skip to content

Social Engineering

You will learn the attacks aimed at people, not systems: the phishing spectrum, pretexting and tailgating, and lures a correct login does not stop. Interviewers ask because most breaches start here.

on this pageshow

explore

questions

page 1 of 2

Why does an OAuth consent grant to a mailbox survive the user's password reset?

level: juniorimportance: must knowfreq 60%

answer

  1. authorization, not authentication
  2. the application holds it, not the user
  3. refresh token bound to the grant
  4. the password was never in the loop
  5. a separate record with its own owner

basics

~20 s

A consent grant is an authorization the user gave to an application, not a credential the user holds. It is a separate record with its own refresh token, so rotating the password changes nothing the application depends on.

solid answer

~50 s

Two different objects are being confused. A password is an authentication factor: it proves who is present at a sign-in. A consent grant is an authorization record created when someone clicked Accept on an application's request, saying that this registered application may act on my behalf with these scopes. The application then holds a refresh token bound to that grant and redeems it for fresh access tokens with no sign-in at all, so neither the password nor the second factor is ever in the loop. Rotate the password and you invalidate the credential; the grant record is untouched and mail keeps being read. Re-registering the second factor changes nothing either. What ends it is action against the grant and the application's tokens, which is a different object with a different owner. ATT&CK names the acquisition `T1528` and the reuse `T1550.001`.

go deeper

for a junior

Be ready to state the difference in one line: a password authenticates a person, a consent grant authorizes an application. Then say plainly that resetting one does not touch the other.

for a middle

Explain the token mechanics — the grant holds a refresh token, the application exchanges it at the token endpoint for short-lived access tokens, and that exchange never prompts for a credential or a factor.

for a senior

Show that you would reclassify the incident before acting: identify the grant and the application identity as the objects that matter, and say why the credential-focused reflex removes nothing.

for a principal

Own the framing for the organisation: which access artefacts your identity platform can issue, who is accountable for each, and why an access-removal process written only around credentials leaves a whole class of access standing.

## Two objects that get called the same thing When people say "the account was compromised", they usually mean one of two very different things. **A credential** is something the user proves themselves with: a password, a one-time code, a hardware authenticator. It is consumed at sign-in. Change it and the old one stops working. **A consent grant** is a record in the directory saying that a *registered application* may act on a user's behalf, limited to a named set of scopes such as reading mail. The user creates it by pressing Accept on a consent request. Nothing about it belongs to the user afterwards; it belongs to the application. The entire question turns on that second sentence. The attacker who ran a consent lure never obtained a credential, so there is no credential to invalidate. ## What the application actually holds A grant that includes offline access lets the application hold a **refresh token**. A refresh token is not a session and not a password: it is a bearer artefact the application presents directly to the token endpoint to obtain a fresh, short-lived access token. That exchange is machine-to-machine. There is no sign-in page, no password prompt, no second-factor challenge, and no interactive session for anyone to look at. So the loop the operator runs is: 1. Present the refresh token bound to the grant. 2. Receive a new access token, typically valid for an hour or so. 3. Call the mail API with it. 4. Repeat before the access token expires. Nothing in that loop reads the user's password, so nothing in that loop notices that the password changed. The same reasoning covers the second factor: a factor is presented at authentication, and no authentication is happening. ## How the grant got there The usual route is a lure that does not look like a phishing page at all, because it isn't one. The user receives a link to the *genuine* identity provider's consent screen, for an application the operator registered — often with a plausible name suggesting a document viewer, a scanner, or an internal tool. The user authenticates correctly, to the correct site, with the correct factor, and then approves the request. Every step of the authentication was legitimate. The deception is in the authorization, not the login. That is why the classification matters so much in practice: the story contains no stolen password, so the reflex response of "reset it" removes nothing. ## What actually ends it The grant is its own object, so the remedy is aimed at the grant and at the application identity behind it — the tokens issued against it stop being redeemable only when the authorization itself is gone. The important part for an interview is knowing *which* object you must act on and why the credential is the wrong one; the operational procedure for doing so sits with whoever owns access removal in your organisation. ## Getting the direction of the claim right A grant record proves that an authorization was recorded for a principal. It does not prove the user understood the request, and it does not prove a human was even at the keyboard when the underlying access token was last used. Conversely, a successful password rotation proves the credential changed; it proves nothing whatsoever about outstanding authorizations. ## Framework vocabulary In MITRE ATT&CK the theft of the token or grant is **Steal Application Access Token (`T1528`)** and reusing it in place of a normal logon is **Use Alternate Authentication Material: Application Access Token (`T1550.001`)**. Naming them this way is useful because it forces the distinction the question is about: the technique is described as *alternate* authentication material precisely because it substitutes for the credential path rather than travelling down it. ## The common wrong answers - "They must still have the password, or they couldn't read the mail." They never needed one. - "MFA would have stopped this." The factor is presented correctly, by the right person, at the right site, in most versions of this lure. - "The token will expire soon anyway." The *access* token will; the refresh token keeps producing new ones for as long as the grant stands. - "It is a session hijack." A session belongs to a browser and a user; this belongs to an application identity and outlives every browser involved.

  • Does re-registering the user's second factor end the attacker's access?
    No. A second factor is presented during authentication, and the application is not authenticating as the user. It redeems a refresh token bound to the grant directly at the token endpoint, which never issues a factor challenge. Re-registering the factor protects future interactive sign-ins and leaves the grant exactly as it was.
  • If not with the user's account, where does the access actually live?
    With the application identity — the service principal for the registered application in the tenant — plus the grant record binding it to a principal and a scope set. That identity was created by the operator, is not tied to any employee, and does not disappear when an employee's credential changes or when the employee leaves.
  • Does a consent grant expire on its own?
    Not reliably. Access tokens are short-lived, typically around an hour, but the grant itself commonly carries no expiry, and the refresh token keeps being exchanged while the grant stands. Treat the shelf life as indefinite until someone acts on the grant, rather than assuming time solves it.

Changing the lock on your front door does not cancel the key you gave the cleaning company last year. The key was issued to them, under a separate arrangement, and it opens the door whatever you do to your own key.

saying these in an interview costs you the question

  • Says a password reset ends the attacker's access
  • Calls the consent grant a stolen credential
  • Assumes re-registering MFA invalidates issued tokens
  • Thinks the attacker must sign in as the user to read mail
  • Claims short token lifetimes make the access self-limiting

context

open as a page

What does a credential harvest page actually hand its operator, and what kills that product?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Only the strings the victim typed, usually an account name and a password. The genuine site never saw the attempt, so nothing confirms the password is correct, and it stops being worth anything the moment the victim changes it.

open as a page

A supplier emails new bank details for a real, unpaid invoice - what attack is this and why doesn't patching help?

level: juniorimportance: must knowfreq 72%

basics

~10 s

Payment diversion: the operator changes where a genuine, already-owed payment lands. No link, attachment or malware appears anywhere in the chain, so patching, attachment scanning and endpoint controls have nothing to act on.

open as a page

An SMS lure carries only a phone number — which anti-phishing controls still apply?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Almost none. SPF, DKIM, DMARC and attachment detonation all live on the mail hop, and an SMS-plus-callback lure never crosses it. What survives is account-side: the identity controls, and whatever the service desk demands before it acts.

open as a page

In a watering-hole attack, how does the attacker target a specific group without sending anything?

level: juniorimportance: must knowfreq 66%

basics

~20 s

A watering hole works by poisoning a site only the target group reads, so the readership performs the selection. No message is sent, no recipient is ever chosen, and no mail path exists anywhere on the route.

open as a page

What does a badge reader actually grant when someone tailgates in behind a badged employee?

level: juniorimportance: must knowfreq 58%

basics

~20 s

It granted one credential presentation, not a headcount. A reader releases a lock for a few seconds and cannot tell how many bodies cross the threshold. Everyone after the first entered on a badge that is not theirs.

open as a page

Why do pretext callers impersonate an outsourced desk engineer rather than a colleague on your floor?

level: juniorimportance: must knowfreq 58%

basics

~20 s

Impersonation works where the target has no sideways check. A colleague can be confirmed by walking over or asking someone who knows them; an outsourced overnight engineer is a name nobody has met, on a rota nobody here can read.

open as a page

Why is a phishing request the recipient already performs weekly harder to refuse than an urgent one?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Because the recipient has no decision to make. A routine ask matches what they already do, so it runs on habit rather than judgment, while urgency and authority are exactly the pressure cues people are taught to notice and question.

open as a page

How can a device-code lure put a working token on an operator's device when the user's FIDO2 key was presented correctly?

level: middleimportance: must knowfreq 52%

basics

~20 s

The token is issued to whoever started the device authorization flow, not to whoever authenticated. The operator starts it, the victim types the short code at the genuine page and authenticates honestly, and the operator's waiting client collects the token.

open as a page

In a relay phishing page that reverse-proxies the real login, what does the victim's browser load?

level: middleimportance: must knowfreq 62%

basics

~20 s

The genuine page, relayed. The operator's server terminates TLS on its own domain, fetches each response from the real login origin and forwards every field both ways, ending the exchange holding the session cookie the real service issued.

open as a page

A supplier bank-change email passes SPF, DKIM and DMARC - what has that actually proved?

level: middleimportance: must knowfreq 64%

basics

~20 s

Only that the message really came from the domain shown in its From header, with that domain's blessing. It proves nothing about whether that domain is your supplier's, who typed the message, or whether the banking change is honest.

open as a page

Why does patching a browser do nothing against a fake 'update required' download prompt?

level: middleimportance: must knowfreq 58%

basics

~20 s

Patching removes software flaws, and a fake update prompt uses none. The page persuades a person to download and run an installer, so execution is granted by consent. Browser version, sandbox and patch level are all irrelevant to that.

open as a page

AutoRun is disabled fleet-wide — how does a dropped USB device still run commands?

level: middleimportance: must knowfreq 62%

basics

~10 s

AutoRun only governs how the OS handles removable storage. A device can declare itself a keyboard instead; the OS binds a keyboard driver automatically and accepts its keystrokes. No media, no setting, no prompt.

open as a page

Why does an incoming call showing your company's own number prove nothing about the caller?

level: middleimportance: must knowfreq 64%

basics

~20 s

Calling-line identity is supplied by the originating side and relayed onward; nothing in a normal call path proves the caller is entitled to the number shown. The displayed name is usually just a lookup on that asserted number.

open as a page

Across bulk, spear and executive phishing lures, which rung pays most per operator hour?

level: middleimportance: must knowfreq 62%

basics

~20 s

Usually the middle rung. Spear reuses one block of organisation-level research across dozens of named recipients, so success per recipient rises steeply while hours per recipient stay small. Bulk yields commodity accounts; executive stakes a week on one attempt.

open as a page

What must phone-based authenticator re-enrolment require that a caller with a name cannot supply?

level: seniorimportance: must knowfreq 56%

basics

~10 s

Possession, or an assertion the caller cannot make for themselves: an approval signed from an already-enrolled credential, identity proofing off the phone, or confirmation on a channel the organisation controls. Knowledge checks change nothing.

open as a page

We train staff to check sender domains and spot bad grammar — what does that actually catch?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Only the cheapest rung. Both tells are artefacts of lures the operator paid nothing for, and both vanish once the message is sent from a real mailbox on a real domain, where prose and address are genuine.

open as a page

Which company-published facts make a phishing lure credible at zero research cost?

level: juniorimportance: should knowfreq 50%

basics

~10 s

The organisation's own published surface: job adverts naming internal systems and approval chains, certificate transparency and DNS entries naming hostnames, regulatory filings naming who signs, and conference bios naming who reports to whom.

open as a page

In invoice payment diversion, how does the operator time the bank-change request, and why does timing decide it?

level: middleimportance: should knowfreq 55%

basics

~20 s

The ask is placed against an invoice that is real, already approved and about to be paid, shortly before the payment run. Riding an existing obligation means the change survives reconciliation, and paying early beats the supplier's chase.

open as a page

A dropped document fetches a single remote image on open — what does that tell whoever left it?

level: middleimportance: should knowfreq 40%

basics

~20 s

That the fetch arrived: the file was opened, roughly when, and from which egress address. It proves some client rendered the document, not that a particular person read it — and since no code ran, there is nothing to patch.

open as a page

A 40-second webinar clip clones your CTO's voice on a call - what has actually changed?

level: middleimportance: should knowfreq 47%

basics

~10 s

The price, not the possibility. Voice was never an authenticator; it was a familiarity cue that used to be expensive to fake for a named person. Cheap cloning makes anyone with public audio impersonable.

open as a page

How does a hijacked email reply chain make a lure indistinguishable from a real thread?

level: middleimportance: should knowfreq 55%

basics

~20 s

The operator has a foothold in a third party's mailbox and replies to a conversation the recipient started. The threading fields, the quoted history and the sender are all genuine, so nothing is fabricated for the recipient to notice.

open as a page

A mailbox is still being read a week after the password rotation and MFA re-registration — what does the operator hold?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Almost certainly a consent grant to an application the operator registered, not a credential. The next question is whether the grant covers one user or the whole tenant, because that decides whether one mailbox or every mailbox is exposed.

open as a page

A genuine supplier bank change and a fraudulent one look identical - what single step separates them?

level: seniorimportance: should knowfreq 47%

basics

~20 s

Contact through a route the requester did not supply. Both changes are the same fields edited by the same authorised clerk, so only a callback to a number captured at onboarding or written into the contract separates them.

open as a page

A sponsored search result served an installer, but the same link now shows the vendor's real page - why?

level: seniorimportance: should knowfreq 35%

basics

~20 s

The advertisement's click-through URL points at a redirector the operator controls. It inspects the visitor - address, geography, user agent, referrer, whether they have been seen before - and hands non-matching visitors the genuine page. One URL, two destinations.

open as a page

Why does cloning a 125 kHz proximity badge work, and which control class removes it?

level: seniorimportance: should knowfreq 34%

basics

~20 s

The card is a passive transponder that answers any powering field with the same fixed number, with no key and no challenge. Anything that hears it once can replay it. Only a credential that never transmits its secret removes the copy.

open as a page

What verification survives a caller who has the right voice, the right number and weeks of rapport?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Only a check that consumes a fact the caller did not supply and cannot influence, reached over a path they did not choose. Shared knowledge fails - weeks of friendly contact is how that history was manufactured.

open as a page

How do you price the claim that serious attackers write a bespoke phishing lure per person?

level: seniorimportance: should knowfreq 45%

basics

~10 s

In operator hours the claim is cheap: forty recipients at two hours each is roughly two operator-weeks, and much of that reading is shared across all forty. Tailoring prices the message, not the sender.

open as a page

Why is a one-time code sent to a phone number only as strong as the carrier's recovery desk?

level: middleimportance: nice to knowfreq 38%

basics

~10 s

Because a phone number is an address a carrier assigns, not a possession the user holds. Whoever talks the carrier's own recovery process into re-issuing that number receives every code routed to it.

open as a page

showing 1–30 of 38