Social engineering · Ingeniería social
Hacking the human
- The weakest part of any system is often people, not computers.
- Social engineering means tricking a person into giving away secrets or access. No malware needed.
Hackear al ser humano
- La parte más débil de cualquier sistema suelen ser las personas, no los ordenadores.
- La ingeniería social significa engañar a una persona para que revele secretos o conceda acceso. No se necesita malware.
Phishing and pharming
- Phishing — a fake email or message that looks real, asking you to "log in" on a fake site that steals your password.
- Pharming — redirecting you to a fake website even when you typed the correct address.
- Both aim to steal your login details by pretending to be a site you trust.
Phishing y pharming
- Phishing — un correo electrónico o mensaje falso que parece legítimo, en el que te piden que "inicies sesión" en un sitio web falso que roba tu contraseña.
- Pharming — redirigiéndote a un sitio web falso incluso cuando has escrito la dirección correcta.
- Ambos buscan robar tus datos de inicio de sesión haciéndose pasar por un sitio web en el que confías.
Spotting a phishing message
- Check the sender's address and the link — hover to see where it really goes.
- Watch for urgency ("act now or your account closes!") and spelling mistakes.
- A real bank will never ask for your password by email.
Cómo identificar un mensaje de phishing
- Revisa la dirección del remitente y el enlace: pasa el cursor sobre ellos para ver a dónde llevan realmente.
- Presta atención a la urgencia ("¡actúa ahora o tu cuenta se cerrará!") y a los errores ortográficos.
- Un banco real nunca pedirá tu contraseña por correo electrónico.
Other tricks
- Shoulder surfing — simply watching you type your PIN.
- Baiting — leaving an infected USB stick for a curious person to plug in.
- The defence is awareness: slow down and check before you click or type.
Covers: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
Otras técnicas
- Shoulder surfing — simplemente observarte mientras escribes tu código PIN.
- Baiting — dejar una memoria USB infectada para que alguien curioso la conecte.
- La defensa es la conciencia: frena y verifica antes de hacer clic o escribir.
Cubre: IGCSE 5.3 (phishing, pharming, ingeniería social), AP CSP Big Idea 5.
Now you try
- First build a tiny phishing filter: check the sender's address and where the link really points.
- Then match three more tricks to their names — exactly what the exam asks you to do.
Ahora tú lo intentas
- Primero construye un filtro de phishing muy básico: revisa la dirección del remitente y a dónde apunta realmente el enlace.
- Luego asocia tres técnicas más con sus nombres, exactamente como pide el examen.
Common mistakes
- The weakest link is often people, not software.
- Phishing tricks you into giving up secrets — check the sender and the link first.
Errores comunes
- El eslabón más débil suele ser la gente, no el software.
- El phishing te engaña para que entregues secretos; primero revisa al remitente y el enlace.
Build a tiny phishing filter. The real bank writes from addresses ending @mybank.com and its links start with https://mybank.com. Print phishing if either check fails, otherwise ok. · Construye un filtro de phishing pequeño. El banco real envía correos desde direcciones que terminan en @mybank.com y sus enlaces comienzan con https://mybank.com. Imprime phishing si alguna de las verificaciones falla, de lo contrario imprime ok.
Click Run to see the output here. · Haz clic en Ejecutar para ver la salida aquí.
Name the trick. Set each variable to shoulder surfing, baiting or pharming. · Nombra el truco. Establece cada variable a shoulder surfing, baiting o pharming.
Click Run to see the output here. · Haz clic en Ejecutar para ver la salida aquí.