<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=DMansy</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=DMansy"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/DMansy"/>
	<updated>2026-09-10T08:02:56Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14659</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14659"/>
		<updated>2024-04-04T12:02:25Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources.&lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the &amp;quot;research&amp;quot; stage to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion.&lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved.&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing:&lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving:&lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favors to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation:&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information:&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority:&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help:&lt;br /&gt;
: Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets.&lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown.&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing:&lt;br /&gt;
: Mail phishing is a well-known method; attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action.&lt;br /&gt;
;Spear Phishing:&lt;br /&gt;
: Spear phishing involves a more targeted approach; these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling:&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in this method targets of a high-profile such as CEOs or public figures are the focus. It requires extensive research to gather information for a successful spoof.&lt;br /&gt;
;Baiting:&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to prompt action quickly.&lt;br /&gt;
;Scareware:&lt;br /&gt;
: Scareware exploits the tendency to act rashly when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks associated with freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks, thus highlighting the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness:&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing:&lt;br /&gt;
: Through experiencing the attacker&#039;s perspective, participants learn about the tactics used by cybercriminals.&lt;br /&gt;
;Promote Alertness:&lt;br /&gt;
: The exercise highlights the importance of exercising caution when sharing online.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to personalize an email to an employee, faking familiarity. It begins with users being prompted to access publicly available social media data to gather information about the fictional individual.&lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The email seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the user receives a short text explaining the tactics behind this attack, highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
== Shoulder Surfing Exercise ==&lt;br /&gt;
The exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and user.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
=== Purpose ===&lt;br /&gt;
; Highlighting the Simplicity of Shoulder Surfing:&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
; Promoting Good Password Hygiene:&lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
; Raising Awareness about Password Complexity:&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
=== Scenario ===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by &amp;quot;hacking&amp;quot; a web page. It begins with participants suspecting a coworker of stealing a project and needing evidence to confirm their suspicions. Participants are tasked with extracting information based on the work environment and a shoulder surfing snapshot. Using the observed information, participants attempt to access the coworker&#039;s given data on the site. Once participants successfully &amp;quot;hack&amp;quot; the profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.&lt;br /&gt;
* K. D. Mitnick, The Art of Deception. Wiley, 2002. &lt;br /&gt;
* N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926&lt;br /&gt;
* R. B. Cialdini, Influence: The Psychology of Persuasion. HarperBusiness, 2006.&lt;br /&gt;
* R. Salama, F. Al-Turjman, S. Bhatla, and S. P. Yadav, “Social engineering attack types and prevention techniques- a survey,” in 2023 International Conference on Computational Intelligence, Communication Technology and Networking CICTN), 2023, pp.817–820.&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14658</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14658"/>
		<updated>2024-04-04T12:00:23Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources.&lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the &amp;quot;research&amp;quot; stage to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion.&lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved.&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing:&lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving:&lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favors to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation:&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information:&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority:&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help:&lt;br /&gt;
: Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets.&lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown.&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing:&lt;br /&gt;
: Mail phishing is a well-known method; attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action.&lt;br /&gt;
;Spear Phishing:&lt;br /&gt;
: Spear phishing involves a more targeted approach; these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling:&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in this method targets of a high-profile such as CEOs or public figures are the focus. It requires extensive research to gather information for a successful spoof.&lt;br /&gt;
;Baiting:&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to prompt action quickly.&lt;br /&gt;
;Scareware:&lt;br /&gt;
: Scareware exploits the tendency to act rashly when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks associated with freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks, thus highlighting the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness:&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing:&lt;br /&gt;
: Through experiencing the attacker&#039;s perspective, participants learn about the tactics used by cybercriminals.&lt;br /&gt;
;Promote Alertness:&lt;br /&gt;
: The exercise highlights the importance of exercising caution when sharing online.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to personalize an email to an employee, faking familiarity. It begins with users being prompted to access publicly available social media data to gather information about the fictional individual.&lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The email seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the user receives a short text explaining the tactics behind this attack, highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
== Shoulder Surfing Exercise ==&lt;br /&gt;
The exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and user.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
=== Purpose ===&lt;br /&gt;
; Highlighting the Simplicity of Shoulder Surfing:&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
; Promoting Good Password Hygiene:&lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
; Raising Awareness about Password Complexity:&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
=== Scenario ===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by &amp;quot;hacking&amp;quot; a web page. It begins with participants suspecting a coworker of stealing a project and needing evidence to confirm their suspicions. Participants are tasked with extracting information based on the work environment and a shoulder surfing snapshot. Using the observed information, participants attempt to access the coworker&#039;s given data on the site. Once participants successfully &amp;quot;hack&amp;quot; the profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.&lt;br /&gt;
* K. D. Mitnick, The Art of Deception. Wiley, 2002. &lt;br /&gt;
* N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14657</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14657"/>
		<updated>2024-04-04T11:47:28Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources. &lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the “research” stage, to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion. &lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved. &lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
 	&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing: &lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving: &lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favours to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help&lt;br /&gt;
:Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets. &lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown. &lt;br /&gt;
&lt;br /&gt;
;Mail Phishing&lt;br /&gt;
: Mail phishing is a well-known method, attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action. &lt;br /&gt;
;Spear Phishing&lt;br /&gt;
: Spear phishing involves a more targeted approach, these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in  this method targets of a  high-profile such as CEOs or public figures are the focus. It requires extensive research, to gather information for a successful spoof. &lt;br /&gt;
;Baiting&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to quickly needed action. &lt;br /&gt;
;Scareware&lt;br /&gt;
: Scareware exploits the tendency to act rash when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS  that lead to malware or fake websites collecting sensitive information. &lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks about freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks. Also underlining the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing&lt;br /&gt;
: Through experiencing the attackers perspective, participants learn about the tactics used by Cybercriminals.&lt;br /&gt;
;Promote Alertness&lt;br /&gt;
: The exercise shows importance of exercising caution when sharing online.&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercises aim is to personalize a Mail to a employee, faking familiarity. It begins with Users are prompted to access publicly available social media data to gather information about the fictional individual. &lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The Mail seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID t, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the User gets a short text explaining the tactics behind this attack. Highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
&lt;br /&gt;
==Shoulder Surfing Exercise==&lt;br /&gt;
The Exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and User.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
;Highlighting the Simplicity of Shoulder Surfing&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
;Promote Good Password Hygiene &lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
;Raise Awareness about Password complexity&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by “hacking” a web page. It begins with they suspect a coworker of stealing a project and need evidence to confirm their suspicions. Participants are tasked with extricating information’s based on the work environment and a shoulder surfing snapshot.&lt;br /&gt;
Using the observed information, participants attempt to get into the coworker&#039;s given data on the site.&lt;br /&gt;
Once participants successfully “hack” the Profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.&lt;br /&gt;
* K. D. Mitnick, The Art of Deception. Wiley, 2002. &lt;br /&gt;
* N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14656</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14656"/>
		<updated>2024-04-04T11:31:26Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. [1] It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. [2] The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources. &lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the “research” stage, to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion. &lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved. [2]&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
 	&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing: &lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving: &lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favours to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help&lt;br /&gt;
:Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets. &lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown. [3]&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing&lt;br /&gt;
: Mail phishing is a well-known method, attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action. [3]&lt;br /&gt;
;Spear Phishing&lt;br /&gt;
: Spear phishing involves a more targeted approach, these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success. [3]&lt;br /&gt;
;Whaling&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in  this method targets of a  high-profile such as CEOs or public figures are the focus. It requires extensive research, to gather information for a successful spoof. [3]&lt;br /&gt;
;Baiting&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to quickly needed action. [3]&lt;br /&gt;
;Scareware&lt;br /&gt;
: Scareware exploits the tendency to act rash when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS  that lead to malware or fake websites collecting sensitive information. [3]&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks about freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks. Also underlining the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing&lt;br /&gt;
: Through experiencing the attackers perspective, participants learn about the tactics used by Cybercriminals.&lt;br /&gt;
;Promote Alertness&lt;br /&gt;
: The exercise shows importance of exercising caution when sharing online.&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercises aim is to personalize a Mail to a employee, faking familiarity. It begins with Users are prompted to access publicly available social media data to gather information about the fictional individual. &lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The Mail seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID t, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the User gets a short text explaining the tactics behind this attack. Highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
&lt;br /&gt;
==Shoulder Surfing Exercise==&lt;br /&gt;
The Exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and User.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
;Highlighting the Simplicity of Shoulder Surfing&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
;Promote Good Password Hygiene &lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
;Raise Awareness about Password complexity&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by “hacking” a web page. It begins with they suspect a coworker of stealing a project and need evidence to confirm their suspicions. Participants are tasked with extricating information’s based on the work environment and a shoulder surfing snapshot.&lt;br /&gt;
Using the observed information, participants attempt to get into the coworker&#039;s given data on the site.&lt;br /&gt;
Once participants successfully “hack” the Profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references&amp;gt;&lt;br /&gt;
[1] C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.&lt;br /&gt;
[2] K. D. Mitnick, The Art of Deception. Wiley, 2002. &lt;br /&gt;
[3]N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14655</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14655"/>
		<updated>2024-04-04T11:23:20Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources. &lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the “research” stage, to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion.&lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved.&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
 	&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing: &lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving: &lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favours to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help&lt;br /&gt;
:Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets. &lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown.&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing&lt;br /&gt;
: Mail phishing is a well-known method, attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action.&lt;br /&gt;
;Spear Phishing&lt;br /&gt;
: Spear phishing involves a more targeted approach, these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in  this method targets of a  high-profile such as CEOs or public figures are the focus. It requires extensive research, to gather information for a successful spoof.&lt;br /&gt;
;Baiting&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to quickly needed action.&lt;br /&gt;
;Scareware&lt;br /&gt;
: Scareware exploits the tendency to act rash when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS  that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks about freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks. Also underlining the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing&lt;br /&gt;
: Through experiencing the attackers perspective, participants learn about the tactics used by Cybercriminals.&lt;br /&gt;
;Promote Alertness&lt;br /&gt;
: The exercise shows importance of exercising caution when sharing online.&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercises aim is to personalize a Mail to a employee, faking familiarity. It begins with Users are prompted to access publicly available social media data to gather information about the fictional individual. &lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The Mail seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID t, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the User gets a short text explaining the tactics behind this attack. Highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
&lt;br /&gt;
==Shoulder Surfing Exercise==&lt;br /&gt;
The Exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and User.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
