20/12/2016
Social engineering it is a method (attacks) of unauthorized access to information or to information systems storage without using technical means. The method is based on using weaknesses of human factor and that is very effective. The attacker receives the information, for example, by collecting information about employees of attack objects by means of an ordinary phone call, or by pe*******on to organization under the guise of its employee. The attacker can call to employee of the company (under the guise of a technical service) and to find out (to hook out) the password, referring to the need of solving a little problem in the computer system. Very often this trick works. The most powerful weapon in this case - a pleasant voice and attacker acting skills. The names of employees manage to find out after a series of calls and learning the names of the heads on the company's website and other sources of public information (reports, advertising, etc.). Using real names in conversation with technical support, the attacker tells a fictional story that he can not get to an important meeting at the site with his dial-up accounts (accounts of remote access). Another tool in this method is checking garbage containers of organizations, virtual wastebaskets, stealing a laptop and other storage media. This method is used when the attacker has outlined specific company as a victim