<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0">
    <channel>
        
        <title>
            <![CDATA[ social engineering - freeCodeCamp.org ]]>
        </title>
        <description>
            <![CDATA[ Browse thousands of programming tutorials written by experts. Learn Web Development, Data Science, DevOps, Security, and get developer career advice. ]]>
        </description>
        <link>https://www.freecodecamp.org/news/</link>
        <image>
            <url>https://cdn.freecodecamp.org/universal/favicons/favicon.png</url>
            <title>
                <![CDATA[ social engineering - freeCodeCamp.org ]]>
            </title>
            <link>https://www.freecodecamp.org/news/</link>
        </image>
        <generator>Eleventy</generator>
        <lastBuildDate>Sun, 26 Jul 2026 22:34:15 +0000</lastBuildDate>
        <atom:link href="https://www.freecodecamp.org/news/tag/social-engineering/rss.xml" rel="self" type="application/rss+xml" />
        <ttl>60</ttl>
        
            <item>
                <title>
                    <![CDATA[ Modern Social Engineering Explained – 10 Types of Social Engineering Cyberattacks ]]>
                </title>
                <description>
                    <![CDATA[ Have you ever received a suspicious email or phone call from an unknown number asking for information? Or clicked on that link promising discount deals but ended up entering sensitive information? Chances are you were a victim of a social engineering... ]]>
                </description>
                <link>https://www.freecodecamp.org/news/modern-social-engineering-cyberattacks/</link>
                <guid isPermaLink="false">66d03606c1024fe75b758f22</guid>
                
                    <category>
                        <![CDATA[ cybersecurity ]]>
                    </category>
                
                    <category>
                        <![CDATA[ Security ]]>
                    </category>
                
                    <category>
                        <![CDATA[ social engineering ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Manish Shivanandhan ]]>
                </dc:creator>
                <pubDate>Tue, 21 Mar 2023 22:03:40 +0000</pubDate>
                <media:content url="https://www.freecodecamp.org/news/content/images/2023/03/0_gMWjfaXWX6wgkNtF.jpg" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>Have you ever received a suspicious email or phone call from an unknown number asking for information? Or clicked on that link promising discount deals but ended up entering sensitive information? Chances are you were a victim of a social engineering attack.</p>
<p>Social engineering is a manipulation technique used by attackers to extract information or access from people. </p>
<p>In this article, we will learn what social engineering attacks are, how they work, and the twelve latest forms of social engineering attacks. We will also learn how to identify, and protect yourself, and your business from such attacks.</p>
<p>The 2018 Verizon Data Breach Investigations Report found that social engineering was a factor in <a target="_blank" href="https://legaljobs.io/blog/cyber-crime-statistics/">32 percent of all data breaches</a>.</p>
<p>The 2019 <a target="_blank" href="https://www.ibm.com/downloads/cas/ADLMYLAZ">IBM X-Force Threat Intelligence Index</a> found that phishing was the most common type of attack, making up over one-third of all attacks.</p>
<h1 id="heading-what-are-social-engineering-attacks">What Are Social Engineering Attacks?</h1>
<p>Social engineering attacks are manipulations or deceptive tactics used to gain control over computer systems, data, or sensitive information.</p>
<p>Social engineering attacks have drastically evolved. New methods such as <a target="_blank" href="https://www.youtube.com/watch?v=pkF3m5wVUYI&amp;ab_channel=AlJazeeraEnglish">deep fakes</a> are a growing concern for individuals and businesses. Cybercriminals know their targets, and social engineering is used to take advantage of human weaknesses.</p>
<p>Cybersecurity mistakes like this can cost companies huge sums of money. <a target="_blank" href="https://www.cyberpilot.io/cyberpilot-blog/new-ibm-report-the-real-cost-of-a-data-breach">The average cost of a company data breach is $4.24 million</a>.</p>
<p>Protecting against social engineering has become a pressing issue, and defending against these attacks is essential to avoid being a victim. New methods for exploiting technology trends are constantly being developed by cyber attackers, resulting in efficient social engineering techniques.</p>
<h1 id="heading-how-do-social-engineering-attacks-work">How Do Social Engineering Attacks Work?</h1>
<p>Social engineering attacks can occur in various forms. Once a cybercriminal gains access to your security systems or private information, the damage can be costly. Social engineering attacks pose a threat to various platforms, including iOS, Android, and personal computers.</p>
<p>There are four main phases in social engineering.</p>
<ul>
<li><strong>Discovery and investigation —</strong> The attacker searches for information about their target through social media platforms, dark web forums, or other public sources of information.</li>
<li><strong>Deception and hook —</strong> Once the attacker has gathered enough information, they will attempt to establish trust with their target by deception. They do this through phishing emails or contacting the target using impersonation techniques.</li>
<li><strong>Attack —</strong> If the attacker is successful, they will then attempt to gain access to their system or information. They do this through malicious software, password guessing, and other methods.</li>
<li><strong>Retreat —</strong> After the attacker has successfully accessed the target system or information, they will then begin to cover their tracks by deleting any evidence of their attack.</li>
</ul>
<p><strong>The average time to detect a</strong> <a target="_blank" href="https://www.ibm.com/blogs/ibm-anz/this-type-of-data-breach-will-cost-you-more-time-and-money/"><strong>cyber-attack or data breach is close to 250 days</strong></a><strong>, so you won’t even know what’s happened until they’re long gone.</strong></p>
<h1 id="heading-10-types-of-social-engineering-attacks">10 Types of Social Engineering Attacks</h1>
<p>Now that we know what social engineering attacks are, and how devastating they can be, lets look at 10 types of social engineering attacks.</p>
<h2 id="heading-phishing"><strong>Phishing</strong></h2>
<p>Phishing attacks are the most common type of social engineering attacks. They involve sending fraudulent emails to a number of people making the email appear to be from a legitimate source, such as a bank or government agency. The email will usually contain a link that leads to a malicious website designed to steal personal information.</p>
<p>In 2017, there was a <a target="_blank" href="https://www.itgovernanceusa.com/blog/email-phishing-scam-targeted-millions-of-netflix-subscribers#:~:text=Throughout%202017%2C%20Netflix%20subscribers%20have,cyber%20threat%20in%20January%202017.">pretexting attack that targeted Netflix users</a>. The attackers sent out emails that appeared to be from Netflix, asking the recipients to update their payment information. If they did so, they would be redirected to a fake website that would steal their login credentials and credit card number.</p>
<h2 id="heading-spear-phishing"><strong>Spear phishing</strong></h2>
<p>Spear phishing attacks are like phishing attacks, but they are targeted at specific individuals or organizations. The attacker will customize the email with information about their target, making it difficult for them to spot the fraud.</p>
<p>A new take on spear phishing is known as angler phishing. This occurs when scammers impersonate customer service accounts on social media. Their goal is to get access to their login information with promises of help.</p>
<h2 id="heading-smishing-and-vishing"><strong>Smishing and vishing</strong></h2>
<p>Smishing is a type of phishing attack that uses text messages. The attacker will send a message that appears to be from a legitimate organization, asking you to click on a link or call a phone number.</p>
<p>Vishing is like smishing, but the attacker will use voice calls instead of text messages. They may spoof the caller ID so it appears as if they are calling from a legitimate source or even a friend.</p>
<p>In 2019, there was a <a target="_blank" href="https://www.recordedfuture.com/amid-phishing-boom-fraudsters-target-small-and-mid-sized-banks">massive vishing campaign targeting customers of major US banks.</a> The attackers would call victims and pretend to be from the bank’s fraud department. They would then try to get the victim to give them their login information or credit card number.</p>
<h2 id="heading-piggybackingtailgating"><strong>Piggybacking/Tailgating</strong></h2>
<p>Piggybacking refers to an attack where the attacker gains access to a secured area by following someone who has legitimate access.</p>
