Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Maltego 3: First Look
August 2010 Free Giveaway Sponsor - CareerAcademy.com
July 2010 Free Giveaway Winner - SANS vLive
Review: SANS FOR610 Reverse Engineering Malware
Book Review: The Art of Assembly Language 2nd Ed
June 2010 Free Giveaway Winner - Black Hat USA
Interview: Lenny Zeltser of Savvis and SANS Institute
The Guide to Neuroscience for Social Engineers
May 2010 Free Giveaway Winners - eLearnSecurity
April 2010 Free Giveaway Winners - CBT Nuggets
Tutorial: SEH Based Exploits and the Development Process
Review: eLearnSecurity’s Penetration Testing Pro (PTP)
March 2010 Free Giveaway Winners - Offensive Security
Miracle on Thirty-Hack Street - Answers and Winners
Review: CEH iClass by EC-Council
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 54 guests and 5 members online
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
EH-Net
Special Events
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
EH-Net
September 02, 2010, 11:37:11 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
:
Advertise on EH-Net!!
- Reasonable Rates, Highly Targeted Audience.
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
Special Events
(Moderator:
don
) >
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
Pages: [
1
]
2
3
Go Down
« previous
next »
Print
Author
Topic: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing (Read 21973 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3281
Editor-In-Chief
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
on:
February 20, 2009, 06:00:28 PM »
Slide Deck in Searchable PDF
38 Slides
6.74 MB
Look for video soon!
This is EH-Net's first of hopefully many more webcasts. How many more we do depends greatly on the size of the audience we reach. So now is the time for you to help the entire EH-Net Comunity by spreading the word and getting as many as you can to attend. Many thanks in advance.
Two additional announcements:
- After the live event, come right back to this thread to talk to Chris and Mike.
- A coupon code for a huge discount to the
Social Engineering Master Class at ChicagoCon 2009s
will be shown during the webcast. Don't miss it!!
This one is sponsored by
Core Security Technologies
.
Permanent link:
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
Quote
The world of Information Security is changing. Budgets are tighter, attacks are more sophisticated, and the corporate network is no longer the low hanging fruit. That leaves web-enabled applications as the vector-du-jour, but that well is quickly drying up for organized crime as well. As they creep up the OSI Model looking for easier ways to steal your corporate assets, they are quickly making their way up the stack to the unspoken 8th layer, the end user. So what is the next step in the never-ending escalation of this cyber war?
To find out, we must do as Sun Tzu taught. "Think like our enemy!" That is, after all, the primary tenet of penetration testing AKA ethical hacking, isn't it? After years of hardening physical systems, networks, OSs, and applications, we have now come full circle to a new dawn of attack.
People are now the target of the advanced hacker, and the cross-hairs are focused squarely on their foreheads... literally.
It is only a matter of time before corporations feel the pain of wetware hacking requiring a new approach to testing and defense.
Join world-renowned social engineers,
Chris Nickerson
of TruTV's Tiger Team and noted expert and international speaker,
Mike Murray
, as they prepare you for the future of pen testing. This webcast on
Tuesday March 10, 2009 at 11:00 CST
is your primer to the world of "Modern Social Engineering."
Let us know what topics you'd like for us to cover in the future,
Don
«
Last Edit: March 11, 2009, 12:31:18 PM by don
»
Logged
CISSP, MCSE, CEH, Security+ SME
xXxKrisxXx
Sr. Member
Offline
Posts: 383
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #1 on:
February 20, 2009, 06:57:23 PM »
Sweet just registered.
Logged
OSCP
Andrew Waite
Hero Member
Offline
Posts: 816
aka RoleReversal
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #2 on:
February 21, 2009, 05:59:16 AM »
Cool, looking forward to it.
Logged
--
http://www.infosanity.co.uk
--
http://infosanity.wordpress.com
gregtampa
Newbie
Offline
Posts: 2
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #3 on:
February 24, 2009, 12:23:27 PM »
who else is going to chicon?
I'm try to make plans to be there!
Logged
MicroJay
Jr. Member
Offline
Posts: 93
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #4 on:
February 24, 2009, 07:05:06 PM »
Just registered! Met Chris a couple years back. Very interesting person.
