1
1

00:00:00,300  -->  00:00:02,380
<v ->Social engineering attacks.</v>
2

2

00:00:02,380  -->  00:00:04,120
In this lesson, we're going to focus on
3

3

00:00:04,120  -->  00:00:06,390
the different types of social engineering attacks,
4

4

00:00:06,390  -->  00:00:09,130
including phishing, tailgating, piggy-backing,
5

5

00:00:09,130  -->  00:00:12,300
shoulder surfing, eavesdropping and dumpster diving.
6

6

00:00:12,300  -->  00:00:14,400
Now, before we get into the specific attacks,
7

7

00:00:14,400  -->  00:00:16,460
let's define social engineering.
8

8

00:00:16,460  -->  00:00:19,200
Social engineering is any attempt to manipulate users
9

9

00:00:19,200  -->  00:00:21,160
into revealing confidential information
10

10

00:00:21,160  -->  00:00:22,500
or performing other actions
11

11

00:00:22,500  -->  00:00:24,150
that are detrimental to that user
12

12

00:00:24,150  -->  00:00:26,180
or the security of our systems.
13

13

00:00:26,180  -->  00:00:29,020
Social engineering is always focused on the human element
14

14

00:00:29,020  -->  00:00:30,590
and trying to find a way to bypass
15

15

00:00:30,590  -->  00:00:33,620
our systems' technical controls by simply hacking the human
16

16

00:00:33,620  -->  00:00:35,480
instead of hacking the technology.
17

17

00:00:35,480  -->  00:00:36,313
For example,
18

18

00:00:36,313  -->  00:00:38,130
if I wanted to break into your wireless network,
19

19

00:00:38,130  -->  00:00:39,810
and I found that you had implemented a long,
20

20

00:00:39,810  -->  00:00:43,580
strong password for your WPA2 AES encrypted network,
21

21

00:00:43,580  -->  00:00:45,330
it could take me years upon years
22

22

00:00:45,330  -->  00:00:47,100
to brute force that password.
23

23

00:00:47,100  -->  00:00:50,030
But if I instead figure out a way to trick you or your users
24

24

00:00:50,030  -->  00:00:51,740
into sharing that password with me,
25

25

00:00:51,740  -->  00:00:53,210
I might be able to access that network
26

26

00:00:53,210  -->  00:00:54,610
by the end of the day,
27

27

00:00:54,610  -->  00:00:56,800
that's the idea of social engineering.
28

28

00:00:56,800  -->  00:00:58,180
In most of our networks,
29

29

00:00:58,180  -->  00:01:00,500
the weakest link in our security is our end users
30

30

00:01:00,500  -->  00:01:01,640
and our employees.
31

31

00:01:01,640  -->  00:01:02,640
This is why conducting
32

32

00:01:02,640  -->  00:01:04,710
good annual user cybersecurity training
33

33

00:01:04,710  -->  00:01:07,550
is so important to the security of your organization.
34

34

00:01:07,550  -->  00:01:10,850
So let's take a look at a few social engineering attacks.
35

35

00:01:10,850  -->  00:01:13,040
The first one we have is phishing.
36

36

00:01:13,040  -->  00:01:15,600
A phishing attack occurs when an attacker sends an email
37

37

00:01:15,600  -->  00:01:17,710
in an attempt to get a user to click a link.
38

38

00:01:17,710  -->  00:01:20,060
For example, if an attacker is going to send an email
39

39

00:01:20,060  -->  00:01:21,400
claiming they're from PayPal
40

40

00:01:21,400  -->  00:01:23,550
and they're asking you to confirm your account information,
41

41

00:01:23,550  -->  00:01:26,230
this is a prime example of a phishing attack.
42

42

00:01:26,230  -->  00:01:29,250
In this example, the attacker may include PayPal's logo,
43

43

00:01:29,250  -->  00:01:31,950
the same format that PayPal uses in their emails normally,
44

44

00:01:31,950  -->  00:01:34,350
and other things that make it appear legitimate.
45

45

00:01:34,350  -->  00:01:36,770
But if you or your users click on that link,
46

46

00:01:36,770  -->  00:01:39,010
it would instead take you to a PayPal login page
47

47

00:01:39,010  -->  00:01:40,550
hosted on the attacker site,
48

48

00:01:40,550  -->  00:01:42,030
where they're going to try to get you to login
49

49

00:01:42,030  -->  00:01:44,290
by entering your username and your password
50

50

00:01:44,290  -->  00:01:46,510
and now they have your account details
51

51

00:01:46,510  -->  00:01:49,330
and can steal any money you may have in your account.
52

52

00:01:49,330  -->  00:01:51,630
Now, how many people do you think fall for this?
53

53

00:01:51,630  -->  00:01:53,620
Well, you'd actually be really surprised
54

54

00:01:53,620  -->  00:01:55,990
because the answer is a lot of people.
55

55

00:01:55,990  -->  00:01:57,300
In phishing attempts that I've done
56

56

00:01:57,300  -->  00:01:58,870
as part of a penetration test,
57

57

00:01:58,870  -->  00:02:00,440
I've personally seen response rates
58

58

00:02:00,440  -->  00:02:02,820
as high as 60 or 70% of users
59

59

00:02:02,820  -->  00:02:05,270
clicking the links inside those emails.
60

60

00:02:05,270  -->  00:02:08,430
Even when I include things like bad grammar, poor spelling,
61

61

00:02:08,430  -->  00:02:10,730
improper logos, and other things like that,
62

62

00:02:10,730  -->  00:02:12,400
users still end up clicking the links
63

63

00:02:12,400  -->  00:02:15,020
at a rate about 30 to 40%.
64

64

00:02:15,020  -->  00:02:17,830
This means phishing works really well for an attacker,
65

65

00:02:17,830  -->  00:02:19,700
and it's really hard for us to prevent.
66

66

00:02:19,700  -->  00:02:21,350
Now, phishing is a bad thing
67

67

00:02:21,350  -->  00:02:23,040
and the best thing you can do to prevent it
68

68

00:02:23,040  -->  00:02:24,830
is really train all of your end users
69

69

00:02:24,830  -->  00:02:26,390
and make them aware of it.
70

70

00:02:26,390  -->  00:02:29,180
Now phishing itself takes one of three forms.
71

71

00:02:29,180  -->  00:02:32,390
This is either known as phishing, spear phishing or whaling.
72

72

00:02:32,390  -->  00:02:35,400
In phishing, this is the most broad type of these three.
73

73

00:02:35,400  -->  00:02:38,060
In a phishing campaign, an attacker isn't really targeting
74

74

00:02:38,060  -->  00:02:39,640
any particular person or group,
75

75

00:02:39,640  -->  00:02:41,080
but instead sends out emails
76

76

00:02:41,080  -->  00:02:43,370
that are likely to capture the most people.
77

77

00:02:43,370  -->  00:02:46,150
For example, the PayPal phishing email I mentioned earlier
78

78

00:02:46,150  -->  00:02:47,730
is a great form of phishing
79

79

00:02:47,730  -->  00:02:51,350
because there's over 377 million users of PayPal.
80

80

00:02:51,350  -->  00:02:53,910
So if I just send out that email to every email address
81

81

00:02:53,910  -->  00:02:56,550
I had, most likely, a lot of those people
82

82

00:02:56,550  -->  00:02:57,820
are going to have PayPal accounts
83

83

00:02:57,820  -->  00:03:00,290
and they'll possibly click the links in my email.
84

84

00:03:00,290  -->  00:03:02,830
Spear phishing on the other hand is more targeted.
85

85

00:03:02,830  -->  00:03:04,900
For example, let's pretend that you are a member
86

86

00:03:04,900  -->  00:03:07,800
of a small local bank called DT Savings and Loan.
87

87

00:03:07,800  -->  00:03:09,600
Now, unfortunately, DT Savings and Loan
88

88

00:03:09,600  -->  00:03:10,940
had a data breach last year.
89

89

00:03:10,940  -->  00:03:12,890
And that resulted in all the names and emails
90

90

00:03:12,890  -->  00:03:14,190
of all their account holders
91

91

00:03:14,190  -->  00:03:16,010
being downloaded by that attacker.
92

92

00:03:16,010  -->  00:03:18,280
That list is now on the dark web.
93

93

00:03:18,280  -->  00:03:19,780
Now an enterprising young hacker
94

94

00:03:19,780  -->  00:03:21,630
decides to craft a spear phishing email
95

95

00:03:21,630  -->  00:03:24,110
that targets a hundred of the users on that list.
96

96

00:03:24,110  -->  00:03:25,490
In that email they create,
97

97

00:03:25,490  -->  00:03:27,750
they pretend to be from DT savings and loan,
98

98

00:03:27,750  -->  00:03:29,770
and they only sent this email to people they know
99

99

00:03:29,770  -->  00:03:32,060
have accounts at DT savings and loan.
100

100

00:03:32,060  -->  00:03:33,080
You see the difference?
101

101

00:03:33,080  -->  00:03:35,260
Instead of trying to send the email to a million people
102