<p>Tailgating is similar to piggybacking, but the attacker will try to gain access by asking someone for their badge or ID. Once they have the badge, they can use it to tailgate their way into the building.</p>
<h2 id="heading-baiting"><strong>Baiting</strong></h2>
<p>Baiting attacks use physical media. This includes USB drives or CDs, to lure victims into infecting their own computers. The attacker will leave the infected media in a public place, and wait for someone to take it and plug it into their computer.</p>
<p>In 2017, there was a baiting attack <a target="_blank" href="https://www.reuters.com/article/britain-security-nhs-idUKL9N1GZ00L">targeting staff at the UK’s National Health Service (NHS)</a>. The attacker left USB sticks around hospitals and clinics that appeared to contain information about patient care. When plugged in, the devices would actually install malware that could give the attacker access to sensitive patient data.</p>
<h2 id="heading-business-email-compromise-bec"><strong>Business Email Compromise (BEC)</strong></h2>
<p>Business email compromise (BEC) is a type of social engineering attack where the attacker gains access to a business email account and uses it to send fraudulent emails.</p>
<p>The most common type of BEC attack is known as invoice fraud. This is when the attacker sends out an email that appears to be from a known vendor, asking the recipient to pay an invoice. The payment will go into the attacker’s account instead of the legitimate vendor.</p>
<h2 id="heading-quid-pro-quo-attacks"><strong>Quid Pro Quo attacks</strong></h2>
<p>In Quid pro quo attacks, the attacker offers something to the victim in exchange for personal information or access to a system.</p>
<p>For example, an attacker may call someone pretending to be from IT. And, they offer to help troubleshoot their computer issues if they provide their login credentials.</p>
<h2 id="heading-honeytraps"><strong>Honeytraps</strong></h2>
<p>The term “honeytrap” refers to a social engineering attack, in which an attractive person is used to entice targets.</p>
<p>Honey trapping involves using an attractive individual to seduce and manipulate a target into revealing sensitive information or compromising their position. The attacker uses an attractive person to lure the victim into disclosing personal information or committing a crime.</p>
<p>Honey trapping is also a common espionage tactic that has been used by various intelligence agencies around the world. It helps them to extract sensitive information from individuals in positions of power. There have been some <a target="_blank" href="https://foreignpolicy.com/2010/03/12/the-history-of-the-honey-trap/">high-profile cases</a> of alleged honey trapping involving individuals associated even with the military.</p>
<h2 id="heading-scareware"><strong>Scareware</strong></h2>
<p>Scareware is a type of social engineering attack where the attacker uses fear to trick the victim into taking an action. This includes clicking on a link, downloading malware, or buying something online.</p>
<p>For example, how an attacker may send an email that appears to be from a legitimate company like Microsoft. It will then warn the recipient that their computer has been infected with a virus. The email would then tell them to click on a link to download “antivirus software” which would eventually be malware.</p>
<p>In 2012, there was a <a target="_blank" href="https://www.zdnet.com/article/android-users-hit-by-scareware-scam/">scareware attack targeting Android users</a>. The attackers created fake antivirus apps and advertised them online. When victims installed the apps, they would display fake virus warnings and prompt the user to buy the “full version” of the app to remove the malware.</p>
<h1 id="heading-how-to-protect-yourself-from-social-engineering">How to Protect Yourself from Social Engineering</h1>
<p>The best way to protect yourself from social engineering attacks is to be aware of them so you can recognize when one might be happening and not fall for it. </p>
<p>Cybercriminals come up with new ways of attacking targets and it’s important to keep up-to-date on the latest threats.</p>
<p>Here is a quick checklist.</p>
<ul>
<li>Carefully check emails including names, addresses, and copies. Look out for unusual/unfamiliar features that don't quite look right.</li>
<li>Be wary of unexpected attachments.</li>
<li>Recognize common phishing email subject lines (“urgent action required”, “account has been compromised”).</li>
<li>Verify the identity of anyone you don’t know personally.</li>
<li>Be extra careful around social media.</li>
<li>Never pay a ransom, and report ransomware to the relevant authorities. If you are in the US, you can report to the FBI at <a target="_blank" href="http://www.ic3.gov/">www.IC3.gov</a>.</li>
<li>Always use two or <a target="_blank" href="https://www.onelogin.com/learn/what-is-mfa">multi-factor authentication</a> (2FA/MFA).</li>
</ul>
<h1 id="heading-how-to-protect-your-business-from-social-engineering">How to Protect Your Business from Social Engineering</h1>
<p>Here is how we can protect businesses from social engineering attacks.</p>
<ul>
<li>Educate and train employees on social engineering attacks.</li>
<li>Create and enforce strong security policies.</li>
<li>Install technical safeguards like antivirus and firewalls.</li>
<li>Track activity and audit logs.</li>
<li>Implement strong password policies and Multi-Factor Authentication (MFA).</li>
<li>Restrict access to sensitive information using the <a target="_blank" href="https://blog.manishmshiva.com/protect-your-business-using-the-principle-of-least-privilege-31b0b385caf2">Principle of Least Privilege.</a></li>
<li>Track employee activity with a <a target="_blank" href="https://www.microsoft.com/en-us/security/business/security-101/what-is-siem">SIEM solution</a>.</li>
</ul>
<h1 id="heading-summary">Summary</h1>
<p>As social engineering attacks become more advanced, it's essential to be aware of how hackers try to manipulate you, your business, and your family. Most social engineering attacks can be recognized, controlled, and mitigated.</p>
<p>It is crucial that we take social engineering attacks seriously. By employing the right defensive strategies, we can safeguard ourselves against all forms of social engineering attacks.</p>
<p>Stay up-to-date, be alert, and make yourself a hard target.</p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ What is a Social Engineering Cyberattack? ]]>
                </title>
                <description>
                    <![CDATA[ Social engineering is when people try to trick others into giving them sensitive information or doing things that might not be a good idea. Hackers and cybercriminals often use social engineering to get into systems or steal data. Social Engineering ... ]]>
                </description>
                <link>https://www.freecodecamp.org/news/what-is-a-social-engineering-cyberattack/</link>
                <guid isPermaLink="false">66d0362b31fbfb6c3390f1f5</guid>
                
                    <category>
                        <![CDATA[ cybersecurity ]]>
                    </category>
                
                    <category>
                        <![CDATA[ information security ]]>
                    </category>
                
                    <category>
                        <![CDATA[ social engineering ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Manish Shivanandhan ]]>
                </dc:creator>
                <pubDate>Mon, 02 Jan 2023 14:00:00 +0000</pubDate>
                <media:content url="https://www.freecodecamp.org/news/content/images/2023/01/social-engineering-article-image.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>Social engineering is when people try to trick others into giving them sensitive information or doing things that might not be a good idea. Hackers and cybercriminals often use social engineering to get into systems or steal data.</p>
<p>Social Engineering attacks prey on human emotions and trust. This makes them highly effective in tricking people into giving out sensitive information.</p>
<p>Social engineering is dangerous because it is used to trick people into giving away private data. For example, a hacker might send an email that looks like it’s from a friend but is actually a trick to get you to click on a link. This link will then install malware on your computer.</p>
<p>Or, someone might call you pretending to be from a bank, and try to get you to give them your account password. </p>
<p>If you give away this kind of information, it can be used to steal your money or even your identity. This means that someone could use your name and personal information to do things that could get you in trouble or cause other problems.</p>
<p>There are many different types of social engineering attacks. Let’s look at some of the common ones.</p>
<h2 id="heading-what-is-phishing">What is Phishing?</h2>
<p>Phishing is a type of social engineering attack in which a hacker or cybercriminal uses fake emails or websites to trick people into giving away sensitive information. </p>
<p>The goal of a phishing attack is to steal this information, which can then be used to access accounts, make fraudulent purchases, or steal someone’s identity.</p>
<p>One common type of phishing attack is called “spoofing”. Here, the attacker creates an email or website that looks legitimate but is actually fake. </p>
<p>For example, the attacker might send an email that looks like it’s from your bank, asking you to log in to your account to update your information. </p>
<p>The email might include a link that takes you to a fake website that looks just like your bank’s website. If you enter your login information on this fake website, the attacker can use it to access your account and steal your money.</p>
<p>Another type of phishing attack is called “spear phishing”. In this attack, the attacker targets a specific individual or organization. The attacker might gather information about the victim through social media or other online sources. They will then use this information to create a personalized email or website that is more likely to trick the victim into giving away sensitive information.</p>
<h2 id="heading-what-is-pretexting">What is PreTexting?</h2>
<p>Pretexting is a type of social engineering attack in which an attacker creates a fake story or scenario to trick a victim. The goal of pretexting is to manipulate the victim into believing that the attacker is someone trustworthy, such as a colleague or a friend.</p>
<p>One common example of pretexting is “imposter scams,”. Here the attacker poses as a representative of a company or government agency and asks the victim to provide sensitive information or take an action.</p>
<p>For example, the attacker might call the victim and claim to be from a bank, saying that there has been suspicious activity on the victim’s account. They will then ask for the victim’s account number or login credentials. You should always be aware of the signs of pretexting, such as unexpected requests for sensitive information or requests that seem unusual.</p>
<h2 id="heading-what-is-baiting">What is Baiting?</h2>
<p>Baiting is a type of social engineering attack in which an attacker tempts a victim with something desirable. The goal of baiting is to manipulate the victim into taking action that will benefit the attacker.</p>
<p>One common example of baiting is offering a free trial or sample of a product or service in exchange for personal information. </p>
<p>For example, an attacker might create a website that offers a free trial of a new video game. This will require the user to provide their email address and other personal information to access the trial. The attacker can then use this information to send phishing emails or engage in other types of cybercrime.</p>
<p>Another example of baiting is offering access to a restricted or exclusive piece of content. The victim might be tempted to provide sensitive information or take an action in order to access the content, but the attacker can then use this information or access to further exploit the victim.</p>
<p>You would have heard about the Nigerian prince scam asking for a couple of thousand dollars in exchange for a fortune. This is an example of a baiting attack.</p>
<h2 id="heading-social-engineering-toolkit-set">Social Engineering Toolkit (SET)</h2>
<p><img src="https://www.freecodecamp.org/news/content/images/2023/01/image-33.png" alt="Image" width="600" height="400" loading="lazy">
<em>Social Engineering Toolkit</em></p>
<p>If you want to ethically perform a social engineering attack on your client or their business to test for vulnerabilities in their system, you can use the Social Engineering Toolkit or (SET). </p>
<p>SET is a collection of tools and resources that you can use to execute and test social engineering attacks. Using SET, you can:</p>
<ul>
<li>send simulated phishing emails.</li>
<li>use pretexting scripts to create fake but believable stories to trick people.</li>
<li>Bait users with fake promotions or offers to lure them into giving sensitive information.</li>
</ul>
<p>SET is a great tool for internal auditing, but it is also used by malicious attackers. If you do a pen test for a client, always include social engineering auditing as well. People are the weakest link in every security framework.</p>
<h2 id="heading-recap">Recap</h2>
<p>Social engineering is when people try to trick others into giving them sensitive information or doing things that might not be a good idea. </p>
<p>Hackers use different tactics to do this, such as phishing (sending fake emails or creating fake websites to steal information), baiting (offering something desirable to get information), and pretexting (pretending to be someone else to get someone to do something). </p>
<p>It’s always important to be careful and not give out personal information or click on links from people you don’t know.</p>
<p>If you want to master the concept of social engineering, I would recommend reading “Social Engineering: The Science of Human Hacking” by Christopher Hadnagy. It’s an amazing book and I loved every bit of it.</p>
<p>Hope you enjoyed this article. You can find more about my articles and videos on <a target="_blank" href="https://www.manishmshiva.com/">my website</a>.</p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ Social Engineering — The Art Of Hacking Humans ]]>
                </title>
                <description>
                    <![CDATA[ Social engineering is the act of manipulating someone into divulging information or doing something that's not usually in their best interest. In this article, we will look at a few common ways Social Engineers try to manipulate you. Disclaimer: My ... ]]>
                </description>
                <link>https://www.freecodecamp.org/news/social-engineering-the-art-of-hacking-humans/</link>
                <guid isPermaLink="false">66d0361eba54db009200dc91</guid>
                
                    <category>
                        <![CDATA[ cybersecurity ]]>
                    </category>
                
                    <category>
                        <![CDATA[ information security ]]>
                    </category>
                
                    <category>
                        <![CDATA[ #infosec ]]>
                    </category>
                
                    <category>
                        <![CDATA[ social engineering ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ Manish Shivanandhan ]]>
                </dc:creator>
                <pubDate>Mon, 28 Sep 2020 19:16:11 +0000</pubDate>
                <media:content url="https://www.freecodecamp.org/news/content/images/2020/09/wall-2.jpeg" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>Social engineering is the act of manipulating someone into divulging information or doing something that's not usually in their best interest. In this article, we will look at a few common ways Social Engineers try to manipulate you.</p>
<blockquote>
<p><em>Disclaimer: My articles are purely educational. If you read them and cause damage to someone, that's on you. I don't encourage any malicious activity or black hat practices. <a target="_blank" href="https://www.sans.org/security-resources/ethics">Read the code of ethics here</a>.</em></p>
</blockquote>
<p>One common type of scam is the <a target="_blank" href="https://en.wikipedia.org/wiki/Spanish_Prisoner">Spanish Prisoner</a>, which dates back to the 18th century and has lots of modern incarnations. </p>
<p>It usually involves someone who's in trouble and needs your help to access their fortune. You just need to wire a few thousand dollars, then they'll pay you back ten times over. But you can guess how that ends.</p>
<p>There are similar scams that have circulated the internet: The IRS scam, Lottery scams, and so on. These are broadly classified as <a target="_blank" href="https://en.wikipedia.org/wiki/Advance-fee_scam">Advance offer scams</a>. You have something waiting for you but you have to pay an advance to receive it.</p>
<p>To the average person, these will seem like poorly executed scam attacks. But these scams have caused thousands of people to lose their hard-earned money. In some cases, <a target="_blank" href="https://www.youtube.com/watch?v=_1sRz6CHPFs&amp;ab_channel=NEWSCENTERMaine">their life savings</a>.</p>
<p>These are all examples of social engineering in action.</p>
<p>The idea behind social engineering is to take advantage of a potential victim’s natural tendencies and emotional reactions. Fear and greed are the most vulnerable emotions that are usually taken advantage of by Social Engineers. </p>
<p>Below is a great example of a real-world Social engineering attack.</p>
<div class="embed-wrapper">
        <iframe width="560" height="315" src="https://www.youtube.com/embed/fHhNWAKw0bY" style="aspect-ratio: 16 / 9; width: 100%; height: auto;" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen="" loading="lazy"></iframe></div>
<h2 id="heading-types-of-social-engineering-attacks">Types of Social Engineering Attacks</h2>
<p>Social engineering can be broadly classified into five types of attacks based on the type of approach used to manipulate a target. Let's go through each one of them.</p>
<h3 id="heading-spamming-email-text-whatsapp">Spamming (Email, Text, Whatsapp)</h3>
<p>Spamming involves sending messages to large groups of people whose contact info is usually obtained through nefarious methods. Spamming is a general term used to define both malicious and non-malicious message broadcasting.</p>
<p>Non-malicious spamming is used by advertisers who try to promote their products to random strangers by emailing them in bulk. Their motive is not to cause damage, but to try and get people to buy their products or promote their services.</p>
<p>Malicious spamming includes messages that try to lure users to the attacker’s website to divulge personal information. This information is then used to craft targeted phishing/vishing attacks on the potential victim.</p>
<h3 id="heading-phishing-and-vishing">Phishing (and Vishing)</h3>
<p>When the attacker uses text messaging, email, or voice calling (voice phishing = vishing), it is called Phishing. </p>
<p>Phishing is used to make the target believe they are being called by a legitimate institution or an entity in order to extract valuable information from the target.</p>
<p>If someone calls your company pretending to be your printer supplier, they might be able to gain specific information about the printer — the model, IP address (if connected to the internet), and so on. </p>
<p>And once this information is given, the printer might be attacked in order to gain access to your internal network.</p>
<p>Email-based phishing attacks are also common. An attacker can email someone in your company pretending to be Facebook. Once a team member clicks a link, they will end up on a page that looks like Facebook, asking them for their login information. This login information will be sent to the attacker’s server after which they have complete access to the victim’s Facebook account.</p>
<p>The major difference between Phishing and Scamming is that phishing attacks are highly targeted. The attacker knows whom they want to attack and what type of information they are looking for.</p>
<h3 id="heading-baiting">Baiting</h3>
<p>Baiting involves designing a trap and waiting for the potential victim to walk into the trap. As a simple example, if an attacker drops a few USB drives in your company’s parking lot, chances are, one of your employees will try and plug it into their computer to check the contents of the USB drive.</p>
<p>This might sound silly but there have been numerous instances where simple tricks by Social Engineers have resulted in massive corporate data breaches. It is usually easy to bait people with scams such as the Advance offer scams that are still circulating the internet, feeding on gullible people.</p>
<p>Another common type of baiting is found in pirated software. The attacker will embed malicious software within a popular operating system or a movie for the victim to download. Once the victim downloads and runs the software, the malicious code executes on the victim’s system, and the attacker gains full access to the victim’s machine.</p>
<h3 id="heading-piggybacking">PiggyBacking</h3>
<p>PiggyBacking means using someone else to attack a potential victim. The attacker will use a third-party (usually innocent) who has access to the victim in order to carry out a piggybacking attack.</p>
<p>There are many variations of Piggybacking. If an attacker follows your employee to your office using their access card, this is one form of piggybacking called tailgating.</p>
<p>There have been many cases of piggybacking attacks, especially for classified information. Vendor companies that supply hardware/software to government organizations are usually the target of piggybacking attacks.</p>
<p>Once these vendors are compromised, it is easy to attack the target institution since the vendor already has a level of access to the target.</p>
<p>Piggybacking is also associated with some forms of <a target="_blank" href="https://whatis.techtarget.com/definition/wiretapping">active Wiretapping</a>. The attacker will use a legitimate connection of the victim in order to eavesdrop on the network.</p>
<p><a target="_blank" href="https://medium.com/manishmshiva/wireshark-a-walkthrough-of-the-best-packet-analyzer-in-the-world-9af0358ed9a1">I recently wrote an article on Wireshark which you might find interesting.</a></p>
<h3 id="heading-water-holing">Water Holing</h3>
<p>Water Holing takes into account the routine actions of the target and using one of those actions to gain unauthorized access. For example, an attacker will find the websites that the target uses on a daily basis and tries to install malware on one of those websites.</p>
<p>The name “Water Holing” is derived from the fact that predators in the wild often wait for their prey near their common watering holes.</p>
<p>An example is the 2019 <a target="_blank" href="https://www.techrepublic.com/article/holy-water-watering-hole-attack-targets-visitors-of-certain-websites-with-malware/">Holy Water Campaign,</a> which targeted Asian religious and charity groups. The website was compromised after which the visitors were asked to install Adobe Flash on their browsers.</p>
<p>Since Adobe Flash has a number of vulnerabilities, it was easy for the attackers to then execute malicious code on the victim’s machines. Watering hole attacks are uncommon but they pose a considerable threat since they are very difficult to detect.</p>
<h2 id="heading-protecting-yourself-from-social-engineering">Protecting Yourself From Social Engineering</h2>
<p>Now that we have seen the different types of approaches used by social engineers, let's look at how we can protect ourselves and our organization from social engineering attacks.</p>
<h3 id="heading-install-email-amp-spam-filters">Install email &amp; spam filters</h3>
<p>Though spam filters cannot catch highly targeted attacks, they will prevent most of the spam and malicious emails from reaching your account.</p>
<h3 id="heading-keep-antivirus-and-firewall-updated">Keep Antivirus and firewall updated</h3>
<p>Similar to spam filters, an updated antivirus software will protect against most of the common <a target="_blank" href="https://medium.com/manishmshiva/penetration-testing-100-terms-you-need-to-know-a723c38cd8c8">viruses, trojans, and malware</a>.</p>
<h3 id="heading-ask-for-verification">Ask for verification</h3>
<p>Always ask for verification when someone calls you claiming to represent an organization, for example your bank. Never share confidential details such as credit card numbers or passwords over phone or email.</p>
<h3 id="heading-create-awareness">Create awareness</h3>
<p>The best way to prevent your organization from getting exploited is to create security awareness programs. Educating your employees is a great long-term investment to keep your company secure.</p>
<h3 id="heading-if-it-seems-too-good-to-be-true-it-is">If it seems too good to be true, it is</h3>
<p>Finally, if something sounds too good to be true, it usually is. Never trust strangers promising to get you rich quick. As someone once said, “trying to get rich quick is the quickest way to lose all your money”.</p>
<h2 id="heading-conclusion">Conclusion</h2>
<p>Social Engineers are masters of manipulation. Unless a company’s employees are trained in social engineering awareness, it is very hard for them to avoid falling into a social engineer’s trap.</p>
<p>Social engineers work with people’s emotions, usually fear and greed. So whenever you are performing an action based on these two emotions, you might want to take a step back and see if you are being manipulated.</p>
<p>There is a famous TED talk where someone started a conversation with a spammer. <a target="_blank" href="https://www.youtube.com/watch?v=LiLS7U7YIdc&amp;ab_channel=EisseCatherineWade">Watch the full video here</a>.</p>
<p><a target="_blank" href="https://tinyletter.com/manishmshiva"><strong><em>You can get a summary of my articles</em></strong></a> <em>and videos sent to your email every Monday morning. You can also</em> <a target="_blank" href="https://www.manishmshiva.com/"><strong><em>learn more about me</em></strong></a> <em>here.</em></p>
 ]]>
                </content:encoded>
            </item>
        
