Social Engineering is used primarily in the cracking world. These previous defintions talking about free drinks etc IS NOT social engineering. That is a con or scam. Social Engineering is a art form. It is the ability to gain peoples trust and using that information for your own nefarious purposes. Social Engineering can range from the most mundane to elaborate ruses. It can be someone asking a another person for their password or it can be someone pretending to be a a employee of a trusted company to get access to something. Keep in mind the ultimate goal is to get access to something. People are not stupid which is why social engineering came about. A usual direct question to someone for a password or login is going to give you a no answer. However when applying social engineering you would be calling or speaking to this person under the premise that you work for the helpdesk or the telephone co. You temporarily befriend this person get their guard down then get the information you need. Kevin Mitnick was a master of Social of Engineering.

I was able to use Social Engineering with Joe by pretending to work for the Phone Company. I called him and was able to get the employee login list.

I made a fake badge for a tech firm and was able to social engineer my way into the datacenter where I got access to some servers where I was able to install a backdoor.

by Hi-Tech-H8 November 12, 2005
