What is Social Engineering?
Social engineering is the art of manipulating users of a computing system into revealing confidential information that can be used to gain unauthorized access to a computer system. The term can also include activities such as exploiting human kindness, greed, and curiosity to gain access to restricted access buildings or getting users from installing backdoor software.
Knowing the tricks used by hackers to trick users into releasing vital login information among others is fundamental in protecting computer systems
In this tutorial, we will introduce you to the common social engineering techniques and how you can come up with security measures to counter them.
How social engineering Works?
Gather Information: This is the first stage, the learns as much as he can about the intended victim. The information is gathered from company websites, other publications, and sometimes by talking to the users of the target system.
Plan Attack: The attackers outline how he/she intends to execute the attack
Acquire Tools: These include computer programs that an attacker will use when launching the attack.
Attack: Exploit the weaknesses in the target system.
Use acquired knowledge: Information gathered during the social engineering tactics such as pet names, birthdates of the organization founders, etc. is used in attacks such as password guessing.
Common Social Engineering Techniques
1. Familiarity Exploit
2.Intimidating Circumstances
3. Phishing
4. Tailgating
5. Exploiting human curiosity
6. Exploiting human greed
7. Quid Pro Quo
8. Pretexting
9. Baiting
Social engineering prevention
Social Engineers manipulate human feelings, such as curiosity or fear, to carry out schemes and draw victims into their traps. Therefore, be wary whenever you feel alarmed by an email, attracted to an offer displayed on a website, or when you come across stray digital media lying about. Being alert can help you protect yourself against most social engineering attacks taking place in the digital realm.
The following tips can help to prevention :
• Don’t open emails and attachments from suspicious sources
• Use multifactor authentication
• Be wary of tempting offers
• Keep your antivirus/antimalware software updated
Best Social engineering Books
1)Social Engineering: The Science of Human Hacking
2)Social Engineering: The Art of Human Hacking
3)The Art of Deception: Controlling the Human Element of Security
0 Comments