Social engineering · 社会工程学
This page needs a recent browser (with SharedArrayBuffer support). Please update Chrome, Edge, Firefox or Safari to the latest version. · 此页面需较新浏览器(支持 SharedArrayBuffer)。请升级 Chrome、Edge、Firefox 或 Safari 至最新版本。
English
Hacking the human
- The weakest part of any system is often people, not computers.
- Social engineering means tricking a person into giving away secrets or access. No malware needed.
中文
攻击“人”这一环
- 任何系统最薄弱的部分往往是人,而不是计算机。
- 社会工程学指的是哄骗一个人交出秘密或访问权限。完全不需要恶意软件。
English
Phishing and pharming
- Phishing — a fake email or message that looks real, asking you to "log in" on a fake site that steals your password.
- Pharming — redirecting you to a fake website even when you typed the correct address.
- Both aim to steal your login details by pretending to be a site you trust.
中文
钓鱼与域欺骗
- 钓鱼(phishing) —— 一封看起来很真的假邮件或消息,要你去一个假网站“登录”,从而窃取你的密码。
- 域欺骗(pharming) —— 把你重定向到假网站,哪怕你输入的是正确的网址。
- 两者都假冒你信任的网站,目的是盗取你的登录信息。
English
Spotting a phishing message
- Check the sender's address and the link — hover to see where it really goes.
- Watch for urgency ("act now or your account closes!") and spelling mistakes.
- A real bank will never ask for your password by email.
中文
识别钓鱼消息
- 检查发件人地址和链接 —— 把鼠标悬停上去,看清它真正指向哪里。
- 警惕紧迫感(“立即操作,否则账户将被关闭!”)和拼写错误。
- 真正的银行绝不会通过邮件索要你的密码。
English
Other tricks
- Shoulder surfing — simply watching you type your PIN.
- Baiting — leaving an infected USB stick for a curious person to plug in.
- The defence is awareness: slow down and check before you click or type.
Covers: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
中文
其他伎俩
- 肩窥(shoulder surfing) —— 仅仅是在旁边看你输入 PIN。
- 诱饵(baiting) —— 故意留下一个带毒的 U 盘,等好奇的人把它插上。
- 防御之道在于警觉:在点击或输入之前,慢下来,核对一下。
涵盖:IGCSE 5.3(钓鱼、域欺骗、社会工程学)、AP CSP Big Idea 5。
English
Now you try
- First build a tiny phishing filter: check the sender's address and where the link really points.
- Then match three more tricks to their names — exactly what the exam asks you to do.
中文
现在你来试
- 先做一个小小的钓鱼过滤器:检查发件人地址,以及链接真正指向哪里。
- 然后把另外三种伎俩和它们的名字配对 —— 考试正是这样考的。
English
Common mistakes
- The weakest link is often people, not software.
- Phishing tricks you into giving up secrets — check the sender and the link first.
中文
常见错误
- 最薄弱的环节往往是人,而不是软件。
- 钓鱼诱骗你交出秘密——先检查发件人和链接。
Build a tiny phishing filter. The real bank writes from addresses ending @mybank.com and its links start with https://mybank.com. Print phishing if either check fails, otherwise ok. · 做一个小小的钓鱼过滤器。真正的银行只用以 @mybank.com 结尾的地址发信,链接都以 https://mybank.com 开头。任一检查不通过就打印 phishing,否则打印 ok。
Click Run to see the output here. · 点击“运行”查看此处输出。
Name the trick. Set each variable to shoulder surfing, baiting or · 或 pharming. · 说出伎俩的名字。把每个变量设为 shoulder surfing、baiting 或 pharming。
Click Run to see the output here. · 点击“运行”查看此处输出。