102

00:03:35,260  -->  00:03:37,670
and hoping some of them have a PayPal account,
103

103

00:03:37,670  -->  00:03:40,200
instead, we are now targeting people we know
104

104

00:03:40,200  -->  00:03:43,170
have a banking relationship with DT savings and loan.
105

105

00:03:43,170  -->  00:03:45,910
The final type of phishing we have is known as whaling.
106

106

00:03:45,910  -->  00:03:47,330
Whaling is like spear phishing,
107

107

00:03:47,330  -->  00:03:50,200
but it's focused on key executives within an organization,
108

108

00:03:50,200  -->  00:03:55,200
such as your CEO, COO, CFO, CIO, and many other key leaders,
109

109

00:03:55,220  -->  00:03:57,960
executives, and managers within your company.
110

110

00:03:57,960  -->  00:04:00,520
Now the second type of social engineering attack we have
111

111

00:04:00,520  -->  00:04:02,150
is known as tailgating.
112

112

00:04:02,150  -->  00:04:03,780
Tailgating is going to occur when an attacker
113

113

00:04:03,780  -->  00:04:05,260
attempts to enter a secure portion
114

114

00:04:05,260  -->  00:04:06,660
of the organization's building
115

115

00:04:06,660  -->  00:04:09,260
by following an authorized person into that area
116

116

00:04:09,260  -->  00:04:11,290
without their knowledge or consent.
117

117

00:04:11,290  -->  00:04:13,640
For example, if I just went up to the server room door
118

118

00:04:13,640  -->  00:04:16,580
and I swipe my access badge and I entered my pin,
119

119

00:04:16,580  -->  00:04:19,200
the door would beep and unlock and I can walk in
120

120

00:04:19,200  -->  00:04:21,770
because I'm part of the authorized personnel list.
121

121

00:04:21,770  -->  00:04:23,790
Now, as I open the door and walk through,
122

122

00:04:23,790  -->  00:04:25,510
but before the door shuts behind me,
123

123

00:04:25,510  -->  00:04:27,640
somebody could sneak in and get in there
124

124

00:04:27,640  -->  00:04:30,320
without my knowledge, that would be tailgating.
125

125

00:04:30,320  -->  00:04:32,550
For this reason, you should always train your employees
126

126

00:04:32,550  -->  00:04:34,350
to pull the door shut behind them
127

127

00:04:34,350  -->  00:04:37,140
and not simply walk away in hopes the force of gravity
128

128

00:04:37,140  -->  00:04:38,950
is going to shut the door for them.
129

129

00:04:38,950  -->  00:04:41,570
Now, the other side of this is known as piggybacking.
130

130

00:04:41,570  -->  00:04:43,440
This is something that is similar to tailgating,
131

131

00:04:43,440  -->  00:04:46,230
but it occurs with the employee's knowledge or consent.
132

132

00:04:46,230  -->  00:04:48,360
Now, piggybacking might occur when an attacker
133

133

00:04:48,360  -->  00:04:51,070
walks up to a secure area carrying a bunch of boxes
134

134

00:04:51,070  -->  00:04:53,140
and they ask somebody to nicely open the door for them
135

135

00:04:53,140  -->  00:04:54,530
because their hands are full.
136

136

00:04:54,530  -->  00:04:56,210
If the employee trying to be nice,
137

137

00:04:56,210  -->  00:04:58,870
opens the door and lets the attacker walk into the building,
138

138

00:04:58,870  -->  00:05:00,480
this is known as piggy-backing
139

139

00:05:00,480  -->  00:05:02,760
because two people are entering on one swipe
140

140

00:05:02,760  -->  00:05:04,790
of the employee's access card.
141

141

00:05:04,790  -->  00:05:06,960
The next social engineering attack we have to talk about
142

142

00:05:06,960  -->  00:05:08,720
is known as shoulder surfing.
143

143

00:05:08,720  -->  00:05:10,210
Now, shoulder surfing occurs
144

144

00:05:10,210  -->  00:05:12,140
when an attacker comes up behind an employee
145

145

00:05:12,140  -->  00:05:13,980
and tries to use direct observation
146

146

00:05:13,980  -->  00:05:16,170
to obtain authentication information.
147

147

00:05:16,170  -->  00:05:18,070
For example, you're sitting at your desk
148

148

00:05:18,070  -->  00:05:19,800
and you're logging into your computer in the morning.
149

149

00:05:19,800  -->  00:05:22,210
If I were to walk up near you and look over your shoulder,
150

150

00:05:22,210  -->  00:05:23,630
as you typed in your password,
151

151

00:05:23,630  -->  00:05:25,300
I might see your finger start going
152

152

00:05:25,300  -->  00:05:28,930
P-A-S-S-W-O-R-D, password.
153

153

00:05:28,930  -->  00:05:30,640
Now I know what your password is.
154

154

00:05:30,640  -->  00:05:32,880
Now, this is the idea of shoulder surfing
155

155

00:05:32,880  -->  00:05:35,550
because I've looked at your hands as you were doing it.
156

156

00:05:35,550  -->  00:05:37,220
Now, usually it won't be as obvious
157

157

00:05:37,220  -->  00:05:38,640
as me standing right behind you
158

158

00:05:38,640  -->  00:05:39,860
and looking over your shoulder,
159

159

00:05:39,860  -->  00:05:42,150
but it can take a lot of different forms.
160

160

00:05:42,150  -->  00:05:43,990
Maybe I work at the desk next to yours
161

161

00:05:43,990  -->  00:05:45,690
and I glance over your computer screen
162

162

00:05:45,690  -->  00:05:47,940
and I see your bank balance or your credit card number
163

163

00:05:47,940  -->  00:05:49,210
or something like that.
164

164

00:05:49,210  -->  00:05:51,440
Any kind of information that someone's able to see
165

165

00:05:51,440  -->  00:05:53,320
that they're not really authorized to see,
166

166

00:05:53,320  -->  00:05:55,610
could be gained using shoulder surfing.
167

167

00:05:55,610  -->  00:05:58,700
In the same way I can use eyes to conduct shoulder surfing,
168

168

00:05:58,700  -->  00:06:01,470
I can also use my ears to conduct eavesdropping.
169

169

00:06:01,470  -->  00:06:02,940
Now, maybe I'm going to stand around
170

170

00:06:02,940  -->  00:06:04,210
while you're talking with your boss
171

171

00:06:04,210  -->  00:06:06,010
and I overhear you telling him some information
172

172

00:06:06,010  -->  00:06:08,590
about the projections for next quarter's profits.
173

173

00:06:08,590  -->  00:06:09,960
By listening to your conversation
174

174

00:06:09,960  -->  00:06:12,200
and doing that direct observation with my ears,
175

175

00:06:12,200  -->  00:06:14,340
I'm now able to listen in on that conversation
176

176

00:06:14,340  -->  00:06:16,940
and get the information that I might want to get.
177

177

00:06:16,940  -->  00:06:18,960
The final method of social engineering we have
178

178

00:06:18,960  -->  00:06:20,540
is known as dumpster diving.
179

179

00:06:20,540  -->  00:06:22,420
Now, dumpster diving occurs when an attacker
180

180

00:06:22,420  -->  00:06:25,640
actually scavenges for personal or confidential information
181

181

00:06:25,640  -->  00:06:28,050
inside the garbage or recycling containers.
182

182

00:06:28,050  -->  00:06:30,590
Yes, I know it sounds dirty, but guess what?
183

183

00:06:30,590  -->  00:06:33,870
This works really well and so hackers are willing to do it
184

184

00:06:33,870  -->  00:06:35,980
because they will find some really great information
185

185

00:06:35,980  -->  00:06:37,520
inside those dumpsters.
186

186

00:06:37,520  -->  00:06:39,760
If the attacker needs to break into an organization,
187

187

00:06:39,760  -->  00:06:42,270
they're first going to look through your trash for clues.
188

188

00:06:42,270  -->  00:06:44,820
For example, maybe I can perform dumpster diving
189

189

00:06:44,820  -->  00:06:47,260
against an organization before I do a pen test.
190

190

00:06:47,260  -->  00:06:49,470
And from there I can find a phone list.
191

191

00:06:49,470  -->  00:06:51,760
Now, I have people's names and their positions
192

192

00:06:51,760  -->  00:06:54,370
and their phone numbers, and maybe even their emails.
193

193

00:06:54,370  -->  00:06:56,780
All of this is great information for me to use.
194

194

00:06:56,780  -->  00:06:59,200
So how do you prevent an attacker from gaining access
195

195

00:06:59,200  -->  00:07:01,360
to your information using dumpster diving?
196

196

00:07:01,360  -->  00:07:03,200
Well, you either need to shred your paperwork
197

197

00:07:03,200  -->  00:07:05,630
prior to throwing it away using a cross-cut shredder,
198

198

00:07:05,630  -->  00:07:07,840
or you need to use a lock trashcan
199

199

00:07:07,840  -->  00:07:09,060
that only your organization
200

200

00:07:09,060  -->  00:07:11,460
and the waste management company have access to.