;Highlighting the Simplicity of Shoulder Surfing&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
;Promote Good Password Hygiene &lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
;Raise Awareness about Password complexity&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by “hacking” a web page. It begins with they suspect a coworker of stealing a project and need evidence to confirm their suspicions. Participants are tasked with extricating information’s based on the work environment and a shoulder surfing snapshot.&lt;br /&gt;
Using the observed information, participants attempt to get into the coworker&#039;s given data on the site.&lt;br /&gt;
Once participants successfully “hack” the Profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14654</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14654"/>
		<updated>2024-04-04T11:03:42Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources. &lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the “research” stage, to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion.&lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved.&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
 	&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing: &lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving: &lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favours to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help&lt;br /&gt;
:Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets. &lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown.&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing&lt;br /&gt;
: Mail phishing is a well-known method, attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action.&lt;br /&gt;
;Spear Phishing&lt;br /&gt;
: Spear phishing involves a more targeted approach, these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in  this method targets of a  high-profile such as CEOs or public figures are the focus. It requires extensive research, to gather information for a successful spoof.&lt;br /&gt;
;Baiting&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to quickly needed action.&lt;br /&gt;
;Scareware&lt;br /&gt;
: Scareware exploits the tendency to act rash when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS  that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks about freely available personal information. Especially focusing on social media platforms. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks. Also underlining the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing&lt;br /&gt;
: Through experiencing the attackers perspective, participants learn about the tactics used by Cybercriminals.&lt;br /&gt;
;Promote Alertness&lt;br /&gt;
: The exercise shows importance of exercising caution when sharing online.&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercises aim is to personalize a Mail to a employee, faking familiarity. It begins with Users are prompted to access publicly available social media data to gather information about the fictional individual. &lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The Mail seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID t, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the User gets a short text explaining the tactics behind this attack. Highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
&lt;br /&gt;
==Shoulder Surfing Exercise==&lt;br /&gt;
The Exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and User.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
;Highlighting the Simplicity of Shoulder Surfing&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
;Promote Good Password Hygiene &lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
;Raise Awareness about Password complexity&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by “hacking” a web page. It begins with they suspect a coworker of stealing a project and need evidence to confirm their suspicions. Participants are tasked with extricating information’s based on the work environment and a shoulder surfing snapshot.&lt;br /&gt;
Using the observed information, participants attempt to get into the coworker&#039;s given data on the site.&lt;br /&gt;
Once participants successfully “hack” the Profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Privacy_Focused_Operating_Systems&amp;diff=14430</id>
		<title>Privacy Focused Operating Systems</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Privacy_Focused_Operating_Systems&amp;diff=14430"/>
		<updated>2024-03-02T14:30:53Z</updated>

		<summary type="html">&lt;p&gt;DMansy: Created page with &amp;quot;== Introduction ==  Privacy-focused operating systems aim to safeguard user privacy and security through advanced features such as encryption, anonymization, and strict data access control. In contrast to traditional operating systems, these privacy-centric alternatives prioritize minimizing privacy risks and thwarting unauthorized data collection, tracking, and surveillance.  === Overview of Main Problems ===  ==== Data Breaches and Unauthorized Access ====  Traditional...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
Privacy-focused operating systems aim to safeguard user privacy and security through advanced features such as encryption, anonymization, and strict data access control. In contrast to traditional operating systems, these privacy-centric alternatives prioritize minimizing privacy risks and thwarting unauthorized data collection, tracking, and surveillance.&lt;br /&gt;
&lt;br /&gt;
=== Overview of Main Problems ===&lt;br /&gt;
&lt;br /&gt;
==== Data Breaches and Unauthorized Access ====&lt;br /&gt;
&lt;br /&gt;
Traditional operating systems are vulnerable to hacking attempts, leading to unauthorized access and data loss. Privacy-focused operating systems, exemplified by Qubes OS, address these concerns by implementing innovative security measures.&lt;br /&gt;
&lt;br /&gt;
==== Data Tracking and Profiling ====&lt;br /&gt;
&lt;br /&gt;
Many operating systems and applications engage in intrusive data collection for various purposes, resulting in targeted advertising and profiling. Privacy-focused OS like Tails counteract this by limiting data collection, ensuring user consent is a primary focus.&lt;br /&gt;
&lt;br /&gt;
==== Lack of Transparency ====&lt;br /&gt;
&lt;br /&gt;
Standard operating systems often lack transparency regarding data collection and utilization. Privacy-focused OS, such as Whonix, strive to provide clear information on data usage, fostering trust between the OS and its users.&lt;br /&gt;
&lt;br /&gt;
=== Security and Privacy Features ===&lt;br /&gt;
&lt;br /&gt;
==== Qubes OS ====&lt;br /&gt;
&lt;br /&gt;
Qubes OS, first released in 2012, employs compartmentalization and isolation through &amp;quot;qubes&amp;quot; or virtual machines. This innovative security architecture ensures that even if one application is compromised, it cannot affect others, minimizing the probability of data breaches.&lt;br /&gt;
&lt;br /&gt;
==== Advantages and Benefits ====&lt;br /&gt;
&lt;br /&gt;
# Enhanced Security: Qubes OS sets a new standard by isolating compromised sections, minimizing potential damage from cyber attacks.&lt;br /&gt;
# Privacy and Anonymity: Users can categorize security levels based on needs, ensuring customizable security configurations.&lt;br /&gt;
# Challenges and Limitations: High hardware requirements and a learning curve, making it less accessible to average users.&lt;br /&gt;
# Architecture: Qubes OS categorizes security levels as &#039;work,&#039; &#039;personal,&#039; or &#039;untrusted,&#039; allowing users to customize security configurations. The architecture utilizes controlled channels for communication between qubes, ensuring user-defined communication.&lt;br /&gt;
# Unique Features: Qubes OS offers throw-away VMs for extra security, allowing users to discard virtual machines after use, reducing the risk of compromise.&lt;br /&gt;
&lt;br /&gt;
==== Tails ====&lt;br /&gt;
&lt;br /&gt;
Tails, first released in 2009, introduces the concept of &amp;quot;digital amnesia,&amp;quot; ensuring a high level of anonymity by erasing all traces in each session. It operates as a live OS, leaving no digital footprint, and prioritizes privacy and anonymity through the use of the Tor network.&lt;br /&gt;
&lt;br /&gt;
==== Advantages and Benefits ====&lt;br /&gt;
&lt;br /&gt;
# Strong Privacy Emphasis: Tails ensures no traces are left behind, promoting a high level of privacy and anonymity.&lt;br /&gt;
# Amnesic Design: Each session starts fresh, enhancing user privacy by not retaining data from older sessions.&lt;br /&gt;
# Challenges and Limitations: Potential performance limitations, persistent storage challenges, and a learning curve for new users.&lt;br /&gt;
# Architecture: Tails operates as a live OS, running from a USB stick or DVD without installing anything on the client. It prioritizes &amp;quot;digital amnesia,&amp;quot; erasing traces after each session, and employs the Tor network for enhanced privacy.&lt;br /&gt;
# Security Tools: Tails includes pre-installed security tools like KeePassXC for password management and VeraCrypt for disk encryption, enhancing overall system security.&lt;br /&gt;
&lt;br /&gt;
==== Whonix ====&lt;br /&gt;
&lt;br /&gt;
Whonix, first released in 2012, enhances user anonymity and security by combining two virtual machines – a Gateway and a Workstation. The Gateway manages Tor connections, routing all traffic through the Tor network, while the Workstation provides a secure environment for user interactions.&lt;br /&gt;
&lt;br /&gt;
==== Advantages and Benefits ====&lt;br /&gt;
&lt;br /&gt;
# Enhanced Anonymity and Privacy: Whonix channels all traffic through the Tor network, obscuring user identity and online activities.&lt;br /&gt;
# Isolation of Applications: Whonix employs two virtual machines, preventing direct communication between applications and the internet.&lt;br /&gt;
# Challenges and Limitations: Potential learning curve, resource-intensive operation, and initial setup complexity.&lt;br /&gt;
# Architecture: Whonix operates on a dual VM design with a Gateway and Workstation, ensuring user anonymity by routing all traffic through the Tor network. The separation of Gateway and Workstation enhances security by isolating applications from direct internet communication.&lt;br /&gt;
# Protection Against Malware: Whonix&#039;s isolated environment reduces the risk of malware infections, providing enhanced security against various cyber-attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references&amp;gt;&lt;br /&gt;
Nie, Xiao-wei; Feng, Deng-guo; Che, Jian-jun; Wang, Xin-pu (2006). &amp;quot;Design and implementation of security operating system based on trusted computing.&amp;quot; In: 2006 International Conference on Machine Learning and Cybernetics, pages 2776–2781.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tails Project. (2023). &amp;quot;Tails OS Architecture.&amp;quot; [https://tails.net/doc/index.en.html]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Whonix Project. (2023). &amp;quot;Whonix OS Architecture.&amp;quot; [https://www.whonix.org/wiki/About]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Qubes OS Project. (2023). &amp;quot;Qubes OS: A reasonably secure operating system.&amp;quot; [https://www.qubes-os.org/]&amp;lt;/ref&amp;gt;&lt;br /&gt;
Information Technology and Privacy. &amp;quot;https://plato.stanford.edu/entries/it-privacy/&amp;quot;. Accessed on: December 15, 2023.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yile, Fan. (2016). &amp;quot;Research on the security problem in windows 7 operating system.&amp;quot; In: 2016 Eighth International Conference on Measuring Technology and Mechatronics Automation (ICMTMA), pages 568–571.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14426</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=14426"/>
		<updated>2024-02-29T16:52:47Z</updated>

		<summary type="html">&lt;p&gt;DMansy: Created page with &amp;quot;== Social Engineering ==  &amp;#039;&amp;#039;&amp;#039;Social Engineering&amp;#039;&amp;#039;&amp;#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.  === Social Engineering Attack Cycle ===  Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Social Engineering&#039;&#039;&#039; is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
=== Social Engineering Attack Cycle ===&lt;br /&gt;
&lt;br /&gt;
Social engineering is a process that requires a deep understanding of psychology, keen senses, and tons of research in order to gain trust and access. The cycle typically involves the following stages:&lt;br /&gt;
;Research&lt;br /&gt;
: Gathering information about the target before initiating any communication. This includes studying freely accessible websites, social media profiles, and other public sources. &lt;br /&gt;
;Developing a Relationship&lt;br /&gt;
: Applying the information from the “research” stage, to establish trust or authority with the target. The goal is to convince the target to provide information or grant access seemingly of their own free will.&lt;br /&gt;
;Exploiting the Connection&lt;br /&gt;
: Asking for the desired action or information while maintaining the target&#039;s trust to avoid suspicion.&lt;br /&gt;
;Utilizing Information&lt;br /&gt;
: Reusing gathered information or access in following attacks until the original objective is achieved.&lt;br /&gt;
&lt;br /&gt;
== Social Engineering Attack Methods ==&lt;br /&gt;
&lt;br /&gt;
Social engineering encompasses various methods, including physical and psychological tactics, to gain unauthorized access.&lt;br /&gt;
&lt;br /&gt;
 	&lt;br /&gt;
&lt;br /&gt;
===Physical Attacks===&lt;br /&gt;
;Tailgating:&lt;br /&gt;
:Gaining access to restricted areas by following authorized personnel.&lt;br /&gt;
;Shoulder Surfing: &lt;br /&gt;
:Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
;Dumpster Diving: &lt;br /&gt;
:Sorting through discarded materials to obtain valuable information like passwords, customer numbers, or contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favours to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help&lt;br /&gt;
:Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
==Phishing==&lt;br /&gt;
Phishing is a subfield of social engineering, which includes multiple strategies and methods aimed to gain personal information from targets. &lt;br /&gt;
These attacks can be executed through various mediums such as Mail, text messages, or phone calls, and can be customized to the individual or sent out on a larger scale. In the following paragraphs multiple methods are shown.&lt;br /&gt;
&lt;br /&gt;
;Mail Phishing&lt;br /&gt;
: Mail phishing is a well-known method, attackers impersonate legitimate sources and send emails to a wide range of Mail addresses. These often contain links or forms to fill out. These emails typically create a sense of urgency to prompt action.&lt;br /&gt;
;Spear Phishing&lt;br /&gt;
: Spear phishing involves a more targeted approach, these Mails are tailored to specific individuals or companies. Attackers make use of personal information to create an illusion of trustworthiness and legitimacy, increasing the likelihood of success.&lt;br /&gt;
;Whaling&lt;br /&gt;
: Whaling is similar to spear phishing. The significant difference is that in  this method targets of a  high-profile such as CEOs or public figures are the focus. It requires extensive research, to gather information for a successful spoof.&lt;br /&gt;
;Baiting&lt;br /&gt;
: Baiting attacks offer baits such as random USB sticks, email attachments, or links to invoke curiosity or offer desirable goods for free. They often use offers or a sense of urgency, like last-minute sales, to quickly needed action.&lt;br /&gt;
;Scareware&lt;br /&gt;
: Scareware exploits the tendency to act rash when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS  that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks about freely available personal information. Especially focusing on social media platforms. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks. Also underlining the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
*[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing&lt;br /&gt;
: Through experiencing the attackers perspective, participants learn about the tactics used by Cybercriminals.&lt;br /&gt;
;Promote Alertness&lt;br /&gt;
: The exercise shows importance of exercising caution when sharing online.&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercises aim is to personalize a Mail to a employee, faking familiarity. It begins with Users are prompted to access publicly available social media data to gather information about the fictional individual. &lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The Mail seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID t, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the User gets a short text explaining the tactics behind this attack. Highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
&lt;br /&gt;
==Shoulder Surfing Exercise==&lt;br /&gt;
The Exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and User.&lt;br /&gt;
&lt;br /&gt;
*[[File:Shoulder.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
;Highlighting the Simplicity of Shoulder Surfing&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
;Promote Good Password Hygiene &lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
;Raise Awareness about Password complexity&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by “hacking” a web page. It begins with they suspect a coworker of stealing a project and need evidence to confirm their suspicions. Participants are tasked with extricating information’s based on the work environment and a shoulder surfing snapshot.&lt;br /&gt;
Using the observed information, participants attempt to get into the coworker&#039;s given data on the site.&lt;br /&gt;
Once participants successfully “hack” the Profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Mail.PNG&amp;diff=14424</id>
		<title>File:Mail.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Mail.PNG&amp;diff=14424"/>
		<updated>2024-02-29T16:46:48Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Shoulder2.PNG&amp;diff=14416</id>
		<title>File:Shoulder2.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Shoulder2.PNG&amp;diff=14416"/>
		<updated>2024-02-29T16:40:29Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Shoulder.PNG&amp;diff=14415</id>
		<title>File:Shoulder.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Shoulder.PNG&amp;diff=14415"/>
		<updated>2024-02-29T16:40:18Z</updated>

		<summary type="html">&lt;p&gt;DMansy: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DMansy</name></author>
	</entry>
</feed>