All language subtitles for 2. Social Engineering Techniques

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic Download
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Are you aware of the different methods of social engineering used by bad actors 2

today to infiltrate multiple different kinds of networks? 3

If not, well, good news is we're going to have that conversation starting right now. 4

>> You're watching ITProTv. 5

[MUSIC] 6

>> Well, welcome back to Security+ here at ITProTV, and 7

in today's episode we will be talking all about social engineering. 8

This is the art of human hacking as they say. 9

And Wes, you're going to definitely take us down the road because we think 10

social engineering, it's one of those umbrella terms in a lot of ways. 11

But there are many different ways and avenues in which this could be teased out, 12

as it were. 13

>> Definitely. >> Where do we begin when we start having 14

this conversation on social engineering? 15

>> When CompTIA puts the social engineering objectives together, 16

they put it in an area called threats, vulnerabilities and attacks. 17

So what I thought would be good is right before we dive into social engineering, 18

we look at just some basic terminology that you really have to keep in your mind 19

as we go through, really, the rest of the entire series. 20

So how about we start with some of just the basic principles, if you will? 21

>> Start at the beginning? 22

>> That's right, Dan, that sounds good. 23

So we're gonna go ahead, and what do you say we get started with a concept known as 24

the principles of security? 25

So let's dive right in and 26

we're talking about here is something known as the CIA triad. 27

You may have seen this before or maybe you're not aware of it, right? 28

And the CIA triad is really about these three principles, right? 29

It's our goals in security, 30

I've heard people say the pillars of security as well. 31

And that's confidentiality, 32

making sure that only the authorized users have access to the information. 33

Integrity, making sure that the information that they should have access 34

to stays in its own state, right? 35

It's what we expect, it hasn't been modified whether it's through transmission 36

errors or malicious means, but it stays in the state that we expect. 37

And then finally, 38

one that might be forgotten as a principal security is availability. 39

And that means that the authorized users have access to the data, 40

the data maintains its integrity, but it's also available to them when they need it. 41

So be aware of what's known as the CIA triad. 42

Now, some of the other basic terms that we have are things like vulnerabilities. 43

And a vulnerability, essentially, boil it down to just a weakness, it's a weakness. 44

And that weakness can be in things like for instance, software bugs, it could 45

be things like some of the default configurations, and we talk about later on 46

in the series here, we'll talk more about some examples of vulnerabilities. 47

But defaults, leaving the default configurations that can be checked on 48

vendors' websites and then people can gain access to whatever it might be, a piece of 49

software, a piece of network equipment, things like weak passwords, right? 50

This is going to be all examples of vulnerability, right? 51

So be aware that vulnerability is typically some kind of weakness. 52

>> Now that's not the only thing we got to be worried about, because a lot of times 53

these two terms can get a little confused, and for good reason, 54

they're very similar but there is a distinction that we need to make. 55

So you've mentioned vulnerabilities, what I'm talking about are threats. 56

Could you help us understand what the difference is there so 57

that we don't make that mistake? 58

>> Sure, absolutely. 59

When it comes to something like a threat, a threat, you'll hear it formally 60

saying any event or circumstance that violates the CIA, all right? 61

It's any condition that leaves you open to some kind of attack. 62

And you'll see that we'll talk about, in later episodes, things like threat 63

hunting, we'll talk about vulnerabilities, threats and exposure. 64

We'll talk about all of this stuff, but basically coming down to any kind of 65

circumstance, a capability or an action that could lead to causing harm, right? 66

And it's information technology, so a lot of times we say harm, 67

it's harming your business's reputation through gaining access to your data, 68

stealing your user credentials, things like that. 69

So some examples, malware, we have phishing scams where people try to gain 70

access to your sensitive information, hackers as well. 71

All different potential threats that we would need to be aware of. 72

>> Now all of these threats ultimately could make you, and 73

I think you actually used the term of an attack as well. 74

So define attack so we can make sure that when I say attack and 75

you say attack were all meaning the same thing. 76

>> Absolutely, we can do that. 77

So a vulnerability is a weakness, all right, 78

an attack is the technique that exploits the vulnerability. 79

That's essentially an attempt to expose, if you will, alter, disable, 80

destroy, steal or gain some kind of unauthorized access, right? 81

Things like network based attacks, application attacks, right? 82

Again, it's a technique that exploits a weakness or a vulnerability in a system. 83

So, definitely be aware of some of the basic terminology as we move through 84

Security+. 85

>> All right, so this has been a really good primer, right? 86

So, we've set up our idea of security as a philosophy, 87

looked at some of the underlying terminology that goes along with it, 88

as well as even an idea into the actual nuts and bolts of the things, 89

that there are attacks and vulnerabilities and things of that nature. 90

Typically very technical in nature. 91

But this is about social engineering. 92

Where does social engineering come into this arena? 93

Well, social engineering, 94

this can be something that is essentially an attack, right? 95

If you think about it, it's attacking some kind of system, and let's go ahead and 96

boil this one down. 97

Social engineering, bad people tricking authorized users, right? 98

It's usually for the purposes of trying to gain credentials, 99

sensitive information that maybe can lead people, or bad actors, if you will, 100

into having access to things that they normally shouldn't have access to. 101

So bad people tricking the authorized users. 102

Now, there are several different types of social engineering scams that we have to 103

worry about, techniques if you will. 104

And probably one of the most prevalent on the block today is something known as 105

phishing. 106

Now I will tell you there are a lot of forms of phishing and 107

it's really just slight variations on the term phishing, right? 108

Phishing is an email based scam, right? 109

This is where somebody sends you an email that says, 110

hey you need to have some kind of, I don't know, I'm trying to think here, 111

we need you to send us money for Apple Pay cards, right? 112

>> That's a popular one there. 113

>> And it's a very, very popular one, just send us four or five of those $500 Apple 114

cards, right, and we can get whatever it is that we need to get done. 115

Now there are some other ones like vishing. 116

Vishing is a form of phishing, 117

the difference is it's typically with a voice over IP system. 118

Smishing, we'll talk about that one coming up. 119

Spear fishing, we also have whaling. 120

And then finally just some of the ways that phishing scams can be successful, 121

it's typically through things like spam, as well as things that can be 122

sent through an instant messenger, I wish I was making this up, 123

but there's a spim, and that's a spam essentially of instant messaging. 124

So let's dive into these a little bit more, because I couldn't for 125

the life of me think about the Apple Pay phishing example [LAUGH]. 126

>> [LAUGH] I love when your brain goes, I'm going on a break. 127

>> That's right. 128

I don't care where you're going but I won't be there when you get there [LAUGH]. 129

>> I'll be here cooking with a smile out. 130

>> [LAUGH] That's right. 131

So you've probably seen one of these before, right? 132

This is a typical type of phishing scam where somebody sends you something that 133

looks like it's coming from an authorized or an authoritative location. 134

We just used an example of iTunes, and by the way, iTunes, it's safe, 135

we're not picking on Apple, these are just the avenues and the methods, 136

right, that they use. 137

The attack vector, if you will, being, hey, this is coming in via email, right? 138

And we're basically trying to trick you into giving us credentials 139

to your cloud based platform. 140

>> Yeah, back when I worked Helpdesk, back when dinosaurs roamed the earth, I had 141

a guy, he was getting a malware installed, my antivirus system was going crazy. 142

He said, yeah, I got this email from DHL that said I had a package ready. 143

I said, do you have a package that you're expecting from DHL? 144

He said, no. 145

>> [LAUGH] >> So 146

why would they be telling you that you have a package ready if you don't? 147

>> He said, I don't know, but I wanted to see what it was. 148

And it was just a fishing length and [CROSSTALK] You click the link, 149

it was installing malware. 150

So you might not be itunes, you might not be DHL you might not be Fedex. 151

That's the whole idea behind this. 152

Right? It's [CROSSTALK] Absolutely use it as 153

camouflage. 154

Get somebody click on. 155

That's right. 156

A lot of people don't hover over these links and 157

realize that these links don't lead to anywhere in Apple. 158

They lead to some other Gmail account or 159

some kind of just recently made yahoo account right now. 160

So when we look at vishing alright vishing is just again this is a voice over IP. 161

Type of attack right? 162

We're trying to gain information out of a voice over IP. 163

Or even by phone. 164

It could be a hoax right? 165

Somebody calling you on the phone saying hey and 166

unfortunately this does happen saying hey your relative just got in an accident 167

there sitting in the emergency room. 168

They need 1200 bucks to be able to take care of them, right? 169

They play on the urgency, they play on your heart, pull your heart strings and 170

try to get money out of you that way. 171

We talked about smashing, right, skirmishing again. 172

Think of SmS. 173

It's a phishing scam, but it's through SMS text messages, right? 174

In fact, one of our entertainers about a couple weeks back received a text message 175

from the United States Postal Service saying there was something wrong with 176

the shipment and they needed to contact or get some contact information and 177

click the link. 178

The United States Postal Service is not gonna be emailing or texting you 179

personally to let you know that they've done something wrong with your package or 180

something that's happening. 181

So that should be a clear indicator that it might seem urgent. 182

You might trust it the authority over it, but it's not valid. 183

>> I mean, the United States Postal Service is a hard time just getting you 184

your package. 185

>> [LAUGH] >> They're not going out of their 186

way to text you personally, you know, something's ready. 187

>> Yeah, sure. 188

And you know, it goes back to the end user that you were supporting dan, you know, 189

they just don't know that's why users on awareness is one of the very 190

first methods and layer of defense. 191

I know dan's done some security user awareness training here, I know helped set 192

that up and we do it here to make people aware that this is a very real threat and 193

it's a very real attack vector that you need to be aware of. 194

Now, spearfishing, you're going to notice something that looks the same, right? 195

It's a phishing scam. 196

But now who we're going after is a little bit different in a phishing scam, 197

it's spam, it's just blanket. 198

We're just gonna throw a big old net out there. 199

I think I got that, I'm gonna steal dance term here, 200

throw that net out there as wide as you can. 201

Just get as many people as you can. 202

All right, spear phishing attack is a little bit different because now it's 203

a targeted attack. 204

Now we know that dan works for X, y, Z company and he's the admin and we also 205

see some other people here that are having to log into the specific portal and 206

we know they work for this company. 207

So we're gonna set just the people within that company, 208

a bunch of these type of phishing attacks and again, it's a targeted attack. 209

It's really the only thing they're going after that specific company instead of 210

just saying, hey, whatever I get his grades, I like them. 211

I think they got some money or they gotta something I'm going to go after. 212

Absolutely target the most, definitely not just blanketing the entire email 213

infrastructure, but an actual attack against a specific company. 214

Now you're gonna notice whaling here? 215

Well, that's a boy. 216

We're getting a lot of re use out of this phishing email here because the difference 217

between this, it's still a phishing scam. 218

But now what you're doing is you are targeting the big fish. 219

Hence the term whaling. 220

We're looking for the people that most or probably have some of the higher level 221

of authority within their company and we're going after them. 222

So for instance, somebody doing an attack that a phishing attack that here at I 223

t pro TV, that's maybe targeting things like for instance, 224

maybe Tim broom our owner or don possessed right? 225

Our co founder, right? 226

The higher ups in the organization because they have a potential to have access to 227

