Social Engineering Essay

Social Engineering (SE) is both incredibly complex and amazingly simple. What really is social engineering? We define it as the act of influencing a person to accomplish goals that may or may not be in the “target’s” best interest. This may include obtaining information, gaining access, or getting the target to take certain action. It may also include positive forms of communication such as with parents, therapists, children, spouse and others. Due to the mystery surrounding this dark art many people are afraid of it, or they feel they will never be able to accomplish a successful social engineering test. However, every time you try to get someone to do something that is in your interest, you are engaging in social engineering. From children trying to get a toy from their parents to adults trying to land a job or score the big promotion, all of it is a form of social engineering. One day we started to search for information to develop some training on the topic of SE as it applies to pentesting. We were astounded to see that the web really lacked a good source of information on this valuable topic. There was a multitude of sources of great technical pentesting info, but SE was a different story. We found plenty of stories about getting free pizzas, tons of stories of famous social engineers and their adventures and more than a few good articles, but not one site that collectively contained, developed and organized this information. Nothing even close to the level of documentation required to treat social engineering like a science…. like an

