Post: Social Engineering and Baiting
07-11-2009, 09:51 PM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Note: I BleedingPainter, nor NextGenUpdate, take legal responsiblity what is acted upon of other individuals. This post is only for educational purposes and is NOT to be acted upon. If you do, you forfeit any affiliation with BleedingPainter or NGU.

Social Engineering, defined as;
The act of manipulating people into performing actions or divulging confidential information. While similar to a confidence trick or simple fraud, the term typically applies to trickery or deception for the purpose of information gathering, fraud, or computer system access; in most cases the attacker never comes face-to-face with the victim.

Which is exactly what you want to happen, and never want to happen. You want to obtain personal information and never be confronted with the person face-to-face.

Most common forms of social engineering is for online games such as Habbo Hotel, RuneScape, even WOW. Basically on games such as these, you become friends with the Victim, you know BFFLZLZ!!! and you share each others passwords. Easy right? Right. You screw the other person over and take there stuff, just because they trusted the wrong person.

To teach basic social engineering, you have to go back to when you were a nice person and you would have never thought to look at a post like this! You're going to be the All American Kid, if you can relate to that.. you did everything right, you're nice to everyone, and you get what you want.

Now, say you wanted to find someone's secret question to their email.. (refer to my Ancient MSN Recovery) and their question is, "Where did your mother grow up?" Betting that they forgot their question, you're in, if you're slick. A conversation would go like this..

You; Hey hows it going? (talk about some dumb shit) Oh yeah did you see that new glitch in Lumber Mills?
Victim; No way! You'll have to show me and I'm doing fine, blahblahblah.
Y: Yeah my family is from Arkansa, there are a lot of lumber mills there, that's probably how I discovered it all by myself Smile And you're going to be the only person that knows besides me! LOL.
V: Thanks!
Y: Where's your family from? Like your mom and dad?
V: My mom is from New York City, that's where she grew up.

Now that's if the person is totally trust worthy, loves you, and considers you like teh l33t.

Easy enough, correct? Now you can do this certain ways, even making them accept files that they know are virii, keylogs, etc.
Have fun with it, but if you are ever caught, deny and delete Smile


Baiting; one of my personal favorites, knowing you can cheat other mean stupid people.

Step1; Get a blank disk and your virus, trojan, keylog, etc. ready. Load it on the disk.

Step2; burn it on the disk and give the disk a very curious name such as, "Beach Party 2009 with the girls" or "2009 Bank Account Info" or such.
Note; whatever you label the disk as, make sure you put files related to the name.. if you have it as bank account shit, put a few text files on it with phony info.. if it's beach party, bind the keylog to a picture so they'll open it.

Step3: Have fun and "accidentally" drop your disk some where so you'll know someone will pick it up and be a total asshole, opening it when they get home!

Step4: Wait, get info, do whatever you please with it!
(adsbygoogle = window.adsbygoogle || []).push({});

The following 4 users say thank you to DonVodka for this useful post:

KINGLAWLOR4, LordOfSpoon™, NanuGama, Tons
07-15-2009, 01:41 AM #2
Haha im the master at Social Engineering. I would give some tips to you all but if i try it on you youl know whats going on.
Thanks Bleeding, you have taught me well
07-15-2009, 02:19 AM #3
Convivium
Dieu et les Dames
how could someone ever prove they got baited? I mean they are the one that took the disc and used it.

Does the keylogger have to be load into one of the fake files?
08-03-2009, 01:05 PM #4
wow ive never thought of doing that before
09-02-2009, 03:18 PM #5
Tons
hacks 4 vbux
deleted
09-02-2009, 04:23 PM #6
Mighty Jebuz
Nerds √16 Ever!
wow thatd be a fun thing to do at school
09-02-2009, 04:44 PM #7
Velcrohead-
Little One
Lmao, I didn't know that was social engineering.

The best thing about it, is how easy it is. Seriously, you can find a load of rich young kids on games like Runescape.. all you need is to be nice to them, tell them a few little "hints", maybe share some potions and shit.. Done this so many times
09-03-2009, 01:35 AM #8
what with you and email hacks? lol
11-19-2009, 10:46 PM #9
iSaboteur
Error… Cat invasion!
i did this to someone to get their runescape account (did it YEARS ago... i hate runescape now. i only played it for like 4 months), but nice info Smile
11-19-2009, 11:27 PM #10
Smile It's kinda backstabbing and all.. but you have got to love it. To avoid shit like this it's easy too.. just use common sense. I love the blank disk thing though, people are so tempted all the time to open it! You'll never know what you will come up with if they do!

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo