{"id":24896,"date":"2015-08-03T00:00:00","date_gmt":"2015-08-03T00:00:00","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/nohacked-how-to-recognise-and-protect-yourself-against-social-engineering\/"},"modified":"2015-08-03T00:00:00","modified_gmt":"2015-08-03T00:00:00","slug":"nohacked-how-to-recognise-and-protect-yourself-against-social-engineering","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/nohacked-how-to-recognise-and-protect-yourself-against-social-engineering\/","title":{"rendered":"#NoHacked: How to recognise and protect yourself against social engineering"},"content":{"rendered":"<p class=\"gargardate\">Monday, August 03, 2015<\/p>\n<p>\n  Today in our #NoHacked campaign, we&#8217;ll be talking about social engineering. Follow along with<br \/>\n  discussions on <a href=\"https:\/\/twitter.com\/googlesearchc\" class=\"external-link\">Twitter<\/a> and<br \/>\n  <a href=\"https:\/\/google.com\/+googlewebmasters\" class=\"external-link\">Google+<\/a><br \/>\n  using the #nohacked hashtag.<br \/>\n  (<a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/nohacked-how-to-avoid-being-the-target-of-hackers\/\">Part 1<\/a>)\n<\/p>\n<p><img decoding=\"async\" alt height=\"320\" src=\"https:\/\/alienroad.com\/wp-content\/uploads\/kb-gorsel\/g-243d9316e433.png\" loading=\"lazy\" width=\"640\"><\/p>\n<p>\n  If you&#8217;ve spent some time on the web, you have more than likely encountered some form of<br \/>\n  <a href=\"https:\/\/en.wikipedia.org\/wiki\/Social_engineering_(security)\" class=\"external-link\">social engineering<\/a>.<br \/>\n  Social engineering attempts to extract confidential information from you by manipulating or<br \/>\n  tricking you in some way.\n<\/p>\n<h2 id=\"phishing\" tabindex=\"-1\">Phishing<\/h2>\n<p>\n  You might be familiar with phishing, one of the most common forms of social engineering. Phishing<br \/>\n  sites and emails mimic legitimate sites and trick you into entering confidential information like<br \/>\n  your username and password into these sites. A<br \/>\n  <a href=\"https:\/\/research.google.com\/pubs\/pub43469.html\" class=\"external-link\">recent study from Google<\/a><br \/>\n  found that some phishing sites can trick victims 45% of the time! Once a phishing site has your<br \/>\n  information, the information will either be sold or be used to manipulate your accounts.\n<\/p>\n<h2 id=\"other-forms-of-social-engineering\" tabindex=\"-1\"> Other Forms of Social Engineering<\/h2>\n<p>\n  As a site owner, phishing isn&#8217;t the only form of social engineering that you need to watch out<br \/>\n  for. One other form of social engineering comes from the software and tools used on your site. If<br \/>\n  you download or use any<br \/>\n  <a href=\"https:\/\/en.wikipedia.org\/wiki\/Content_management_system\" class=\"external-link\">Content Management System<\/a><br \/>\n  (CMS), plug-ins, or add-ons, make sure that they come from reputable sources like directly from<br \/>\n  the developer&#8217;s site. Software from non-reputable sites can contain malicious exploits that allow<br \/>\n  hackers to gain access to your site.\n<\/p>\n<p>\n  For example, Webmaster Wanda was recently hired by Brandon&#8217;s Pet Palace to help create a site.<br \/>\n  After sketching some designs, Wanda starts compiling the software she needs to build the site.<br \/>\n  However, she finds out that Photo Frame Beautifier, one of her favorite plug-ins, has been taken<br \/>\n  off the official CMS plug-in site and that the developer has decided to stop supporting the<br \/>\n  plug-in. She does a quick search and finds a site that offers an archive of old plug-ins. She<br \/>\n  downloads the plug-in and uses it to finish the site. Two months later, a notification in Search<br \/>\n  Console notifies Wanda that her client&#8217;s site has been hacked. She quickly scrambles to fix the<br \/>\n  hacked content and finds the source of the compromise. It turns out the Photo Frame Beautifier<br \/>\n  plug-in was modified by a third party to allow malicious parties to access the site. She removed<br \/>\n  the plug-in, fixed the hacked content, secured her site from future attacks, and filed a<br \/>\n  reconsideration request in Search Console. As you can see, an inadvertent oversight by Wanda led<br \/>\n  to her client&#8217;s site being compromised.