            <item>
                <title>
                    <![CDATA[ How I Hacked DEF CON ]]>
                </title>
                <description>
                    <![CDATA[ By Amanda Mork Started in 1992 by the Dark Tangent, DEF CON is the world’s longest running and largest underground hacking conference. It’s held yearly in Las Vegas, Nevada every July. The security industry is a $100B market. As the database of our ... ]]>
                </description>
                <link>https://www.freecodecamp.org/news/how-i-hacked-def-con-c5bf718bb9d8/</link>
                <guid isPermaLink="false">66c34dc893db2451bd441491</guid>
                
                    <category>
                        <![CDATA[ cybersecurity ]]>
                    </category>
                
                    <category>
                        <![CDATA[ defcon ]]>
                    </category>
                
                    <category>
                        <![CDATA[ hacking ]]>
                    </category>
                
                    <category>
                        <![CDATA[ short-story ]]>
                    </category>
                
                    <category>
                        <![CDATA[ social engineering ]]>
                    </category>
                
                <dc:creator>
                    <![CDATA[ freeCodeCamp ]]>
                </dc:creator>
                <pubDate>Mon, 31 Jul 2017 22:56:29 +0000</pubDate>
                <media:content url="https://cdn-media-1.freecodecamp.org/images/1*lGjLtP7MORPjQEZyT3udOA.png" medium="image" />
                <content:encoded>
                    <![CDATA[ <p>By Amanda Mork</p>
<p>Started in 1992 by the Dark Tangent, <a target="_blank" href="https://www.defcon.org/">DEF CON</a> is the world’s longest running and largest underground hacking conference. It’s held yearly in Las Vegas, Nevada every July.</p>
<p><img src="https://cdn-media-1.freecodecamp.org/images/L54CYS8Ua9sYFa84C0ss2xBAxsPP6n2ge4he" alt="Image" width="400" height="276" loading="lazy"></p>
<p>The security industry is a $100B market. As the database of our entire world’s information goes online, software is the the fabric that connects it all. However, where there is software there are vulnerabilities.</p>
<p>In addition, where there are people, there are vulnerabilities. This is where I come in. I’m not a ‘hacker’, or an engineer, sys admin, or programmer. I am in <a target="_blank" href="https://www.contramore.com/">communications</a>. I’m a translator, a chameleon, and an advocate for people, projects and products that I feel are doing things differently.</p>
<p>I decided to go to DEF CON for the first time this year to put myself “in the room” and get a sense of the community, the people and their nuanced archetypes.</p>
<h3 id="heading-i-wanted-to-hack-the-hackers-all-it-took-was-one-65-golf-shirt-from-the-caesars-gift-shop-and-i-navigated-the-entire-conference-for-free">I wanted to hack the hackers. All it took was one $65 golf shirt from the Caesars’ Gift Shop and I navigated the entire conference for free.</h3>
<p>Here’s how I did it:</p>
<ol>
<li>Walked the perimeter to locate the entry and exit points</li>
</ol>
<p>Thursday evening when I arrived, I scoped out Caesars. I walked in, located the conference registration, ran into a few friends and walked around to get the lay of the land. I saw where the big talks were going to be held, mapped out all the elevators, escalators and exits for rooms and hallways. Then, it was time to test my theory: could I walk around the entire conference without a badge?</p>
<p>As I was walking into one of the main elevator rooms I was asked once by a Caesars employee, “excuse me, ma’am, where is your badge?” I replied quickly and softly, “Oh, yes, so sorry. I’m looking for the information booth, it’s this way right?” She nodded, and I continued right past and into a different talk. I always like knowing how to quickly escape if needed.</p>
<ol start="2">
<li>First penetration test: asking for the conference program book</li>
</ol>
<p>Thursday evening, I walked over to registration and told the lovely staff that I had misplaced the schedule book, could they give me another one? “Yes, no problem!” a volunteer mentioned as they handed one over to me. Great, now I have the schedule and an idea of how strict they are on badges, as well as how well-trained the volunteer staff was.</p>
<p>I always look for the elevators at hotel conferences since it’s always faster than taking the stairs or escalators. On the first day I walked right past registration and took the elevators up to the talks. It was low key, not many talks, so no hassle.</p>
<ol start="3">
<li>Camouflage</li>
</ol>
<p><img src="https://cdn-media-1.freecodecamp.org/images/1Crl2GrC4gPaZiP8SuGYt1Pi3CGmu1-vzdpO" alt="Image" width="500" height="333" loading="lazy"></p>
<p>I was in need of a fresh shirt after my flight into Vegas and didn’t have time to check into my room at the Flamingo. Trying to find my way around DEF CON, I walked past the Caesars gift store. There it was…. the perfect shirt. A black v-neck Caesars golf shirt. It was professional enough to look official, but casual enough to make me look like a mid level employee. I purchased the shirt for $65, and combined with my black pants and dress shoes the look was complete.</p>