«
Last Edit: February 25, 2009, 06:10:24 AM by MicroJay
»
Logged
GSEC - GCIH - GSNA
nmehra
Newbie
Offline
Posts: 1
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #5 on:
February 24, 2009, 11:44:33 PM »
I am new to this webcast thing.
Does it require me to pay to attend the webcast?
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3281
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #6 on:
February 24, 2009, 11:54:16 PM »
No sir. It's free... just like everything else on EH-Net.
Welcome to the community,
Don
Logged
CISSP, MCSE, CEH, Security+ SME
alan
Newbie
Offline
Posts: 30
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #7 on:
March 07, 2009, 11:23:29 PM »
will this be recorded? would be interested to check it out but wont be able to watch it live
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3281
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #8 on:
March 10, 2009, 12:34:18 PM »
Thanks everyone for the compliments on and offline. There were many questions we just couldn't get to, even though we allowed about another 10 - 15 minutes of Q&A. Then again, that's why we have this thread.
Here are a few more questions for the guys:
1. What are some ways that I can convince my boss that we should add SE into our normal pen tests both internally and externally?
2. How can I measure ROI for the SE portion of pen testing?
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Don
Logged
CISSP, MCSE, CEH, Security+ SME
cnickerson
Newbie
Offline
Posts: 7
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #9 on:
March 10, 2009, 12:43:33 PM »
#1 here is my linked in profile.. Go there to look for the reading List.
http://www.linkedin.com/in/nickersonlares
Logged
cnickerson
Newbie
Offline
Posts: 7
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #10 on:
March 10, 2009, 01:19:39 PM »
DAMNIT.. I wrote a resp for about 20 min.. and the site timed me out F%$#^%#
ok.. Ill go backwards.
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Its hard to show you everyhting without going over the whole class, but I can tell you some things. The outline is about 10 pages of bullets. Each section from intel collection to - gigging for information comes with training, examples, tools, practical exercise, and scnarios to make you put it all into play.
And what the hell.. don knows I am a liability... so heres a lil 0day.
(part of outline)
Determining Tests
• Types of testing
o Direction of attacks
o External
Electronic
• Phishing
• Client-side / browser side exploitation
• Metasploit
• Core
• By hand
• Malicious attachments
Person to Person
• Phone
• Written
• Social Networks/IM
• Public Manipulation
o Internal
Person to Person
• Gaining access to physical credentials
• Solicitation
• Direct interaction
• Creating spies / information leak sources
o Methods (al mamalik,qulaam, kgb,cia,others)
o Trading information
• Becoming an employee
Electronic
• CD/Key drops
• Authentication bypass
• Key /perimeter bypass
• Falsification of credentials
• RFID/ HID copying
if u need more info... pm me.. =o)
Don
[/quote]
Logged
jakx
Newbie
Offline
Posts: 14
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #11 on:
March 10, 2009, 01:27:14 PM »
Was this video recorded by chance? I was not able to make it and would love to see it.
Logged
timmedin
Sr. Member
Offline
Posts: 454
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #12 on:
March 10, 2009, 01:48:56 PM »
Quote from: don on March 10, 2009, 12:34:18 PM
Thanks everyone for the compliments on and offline. There were many questions we just couldn't get to, even though we allowed about another 10 - 15 minutes of Q&A. Then again, that's why we have this thread.
Here are a few more questions for the guys:
1. What are some ways that I can convince my boss that we should add SE into our normal pen tests both internally and externally?
2. How can I measure ROI for the SE portion of pen testing?
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Don
Question #1 is what I was wonder. A corollary to that is, how do I get him to pay for my training?
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3281
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #13 on:
March 10, 2009, 01:57:16 PM »
The webcast was recorded in a video format. I am reviewing it now. Give me a little bit to review, clips the start and ending, convert, etc. But it will be made available soon for those who didn't catch the coupon code for basically half off the ChicagoCon training.
w00t!!
Don
Logged
CISSP, MCSE, CEH, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 3281
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #14 on:
March 10, 2009, 03:11:47 PM »
It is if you believe it to be.
