Social Engineering

by

AbdElraouf Sabri (@abd3lraouf)

Who am I?

who s who

Android Developer & penTester

Objectives

  1. What does social engineering mean?

  2. Attack vectors

  3. Demo

  4. How to stop it

What is Social Engineering?

You could spend a fortune purchasing technology and services, and your network infrastructure could still remain vulnerable to old-fashioned manipulation.
— Kevin Mitnick

Social Engineering

The hacking of humans by manipulation, deception to gain access to an important info.

Sociology and Psychology

  • Human action can be predicted

  • Actions can be influenced quite easily

Simple Human Behaviour

Two types of responses: Natural vs Learned

Hackers will craft a scenario for you to enter, in order to elicit a secret you tried hard to keep it.

phone hacking

Attack vectors

Common attack methods

  1. Pretexting

  2. Phishing

  3. Baiting

  4. Quid Pro Quo

Pretexting

pretexting

What happens

  • Fraudulent phone calls

  • Used to extract information

  • Also used to setup other attacks such as facility entry or phishing

Phishing

phishing

What happens

Attempts to get users to provide information or perform an action

Baiting

baiting

Quid Pro Quo

give and take

Demo

Anti social engineering

Think before you click

  • Attackers employ a sense of urgency

  • Make you act first and think later

  • Remember: Better be safe than sorry

Research the sources

  • Check domains

  • Typos?

  • Link hover!

Sample : Click here to join our group Facebook.com

Download now & Prize

  • Don’t download files you don’t know

    • Always check files (hashes md5 sha1 etc..)

  • Offers and prizes are fake

Five Ways to Protect Yourself

  1. Delete any request for personal information or passwords

  2. Reject requests for help or offers of help.

  3. Set your spam filters to high.

  4. Secure your devices.

  5. Always be mindful of risks.