Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Are you aware of the different methods of social engineering used by bad actors 2
today to infiltrate multiple different kinds of networks? 3
If not, well, good news is we're going to have that conversation starting right now. 4
>> You're watching ITProTv. 5
[MUSIC] 6
>> Well, welcome back to Security+ here at ITProTV, and 7
in today's episode we will be talking all about social engineering. 8
This is the art of human hacking as they say. 9
And Wes, you're going to definitely take us down the road because we think 10
social engineering, it's one of those umbrella terms in a lot of ways. 11
But there are many different ways and avenues in which this could be teased out, 12
as it were. 13
>> Definitely. >> Where do we begin when we start having 14
this conversation on social engineering? 15
>> When CompTIA puts the social engineering objectives together, 16
they put it in an area called threats, vulnerabilities and attacks. 17
So what I thought would be good is right before we dive into social engineering, 18
we look at just some basic terminology that you really have to keep in your mind 19
as we go through, really, the rest of the entire series. 20
So how about we start with some of just the basic principles, if you will? 21
>> Start at the beginning? 22
>> That's right, Dan, that sounds good. 23
So we're gonna go ahead, and what do you say we get started with a concept known as 24
the principles of security? 25
So let's dive right in and 26
we're talking about here is something known as the CIA triad. 27
You may have seen this before or maybe you're not aware of it, right? 28
And the CIA triad is really about these three principles, right? 29
It's our goals in security, 30
I've heard people say the pillars of security as well. 31
And that's confidentiality, 32
making sure that only the authorized users have access to the information. 33
Integrity, making sure that the information that they should have access 34
to stays in its own state, right? 35
It's what we expect, it hasn't been modified whether it's through transmission 36
errors or malicious means, but it stays in the state that we expect. 37
And then finally, 38
one that might be forgotten as a principal security is availability. 39
And that means that the authorized users have access to the data, 40
the data maintains its integrity, but it's also available to them when they need it. 41
So be aware of what's known as the CIA triad. 42
Now, some of the other basic terms that we have are things like vulnerabilities. 43
And a vulnerability, essentially, boil it down to just a weakness, it's a weakness. 44
And that weakness can be in things like for instance, software bugs, it could 45
be things like some of the default configurations, and we talk about later on 46
in the series here, we'll talk more about some examples of vulnerabilities. 47
But defaults, leaving the default configurations that can be checked on 48
vendors' websites and then people can gain access to whatever it might be, a piece of 49
software, a piece of network equipment, things like weak passwords, right? 50
This is going to be all examples of vulnerability, right? 51
So be aware that vulnerability is typically some kind of weakness. 52
>> Now that's not the only thing we got to be worried about, because a lot of times 53
these two terms can get a little confused, and for good reason, 54
they're very similar but there is a distinction that we need to make. 55
So you've mentioned vulnerabilities, what I'm talking about are threats. 56
Could you help us understand what the difference is there so 57
that we don't make that mistake? 58
>> Sure, absolutely. 59
When it comes to something like a threat, a threat, you'll hear it formally 60
saying any event or circumstance that violates the CIA, all right? 61
It's any condition that leaves you open to some kind of attack. 62
And you'll see that we'll talk about, in later episodes, things like threat 63
hunting, we'll talk about vulnerabilities, threats and exposure. 64
We'll talk about all of this stuff, but basically coming down to any kind of 65
circumstance, a capability or an action that could lead to causing harm, right? 66
And it's information technology, so a lot of times we say harm, 67
it's harming your business's reputation through gaining access to your data, 68
stealing your user credentials, things like that. 69
So some examples, malware, we have phishing scams where people try to gain 70
access to your sensitive information, hackers as well. 71
All different potential threats that we would need to be aware of. 72
>> Now all of these threats ultimately could make you, and 73
I think you actually used the term of an attack as well. 74
So define attack so we can make sure that when I say attack and 75
you say attack were all meaning the same thing. 76
>> Absolutely, we can do that. 77
So a vulnerability is a weakness, all right, 78
an attack is the technique that exploits the vulnerability. 79
That's essentially an attempt to expose, if you will, alter, disable, 80
destroy, steal or gain some kind of unauthorized access, right? 81
Things like network based attacks, application attacks, right? 82
Again, it's a technique that exploits a weakness or a vulnerability in a system. 83
So, definitely be aware of some of the basic terminology as we move through 84
Security+. 85
>> All right, so this has been a really good primer, right? 86
So, we've set up our idea of security as a philosophy, 87
looked at some of the underlying terminology that goes along with it, 88
as well as even an idea into the actual nuts and bolts of the things, 89
that there are attacks and vulnerabilities and things of that nature. 90
Typically very technical in nature. 91
But this is about social engineering. 92
Where does social engineering come into this arena? 93
Well, social engineering, 94
this can be something that is essentially an attack, right? 95
If you think about it, it's attacking some kind of system, and let's go ahead and 96
boil this one down. 97
Social engineering, bad people tricking authorized users, right? 98
It's usually for the purposes of trying to gain credentials, 99
sensitive information that maybe can lead people, or bad actors, if you will, 100
into having access to things that they normally shouldn't have access to. 101
So bad people tricking the authorized users. 102
Now, there are several different types of social engineering scams that we have to 103
worry about, techniques if you will. 104
And probably one of the most prevalent on the block today is something known as 105
phishing. 106
Now I will tell you there are a lot of forms of phishing and 107
it's really just slight variations on the term phishing, right? 108
Phishing is an email based scam, right? 109
This is where somebody sends you an email that says, 110
hey you need to have some kind of, I don't know, I'm trying to think here, 111
we need you to send us money for Apple Pay cards, right? 112
>> That's a popular one there. 113
>> And it's a very, very popular one, just send us four or five of those $500 Apple 114
cards, right, and we can get whatever it is that we need to get done. 115
Now there are some other ones like vishing. 116
Vishing is a form of phishing, 117
the difference is it's typically with a voice over IP system. 118
Smishing, we'll talk about that one coming up. 119
Spear fishing, we also have whaling. 120
And then finally just some of the ways that phishing scams can be successful, 121
it's typically through things like spam, as well as things that can be 122
sent through an instant messenger, I wish I was making this up, 123
but there's a spim, and that's a spam essentially of instant messaging. 124
So let's dive into these a little bit more, because I couldn't for 125
the life of me think about the Apple Pay phishing example [LAUGH]. 126
>> [LAUGH] I love when your brain goes, I'm going on a break. 127
>> That's right. 128
I don't care where you're going but I won't be there when you get there [LAUGH]. 129
>> I'll be here cooking with a smile out. 130
>> [LAUGH] That's right. 131
So you've probably seen one of these before, right? 132
This is a typical type of phishing scam where somebody sends you something that 133
looks like it's coming from an authorized or an authoritative location. 134
We just used an example of iTunes, and by the way, iTunes, it's safe, 135
we're not picking on Apple, these are just the avenues and the methods, 136
right, that they use. 137
The attack vector, if you will, being, hey, this is coming in via email, right? 138
And we're basically trying to trick you into giving us credentials 139
to your cloud based platform. 140
>> Yeah, back when I worked Helpdesk, back when dinosaurs roamed the earth, I had 141
a guy, he was getting a malware installed, my antivirus system was going crazy. 142
He said, yeah, I got this email from DHL that said I had a package ready. 143
I said, do you have a package that you're expecting from DHL? 144
He said, no. 145
>> [LAUGH] >> So 146
why would they be telling you that you have a package ready if you don't? 147
>> He said, I don't know, but I wanted to see what it was. 148
And it was just a fishing length and [CROSSTALK] You click the link, 149
it was installing malware. 150
So you might not be itunes, you might not be DHL you might not be Fedex. 151
That's the whole idea behind this. 152
Right? It's [CROSSTALK] Absolutely use it as 153
camouflage. 154
Get somebody click on. 155
That's right. 156
A lot of people don't hover over these links and 157
realize that these links don't lead to anywhere in Apple. 158
They lead to some other Gmail account or 159
some kind of just recently made yahoo account right now. 160
So when we look at vishing alright vishing is just again this is a voice over IP. 161
Type of attack right? 162
