Skip to Content
Unauthorised Access: Physical Penetration Testing For IT Security Teams
book

Unauthorised Access: Physical Penetration Testing For IT Security Teams

by Wil Allsopp
September 2009
Intermediate to advanced
307 pages
7h 46m
English
Wiley
Content preview from Unauthorised Access: Physical Penetration Testing For IT Security Teams

4.1. Introduction to Guerilla Psychology

This section examines the various facets of the human psyche that can be exploited to obtain information and predict and control behavior. Different people respond to different stimuli according to the makeup of their characters. However people with similar characters are often found in similar roles. Thus it is possible to predict with a certain degree of accuracy which techniques will be effective given sufficient knowledge of a target individual. A basic understanding of the following concepts and threat vectors is critical to obtaining any real success with social engineering as well as having any chance of protecting yourself against it. Social engineers play on states of mind in order to get what they want. In this section, I'll talk about exploiting the following:

  • trust;

  • ignorance;

  • gullibility;

  • greed;

  • the desire to help;

  • the desire to be liked.

4.1.1. Exploiting Trust

Exploiting trust is at the core of social-engineering attacks. People trust the familiar. In the workplace, most people trust their colleagues (at least in the context of the work environment). We humans are by our nature trusting within our own clan or circles and less so outside them. But, more often than not, we err on the side of trust unless we have a specific reason not to.

For example, if someone calls from a marketing company to ask you to participate in a survey, your first inclination is not 'Arrgghh, a social engineer come to plunder my corporate secrets!' but ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Hack I.T.: Security Through Penetration Testing

Hack I.T.: Security Through Penetration Testing

T. J. Klevinsky, Scott Laliberte, Ajay Gupta
Penetration Testing and Network Defense

Penetration Testing and Network Defense

Andrew Whitaker, Daniel P. Newman

Publisher Resources

ISBN: 9780470747612Purchase book