📖 What is Baiting?
Baiting is a social engineering technique that promises a reward to lure a victim into a trap, such as leaving a malware-infected USB drive in a public area. The attacker relies on the victim's curiosity or greed to prompt them to plug the device in.
"This differs from phishing because it usually involves a physical medium (like a USB or CD) rather than a digital message."
📚 Certification: CompTIA PenTest+ (PT0-002)
🔑 What are the Key Concepts of Baiting?
- ▸ Reliance on physical media, such as USB drives or external hard disks, to deliver malicious payloads directly to a target's workstation.
- ▸ Exploitation of psychological triggers, specifically curiosity or greed, often achieved by using enticing labels like 'Confidential' or 'Payroll' on the device.
- ▸ The delivery of malware via auto-run scripts or by tricking the user into manually executing a file hidden on the media.
- ▸ Integration into physical penetration testing to evaluate employee adherence to security policies regarding unauthorized hardware and removable media.
🎯 How does Baiting appear on the PT0-002 Exam?
You may be asked to identify the specific social engineering attack when a scenario describes an attacker leaving 'free' USB drives in a company's lobby to gain internal network access.
A scenario might describe a penetration tester using a 'lost' USB drive labeled 'Q4 Salary Increases' to test the security awareness of a corporate finance department, requiring you to categorize the attack as baiting.
❓ Frequently Asked Questions
What is the primary distinction between baiting and phishing?
Phishing relies on digital communication, such as email or SMS, to deceive victims. Baiting specifically uses a physical lure or a promised reward to trick the user into compromising their system.
Can baiting be performed without a physical device?
Yes, digital baiting occurs when attackers offer enticing free downloads, such as 'cracked' software or free movie links, to lure users into installing malware on their devices via a website.