1 Cybersecurity (Security) and P4 Programmable Switches Social Engineering Attacks Elie Kfoury, Jorge Crichigno University of South Carolina http:ce.sc.educyberinfra Western Academy Support and Training Center (WASTC) University of
"1 Cybersecurity (Security+) and P4 Programmable" is the property of its rightful owner. Permission is granted to
download and print the materials on this website for personal, non-commercial use only, and to display it
on your personal computer provided you do not modify the materials and that you retain all copyright
notices contained in the materials. By downloading content from our website, you accept the terms of this
agreement.
Presentation Transcript
01
1 Cybersecurity (Security+) and P4
Programmable Switches
Social Engineering Attacks
Elie Kfoury, Jorge Crichigno
University of South Carolina
http://ce.sc.edu/cyberinfra
Western Academy Support and Training Center (WASTC)
University of South Carolina (USC)
Energy Sciences Network (ESnet)
June 20th, 2023<br>
02
Outline 2 Social engineering attacks definition
Social engineering techniques
Phishing emails
Credentials harvesting
Reverse shell<br>
03
Social Engineering 3 Technology is not always needed for attacks on IT
Social engineering gathers information by relying on the weaknesses of individuals
It relies on the psychological approaches to persuade a victim<br>
04
Social Engineering 4 Technology is not always needed for attacks on IT
Social engineering gathers information by relying on the weaknesses of individuals
It relies on the psychological approaches to persuade a victim Ciampa, Mark. CompTIA security+ guide to network security fundamentals. Cengage Learning, 2021.<br>
05
Social Engineering 5 Impersonation
Masquerade as a real or fictitious character
Play out the role of that person on a victim
Impersonated parties include IT support, manager, trusted third party
Phishing
Sending (millions) email claiming to be from legitimate source
Trick user into giving private info: password, credit card number, etc.
Variation of phishing attacks
Pharming: automatically redirects the user to the fake site
Spear phishing: targets only specific users; emails are customized
Whaling: spear phishing targeting “big fish,” (wealthy individuals)
Vishing: Instead of using email, a phone call can be used instead (voice phishing)<br>
06
Phishing Emails 6 Phishing emails are hard to distinguish from legitimate ones
Attacker uses logos and colors identical to those provided by a legitimate entity https://www.newcmi.com/blog/tips-for-detecting-a-phishing-email<br>
07
Credentials Harvesting Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts<br>
08
Credentials Harvesting 8 Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts Attacker www.facebook.com Clone HTML Host HTML on attacker’s server http://216.0.0.10<br>
09
Credentials Harvesting 9 Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts Attacker www.facebook.com Victim Send phishing email containing a link to http://216.0.0.10 Clone HTML Host HTML on attacker’s server http://216.0.0.10<br>
10
Credentials Harvesting 10 Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts Attacker www.facebook.com Victim Credentials Clone HTML Host HTML on attacker’s server Send phishing email containing a link to http://216.0.0.10 http://216.0.0.10 email password<br>
11
Credentials Harvesting 11 Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts Attacker www.facebook.com Victim Credentials Clone HTML Host HTML on attacker’s server Forward Send phishing email containing a link to http://216.0.0.10 http://216.0.0.10 email password email password<br>
12
Credentials Harvesting 12 Gathering sensitive user credentials, such as usernames and passwords, with the intent of unauthorized access to systems or accounts Attacker www.facebook.com Victim Credentials Clone HTML Host HTML on attacker’s server Forward Send phishing email containing a link to http://216.0.0.10 http://216.0.0.10 email password email password<br>
13
Reverse Shell 13 Attacker establishes a connection from the victim to their own system
Gain full shell access to the victim’s machine Attacker Create malicious payload / Trojan<br>
14
Reverse Shell 14 Attacker establishes a connection from the victim to their own system
Gain full shell access to the victim’s machine Attacker Create malicious payload / Trojan 216.0.0.10:4444 Starts listener<br>
15
Reverse Shell 15 Attacker establishes a connection from the victim to their own system
Gain full shell access to the victim’s machine Attacker Victim Create malicious payload / Trojan 216.0.0.10:4444 Starts listener Send email containing malicious payload<br>
16
Reverse Shell 16 Attacker establishes a connection from the victim to their own system
Gain full shell access to the victim’s machine Attacker Victim Execute payload Create malicious payload / Trojan 216.0.0.10:4444 Starts listener Send email containing malicious payload Reverse TCP shell opened to Attacker’s machine<br>
17
Reverse Shell 17 Attacker establishes a connection from the victim to their own system
Gain full shell access to the victim’s machine Attacker Victim Execute payload Create malicious payload / Trojan 216.0.0.10:4444 Starts listener Send email containing malicious payload Reverse TCP shell opened to Attacker’s machine Execute remote commands on victim’s machine
(e.g., install backdoor, keylogger, spyware, etc.)<br>