About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Facebook pic
Social networking sites such as Facebook can provide information for hackers
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Social networking websites can help social-engineering attacks

Can be used to find the names of legitimate employees

Tom Royal, Computeract!ve 24 Apr 2008
ADVERTISEMENT

Social networking websites such as Facebook can help in social engineering attacks that attempt to steal private information from companies, according to security experts.

Ian Mann of security firm ECSC said attackers who are challenged by suspicious staff can sometimes escape by simply producing the name of a legitimate employee and pretending to be with them.

“Probably the best place to find a name is Facebook," he said.

Social engineering attacks make use of human error rather than problems with computers or software in order to steal from, damage or deface computer systems. They can be as simple as asking employees for the passwords required to access computers, although others require gaining the confidence of staff over a long period of time.

Such attacks are not always simple to prevent. “If a computer is vulnerable, you can patch it”, explained Roberto Preatoni, founder of the online cybercrime archive Zone-H. “There is no patch for human stupidity”.

“Sooner or later, each one of us will be vulnerable”, he added. Mr Preatoni speaks from experience, as his own website has been broken into and defaced on a number of occasions – including one just seven minutes after it was first launched.

Each time, the attackers stole the required information using social engineering techniques, such as pretending to be Mr Preatoni himself and asking his colleagues for passwords.

He now advocates warning employees of the potential consequences should attackers successfully break into computer systems.

“Training is not enough”, he said. “You should introduce something involving fear … fear is a primal instinct that will always override logic in the priority list in our brain”.


All Hacking and Cyber-crime
Tags: Internet

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Maidstone, United Kingdom | Kent Police
  Assistant Forensic Computer Analyst - Police Headquarters, Maidstone, £20,164 - £23,632 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit ... more >
United Kingdom | London School of Economics and Political Science
  London School of Economics and Political Science The Library Analyst Programmer (fixed term 24 months) Salary: £30,201 - £36,563 pa incl The Library is at the heart of LSE, one of the world's greatest ... more >
York, North Yorkshire, United Kingdom | MyKnowledgeMap Ltd
Web Developers, York, North Yorkshire, Up to £28,000 depending on experience and pension A fantastic opportunity has just opened for enthusiastic Web Developers. Successful candidates will join the company's expanding team of developers, working on ... more >
United Kingdom | MI5 Security Service
Network and Systems Engineers Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT