The Art of Deception: Vocabulary and Key Concepts

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/40

flashcard set

Earn XP

Description and Tags

This set covers essential vocabulary used by Kevin Mitnick to describe social engineering techniques, security vulnerabilities, and data classification policies.

Last updated 12:17 PM on 8/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

41 Terms

1
New cards

Social Engineering

The use of influence and persuasion to deceive people by convincing them that the social engineer is someone he is not, or by manipulation, to obtain information with or without the use of technology.

2
New cards

Crackers

Hackers who maliciously destroy people's files or entire hard drives; also referred to as vandals.

3
New cards

Script Kiddies

Novice hackers who do not bother learning technology but simply download hacker tools to break into computer systems.

4
New cards

Phone Phreaking

A type of hacking that allows individuals to explore the telephone network by exploiting phone systems and phone company employees.

5
New cards

The Human Factor

Noted as security's weakest link, representing the vulnerability that exists when individuals are manipulated or deceived due to gullibility, naivete, or ignorance.

6
New cards

Human Firewall

The people and management elements of an organization that, when properly trained, act as a defense against social engineering attacks.

7
New cards

Mark

The designated victim of a con or social engineering scheme.

8
New cards

Burn the Source

When an attacker allows a victim to recognize that an attack has taken place, making it extremely difficult to exploit that same source in the future.

9
New cards

Mail Drop

A rental mailbox, often used under an assumed name, where a social engineer has documents or packages delivered after duping a victim.

10
New cards

Loop-around

A specific test number used by phone phreaks to find other phreaks to chat with or to create a untraceable call-back number.

11
New cards

Trojan Horse

A program containing malicious or harmful code designed to damage a computer or files, or to provide an infiltrator with covert remote access.

12
New cards

Remote Command Shell

A non-graphical interface that accepts text-based commands to perform functions or run programs on a victim's computer.

13
New cards

Reverse Social Engineering

An attack where the perpetrator sets up a situation that causes the victim to encounter a problem and initiate contact with the attacker to ask for help.

14
New cards

Candy Security

A security scenario described as a 'hard crunchy shell with a soft chewy center,' where the outer firewall is strong but the internal infrastructure is weak.

15
New cards

Speakeasy Security

Security that relies solely on knowing the location of information or using a specific word or name to gain access.

16
New cards

Security Through Obscurity

An ineffective security method relying on keeping the details of how a system works secret, assuming no one outside a trusted group will circumvent it.

17
New cards

Two-Factor Authentication

The use of two different types of authentication to verify identity, such as a physical token combined with a password.

18
New cards

Password Hash

A string of gibberish resulting from a one-way encryption process performed on a password; it is intended to be irreversible.

19
New cards

Dead Drop

An Internet site in a remote country or a low-visibility physical location used by hackers or spies to leave information without being detected.

20
New cards

Malware

Slang for malicious software, including viruses, worms, and Trojan Horses that perform damaging tasks without user consent.

21
New cards

RAT

An abbreviation for Remote Access Trojan, which gives an attacker full access to a victim's computer as if they were sitting at the keyboard.

22
New cards

Root Kit

A modification to an operating system that installs one or more back doors at the system level to change the user's perception of system activity.

23
New cards

Back Door

A covert entry point providing a secret way into a user’s computer that is unknown to the user.

24
New cards

Secure Sockets Layer (SSL)

A protocol providing authentication of both client and server and encryption of information during communication on the Internet.

25
New cards

Dumpster Diving

Going through a company’s garbage to find discarded information that has value or can be used as a tool in a social engineering attack.

26
New cards

Shoulder Surfing

The act of watching a person type at a computer keyboard to detect and steal their password or other user information.

27
New cards

Enumeration

A process used by attackers to reveal details about a system, including enabled services, operating system platforms, and lists of account names.

28
New cards

Dictionary Attack

A password recovery or detection strategy that tries every word in an electronic dictionary to uncover a user's password.

29
New cards

Brute Force Attack

A password detection strategy that systematically tries every possible combination of alphanumeric characters and special symbols.

30
New cards

Spyware

Specialized software used to covertly monitor a target's computer activities, capturing keystrokes, passwords, and screenshots.

31
New cards

Silent Install

A method of installing a software application without the computer user or operator being aware that the installation is occurring.

32
New cards

Thin Client

A diskless workstation or computer where the operating system and applications reside on the corporate network rather than the local device.

33
New cards

War Driving

A technique involving driving or walking around with a laptop to detect and locate wireless networks.

34
New cards

War Dialing

A technique used to identify active modem lines within a range of telephone numbers.

35
New cards

Information Owner

A manager assigned the responsibility for protecting specific information assets and deciding the level of data classification to assign them.

36
New cards

Confidential

The highest data classification for information intended for use ONLY within the organization, such as trade secrets or proprietary source code.

37
New cards

Private

Data classification for personal employee information such as medical history, bank account details, or salary history.

38
New cards

Internal

Data classification for information freely shared with employees but requiring a confidentiality agreement before being disclosed to third parties.

39
New cards

Public

Data classification for information specifically designated for release to the public, such as press releases or brochures.

40
New cards

ANI

Abbreviation for Automatic Number Identification, a service that provides the billing number of a calling party for identification purposes.

41
New cards

Butyl Mercaptan

A harmless chemical that creates the odor of a natural gas leak, sometimes used by intruders to cause an emergency evacuation as a diversion.