About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Facebook pic
Social networking sites such as Facebook can provide information for hackers
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Social networking websites can help social-engineering attacks

Can be used to find the names of legitimate employees

Tom Royal, Computeract!ve 24 Apr 2008
ADVERTISEMENT

Social networking websites such as Facebook can help in social engineering attacks that attempt to steal private information from companies, according to security experts.

Ian Mann of security firm ECSC said attackers who are challenged by suspicious staff can sometimes escape by simply producing the name of a legitimate employee and pretending to be with them.

“Probably the best place to find a name is Facebook," he said.

Social engineering attacks make use of human error rather than problems with computers or software in order to steal from, damage or deface computer systems. They can be as simple as asking employees for the passwords required to access computers, although others require gaining the confidence of staff over a long period of time.

Such attacks are not always simple to prevent. “If a computer is vulnerable, you can patch it”, explained Roberto Preatoni, founder of the online cybercrime archive Zone-H. “There is no patch for human stupidity”.

“Sooner or later, each one of us will be vulnerable”, he added. Mr Preatoni speaks from experience, as his own website has been broken into and defaced on a number of occasions – including one just seven minutes after it was first launched.

Each time, the attackers stole the required information using social engineering techniques, such as pretending to be Mr Preatoni himself and asking his colleagues for passwords.

He now advocates warning employees of the potential consequences should attackers successfully break into computer systems.

“Training is not enough”, he said. “You should introduce something involving fear … fear is a primal instinct that will always override logic in the priority list in our brain”.


All Hacking and Cyber-crime
Tags: Internet

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury    Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
London, United Kingdom | The Crown Estate
 EDM Administrator - London - £22,300 to £24,200pa The Crown Estate is a unique organisation that manages a vast and varied property portfolio, comprising commercial, agricultural and marine interests throughout Britain. We are looking for an ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Central London, United Kingdom | MI5 Security Service
Communications Centre Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT