Hacking the Human Mind: Social Engineering, Phishing & Email Headers


 HELLO FRIENDS!!

WELCOME TO MY CYPHER LOG

   In the last blog we saw about the threat which the attacker used to manipulate systems but today we are going to see about social engineering and also phishing, you may think that what it will be, its just like threat manipulating systems here this will manipulating the human mind using some basic psychology, and also it will be bit interesting to learn. 

Let's see what I have learned today

   As I have said in the above line it's a manipulating mechanism which manipulates the human mind and attackers always rely on psychological triggers and it's not that much complicated than you think actually it's always happening around us everyday. 

Can we see what they are?.

  Attackers use human emotions as their passkey to achieve their goals like stealing data and also money too. We are all emotional fools right, they use it as their weapon. Let's see how it works 

Urgency 

   We all have experienced this through some spam messages that would be like if we didn't do that we would lose everything. It will create a panic without our knowledge we tend to do the things which is in the messages.

Authority

   In this they would act like an authority like a bank manager or some officers, by this we were always conditioned to obey their rules because we thought they were higher officials.

Curiosity / greed

  Actually this is the most powerful weapon for attackers, as our grandma's saying greed will kill us or make us lose what we have already in bedtime stories. But our mind will likely fall for it.

Helpfulness

    In this factor we people love to help someone who is in need actually that's what we have thought to.  But unfortunately attackers made it their weapon. If someone asks for help we would fall into that trap that's how it works.
Next topic is The phishing family tree

The Phishing family tree

   Actually phishing is the most common form of social engineering and it is usually delivered through email and SMS.
And it has many variations too.

Types of phishing

Phishing

  As we have seen before phishing happens through email and messages and it will look like it comes from a legitimate platform. And it will send to tons of common people.

Spear phishing 

     Spear phishing is an advanced level of phishing it will be sent to a targeting individual with their information it looks like a legitimate message.
Attackers usually takes information from LinkedIn. 

Whaling

   It is also like spear phishing but targeting a high profile people like CEOs, or government officials.

Vishing

    It is spam phone calls, they usually act like an customer care service.
Smishing
     This happens through SMS. And attackers send malicious text messages to individuals.

Baiting

    It's leaving a trap for someone in physical or digital mode basically they would Target an employee for this.
For example they would leave a confidential information in the employee's eyesight to make them notice it.
This is how all phishing works. Shall we move into next topic

The email header analysis

     As we seen how scary it is, attackers use every single way to trick us but there is a way to found if it is an phishing email.
We can find it through email's header actually email headers are digital envelopes but it is hidden it shows the exact path an email took from the sender to the recipient. Attackers can easily fake the from name but the headers reveal the truth.
There are some key headers to check 

Return path

   The actual email address where the bounced messages go, it is often different from the displayed from address.

Received

   If a phishing happens investigators usually check the list of every server the email passed through. They would read this from bottom to top to trace the truth origin IP address.

SPF, DKIM, DMARC

   I know you may think that what these terms will be actually it not complicated than you think. Let me explain it clearly.
These are the email authentication protocols.

SPF will check if the sending server is authorised to send email for that domain. It acts like a security guard who checks our Id card to let us in.

DKIM adds a digital signature to prove the e-mail wasn't altered in transit.

DMARC will tells the server what to do if both the SPF and DKIM fails in their role
  It will send that email to spam or reject it entirely.

So that's all guys we have learned about phishing today what your thought in this let me know in the comments, I hope you guys understand it well.

If you want to learn more about this you can get study guide through this

                                      THANK YOU



Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth