Today I learned a very valuable lesson that I think should be shared with everyone. Today when I went to log into my e-mail it would not let me in. I could not understand why it would not let me in. But after several failed attempts I decided to just change my password. well this worked, but what I found out was that my account had been hacked and my password had been changed. Now the good thing about this was it had been hacked by someone I knew very very well so nothing else was done to my account. His point was to show me just how easy it was to get into someone's account if a hacker really wanted to, which could result in ID theft and many other very bad things. I was so impressed by this I asked him to write the following article so everyone could be more informed. Please read the following article and share it with everyone you know, it’s very very good. The pictures were provided by me.
Hello everyone,
This article is targeted towards online account security. Now just about everyone has an online account of some sort whether it be an e-mail account or your banking account. I am not going to focus on actual account hacking through programs, but something many of you may be unaware of. The method I will talk about is called Social Engineering. Social Engineering is a method of hacking used though general conversation. This method can be the most dangerous kind because you are giving a hacker the information he or she wants straight from your own mouth.
For example: Let’s say there is someone at work that wants to hack your e-mail account. If they wanted to know your e-mail address (which is half the battle) all they could do is simply say something like “Hey, I got this e-mail the other day that I thought was pretty funny, what’s your e-mail address?” Like most people you would probably give it to them. Now I’m not saying don’t give out your address, just be proactive. Now once they have your e-mail address then can go to let’s say hotmail.com (if you gave them an msn e-mail address) from this point on they would most likely click on the “Forgot password?” link in which they can use reset your password provided they know enough about you. Most online accounts ask you for general information when resetting your password such as: City, State, Zip code, and a secret question. Chances are if you work with them they already know you city, state, and possibly zip code. The secret questions can be anything from: Your first pet, mother’s maiden name, favorite vacation spot, where you met your spouse. All of these answers can easily be drawn out of an unsuspecting victim. Let’s say you set your secret question to “Favorite vacation spot” and the answer might be something like “San Diego”. Now three days have passed and it’s Thursday at work. That co-worker sent you an e-mail containing something you thought was pretty funny, and he came to ask you what you thought of it. I’m going to do a sort of role play for a minute.
Victim “That e-mail was great, where did you get it?”
Hacker “Oh, one of my friends set it to me the other day, glad you liked it”
Hacker “Hey, I’m thinking of going on vacation in a few weeks, where do you usually go?”
Victim “Well sometimes I go to Florida, or California, I like it where its hot.”
Hacker “Yea me too! Do you have family there?”
Victim “ I do in California, but not Florida, I like going to California for that reason.”
Hacker “Yea, I have family there as well, where in California do you visit?”
Victim “San Diego”
Hacker “Really, I heard it’s great there, I may go to Florida, I have never been there, where do you go?”
Victim “Palm Beach, it’s really humid though!”
Now the hacker has two guesses at to where your favorite vacation spot is, and guess what you told him! Now the next time he tries to reset you password he will more than likely know you secret answer to your question. If by chance it’s wrong, all he has to do is simply go up to you and keep talking to you about vacation. Once he has all the correct information the account is his, he can change your secret question and answer so when you try to reset your own password you fail. This is very important because some people get bank statements and other sensitive date sent to their e-mail. This scenario does not just have to be at work, it can be anywhere, your favorite store in which you have a favorite sales person (they are nosy by nature), or for you women it can be your barber. The ways to avoid putting yourself at risk is simple. DO NOT directly answer your secret question. For example if you chose the vacation question. Make your answer your favorite dinner, car, or video game. Use the same concept for all your accounts. E-mail is targeted heavily because a lot of online bank accounts are tied to them. If they hack your e-mail they can more than likely hack your bank account by requesting a password reset from the bank’s site. Most bank sites then send a link to your e-mail with instructions on how to change your password. Some of the greatest known hackers in the world use primarily Social Engineering. I remember hearing about a guy who walked into a building dressed as a technician and said he was there for server maintenance, and people led him right to the server room! From there he created a back door to the network. When he was arrested he was asked why he did it his answer was simply “It’s so easy it’s funny to me”
I have gone on for far too long if you wish to learn more about this please e-mail me at justinsalter24@gmail.com (I did half the work for you).

















