Social Engineering

Social engineering is an age-old art that is still popular (and effective) today. Social engineering is the act of tricking someone into

  • Divulging privileged information such as passwords, equipment, architectures, personnel information, or just about anything else you can imagine.

  • Making some adjustment to the system that will allow or facilitate privilege elevation, system compromise, removal of an audit trail, or the like.

  • Adjusting privileged data directly, such as salary, discipline records, and so on.

  • Running a malicious or Trojan program (see the next section about Trojan programs).

Consider the following classic example, which starts with a phone call to the help desk of a large corporation. A relatively young and inexperienced ...

Get Microsoft® Windows® 2000 Security Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.