- Learn Penetration Testing
- Rishalin Pillay
- 313字
- 2021-06-24 14:09:21
Pretexting
Pretexting can be defined as the practice of presenting yourself as someone else, with the intention of obtaining information. Pretexters can impersonate co-workers, IT staff, bankers, friends and family, or anyone that can be perceived as trustworthy or having authority over the target.
Pretexting forms the foundation for any social engineering attack. When you're performing a penetration test, make sure that you spend enough time building a solid and believable pretext.
For example, we have all received emails claiming that we have inherited a small fortune, but in order to claim it, we need to either provide some kind of information or click on a link. The chances of a person falling for this is very slim, as the pretext is very poor. Let's assume that you always purchase online from Amazon, and now you receive an email from Amazon stating that there is a package that cannot be delivered due to missing information. This becomes more believable as the pretext is more solid.
During a penetration test, you need may need to simulate a social engineering attack. Conducting proper information gathering on your target is critical to building a believable pretext. Some of the things that you would consider are company size, locations, number of employees, emails, employee information, and so on. You would also look at what is available from a technological standpoint, such as public-facing web servers, VPNs, and email servers.
Once you have obtained enough information, you can start defining success criteria for each pretext. For example, if the target organization does not have offices spread across the country, the chance of success of posing as an employee is low, as the employees are probably well-known. However, if the organization has a large presence that spans across multiple countries, you have a higher success rate of posing as an employee from a department in another location.
- 腎病綜合征
- 陳衛(wèi)川中回醫(yī)臨證實(shí)錄方
- 口腔科常見(jiàn)及多發(fā)病就醫(yī)指南系列:口腔黏膜病就醫(yī)指南
- 腫瘤精準(zhǔn)放射治療靶區(qū)勾畫(huà)叢書(shū):泌尿系統(tǒng)腫瘤
- 謠言背后的健康真相
- Hands-On Functional Programming with C++
- 高脂血癥百家百方
- 前列腺癌標(biāo)準(zhǔn)數(shù)據(jù)集(2021版)
- 再生醫(yī)學(xué)基礎(chǔ)與臨床
- 眼科裂隙燈顯微鏡操作手冊(cè)
- 走進(jìn)孤獨(dú)的世界:為家長(zhǎng)專業(yè)解讀自閉癥
- 龍層花健脊防癌方案
- 腦卒中診療與康復(fù)問(wèn)答
- 常見(jiàn)老年病家庭康復(fù)操作指南
- 電子喉鏡臨床應(yīng)用:鼻咽喉部腫瘤窄帶成像內(nèi)鏡圖譜