Wednesday, June 6, 2007
Search Site:
Home | About Us | Subscribe | Contact Us | Archives | Feedback | DH Avenues
News
National
State
District
City
Business
Foreign
Sports
Comments
Edit Page
Panorama
Net Mail
Your Take
Infoline
In City Today
HelpLine
Daily Almanac
Festivals of India
Weather
Leisure
Crossword
Horoscope
Year 2007
Weekly
Daily Astrospeak
Calendar 2007
Pearls of Wisdom
"Only when we are no longer afraid do we begin to live."
- Dorothy Thompson
Supplements
Economy & Business
Metro Life - Mon
DH Avenues
Cyber Space
Metro Life - Thurs
DH Education
Studying Abroad
Studying In India
Metro Life - Fri
Open Sesame
Metro Life - Sat
Living
DH Realty
Fine Art / Culture
Articulations
Entertainment
Science & Technology
Spectrum
Sportscene
She
Sunday Herald
Reviews
Book Reviews
Movie Reviews
Art Reviews
Columns
Kuldip Nayar
Khushwant Singh
N J Nanporia
Tavleen Singh
Swami Sukhabodhananda
Bittu Sehgal
Suresh Menon
Shreekumar Varma
Movie Guide
Ad Links
Deccan
International School
Real Estate Properties in Bangalore
Deccan Herald
Now Available
Globally
in Print Format
Others
About Us
Subscription

Send your Suggestions / Queries about the Website to the
Webmaster


To send letters to Editor :
Letters to Editor

You are welcome to post your letters/responses to NETMAIL here.

For enquiries on advertisements :
Contact Us

Deccan Herald » Cyber Space » Detailed Story
Social engineering: Tinkering with the human psyche
Social Engineering is the , says Ravichandra M.

Social Engineering is not a new branch offered by Visvewaraiah Technological University (VTU).
It is the technique of exploiting the most vulnerable link in your organisation’s computer network, i.e. humans.

Scenario 1:
Assume that you are working for an IT giant and all of a sudden a disaster similar to September 9/11 strikes.
Your company plans to reduce the  work force by detaining some employees.

The curiosity to know who have been short listed to be fired naturally spurts among employees isn’t it.
 Such a situation is ideally suited for the social engineering attack, where the hacker leaves a DVD /CD labeled “companies’ new policy” on the cubicles of different employees.

Employees curious to know about the organisation’s new policy might use the media in their PC and thus make way for malware to enter the organisation’s network. Such an attack is referred to as Gimmes/Trojan Horse attack

Scenario 2:
One fine morning the helpdesk of your organisation receives a call asking them to connect to the accountant.
 As soon as phone is transferred to the accountant:

Intruder: “Hi, Topiwala, Today isn’t a great day for you?

Accountant: It’s fine, I have no problems

Intruder: Don’t you know that your PC is malfunctioning

Accountant: No, it’s absolutely fine

Intruder: No, from the server room we are able to trace certain problems in your system, please logout and login again
(Accountant routinely follows the instruction given logs off and login without finding any bugs)

Intruder: De-fragment your system and switch off and switch on. (Accountant blindly follows the instruction given by the intruder auspiciously)

After making the accountant to carry out a series of operations, the Intruder asks for the login ID and password of the accountant in order to remotely login to the system.

The accountant carelessly hands over the password!

This is creative /inventive form of attack known as pretexting.

Scenario 3:
Quid pro Quo attack (something for something attack)

The famous AOL attack is a classical example for this form of attack.
A hacker started chatting with the technical support of AOL  and during the conversation, revealed that he had a car for sale at a throwaway price.

When technical support expressed interest in the offer, the hacker sent him an attachment containing pictures of car. As soon as technical support opened the attachments, malware running as a background process took entry into AOL’s network.

According to wikipedia in one of the surveys, more than 90 per cent of office workers gave away their passwords in exchange for a cheap pen!
Scenario 4:
Online attack, or phishing as it is popularly known is also one of the social engineering attacks.

Here hackers send links of a bank or financial institutions which contains the  logo and format of a legitimate bank and asks for credentials of the customer for some kind of verification.

Since the look and feel of the website appears legitimate, customers tend to give away their personal information to a fake site.

comment on this article
Other Headlines
Take charge of your computers
Social engineering: Tinkering with the human psyche
IT BYTES
E Utilities
Ad Links
Flowers to India , Gifts to India
Your Life Partner? Get personalized proposals daily. Thousands of New members with Photo Profiles. Profession,Religion, Community searches & more. Register FREE!
Gifts to India, Flowers to India, Gifts to India, Bangalore, Gifts to India, Mumbai, Delhi, Rakhi
Gifts to India , Flowers to Bangalore India
No minimum balance NRI account
India Flowers - Dehradun Hyderabad Kolkata Gurgaon Punjab
Flowers to India Flowers Gifts Delhi Bangalore Mumbai Chennai
Flowers to Bangalore, Chennai, Hyderabad, Delhi, Mumbai, Pune Kolkata.
Send Flowers, Cakes, Chocolate, Fruits to Pune.
Flowers to India , France , Japan, Germany, Hong Kong, Singapore, Mexico, USA
Flowers to India , Mumbai , Pune, Delhi, Chennai,
click here
Copyright 2007, The Printers (Mysore) Private Ltd., 75, M.G. Road, Post Box No 5331, Bangalore - 560001
Tel: +91 (80) 25880000 Fax No. +91 (80) 25880523
200x200
Gender:MaleFemale

Email:

click here
click here
click here