For the REAL skinny on social engineering...

Social engineering is the art of manipulating people into performing actions or divulging confidential information. While similar to a confidence trick or simple fraud, the term typically applies to trickery for information gathering or computer system access and in most cases the attacker never comes face-to-face with the victim.

Post by Karec on Sun Nov 16, 2008 3:10 am
stochastic-lies wrote:
ImToast wrote:I don't see the point in Social engineering in my opinion.

Social engineering is an exceptionally dangerous "tool" when one can use it correctly. Think how stupid some people are. The biggest vulnerability in security is generally the human. Why not exploit a system from its weakest link, rather than spending twice as long using a much longer method to get whatever you want?

Stochastic-lies, is pretty dead on about this. Why spend hours trying to find a vunerability in a system when you can coax someone unfamilar on company protocal to give it to you.

I personally own the book and my personal opinion is as follows:
The Art of Deception is an good introductory book into Social Engineering. It gives you many examples in context and theory that get the reader interested and illustrates principles behind the practice. However it lacks in actual instruction on how to practice those skills. It is like a math book with theories and proofs without practice problems. You can state the quadratic equation or what a derative is and give examples on how they are used countless times in a book or on a blackboard. However until the student themself applies them they will not truly have an understanding of the concepts.
"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning."
-Rick Cook, The Wizardry Compiled
Post by frienz on Thu Aug 06, 2009 10:17 pm
The Art of Deception is one of the most informative books/manuals you can get on SE related information. Anything beyond is classified or written by some idiot on the internet.
