering?
When a hacker tries to convince users to give data by becoming familiar or “friends” with a user
What is Trust relating to Social Engineering?
When a hacker builds trust with a user to gather data