We're trying to gain information out of a voice over IP. 163
Or even by phone. 164
It could be a hoax right? 165
Somebody calling you on the phone saying hey and 166
unfortunately this does happen saying hey your relative just got in an accident 167
there sitting in the emergency room. 168
They need 1200 bucks to be able to take care of them, right? 169
They play on the urgency, they play on your heart, pull your heart strings and 170
try to get money out of you that way. 171
We talked about smashing, right, skirmishing again. 172
Think of SmS. 173
It's a phishing scam, but it's through SMS text messages, right? 174
In fact, one of our entertainers about a couple weeks back received a text message 175
from the United States Postal Service saying there was something wrong with 176
the shipment and they needed to contact or get some contact information and 177
click the link. 178
The United States Postal Service is not gonna be emailing or texting you 179
personally to let you know that they've done something wrong with your package or 180
something that's happening. 181
So that should be a clear indicator that it might seem urgent. 182
You might trust it the authority over it, but it's not valid. 183
>> I mean, the United States Postal Service is a hard time just getting you 184
your package. 185
>> [LAUGH] >> They're not going out of their 186
way to text you personally, you know, something's ready. 187
>> Yeah, sure. 188
And you know, it goes back to the end user that you were supporting dan, you know, 189
they just don't know that's why users on awareness is one of the very 190
first methods and layer of defense. 191
I know dan's done some security user awareness training here, I know helped set 192
that up and we do it here to make people aware that this is a very real threat and 193
it's a very real attack vector that you need to be aware of. 194
Now, spearfishing, you're going to notice something that looks the same, right? 195
It's a phishing scam. 196
But now who we're going after is a little bit different in a phishing scam, 197
it's spam, it's just blanket. 198
We're just gonna throw a big old net out there. 199
I think I got that, I'm gonna steal dance term here, 200
throw that net out there as wide as you can. 201
Just get as many people as you can. 202
All right, spear phishing attack is a little bit different because now it's 203
a targeted attack. 204
Now we know that dan works for X, y, Z company and he's the admin and we also 205
see some other people here that are having to log into the specific portal and 206
we know they work for this company. 207
So we're gonna set just the people within that company, 208
a bunch of these type of phishing attacks and again, it's a targeted attack. 209
It's really the only thing they're going after that specific company instead of 210
just saying, hey, whatever I get his grades, I like them. 211
I think they got some money or they gotta something I'm going to go after. 212
Absolutely target the most, definitely not just blanketing the entire email 213
infrastructure, but an actual attack against a specific company. 214
Now you're gonna notice whaling here? 215
Well, that's a boy. 216
We're getting a lot of re use out of this phishing email here because the difference 217
between this, it's still a phishing scam. 218
But now what you're doing is you are targeting the big fish. 219
Hence the term whaling. 220
We're looking for the people that most or probably have some of the higher level 221
of authority within their company and we're going after them. 222
So for instance, somebody doing an attack that a phishing attack that here at I 223
t pro TV, that's maybe targeting things like for instance, 224
maybe Tim broom our owner or don possessed right? 225
Our co founder, right? 226
The higher ups in the organization because they have a potential to have access to 227
maybe more than the average user, right? 228
Imagine getting access to as ceos inbox, right? 229
You're going to have probably a plethora, 230
I just want to be able to say platform, great information as a hacker. 231
You see this a lot with business email compromise or B E C. 232
They go after the whales because they do have that authority and access. 233
Now if I can take over their account or maybe impersonate them in some way, 234
shape or form that I can say, hey, transfer some funds to such and such and 235
whomever just goes, it's the boss. 236
Just do it. 237
Yeah. And there You go. 238
Yeah. And you know, 239
we're mentioning some of these terms they call that. 240
Is that the principles for success? 241
Right? Why are these phishing scams 242
success successful? 243
Well, there's urgency. 244
You gotta do it now. 245
They're scarcity 30 seconds before it times out and 246
you're never gonna have access to it again. 247
I don't know if I mentioned authority coming from somebody that looks like 248
the ceo, man. 249
You know what tim's telling me, I need to send him my some information or 250
credit card number because he needs to buy something. 251
Well, that's authority, Right? 252
That's trust. 253
Right? And 254
that's one of the reasons, one of quite a few reasons really 255
that these social engineering attacks are are successful. 256
>> Let's move on to some other types of techniques that we might see when it 257
comes to using social engines. 258
Sure. 259
So we did mention there was a couple more and you ladies and gentlemen out there, 260
you're smart crowd, you've seen this probably if even if you haven't been in I. 261
T. You've probably opened email once or 262
twice and you've seen the span. 263
So we're not gonna harp on that one too much. 264
But understand that in a phishing attack where they're blanketing everybody, 265
they're casting the net spam is typically going to be the way that they're going 266
to do that. 267
And again remember spam and spam. 268
Right. One is just gonna be a flooding of emails, 269
the other one's just gonna be a flooding of sMS messages, right? 270
You know, just to try to again scrape some of that, that very important information. 271
But what about farming? 272
This this seems to have gone up in populated here in the recent past and 273
explain a little bit about farming. 274
Sure farming is typically there's gonna be some kind of manipulation of the DNS 275
infrastructure and we'll talk about DNS a little bit later. 276
Just bear, just real basically remember what DNS does I type in a name, www. 277
My website dot com and it goes over to the internet. 278
DNS resolves it to an I. 279
P. Address and my browser connection. 280
That's all I have to do. 281
If I can put a bad response. 282
Let me show you what I mean here. 283
If I can put a bad response in that with that DNS request and I can tell you that. 284
Yeah my website goes to and it's a malicious I. 285
P. 286
Then what we can do is we can tell all of the people for 287
instance that are logging into this web site. 288
They think they're logging into my bank dot net. 289
Right. Some kind of banking application, 290
they're actually being redirected to a malicious website that may be spoofed it. 291
And what they're doing is they're farming. 292
If you can see it's kind of like bringing everybody in to try to gain all of 293
their gain, a whole bunch of just sensitive information from them. 294
Watering hole attacks and another one that has come up quite recently, actually very, 295
very popular. 296
If you can pull it off, it's very devastating. 297
Sure. 298
So, you know, the waterhole attack again, when we talk about farming, right? 299
One of the things that you might do in a farming attack, as you might find out by, 300
hey, where's everybody going? 301
If I can spoof one website, what should I spoof? 302
Well, let's look at where all the employees are going. 303
That's where, where they're all coming to. 304
And if we can make, you know, exploit some vulnerability in that web application 305
then, since everybody's going there, take of a watering hole, right? 306
Think about the watering hole attack, 307
where they always think of the Nile crocs, right? 308
Everybody all the wildebeest, they're all coming down to one location. 309
Well why are the Nile crocs there? 310
They know everybody is going to have to come down and get a drink and 311
when they mount an attack, it's going to be successful. 312
And for them it's gonna be lunch for our Attackers. 313
It means that they're gonna probably do something like maybe even credential 314
harvesting, where they're gonna get all of this information, 315
start out with a waterhole watering hole attack, bring everybody in and 316
as everybody starts logging into what they think is the legitimate website. 317
It's actually a malicious website and they're storing all those credentials may 318
be to sell them later on the dark web, and make some money on them dan you, 319
I think you were telling me that that's become quite a trend. 320
Almost like hacking as a service where hey, if I can get in and 321
get these large pools of credentials, we go out to the dark web and we can just 322
sell the credentials and make money and I don't even have to attack anything. 323
>> Yeah. Hey, if you get people want something, 324
there's gonna be a supply and demand kind of thing going on and 325
people will be able to make a little bit of money off that now that being said. 326
There are some really tricky mechanisms that are being used by these threat actors 327
to pull off these social engineering. 328
Because we all know you look at links, you verify that email, 329
are their U R L address. 330
Should I say before you click on those links and 331
if you click on them at all right, that might not be a good idea. 332
How do they get away with clicking or making it look legitimate for an end user? 333
