ComputingRevision.net

1.4.1b Social Engineering

Every System's Weak Point

Most computer systems are very well protected against hackers! Even a highly skilled hacker might struggle to break into some systems.

However, every system has the same weak-point: the human!

It is often easier for a hacker to trick a user into revealing a password or sensitive information, than to try to hack into it.

The techniques used to trick users are called social engineering.

Puppet on a string

Common Social Engineering Techniques

There are lots of different techniques. Here are three of the most common (click to view the details):

Phishing
Pretexting
Shoulder Surfing

Phishing

Phishing

Fake messages (like an email or text) pretending to be a real company to try to trick you into giving personal information.

Example:

  • An email which looks like its from your bank
  • It says you need to urgently check your account because of some problem (like a large amount of cash has been taken)
  • Clicking the email link takes you to a realistic-looking website
  • When you enter your username and password, nothing seems to happen – but it is sent to the hackers for them to use!

Pretexting

Pretexting

A person pretends to be someone they’re not to get private information from you.

Example:

  • A person contacts you saying they are from your broadband provider's security team
  • They say there is a problem with your account
  • They offer to help you, but say they need your username and password to confirm who you are, or they tell you to install some software
  • They can now access your private account or take-over your computer

Shoulder Surfing

Shoulder Surfing

Looking over someone’s shoulder to see them typing passwords or other sensitive information

More high-tech examples include:

  • Cameras hidden above keypads
  • Card skimmers, which copy your bank card details, placed over cash machine card slots