官术网_书友最值得收藏!

Baiting

This preys upon the greed or curiosity of a certain target. It is one of the simplest social engineering techniques since all that it involves is an external storage device (1). An attacker will leave a malware-infected external storage device in a place where other people can easily find it. It could be in the washroom of an organization, in the elevator, at the reception desk, on the pavement, or even in the parking lot. Greedy or curious users in an organization will then retrieve the object and hurriedly plug it into their machines. Attackers are normally crafty and will leave files in the flash drive that a victim will be tempted to open. For example, a file labeled "the executive summary of salaries and upcoming promotions" is likely to get the attention of many.

If this does not work, an attacker might replicate the design of corporate thumb drives and then drop a few around the organization where they can be picked up by some of its staff. Eventually, they will end up being plugged into a computer and files will be opened. Attackers will have planted malware to infect the computers the flash drive is plugged into. Computers configured to auto-run devices once plugged in are in greater danger, since no user action is required to initiate the malware infection process.

In more serious cases, attackers might install rootkit viruses in the thumb drive that infect computers when they boot, while an infected secondary storage media is then connected to them. This will give attackers a higher level of access to the computer and the ability to move undetected. Baiting has a high success rate because it is human nature to either be greedy or curious and open and read files that are above their level of access. This is why attackers will choose to label storage media or files with tempting titles such as "confidential" or "executive" since internal employees are always interested in such things.

主站蜘蛛池模板: 延津县| 将乐县| 离岛区| 汉寿县| 崇阳县| 应城市| 永年县| 卢湾区| 龙泉市| 久治县| 惠来县| 怀仁县| 云浮市| 布尔津县| 融水| 鹰潭市| 宜川县| 阿拉善左旗| 喀什市| 中牟县| 定州市| 淳化县| 余姚市| 恩平市| 屏东市| 灵寿县| 丹江口市| 武定县| 恭城| 河间市| 嘉荫县| 明溪县| 建阳市| 泰州市| 岱山县| 东辽县| 云林县| 金塔县| 施秉县| 博白县| 梁山县|