<p>The Caesars shirt was the perfect balance. It was enough to override the DEF CON “goons” since I assumed they were instructed to not mess with hotel staff. It was also perfect to pass by the Caesar’s staff since they were there to focus on maintaining order for the DEF CON attendees, not the hundreds of random Caesars staff members.</p>
<p><img src="https://cdn-media-1.freecodecamp.org/images/LDy3i7VQF6srZVBHNvu5rb-U1w5yKixkbvwK" alt="Image" width="800" height="1064" loading="lazy">
<em>The Caesars’ golf shirt.</em></p>
<ol start="4">
<li>Walking with conviction</li>
</ol>
<p>Wherever I went around the conference center, I walked confidently and with purpose at all times. Not too fast as if I were being chased, but not too slow to as if I was lost (even when I was), just enough to show that I had conviction. I wore a grey baseball hat and made a point not to make a lot of eye contact with attendees or look up to read names of rooms, I simply looked forward and continued on my mission. I also looked at my cat watch a lot.</p>
<p><img src="https://cdn-media-1.freecodecamp.org/images/Dr6XTuNgyAuKgRcf4gihKx-IHmj-1EUuS36F" alt="Image" width="800" height="1066" loading="lazy">
<em>Cat watch. This can also be used as a metro pass in Hong Kong.</em></p>
<ol start="5">
<li>Avoiding linecon</li>
</ol>
<p><img src="https://cdn-media-1.freecodecamp.org/images/IIO2Qcbj46jOrxinran7vw7LbGeJs7ODgFwF" alt="Image" width="800" height="600" loading="lazy">
<em>Talk on hacking digital voting booths.</em></p>
<p>Whenever I wanted to go see a talk, I would always locate additional doors to the room. I didn’t wait in a single line for the whole event. Instead I waited for the lines to start moving and joined at the right moment, waited 10 minutes for the talk to start, or simply waited for someone to leave the room after the event started and asked them to hold the door for me.</p>
<ol start="6">
<li>Hacking the Social Engineering Room</li>
</ol>
<p>By Friday afternoon at 12:30 pm I had seamlessly enjoyed the morning talks and successfully walked around the conference for 4 hours completely undetected. I wanted to up the ante, so I figured I’d give the Social Engineering room a run for their money.</p>
<p>I snuck in the back door, past the line of course, and right into the back of the room. Attendees didn’t give me a second glance since I still looked like hotel staff. I walked in as they were doing a Q&amp;A with the audience after someone just made a phone call in the soundproof room on stage.</p>
<p>Right as the Q&amp;A with the audience was dwindling down… I saw my entrance. I made my way up the side of the room, standing with attention, and glancing diligently at my watch to give the impression of impatience. Then, I took my chance.</p>
<p>I walked right up to the stage technicians who were running the stage, bent down to their table and calmly said…</p>
<p><em>Me: “Hey guys, I just wanted to let you know that we are having a problem with the air conditioning in this room and we are going to have to evacuate the room as soon as possible.”</em></p>
<p><em>Technician 1: Looking slightly confused said calmly, “well ok, sure, we are just about to end for a lunch break. Do you think your team can wait 15 minutes?”</em></p>
<p><em>Me: “Well, you know, this is a union house so we really have to have everything super on time or else your conference will incur additional charges… but let me see what I can do. You said you break in 5–10 minutes?”</em></p>
<p><em>Technician 2: Looking a little suspicious, “Yes. Ok, so you need to evacuate the whole room? Can some of our staff remain in here?”</em></p>
<p><em>Me: “Yes sure that should be fine, but we really need to move quickly and evacuate everyone else in five minutes on the dot.”</em></p>
<p><em>Technician 1: “Got it, one second. Let me pull in someone quickly.”</em></p>
<p><em>Me: Seeing that they were pulling in the main organizers for the Social Engineering room… extended my hand to the organizer and said, “Hi, my name is Amanda. I don’t work for Caesars. I wanted to see if I could hack the conference and the social engineers!”</em></p>
<p><em>Event Organizer: She laughed, she loved it. “Yes! This is great. You nailed it.”</em></p>
<p><em>Technician 2: “We had a feeling you might be pulling one on us. But good work, If anyone gives you any problems, just tell them you are with us.”</em></p>
<p>I smiled, gave her my card and walked out. Mission accomplished.</p>
<p>This entire experience had me thinking. Social engineering is a form of security, but like ‘hacking” it sometimes gets a bad reputation. Let’s think about what applications these techniques can be used for beyond DEF CON.</p>
<p>Social engineering can be used for many things, not just hacking into events, but for many situations in life, even getting out of dangerous real-world situations.</p>
<p>Of course, there was an element of luck in this whole strategy since this was the first year the conference was held at Caesars. This means there is a learning curve for the hotel staff and the DEF CON volunteers.</p>
<p>When it comes to hacking, it’s better to be lucky than good.</p>
 ]]>
                </content:encoded>
            </item>
        
    </channel>
</rss>
