4.2. Tactical Approaches to Social Engineering

Having discussed in general the overall philosophy of the social engineer, this section provides tips and hints for social engineers. It looks at the specific tactics that can be employed within conversations to achieve your goals (or at least speed up the process). After reading each section, think about people you know and how you think they would respond to each approach. This is actually a lot easier than you might imagine. For example, acting belligerent and imperious with middle management is going to get you nowhere fast (unless you can convince your victim you are upper management), similarly don't expect to carry out a successful IT-based attack against IT staff. You will find this kind of mental templating very useful.

4.2.1. Acting Impatient

Acting with impatience when someone is moving too slowly or appears to be considering verifying your story can be effective in derailing some people's adherence to accepted security protocols. Usually you can expect one of three responses:

  • The flustered target – This is when people panic because they're out of their depth and feel expected to handle a situation they're not trained to deal with. People who don't know what to do are easily manipulated. If this kind of reaction occurs, you should immediately change tack – become reassuring but at the same time firm. Adopt an alpha personality that implies that you know what needs to be done and you will take charge of the situation to ...

Get Unauthorised Access: Physical Penetration Testing For IT Security Teams now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.