Social engineering is the acquisition of security-sensitive information or unauthorised access privileges by an outside attacker, based upon the abuse of a trust relationship.

Human-based social engineering:

  • Social engineer may call a help desk, the engineer will often know names of employees and lingo of the company.
  • A social engineer may pretend to be an important user which means their request is less likely to be turned down, and they may threaten to report the employee to their supervisor if they don’t comply.
  • The social engineer may have obtained the name of someone in the organisation who has authority to grant access information, and thereby pretend that they sent them.
  • A social engineer may pretend to be someone from an infrastructure-support group.

Computer-based social engineering:

  • Malware in mail attachments
  • Websites which farm credentials
  • Popup windows that farm information
  • Fake wireless networks that could capture information
  • Phishing: attackers use web-based services to launch attacks on devices connected to web to acquire various bits of information by masquerading as someone trustworthy within some electronic communication.
    • SMiShing: phishing over SMS
    • Vishing: phishing over VoIP