1 / 4100%
Running Head: Lab 4-2
1
4-2 Lab Activity: Social Engineering Using SET
SNHU
Social engineering can be defined as attack vector which strongly depends on the
human interaction. A cyber attacker might choose social engineering over other kinds of
Lab 4-2
2
attacks as the former approach will enable him to manipulate people so that they will
break the standard security protocols. The social engineering technique enables the
attackers to conceal their true identity and present themselves as reliable individuals or
information source. A mistake on the part of the victim will allow the attacker to gain
access into their network, or system (Bacon, 2018).
According to Kaabouch and Salahdine, the social engineering technique can
basically challenge the entire security system irrespective of the robust nature of the
firewalls, antivirus software, intrusion detection systems, and cryptography methods
(Salahdine & Kaabouch, 2019, p 1). Since humans are the weakest link in the security
chain, hackers are increasingly using this attack model over other attack methods.
Rationale
In the lab menu a number of choices were made in the Social Engineering
Toolkit which successfully activated specific automated attack features. In addition to
this, the Facebook phishing attack was also initiated. The fake Facebook account was
created as in the current times, the use of Facebook is widespread and an attack on the
popular platform can give an upper hand to the attacker (What is Social Engineering |
Attack Techniques & Prevention Methods | Imperva, 2019). The Facebook phishing
attack technique was used because not many users would give a second thought before
logging into their Facebook page. Thus the hacker would be successful to deceive a user
to log into the popular social media website and become a victim of the security attack.
The users would think the Facebook page to be a genuine site which they regularly use
but in reality, they would become a target of the Facebook phishing attack by the
hacker.
Viability of the attack strategy
Lab 4-2
3
The stimulated end-user or victim’s responses confirmed the viability of the
attack strategy by the online hacker. This is understood from the fact that after the
actions of the victim, a message was received in the attacker’s end which stated that a
connection had been established. The terminal reported that the victim of the online
attack had logged onto the Facebook page. It meant that the initiation of the attack had
been converted into a complete process as the victim had responded as per the
intentions of the online hacker. The response that was generated by the victim shows
that the attack by the cyber attacker had become successful and he would be able to
compromise the security posture of the network.
Automation aspects of the exploit toolkit – Advantage for an attacker and
disadvantage for a defender
The automation aspects of the Social Engineering Toolkit played a key role to
give an advantage to the online attacker and compromise the overall security of the user
or the victim. The automation aspects of the exploit toolkit created an advantage by
allowing a wide variety of attack techniques within a short period of time. Thus instead
of manually trying out which attack technique would work, the automation model made
sure that the entire process could be carried out without human interference. While
creating an advantage for the attacker it created disadvantages for the defender as the
techniques used in the individual’s system to defend against such attacks were not
automated in nature. Thus it acted as a major limitation for the user. Since the technique
to safeguard against security attacks would have to be carried out in a manual manner,
the process would take more time and effort as compared to the automated process.
Thus the lack of an automated strategy on the part of the defender acted as the core
disadvantage which increased his overall vulnerability on the online platform.
Lab 4-2
4
References
Bacon, M. (2018). What is social engineering? - Definition from WhatIs.com. Retrieved
from https://searchsecurity.techtarget.com/definition/social-engineering
Salahdine, F., & Kaabouch, N. (2019). Social Engineering Attacks: A Survey. Future
Internet, 11(4), 89.
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva.
(2019). Learning Center. Retrieved 12 September 2019, from
https://www.imperva.com/learn/application-security/social-engineering-attack/
Students also viewed