Tuesday, October 03, 2006

What Is "Social Engineering"?

The term “social engineering” is a generic name of acts whose objects are to access others’ computers illegally and one of the ways hackers and crackers use. In a broad sense, this term means every action to get important information for security, such as passwords, from managers and users of networks by “social” ways. In a narrow sense, that does not include modus operands which use electronic methods.

There are some common ways to do social engineering.
Ex.1) Trashing
…To get information from trash.
Ex.2) Intruding
…To intrude into buildings by using unjust ID cards. This is not for computer networks.
Ex.3) Peeping
…To peep others input their passwords.
Ex.4) Web Spoofing
…To have others accessing fake Web sites and inputting their personal     
    information.

In addition, there are some methods to get information by imposing on others’ psychology.

No comments: