Running Head: Lab 4-2
1
4-2 Lab Activity: Social Engineering Using SET
SNHU
Lab 4-2
2
Social engineering can be defined as attack vector which strongly depends on the
human interaction. A cyber attacker might choose social engineering over other kinds of
attacks as the former approach will enable him to manipulate people so that they will break
the standard security protocols. The social engineering technique enables the attackers to
conceal their true identity and present themselves as reliable individuals or information
source. A mistake on the part of the victim will allow the attacker to gain access into their
network, or system (Bacon, 2018).
According to Kaabouch and Salahdine, the social engineering technique can basically
challenge the entire security system irrespective of the robust nature of the firewalls, antivirus
software, intrusion detection systems, and cryptography methods (Salahdine & Kaabouch,
2019, p 1). Since humans are the weakest link in the security chain, hackers are increasingly
using this attack model over other attack methods.
Rationale
In the lab menu a number of choices were made in the Social Engineering Toolkit
which successfully activated specific automated attack features. In addition to this, the
Facebook phishing attack was also initiated. The fake Facebook account was created as in the
current times, the use of Facebook is widespread and an attack on the popular platform can
give an upper hand to the attacker (What is Social Engineering | Attack Techniques &
Prevention Methods | Imperva, 2019). The Facebook phishing attack technique was used
because not many users would give a second thought before logging into their Facebook
page. Thus the hacker would be successful to deceive a user to log into the popular social
media website and become a victim of the security attack. The users would think the
Facebook page to be a genuine site which they regularly use but in reality, they would
become a target of the Facebook phishing attack by the hacker.
Viability of the attack strategy
Lab 4-2
3
The stimulated end-user or victim’s responses confirmed the viability of the attack
strategy by the online hacker. This is understood from the fact that after the actions of the
victim, a message was received in the attacker’s end which stated that a connection had been
established. The terminal reported that the victim of the online attack had logged onto the
Facebook page. It meant that the initiation of the attack had been converted into a complete
process as the victim had responded as per the intentions of the online hacker. The response
that was generated by the victim shows that the attack by the cyber attacker had become
successful and he would be able to compromise the security posture of the network.
Automation aspects of the exploit toolkit – Advantage for an attacker and disadvantage
for a defender
The automation aspects of the Social Engineering Toolkit played a key role to give an
advantage to the online attacker and compromise the overall security of the user or the
victim. The automation aspects of the exploit toolkit created an advantage by allowing a wide
variety of attack techniques within a short period of time. Thus instead of manually trying out
which attack technique would work, the automation model made sure that the entire process
could be carried out without human interference. While creating an advantage for the attacker
it created disadvantages for the defender as the techniques used in the individual’s system to
defend against such attacks were not automated in nature. Thus it acted as a major limitation
for the user. Since the technique to safeguard against security attacks would have to be
carried out in a manual manner, the process would take more time and effort as compared to
the automated process. Thus the lack of an automated strategy on the part of the defender
acted as the core disadvantage which increased his overall vulnerability on the online
platform.
References
Lab 4-2
4
Bacon, M. (2018). What is social engineering? - Definition from WhatIs.com. Retrieved from
https://searchsecurity.techtarget.com/definition/social-engineering
Salahdine, F., & Kaabouch, N. (2019). Social Engineering Attacks: A Survey. Future
Internet, 11(4), 89.
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva. (2019).
Learning Center. Retrieved 12 September 2019, from
https://www.imperva.com/learn/application-security/social-engineering-attack/