Here are some more questions for Chris & Mike that didn't get answered during the live event:
Q: On a PenTest team, what is the best way to collaborate what you have found? I pentest and I have found that communication break down is one of the biggest problems within the PT team social context.
Q: It seems to me that there is not an orgnaization out there that would not fall for a client side attack. There is always at least one person that will click on a malicious link. Would a failure of such a test be the user clicking on a link, or lack of a safeguard such as A/V to prevent the malicious code from doing its thing?
To combine a bunch of questions... how does someone get into pen testing? What are your general thoughts on certs like CISSP? What foundational training would you recommend as a starting point?
Don
Logged
CISSP, MCSE, CEH, Security+ SME
Pages: [
1
]
2
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Cyber Warfare
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Haddix
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Support EH-Net
Help Support EH-Net with Our Amazon Store
Try CBT Nuggets Free!
Recent Forum Topics
General Certification
: A+ and Net+
(6) by
ziggy_567
Network Pen Testing
: How to hack FTP?
(8) by
Dave 1
Links to cool sites.
: HaXx.Me - Wargames by InterN0T
(4) by
pizza1337
Tutorials
: Having trouble understanding W3AF Pen-Test Results
(1) by
andres.riancho
Web Applications
: MySQL HTTP Header injection help
(7) by
eyenit0
Security
: Advice for next certifications wanted
(14) by
don
Network Pen Testing
: CREST Information
(1) by
charliemong
Tutorials
: How to....
(6) by
Melsy
General Certification
: will pay to be taught how to hack wireless credit card networks(plz dont ban me)
(6) by
don
Tools
: hacking tools: pc keylogger, mac keylogger, mobile keylogger
(3) by
Melsy
Security
: Advise wanted For next step
(5) by
awesec
Other
: Screencasting software
(10) by
Adward
/root
: [Article]-Maltego 3: First Look
(2) by
infowarrior0
CHFI - Computer Hacking Forensic Investigator
: CHFI EXAM
(12) by
dynamik
Other
: Starting Hacker / Computer Group
(5) by
pizza1337
Programming
: Ruby on Rails 3.0 Released
(1) by
hayabusa
OSCP - Offensive Security Certified Professional
: OSCP exam in 1 week - Advice?
(69) by
hayabusa
Wireless
: Does Mobile Security Deserve New Board?
(1) by
Ketchup
Calendar Of Events
: THOTCON 0x2
(0) by
don
Tools
: Wireshark 1.4.0, 1.2.11, and 1.0.16 Released
(0) by
don
Forensics
: Honeynet Project Challenge 5 - Log Mysteries
(0) by
don
Physical Security
: Learning lock picking
(8) by
chrisj
Security
: Passed Security+
(9) by
awesec
News Items and General Discussion About EH-Net
: [Article]-August 2010 Free Giveaway Sponsor - CareerAcademy.com
(5) by
don
Tutorials
: Post your Cheat Sheets
(7) by
pizza1337
Security
: Seven Safe?
(5) by
charliemong
Calendar Of Events
: BugCon 2010
(0) by
don
Links to cool sites.
: (IN)SECURE Magazine Issue 27 Sept 2010 Released
(0) by
don
CEH - Certified Ethical Hacker
: hi all
(12) by
H1t M0nk3y
Tools
: AV-Tracker
(1) by
bery
Tools
: Scanning techniques
(11) by
bery
Calendar Of Events
: BSidesKC 2010
(0) by
don
Calendar Of Events
: Cyber-RAID 0
(0) by
don
Tools
: Why I (Hate||Love) tools
(11) by
Jhaddix
Security
: Learn Security Online
(8) by
BlueEyedSamurai
Incident Response
: My "action" today
(1) by
zeroflaw
Career Central
: How to get the experience!?
(6) by
don
Security
: Advanced Security Certification by CompTIA
(1) by
dynamik
OSCP - Offensive Security Certified Professional
: OSCP - Progress
(18) by
H1t M0nk3y
Web Applications
: HTTP header: PUT, DELETE, etc
(17) by
ethicalhack3r
Vote For EH-Net
progenic.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2010 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.