Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 62 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Physical Security
Physical Security and Social engg.
EH-Net
May 25, 2013, 01:00:13 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Physical Security
(Moderator:
don
) >
Physical Security and Social engg.
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Physical Security and Social engg. (Read 9846 times)
0 Members and 1 Guest are viewing this topic.
COm_BOY
Full Member
Offline
Posts: 129
LivinG DeaD
Physical Security and Social engg.
«
on:
February 03, 2009, 10:13:45 AM »
A friend of mine got a question form a CISSP that :
A person enters an organization pretending to be an electrician and gets access to the Data Center and completes his work . In the whole procedure he does not talk to a single person .
What kind of Flaws are there in this case . He meant that is there Physical Security involved or not and is there Social Engg. involved or not .
My answer to the question was that only Physical Security is the problem , the person was not involved in Social Engg. because Social Engg. means that you interact with a human being , and in the case that person went straight to the data center , but my friend was saying that there is social engg. involved since he disguised himself .
What you guys say ?
Logged
It has become appallingly obvious that our technology has exceeded our humanity.
jason
Hero Member
Offline
Posts: 1012
Re: Physical Security and Social engg.
«
Reply #1 on:
February 03, 2009, 10:28:18 AM »
I'd call it both. If the attacker entered the building dressed as a maintenance worker and got into the data center unchallenged, that would be the social engineering bit. If they managed to do this without talking to or seeing anyone, this is a physical security issue, and it sounds like an unlikely one.
I think the example is a bit contrived though. Unless something unusual was going on in the building, or the person had a very short or concealed route into the data center, or it was in the middle of the night, etc... they would likely have run into someone. In this case, the prepared social engineering bits come into play.
«
Last Edit: February 03, 2009, 10:33:48 AM by jason
»
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Physical Security and Social engg.
«
Reply #2 on:
February 03, 2009, 10:30:17 AM »
COm_BOY,
I'm no SE expert by any stretch of the imagination, but; I'd agree with your friend that there was an element of SE involved. In some environments just 'looking like you belong' is enough to get the access you need. Whilst the 'electrician' in your example didn't speak to anyone when on site, I'd imagine that he may have been challenged more by the onsite staff if he just turned up as a civvy rather than appearing to be a sparky.
Be interested to hear some other thoughts on the scenario though...
RR
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
jadyason
Newbie
Offline
Posts: 7
Re: Physical Security and Social engg.
«
Reply #3 on:
February 10, 2009, 09:09:00 PM »
If the person disguised as an electrician entered the building without seeing anyone else then that would be Physical security only. If that person was seen by anyone, and most likely was, then it's a combination of social engineering and Physical security. The fact that no dialog was exchanged is irrelevant I think. If someone was manipulated into thinking they were an electrician, even by only seeing them, then this is Social Engineering.
Physical security was involved as they were able to walk in without a key, swipe card, signing in etc.
Social Engineering probably was involved as they simply walked in dressed as an electrician, making staff think they were legitimate.
Hope that helps.
Logged
dalepearson
Sr. Member
Offline
Posts: 357
Re: Physical Security and Social engg.
«
Reply #4 on:
February 12, 2009, 09:17:45 AM »
Hmm, this is a tricky one in my opinion.
Clearly in this scenario there are physical security issues without a doubt, as it appears no controls existed to restrict or challenge access.
At the same time we dont have enough information to guage what happened, was a call placed to schedule an engineer visit, was the guy dressed like an electrical maintenance contractor to not arouse suspicion.
To me social engineering is manipulation of human nature and good will. The aim of the act is getting information or access granted that should not be made available to you.
I can kinda see why the fact the guy pretending to be a electrician may come across as being social engineering, but reading the scenario word for word, it doesnt seem to have any context or maniplulation.
So I would say, based on the information I have here, it was a purely physical and awareness issue.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
timmedin
Sr. Member
Offline
Posts: 469
Re: Physical Security and Social engg.
«
Reply #5 on:
February 14, 2009, 04:30:08 PM »
According to US-CERT
Quote
To launch a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.
By wearing the electrician outfit and acting like he knows what he is doing and where he is going I would contend that it was social engineering, but I can understand the counter argument since the was no explicit interaction.
BTW, what is the point of your discussion with your friend? Seems like the real issue is that the security systems in place failed.
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4169
Editor-In-Chief
Re: Physical Security and Social engg.
«
Reply #6 on:
February 15, 2009, 12:29:44 AM »
OK, I have to chime in here. It is Social Engineering through and through. Let's break down the question from your friend (which forgive me for saying doesn't look like a verbatim quote
):
Quote
A person enters an organization pretending to be an electrician and gets access to the Data Center and completes his work . In the whole procedure he does not talk to a single person .
First of all, your use of the word "pretending" states everything one needs to know. The person was not a real electrician but was using it to fool humans.
Second is the issue of whether it is physical or not. Based on your quote, we don't have enough info. It only states the he, "gets access to the Data Center." He could have picked locks, tailgated, broken down the door, utilized his uniform or any number of other methods, but we simply don't know unless there is more you are leaving out.
Now onto your response:
Quote
Social Engg. means that you interact with a human being , and in the case that person went straight to the data center
Just because he did not talk to someone doesn't mean he didn't interact. I'm sure someone saw him as the point seems to be that he didn't have to talk becasue of the uniform. That is interaction. Someone saw him, assumed he was ok, access was attained. Eye contact, body languagem facial expressions... all forms on interaction without using words at all.
If this is someone who is not yet a CISSP and is prepping for the exam, the answer will be SE all the way. If truly already a CISSP (as you state below), I'd be interested in the reason for the question and what expertise your friend may have to make the CISSP go to him. Just curious.
My $.02.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Tutorials
: Pasha Jewelry Offers Elegance At Reasonable Prices
(0) by
storenoh63
J. Peltier
: Amrapali Dream Valley High Rise Residential Villas At Noida Extension
(0) by
storenoh63
Skillz
: Get Paid To Write Online - Right Now Is A Great Time To Make Money Writing!
(0) by
storenoh63
Hoffman
: Infant Bracelets San Pedro California
(0) by
storenoh63
Cyber Warfare
: How Reliable Is Pay-per-click Advertising
(0) by
storenoh63
CWNP Certs
: Hobby classes - for improving physical as well as mental health
(0) by
storenoh63
Mass Media
: Sass And Class Why High Heel Shoes Are Here To Stay
(0) by
storenoh63
OSCP - Offensive Security Certified Professional
: Reasons Why You Should Buy Bmw
(0) by
storenoh63
Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
: Enema Supplies
(0) by
storenoh63
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.