Did you know that Packt offers eBook versions of every book published, with PDF and ePub files available? You can upgrade to the eBook version at www.PacktPub.com and as a print book customer, you are entitled to a discount on the eBook copy. Get in touch with us at service@packtpub.com for more details.
At www.PacktPub.com , you can also read a collection of free technical articles, sign up for a range of free newsletters, and receive exclusive discounts and offers on Packt books and eBooks.
Foreword
I remember precisely where I was when I first saw Erdal talking about social engineering: it was a jam-packed room at Microsoft's TechEd, overflowing into the hallway, if memory serves me. Software developers and IT pros alike had flooded into the room to hear about this phenomenon, which sounded so intriguingthe ability to bend people to your will with what must have seemed like mind control to many people. The audience was in raptures as they learned about how the best technology controls we had at our disposal were so readily circumvented due to the fallibility of the organic matter sitting at the keyboard.
But the memory that sticks with me to this day is not the content, but rather how Erdal made people feel; scared, entertained, and lusting for more. Of course, there was substance to the talk, as there was to many others that day and indeed the hundreds of others I must have seen since then. Substance alone, however, is not what makes a lesson stick, nor is it what makes a lasting impression. Passion, enthusiasm, and engagement were the ingredients that made my first encounter with Erdal memorable, and indeed, they're the traits I've subsequently borrowed from him in my own speaking career.
Upon reflection, I suspect that talk was, itself, a degree of social engineeringhe was manipulating the emotions of the audience. We're all susceptible to it in one form or another simply because we respond to the sentiments it elicits within us. We've all experienced fear, greed, urgency, curiosity, and sympathy, among many of the other feelings an adept social engineer plays upon. The trick is in understanding the right buttons to push in order to bend the victim (or in this case, the audience) to your point of view.
Over time, the mechanics of social engineering has become ever more important for us to understand. Although we humans haven't particularly changed in terms of how we respond to those aforementioned emotions, the technology landscape we live within has changed a great deal in ways that make this style of attack ever more effective. For example, we've never had access to more open source intelligence data than we do today and that same statement will still hold true if you read this again a year from now. The number of channels through which social engineering attacks can be mounted are also expanding; it's no longer just phishing attacks in emails, we see malicious attacks being mounted via every conceivable communication platform by which adversaries can get their message in front of victims.
In this book, Erdal takes a very practical look at the mechanics of how these attacks take place. It's a thorough overview, yet is also readily consumable and packed with real-world examples. Erdal goes beyond the theory and academics and drills down into easily accessible resources, reproducible steps, and industry precedents that demonstrate just how effective social engineering attacks can be. Perhaps most importantly, though, he lays a foundation that paves the way for those of us defending against these attacks to better prepare both our systems and our people.
I hope that you come away from reading this book feeling the same way as Erdal's audience did when I first saw him talkingscared, entertained, and lusting for more!
Troy Hunt
Founder, Have I Been Pwned
Contributors
What this book covers
, Introduction to Social Engineering , is an overview of social engineering. This gives an outline of the social engineering framework, the steps to follow, and a brief discussion of some of the tools used.
, The Psychology of Social Engineering Mind Tricks Used, explains the mind tricks used in social engineering to effectively bring a target's brain under the control of the social engineer.
, Influence and Persuasion , gives an overview of manipulation and reality altering tactics.