• Invasion through the weakest vulnerable spot: Social Engineering

      0 comments

    Can you define the coverage of social engineering? As the world grows faster than ever, the importance of social connection comes to be on the surface as well. World-wide connection may link person by person even on the antipode. And I insist that it’s naturally inclined to be vulnerable for the innate desire of human being infiltrates into the lane. Why is it dangerous? I share my own experience about the subject.

    cooperate

    You might be aghast at the fact that most of your information through electronic device is able to be found by someone. But the more horrible thing is, your behavior might be a weak point to invade into your own space. Is it possible? Yes, because we all have weaknesses for we are not the God.

    One of the good examples is “I love you” virus. In logical thinking, we know that we must not open any suspicious e-mail so as to avoid any virulent macros or scripts. But after reading the fascinating title “I love you”, many people open the mail and get the virus.

    Another example is the misuse of call center. Most companies have their own call centers and they’re eager to do their best toward the callers, saying lots of information about their company including critical security issues. Suppose that someone starts with the question of why the connection slows down in spite of nothing happened. He may ask for more about the system, with no problem, and then finally he gets the OS, its version, server application, DB, etc.

    These abusing cases are not always risky enough. But it may hurt others by spreading a rumor of the victim or by taking someone’s secret in the middle. Even the data can be forged from the source: yourself.

    Then what’s the solution? Actually there’s no complete solution. The only way is to be careful not to allow any fraudulent access into your place. (I feel sorry for offering such a trivial solution) It seems somewhat heartless but safety is more important.