RE: SE Explained 01-15-2018, 05:36 AM
#11
Allow me to clarify a few things here with social engineering. There's a lot people who do In fact completely overlook the SEing side of It, and only take the "end result" Into account hence deem It as no relevance to social engineering.
Simply put and In general terms, SEing Is manipulating the person on the other end Into doing something they're not supposed to do. The end result Is Immaterial. It's the methodology used to achieve the end result that's classed as social engineering.
For example:
(1). You obtain personal Information and credentials such as family names, given names, addresses, date of births, phone number,s bank account name & numbers, merchant Ids, Inter-company codes, usernames & passwords, CC numbers, CC account holder, expiration dates, CVV numbers and the list goes on.
This was performed via person-to-person contact over the phone.
The methodology used to obtain this Information, Is social engineering. Not the end result.
(2). You've been authorized access to a restricted building, bypassing the building's entry code.
This was performed by assuming the role of an employee, dressed accordingly In a suit, wearing (what appeared to be) an authenticated ID and as such, another employee left the door ajar for you and you've walked Into the building.
The methodology used to gain access to the restricted building, Is social engineering. The end result Isn't.
(3). In the case of "Amazon" on this board. The methodology used to steal the Item In question, Is classed as social engineering. The end result Is not.
Yes (where applicable), I agree It Is stealing there's no question about It, but Identifying the vulnerability(s) of the person on the other end, exploiting those vulnerabilities (hence circumventing the human firewall) and getting the person to do something they're not supposed to do (refund/replace the Item) Is social engineering. The end result Is not.
As you can see, the results of all analogies above have a different outcome. However, the key element Is the methods used to get the result- all of which pertain to social engineering.
Simply put and In general terms, SEing Is manipulating the person on the other end Into doing something they're not supposed to do. The end result Is Immaterial. It's the methodology used to achieve the end result that's classed as social engineering.
For example:
(1). You obtain personal Information and credentials such as family names, given names, addresses, date of births, phone number,s bank account name & numbers, merchant Ids, Inter-company codes, usernames & passwords, CC numbers, CC account holder, expiration dates, CVV numbers and the list goes on.
This was performed via person-to-person contact over the phone.
The methodology used to obtain this Information, Is social engineering. Not the end result.
(2). You've been authorized access to a restricted building, bypassing the building's entry code.
This was performed by assuming the role of an employee, dressed accordingly In a suit, wearing (what appeared to be) an authenticated ID and as such, another employee left the door ajar for you and you've walked Into the building.
The methodology used to gain access to the restricted building, Is social engineering. The end result Isn't.
(3). In the case of "Amazon" on this board. The methodology used to steal the Item In question, Is classed as social engineering. The end result Is not.
Yes (where applicable), I agree It Is stealing there's no question about It, but Identifying the vulnerability(s) of the person on the other end, exploiting those vulnerabilities (hence circumventing the human firewall) and getting the person to do something they're not supposed to do (refund/replace the Item) Is social engineering. The end result Is not.
As you can see, the results of all analogies above have a different outcome. However, the key element Is the methods used to get the result- all of which pertain to social engineering.













![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
![[Image: inkexplosion.jpg]](http://i0.wp.com/techverse.net/wp-content/uploads/2013/09/inkexplosion.jpg)














![[Image: 4GNsK67.png]](http://i.imgur.com/4GNsK67.png)




