|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Social engineering 101 By Staff writers, ZDNet Australia November 15, 2004 URL: http://www.zdnet.com.au/insight/security/soa/Social-engineering-101/0,139023764,139166670,00.htm
Online encyclopedia Webopedia defines social engineering as "the act of obtaining or attempting to obtain otherwise secure data by conning an individual into revealing secure information." Sophisticated social engineers take advantage of security vulnerabilities in human nature, and not software, in order to penetrate otherwise well-protected networks. Social engineers use a variety of methods to achieve their goals. Many use flattery; a common line being "you're the only one smart enough to do this for me, please run the attachment I'm about to send you". There are also some easy rules and policies that can help. Almost all the time a social engineer will refuse to give a call-back number. "They'll come up with an excuse ... like 'my mobile phone battery is dying'," says security consultant Kevin Mitnick. By putting in a policy that states if "someone is making a request of a sensitive nature -- and you don't personally know this person -- then you have to call them back", around seven out of 10 social engineering attacks will be foiled. "The key is to train staff to determine what is a legitimate and what is an illegitimate request," says Mitnick. In this special round-up, ZDNet Australia  presents essential reading for any security and/or IT professional, providing comprehensive information on social engineers, the way they work and tips to guard against them.
Social engineering: Don't be fooled
Gartner: Social engineering 'greatest security risk'
Security: Fighting the enemy within
What hackers can teach you about security
Hackers: Under the hood
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |