Skip to navigation | Skip to content

Share your knowledge. Make a difference.

Social Engineering

1 - I can do better 2 - Jury's out 3 - Pretty darn good 4 - Splendiferous 5 - Awesometastic (by 0 people)   Your rating: 1 - I can do better 2 - Jury's out 3 - Pretty darn good 4 - Splendiferous 5 - Awesometastic

Ranked #15607 in Tech & Geek, #295459 overall

Rated G. (Control what you see)

Social Engineering Attacks

 

This lens is about how social engineering attacks are attempted against companies in order to gain access to computer system, data or other company assets. Social attacks are attacks which use employees as a way to gain unauthorized access and information about a company. Companies often hire security consultants to perform penetration tests against their facility to learn where the company has security weaknesses and the social engineering method is often attempted. If you are tasked with trying social engineering attacks, make sure you have written permission to avoid legal issues. This lens will cover social engineering attacks as well as methods to further access once access is achieved.

READ The Social Engineers Toolbox article by Steve Stasiukonis. This article taught me a few new tricks to use.

Icon obtained from DonnellyImages at Flickr.com

Plan Your Attack 

Have a method to your madness!

  • Visit the company's web site and gather employee names and addresses of remote locations. Email addresses could be used for a phishing attack to gain access or user credentials. You might also locate the help desk number and masquerade as an employee who has lost their password.
  • Can you identify the phone numbers associated with the business. Attacking the PBX phone exchange is a potential path for gaining more information.
  • Remember your college days? Dumpster diving can often lead to valuable information such as business contracts, employee names and who knows what else? Most companies now pay for shredding services to ensure sensitive information is not obtained by outsiders.
  • Set up surveillance and watch if employees or technicians have uniforms. It is often trivial to have patches or uniforms made to match a companies business attire or uniforms of service technician working at a location.
  • Check out the building location. Does the company own the building or is it shared with other companies? Have someone visit the front desk to ask a simple question. What security devices do you see? Pin locks, smart card readers?
  • Is a wireless network available from outside the building or from the lobby? A wireless attack might simplify the need for a social attack.
  • Can you monitor internal communications remotely? Are they using a wireless unprotected phone system?

Flickr Photos of where we are trying to go 

_dsc6506 by thedigitel

_dsc6506

_dsc6633 by thedigitel

_dsc6633

Get your t-shirts here by thedigitel

Get your t-shirts he...

_dsc6521 by thedigitel

_dsc6521

_dsc6545 by thedigitel

_dsc6545

_dsc6518 by thedigitel

_dsc6518

_dsc6558 by thedigitel

_dsc6558

_dsc6540 by thedigitel

_dsc6540

Candle & Cake! by thedigitel

Candle & Cake!

_dsc6507 by thedigitel

_dsc6507

Tools...Don't forget your tools. 

You might need a few tools to help if you are not MacGyver! Tools are usually used after physical access is gained.

When I mention Steve below, I am giving him credit for a mentioned idea which I did not know or think about until reading The Social Engineers Toolbox" article by Steve Stasiukonis.
  • Use wireless attacks if possible.
  • Lock Picks. Lock picking is becoming a new skill many computer security professionals are acquiring. If you can get physical access to the building the game is almost over.
  • A hammer and a screw driver. You will often find that the hinges on the data center's large doors to bring in equipment.
  • Steve notes that 1/4" copper tubing can often be molded and used to slide under data center doors to reach the handle from the inside.
  • Can a sound amplifier be used to listen in on employees entering or having lunch outside the building? You might learn names or current company topics.
  • Steve notes that some phone systems use RF frequencies and a RF scanner might be able to capture internal phone conversations.
  • While I have always known about sneaking in behind someone, Steve notes that a laser range finder can be used to stage yourself at an appropriate distance behind employees to follow them in when they open a door. I need to pick one of these up!
  • Steve says a night vision with infrared illumination can help you monitor activity at a location after hours.
  • Many Data Centers have raised floors that extend beyond the data centers access points. Maybe a suction cup would be useful to pull tiles and use your copper tubing to open the door.
  • Digital Audio Recorder to capture conversations.
  • Digital camera

Social Engineering Tools 

Here are a few of the odd tools that you might want to have.

Leatherman 830850 Skeletool CX Multitool

Amazon Price: Too low to display (as of 10/12/2008)

Influence Resources from Amazon 

Social Engineering relies on the fact that humans like to help each other and usually do not consider that someone may be doing something devious. Learn persuasion skills to improve your results.

Mind Hacks: Tips & Tricks for Using Your Brain (Hacks)

Amazon Price: $16.47 (as of 10/12/2008)

Influence: The Psychology of Persuasion (Collins Business Essentials)

Amazon Price: $12.21 (as of 10/12/2008)

The Most Important Thing

Ensure all of your employees are given yearly computer security training which discusses social engineering attack vectors and how to deal with them.

Employees should be trained to ask questions 

Always report suspecious behavior

  • Phone etiquette: never give out information to unauthorized persons. Always ask for a number where someone can return the call if the call seems suspicious. Never give passwords out on the phone. Do not be intimidated since this is often an attack method. Do a little reverse social engineering.
  • All employees must question unknown individuals walking around in secure areas. Employees must also ensure no one follows them into secure areas without authenticating them selves. Ask for credentials.
  • Report all suspicious phone calls or activities at work. This applies to inside as well as outside of the building.
  • Do not discuss sensitive business topics in public.

YouTube video examples of social engineering 

YouTube thumbnail
ATT's Anti Social Engineering ...

Runtime: 6:57 | 6315 views | Comments

YouTube thumbnail
Social Engineering at McDonald...

Runtime: 3:04 | 130156 views | Comments

YouTube thumbnail
Last HOPE Social Engineering s...

Runtime: 1:05 | 21001 views | Comments

Featured Security Lenses 

New Guestbook 

Like this lens? Want to share your feedback, or just give a thumbs up? Be the first to submit a blurb!

Join Squidoo and share your knowledge! 

  • Publish your knowledge of computer security by building a lens. It's easy!
X
Edmands

About Edmands

Todd is a Systems Engineer with a Masters Degree in Systems Engineering/Information Assurance and an undergraduate degree in Geography. When time permits, he builds quality Squidoo lenses or practices his hobbies (Lego Robotics, rocketry, kites and studying creativity). His lenses support National Public Radio (NPR).

Edmands's Pages

See all of Edmands's pages