Ace of Spoofing III
You’ve invented a new spoofing attack.
Threat |
|
An attacker may try to trick customer support into giving them the password or sending them a link to reset the password; this is a social engineering attack called vishing (short for voice phishing). The attacker could also make use of data gathered from social media and the dark web to respond to questions from the operator. This information gathering is called Open Source Intelligence (OSINT). |
|
CAPEC |
CAPEC-656: Voice Phishing CAPEC-98: Phishing |
ASVS |
2.2.4 Ensure there is some protection against impersonation, such as asking the user for a one-time password or some other authentication factor |
CWE |
CWE does not currently cover social engineering... |