#socialengineering #hacking #victims #thinking #planning #hackers #scamming #email #phishing
The world of the hacker is quite an interesting place, and the world of the victim is a blissful plane, where ignorance reigns supreme. As many hackers do they look at this blissful existence and scoff at how dumb people can actually be, they scamper to web forums and proclaim their omnipotent brilliance in comparison to the every day Neanderthal computer user. After all we are smarter aren't we? To clever to fall for the common con. The common con though... isn't made to deceive the hacker of computers, or the wifi hacker, its made to deceive the intended target, there is a level of understanding by the hacker to create such dubious tasks possible.
First to reverse engineer why these hacks work exactly. Social engineering, the ability to speak, converse, and display a level of trust and competence with a side of validation. As discussed multiple times before is the ultimate conning tool. The ultimate weapon against the Nazgul riders of the hackers goal to reach Mordor. To deliver that ever so precious package to the depths of enemy territory. To understand these con's we must first think like the victim and not rule it out as complete stupidity. Their ignorance is the ever important fuel to the journey.
We understand that those who aren't familiar with a certain subject will have a level of ignorance, not everyone can be an expert. As an example let's talk about oil changes. Most of us can figure out how to do it, its pretty dang simple.
- Get tools.
- Jack up car
- Put on jackstands
- Crawl under
- Place Oil Collection pan under oil tank
- Unscrew oil tank plug
- bla bla bla You get the point
This is a weekend afternoon or morning job that can be done in 20 minutes. But not everyone understands the intricacies of this stuff, and if the weather is crap there is no way you're doing that on your own when for $40 Jiffy Lube will do it for you all while you get some coffee in a warm room and only 15 minutes of your day is wasted. That $40 doesn't stay $40 for very long though, as anyone who has ever visited a Jiffy Lube or any of their competitors know that, a majority of their client basis visits based on the fact they don't understand how an internal combustion engine works. Damn they are complicated as hell in all honesty. What does this mean for the oil change company? They can upsell like CRAZY!!! The transmission fluid needs to be changed and that'll cost you your first born child, and your cabin air filter is dirty so you NEED to have that changed or you might sneeze, and your brakes need to be replaced that'll cost you way too damn much. Need need need need need, when all is done what really happens?
You don't NEED your cabin air filter changed, that's a $5 part at autozone, and it sits behind your glove box, and they want to sell it for $35? Your brakes may need to be changed, but $500? You can get real ones and do it yourself in an hour for under $100. But its ignorance that fuels the way this company works. It is ignorance of the product, it is ignorance of how things should be done that convince people into doing something they shouldn't be doing.
This ignorance must be embraced, this ignorance must be understood and must be tucked into our tool belts, you're not going to just hacking websites, hacking games, or hacking phones without it. Mocking at ones brilliance proves one thing, you can't navigate around in the shadows just yet, let it sink in that yes you are a bit more clever than someone else. Our ability to exploit someones ignorance requires a touch of humility to hide the smirk and tuck away the arrogance. Arrogance flaunting you know something just that tiny bit more than someone else, proves you are still a moron yourself. You lack the real ability to take advantage of someone else, as you're still in a state of mind that leaves you open to attack. Learning how to cope with your ability and knowledge without coming off sounding like a blathering idiot is the real challenge.
This seems to be pandemic in the hacker community, that guy... you know "that guy" who comes around and says something like "why would anyone be so stupid to click that link, its obviously a fraud" or "I can't believe people are this dumb, I would never fall for something this stupid." No-one cares about what YOU would do, but obviously you're so damn full of yourself that you find it important enough to share how YOU feel about things. No-one cares, and the attention seeking approach for personal gratification or validation isn't going to be earned here. And advertising you can't see the world beyond the end of your nose only proves to show that... you're not immune to a social engineering attack. As one of the most important skills of social engineering is... exploiting a weakness. Pride and arrogance are easily exploited... just saying.
All my fellow hackers and future hackers, learn humility so you can fully exploit ignorance, learning to think like the target, will allow you to create something they're weak against. Dancing around in public forums about how smart you are solves nothing, but proves more about you than you know about yourself. And as always, be safe my goblins.
I will have to remember this the next time I am called by "Windows Company" about my "computer problems recently"... >:]
ReplyDeleteOh aren't those the best? I may set myself up a better firewall and a dummy system in front of a DMZ, see how it all plays out :-D
Delete