Social Engineering
Social engineering is a mostly non-technical technique for manipulating people to perform actions and/or obtain information from the target. In the realm of hacking, this usually involves a user revealing their login credentials or installing software allowing the attacker in, or even making changes to financial systems for the attacker’s gain.
Your first thought might be, why would someone do that, or how were they able to convince a user to perform the operations to allow the attackers in? This is part of what we will explore here, as well as how defenders might detect social engineering attacks and educate users on what to look for. In this chapter, we will discuss the fundamental ideas of social engineering, including the techniques and tools social engineers employ to manipulate people. You will learn how various social engineering strategies operate, about insider threats, how an attacker assumes another person’s identity on social networking...