maybe more than the average user, right? 228

Imagine getting access to as ceos inbox, right? 229

You're going to have probably a plethora, 230

I just want to be able to say platform, great information as a hacker. 231

You see this a lot with business email compromise or B E C. 232

They go after the whales because they do have that authority and access. 233

Now if I can take over their account or maybe impersonate them in some way, 234

shape or form that I can say, hey, transfer some funds to such and such and 235

whomever just goes, it's the boss. 236

Just do it. 237

Yeah. And there You go. 238

Yeah. And you know, 239

we're mentioning some of these terms they call that. 240

Is that the principles for success? 241

Right? Why are these phishing scams 242

success successful? 243

Well, there's urgency. 244

You gotta do it now. 245

They're scarcity 30 seconds before it times out and 246

you're never gonna have access to it again. 247

I don't know if I mentioned authority coming from somebody that looks like 248

the ceo, man. 249

You know what tim's telling me, I need to send him my some information or 250

credit card number because he needs to buy something. 251

Well, that's authority, Right? 252

That's trust. 253

Right? And 254

that's one of the reasons, one of quite a few reasons really 255

that these social engineering attacks are are successful. 256

>> Let's move on to some other types of techniques that we might see when it 257

comes to using social engines. 258

Sure. 259

So we did mention there was a couple more and you ladies and gentlemen out there, 260

you're smart crowd, you've seen this probably if even if you haven't been in I. 261

T. You've probably opened email once or 262

twice and you've seen the span. 263

So we're not gonna harp on that one too much. 264

But understand that in a phishing attack where they're blanketing everybody, 265

they're casting the net spam is typically going to be the way that they're going 266

to do that. 267

And again remember spam and spam. 268

Right. One is just gonna be a flooding of emails, 269

the other one's just gonna be a flooding of sMS messages, right? 270

You know, just to try to again scrape some of that, that very important information. 271

But what about farming? 272

This this seems to have gone up in populated here in the recent past and 273

explain a little bit about farming. 274

Sure farming is typically there's gonna be some kind of manipulation of the DNS 275

infrastructure and we'll talk about DNS a little bit later. 276

Just bear, just real basically remember what DNS does I type in a name, www. 277

My website dot com and it goes over to the internet. 278

DNS resolves it to an I. 279

P. Address and my browser connection. 280

That's all I have to do. 281

If I can put a bad response. 282

Let me show you what I mean here. 283

If I can put a bad response in that with that DNS request and I can tell you that. 284

Yeah my website goes to and it's a malicious I. 285

P. 286

Then what we can do is we can tell all of the people for 287

instance that are logging into this web site. 288

They think they're logging into my bank dot net. 289

Right. Some kind of banking application, 290

they're actually being redirected to a malicious website that may be spoofed it. 291

And what they're doing is they're farming. 292

If you can see it's kind of like bringing everybody in to try to gain all of 293

their gain, a whole bunch of just sensitive information from them. 294

Watering hole attacks and another one that has come up quite recently, actually very, 295

very popular. 296

If you can pull it off, it's very devastating. 297

Sure. 298

So, you know, the waterhole attack again, when we talk about farming, right? 299

One of the things that you might do in a farming attack, as you might find out by, 300

hey, where's everybody going? 301

If I can spoof one website, what should I spoof? 302

Well, let's look at where all the employees are going. 303

That's where, where they're all coming to. 304

And if we can make, you know, exploit some vulnerability in that web application 305

then, since everybody's going there, take of a watering hole, right? 306

Think about the watering hole attack, 307

where they always think of the Nile crocs, right? 308

Everybody all the wildebeest, they're all coming down to one location. 309

Well why are the Nile crocs there? 310

They know everybody is going to have to come down and get a drink and 311

when they mount an attack, it's going to be successful. 312

And for them it's gonna be lunch for our Attackers. 313

It means that they're gonna probably do something like maybe even credential 314

harvesting, where they're gonna get all of this information, 315

start out with a waterhole watering hole attack, bring everybody in and 316

as everybody starts logging into what they think is the legitimate website. 317

It's actually a malicious website and they're storing all those credentials may 318

be to sell them later on the dark web, and make some money on them dan you, 319

I think you were telling me that that's become quite a trend. 320

Almost like hacking as a service where hey, if I can get in and 321

get these large pools of credentials, we go out to the dark web and we can just 322

sell the credentials and make money and I don't even have to attack anything. 323

>> Yeah. Hey, if you get people want something, 324

there's gonna be a supply and demand kind of thing going on and 325

people will be able to make a little bit of money off that now that being said. 326

There are some really tricky mechanisms that are being used by these threat actors 327

to pull off these social engineering. 328

Because we all know you look at links, you verify that email, 329

are their U R L address. 330

Should I say before you click on those links and 331

if you click on them at all right, that might not be a good idea. 332

How do they get away with clicking or making it look legitimate for an end user? 333

>> Well, one of the ways I think of Don here is something that you've probably 334

seen and maybe even done if you type like me. 335

And as you follow us along through this series, you'll see how bad I type and 336

that's something known as typo squatting. 337

If you've ever typed maybe something like this where 338

you typed google quite a little bit off. 339

Well, google's got really good at a lot of the major websites that you go 340

to have got a really good about buying these names as well. 341

But earlier on there was no guarantee that when you typed 342

something like google with too many os that it would take you and 343

redirect you to an actual legitimate google site. 344

It could redirect you to somebody's malicious website where they can do for 345

whatever nefarious purpose they're doing. 346

But they could maybe do drive by, download and get some malicious code on your 347

network or on your devices and maybe your network by association. 348

So type of squatting is exactly what it sounds like, it's a little, 349

spelling errors on the U R L. 350

Also U R L squatting if you will to that leads you to a malicious site when you 351

think you were gonna supposed to go to some legitimate website. 352

>> Awesome, now, I know you've got a few other techniques for us really quickly, 353

like physical >> Sure 354

>> Of social engineering techniques. 355

What were they? 356

>> Absolutely, so I know we're running a little bit short on time here. 357

So let's just talk about some of the physical techniques that he Don 358

mentioning here. 359

I mentioned or I think about things like dumpster diving, 360

you have to be in the physical area. 361

We think of those desk calendars, any calendar gets thrown away, 362

little post it notes that end up in the dumpster people go through and 363

they can actually scrape that information. 364

And maybe maybe gain things like P Ii or 365

use that information to attack your network. 366

Other things are shoulder surfing, 367

shoulder surfing is exactly what it sounds like. 368

Looking over your shoulder maybe to try to glean what you're typing into, whatever it 369

is that you're working on, whatever application it is that you're working on. 370

Tailgating or piggyback attack is where you have one authorized person that 371

authenticates and two people make their way through the entry. 372

That's where we have, you probably see things like man traps and 373

turnstiles right? 374

Where it rotates and locks and 375

the next person's gotta authenticate that it rotates again. 376

Well that's a way to prevent these tailgating attacks. 377

So tailgating attacks again are just those attacks where one authentication, 378

two people are making their way through, usually an unauthorized user. 379

And then pretexting, pretexting is one of these things where it's more of a, hey, 380

we're gonna have some kind of pre thought of story and we're going to tell you. 381

For instance when we say hey your son Bill, 382

whatever was just in a car accident, right and you need to send this money. 383

I've already come up with that story in my mind and 384

kind of again pretext it pre scripted it if you will before I even talked to you. 385

So those are some of the physical techniques and 386

there's just a couple of little outliers that I want to mention. 387

Things like invoice scams that make it look like you've purchased something and 388

you haven't. 389

And they want you to click on a link there if you will to try to solve the problem by 390

entering your credentials and now they scrape those from you. 391

And then a hoax, 392

hoax if you will is again just like any misleading information sometimes maybe 393

doesn't directly cause harm but can be more of a nuisance than anything. 394

And the last one I would say is gonna be prepending and prepending attack. 395

Some of the examples that I've seen before is where you modify and 396

put information in front of URL and it modifies where it takes you to. 397

So again just other types of attacks that you need to be aware of 398

when it comes to Social Engineering. 399

>> Well there you go now you can understand why social engineering might be 400

such a popular avenue of attack for those threat actors out there. 401

Because well it gets to this machine and not this machine so much. 402

And we are unfortunately a lot of times the weakest links in and 403

that's just because we need to understand how these things work and 404

a lot of times is just all down to that. 405

That being said great stuff here learned all about Social 406

engineering physical social engineering attacks, principles of security. 407

Great stuff more to come in the Security Plus series though. 408

So be sure to stick around for that, as for this episode we're gonna 409

call it a day, thanks for watching, we'll see you next time. 410

Thank you for watching, IT Pro Tv. 411

[BLANK_AUDIO]

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.