3 ms·
We had a guest lecture from a visitor who worked for a penetration testing company. It was surprising how easy he described (in person) social engineering to ga
by Robadob 12y ago
We had a guest lecture from a visitor who worked for a penetration testing company. It was surprising how easy he described (in person) social engineering to gain access to privileged areas and information to be. I can imagine that's one of the hardest areas to defend, especially when some companies have so many potentially vulnerable members of staff.
- 0xdeadbeefbabe 12y agoIf only social engineering were engineering; maybe I'd be better at it.
- Robadob 12y agoWhen a pen-testing company has a contract in place with their client absolving them of any fault, it probably makes peoples confidence in carrying out social engineering (and not getting caught) much greater.
- 6stringmerc 12y agoThat makes total sense. I've read a few of Mitnick's "Art of" books and the l0pht story is really in line with that. One technique that I found to be extremely useful, personally, is a "purposeful intellectual slowdown" with the express purpose of discovering just a couple personality traits that would lead to an exploitable route. As in, does this person like to laugh? Are they all business? It's a lot easier in person, but I've got tons of hours of phone practice through honest work that has honed the skill quite a bit. Once you find the "in" then it's easier to ramp-up the goal pursuit!
- bitexploder 12y agoUsually, you will not get completely indemnified financially. Legally, though, yes. Having a green card to do physical testing is a lot of fun. Some of the time the police do get called or whatever, I have stories. But, the short version is.... nothing happens. You have contacts high up at the company. You have a contract. It spells out you will be doing these things. You usually get paid some amount up front. It's enough to not worry about it very much and just do your job.