\n<\/p>\n<h2 id=\"protecting-yourself-from-social-engineering-attacks\" tabindex=\"-1\">Protecting Yourself from Social Engineering Attacks<\/h2>\n<p>\n  Social engineering is effective because it&#8217;s not obvious that there&#8217;s something wrong with what<br \/>\n  you&#8217;re doing. However, there are a few basic things you can do protect yourself from social<br \/>\n  engineering.\n<\/p>\n<ul>\n<li>\n    <b>Stay vigilant:<\/b> Whenever you enter confidential information online or install website<br \/>\n    software, have a healthy dose of skepticism. Check URLs to make sure you&#8217;re not typing<br \/>\n    confidential information into malicious sites. When installing website software make sure the<br \/>\n    software is coming from known, reputable sources like the developer&#8217;s site.\n  <\/li>\n<li>\n    <b>Use two-factor authentication:<\/b> Two-factor authentication like Google&#8217;s<br \/>\n    <a href=\"https:\/\/www.google.com\/landing\/2step\/\" class=\"external-link\">2-Step Verification<\/a> adds<br \/>\n    another layer of security that helps protect your account even if your password has been stolen.<br \/>\n    You should use two-factor authentication on all accounts where possible. We&#8217;ll be talking more<br \/>\n    in-depth next week about the benefits of two-factor authentication.\n  <\/li>\n<\/ul>\n<p>Additional resources about social engineering:<\/p>\n<ul>\n<li>\n    Learn more about<br \/>\n    <a href=\"https:\/\/support.google.com\/accounts\/answer\/75061\" class=\"external-link\">how to protect yourself from phishing attacks<\/a>\n  <\/li>\n<li>\n    <a href=\"https:\/\/www.google.com\/safebrowsing\/report_phish\/\" class=\"external-link\">Report a Phishing Page<\/a>\n  <\/li>\n<li>\n    <a href=\"https:\/\/support.google.com\/faqs\/answer\/2952493\" class=\"external-link\">Avoid and report Google scams<\/a>\n  <\/li>\n<li>\n    <a href=\"https:\/\/support.google.com\/wallet\/answer\/105822\" class=\"external-link\">Identify &#8220;phishing&#8221; and &#8220;spoofing&#8221; emails<\/a>\n  <\/li>\n<\/ul>\n<p>\n  If you have any additional questions, you can post in the<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/go\/community\" class=\"external-link\">Webmaster Help Forums<\/a><br \/>\n  where a community of webmasters can help answer your questions. You can also join our<br \/>\n  <a href=\"https:\/\/plus.google.com\/events\/csqjnqe8vl28qbn526makjecobc\" class=\"external-link\">Hangout on Air about Security<\/a><br \/>\n  on August 26.\n<\/p>\n<p class=\"byline-author\">\n  Posted by Eric Kuan, Webmaster Relations Specialist and Yuan Niu, Webspam Analyst<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Monday, August 03, 2015 Today in our #NoHacked campaign, we&#8217;ll be talking about social engineering. Follow along with discussions on Twitter and Google+ using the #nohacked hashtag. (Part 1) If you&#8217;ve spent some time on the web, you have more than likely encountered some form of social engineering. Social engineering attempts to extract confidential information [&hellip;]<\/p>\n","protected":false},"menu_order":83350,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[665],"ar_kb_etiket":[],"class_list":["post-24896","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-blog"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24896\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27078"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=24896"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=24896"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=24896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}