Social Engineering Attacks
Before doing CTF of Venus (THE PLANET SERIES), let us know about Social Engineering Attacks.

Social Engineering Attacks
Before doing CTF of Venus (THE PLANET SERIES), let us know about Social Engineering Attacks.
A social engineering attack is a type of cyberattack where someone tricks people into giving away private information or access to systems. Instead of hacking computers directly, the attacker plays on emotions like trust, fear, or curiosity to fool the victim. For example, they might pretend to be a trusted person or company to get someone to click a bad link, share a password, or download harmful software.
Let’s drive in with a practical example,
First, let us find the IP address of our Kali machine.
ifconfig

Now, we use a toolkit to perform Social engineering attacks.
setoolkit

We can see that the social engineering attack is in option one, so we can select it.
After selecting option one, we need a cloned website to capture the details, so we use Attack Vectors and in it we choose Credentials Harvester.


Here, we can see the pre-defined web templates or use site cloner to clone any site. We selected option one for default Web templates.

To clone a website, we use our Kali Linux IP address to capture the credentials on our machine.

We need to select a default template to clone a website. After picking the template, the attack will start.

Before capturing the website’s credentials, we will mail a message saying your password has expired and attach the generated link to the email.
We use a Mass mailer attack to perform this.

After Selecting the Mass mailer attack, we perform for one mail, so we use a single email address.

Now, we can use a pre-defined template or template to write an email. In this case, we are using our template to attach the generated link in the mail.

I am using my email to attack myself and attaching the generated link.


Choosing option 1, using my mail to attack.

Here, we can SET has finished sending the email to the me.

Let’s open the mail and redirect to the generated link.


I have entered the credentials using the link generated using SET.

It has captured the credentials both username and password.
What we should take away from Social Engineering Attacks:
- Constantly check the sender’s address.
- Approach over links before clicking to check where they lead.
- Be cautious of urgent or threatening messages prompting you to act quickly.
- If something feels suspicious, don’t engage — report it to IT immediately.
This exercise wasn’t about catching anyone out — it’s about learning together and becoming more resilient against real threats.
Let’s meet again at Venus CTF…
THANK YOU :)
메타데이터
- post_id
- cc541f582a7c
- slug
- social-engineering-attacks-cc541f582a7c
- url
- https://medium.com/@k05216724/social-engineering-attacks-cc541f582a7c
- canonical_url
- https://medium.com/@k05216724/social-engineering-attacks-cc541f582a7c
- author_url
- https://medium.com/@k05216724
- status
- ok
- fetched_at
- 2026-08-19 21:23:57