>> Well, one of the ways I think of Don here is something that you've probably 334
seen and maybe even done if you type like me. 335
And as you follow us along through this series, you'll see how bad I type and 336
that's something known as typo squatting. 337
If you've ever typed maybe something like this where 338
you typed google quite a little bit off. 339
Well, google's got really good at a lot of the major websites that you go 340
to have got a really good about buying these names as well. 341
But earlier on there was no guarantee that when you typed 342
something like google with too many os that it would take you and 343
redirect you to an actual legitimate google site. 344
It could redirect you to somebody's malicious website where they can do for 345
whatever nefarious purpose they're doing. 346
But they could maybe do drive by, download and get some malicious code on your 347
network or on your devices and maybe your network by association. 348
So type of squatting is exactly what it sounds like, it's a little, 349
spelling errors on the U R L. 350
Also U R L squatting if you will to that leads you to a malicious site when you 351
think you were gonna supposed to go to some legitimate website. 352
>> Awesome, now, I know you've got a few other techniques for us really quickly, 353
like physical >> Sure 354
>> Of social engineering techniques. 355
What were they? 356
>> Absolutely, so I know we're running a little bit short on time here. 357
So let's just talk about some of the physical techniques that he Don 358
mentioning here. 359
I mentioned or I think about things like dumpster diving, 360
you have to be in the physical area. 361
We think of those desk calendars, any calendar gets thrown away, 362
little post it notes that end up in the dumpster people go through and 363
they can actually scrape that information. 364
And maybe maybe gain things like P Ii or 365
use that information to attack your network. 366
Other things are shoulder surfing, 367
shoulder surfing is exactly what it sounds like. 368
Looking over your shoulder maybe to try to glean what you're typing into, whatever it 369
is that you're working on, whatever application it is that you're working on. 370
Tailgating or piggyback attack is where you have one authorized person that 371
authenticates and two people make their way through the entry. 372
That's where we have, you probably see things like man traps and 373
turnstiles right? 374
Where it rotates and locks and 375
the next person's gotta authenticate that it rotates again. 376
Well that's a way to prevent these tailgating attacks. 377
So tailgating attacks again are just those attacks where one authentication, 378
two people are making their way through, usually an unauthorized user. 379
And then pretexting, pretexting is one of these things where it's more of a, hey, 380
we're gonna have some kind of pre thought of story and we're going to tell you. 381
For instance when we say hey your son Bill, 382
whatever was just in a car accident, right and you need to send this money. 383
I've already come up with that story in my mind and 384
kind of again pretext it pre scripted it if you will before I even talked to you. 385
So those are some of the physical techniques and 386
there's just a couple of little outliers that I want to mention. 387
Things like invoice scams that make it look like you've purchased something and 388
you haven't. 389
And they want you to click on a link there if you will to try to solve the problem by 390
entering your credentials and now they scrape those from you. 391
And then a hoax, 392
hoax if you will is again just like any misleading information sometimes maybe 393
doesn't directly cause harm but can be more of a nuisance than anything. 394
And the last one I would say is gonna be prepending and prepending attack. 395
Some of the examples that I've seen before is where you modify and 396
put information in front of URL and it modifies where it takes you to. 397
So again just other types of attacks that you need to be aware of 398
when it comes to Social Engineering. 399
>> Well there you go now you can understand why social engineering might be 400
such a popular avenue of attack for those threat actors out there. 401
Because well it gets to this machine and not this machine so much. 402
And we are unfortunately a lot of times the weakest links in and 403
that's just because we need to understand how these things work and 404
a lot of times is just all down to that. 405
That being said great stuff here learned all about Social 406
engineering physical social engineering attacks, principles of security. 407
Great stuff more to come in the Security Plus series though. 408
So be sure to stick around for that, as for this episode we're gonna 409
call it a day, thanks for watching, we'll see you next time. 410
Thank you for watching, IT Pro Tv. 411
[BLANK_AUDIO]
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.