Social engineering · วิศวกรรมสังคม
Hacking the human
- The weakest part of any system is often people, not computers.
- Social engineering means tricking a person into giving away secrets or access. No malware needed.
แฮกมนุษย์
- จุดอ่อนของระบบส่วนใหญ่มักไม่ใช่คอมพิวเตอร์ แต่คือ มนุษย์
- Social engineering (วิศวกรรมทางสังคม) คือการหลอกลวงบุคคลให้เปิดเผยข้อมูลลับหรือสิทธิ์เข้าถึง ไม่ต้องใช้มัลแวร์
Phishing and pharming
- Phishing — a fake email or message that looks real, asking you to "log in" on a fake site that steals your password.
- Pharming — redirecting you to a fake website even when you typed the correct address.
- Both aim to steal your login details by pretending to be a site you trust.
Phishing และ pharming
- Phishing (การลวงด้วยอีเมล) — อีเมลหรือข้อความปลอมที่ดูเป็นจริง โดยขอให้คุณ "เข้าสู่ระบบ" บนเว็บไซต์ปลอมเพื่อขโมยรหัสผ่านของคุณ
- Pharming (การ redirection แบบปลอม) — redirect คุณไปยังเว็บไซต์ปลอม แม้ว่าคุณจะพิมพ์ที่อยู่ที่ถูกต้องแล้วก็ตาม
- ทั้งสองวิธีมีเป้าหมายเพื่อขโมยข้อมูลการเข้าสู่ระบบของคุณโดย pretending เป็นเว็บไซต์ที่คุณไว้ใจ
Spotting a phishing message
- Check the sender's address and the link — hover to see where it really goes.
- Watch for urgency ("act now or your account closes!") and spelling mistakes.
- A real bank will never ask for your password by email.
การระบุข้อความ Phishing
- ตรวจสอบ ที่อยู่ผู้ส่ง และ ลิงก์ — แตะค้างไว้เพื่อดูว่ามันนำไปยังที่ใดจริงๆ
- ระวังความรู้สึก เร่งด่วน (เช่น "กระทำทันทีมิฉะนั้นบัญชีของคุณจะถูกปิด!") และ ข้อผิดพลาดทางorthography
- ธนาคารที่แท้จริงจะไม่เคยขอรหัสผ่านของคุณผ่านอีเมล
Other tricks
- Shoulder surfing — simply watching you type your PIN.
- Baiting — leaving an infected USB stick for a curious person to plug in.
- The defence is awareness: slow down and check before you click or type.
Covers: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
เทคนิคอื่นๆ
- Shoulder surfing — การแอบมองคุณwhileกำลังพิมพ์รหัส PIN ของคุณ
- Baiting — ทิ้งแฟลชไดรฟ์ที่มีไวรัสไว้เพื่อให้คนอยากรู้อยากเห็นนำไปเสียบ
- การป้องกันคือ ความตระหนักรู้: ช้าลงและตรวจสอบก่อนคลิกหรือพิมพ์
ครอบคลุม: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
Now you try
- First build a tiny phishing filter: check the sender's address and where the link really points.
- Then match three more tricks to their names — exactly what the exam asks you to do.
ลองดูเลย
- สร้างตัวกรอง phishing ขนาดเล็กก่อน: ตรวจสอบที่ส่งอีเมลและลิงก์นั้นจริงๆ แล้วไปไหน
- จากนั้นจับคู่เทคนิคอีกสามอย่างกับชื่อของพวกมัน — ตามที่ข้อสอบต้องการให้คุณทำ
Common mistakes
- The weakest link is often people, not software.
- Phishing tricks you into giving up secrets — check the sender and the link first.
ข้อผิดพลาดที่พบบ่อย
- จุดอ่อนมักจะเป็นคน ไม่ใช่ซอฟต์แวร์
- Phishing หลอกลวงให้คุณเปิดเผยข้อมูลลับ — ตรวจสอบผู้ส่งและลิงก์ก่อนเสมอ
Build a tiny phishing filter. The real bank writes from addresses ending @mybank.com and its links start with https://mybank.com. Print phishing if either check fails, otherwise ok. · สร้างฟิลเตอร์ฟิชชิ่งขนาดเล็ก ธนาคารจริงส่งจากที่อยู่ที่ลงท้ายด้วย @mybank.com และลิงก์ของมันเริ่มต้นด้วย https://mybank.com. พิมพ์ phishing หากการตรวจสอบใดตรวจสอบหนึ่งล้มเหลว มิฉะนั้นพิมพ์ ok
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่
Name the trick. Set each variable to shoulder surfing, baiting or pharming. · ชื่อกุญแจ ตั้งค่าตัวแปรแต่ละตัวเป็น shoulder surfing, baiting หรือ pharming
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่