Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 42 guests and 4 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
EH-Net
Special Events
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
EH-Net
May 22, 2013, 06:00:40 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
Special Events
(Moderator:
don
) >
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
Pages: [
1
]
2
3
Go Down
« previous
next »
Print
Author
Topic: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing (Read 36814 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
on:
February 20, 2009, 06:00:28 PM »
Slide Deck in Searchable PDF
38 Slides
6.74 MB
Look for video soon!
This is EH-Net's first of hopefully many more webcasts. How many more we do depends greatly on the size of the audience we reach. So now is the time for you to help the entire EH-Net Comunity by spreading the word and getting as many as you can to attend. Many thanks in advance.
Two additional announcements:
- After the live event, come right back to this thread to talk to Chris and Mike.
- A coupon code for a huge discount to the
Social Engineering Master Class at ChicagoCon 2009s
will be shown during the webcast. Don't miss it!!
This one is sponsored by
Core Security Technologies
.
Permanent link:
[Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
Quote
The world of Information Security is changing. Budgets are tighter, attacks are more sophisticated, and the corporate network is no longer the low hanging fruit. That leaves web-enabled applications as the vector-du-jour, but that well is quickly drying up for organized crime as well. As they creep up the OSI Model looking for easier ways to steal your corporate assets, they are quickly making their way up the stack to the unspoken 8th layer, the end user. So what is the next step in the never-ending escalation of this cyber war?
To find out, we must do as Sun Tzu taught. "Think like our enemy!" That is, after all, the primary tenet of penetration testing AKA ethical hacking, isn't it? After years of hardening physical systems, networks, OSs, and applications, we have now come full circle to a new dawn of attack.
People are now the target of the advanced hacker, and the cross-hairs are focused squarely on their foreheads... literally.
It is only a matter of time before corporations feel the pain of wetware hacking requiring a new approach to testing and defense.
Join world-renowned social engineers,
Chris Nickerson
of TruTV's Tiger Team and noted expert and international speaker,
Mike Murray
, as they prepare you for the future of pen testing. This webcast on
Tuesday March 10, 2009 at 11:00 CST
is your primer to the world of "Modern Social Engineering."
Let us know what topics you'd like for us to cover in the future,
Don
«
Last Edit: March 11, 2009, 12:31:18 PM by don
»
Logged
CISSP, MCSE, CSTA, Security+ SME
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #1 on:
February 20, 2009, 06:57:23 PM »
Sweet just registered.
Logged
eCPPT, GCIH, OSCP, OSWP
Andrew Waite
Hero Member
Offline
Posts: 928
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #2 on:
February 21, 2009, 05:59:16 AM »
Cool, looking forward to it.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
gregtampa
Newbie
Offline
Posts: 2
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #3 on:
February 24, 2009, 12:23:27 PM »
who else is going to chicon?
I'm try to make plans to be there!
Logged
MicroJay
Full Member
Offline
Posts: 101
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #4 on:
February 24, 2009, 07:05:06 PM »
Just registered! Met Chris a couple years back. Very interesting person.
«
Last Edit: February 25, 2009, 06:10:24 AM by MicroJay
»
Logged
GSEC - GCIH - GSNA - GPEN
nmehra
Newbie
Offline
Posts: 1
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #5 on:
February 24, 2009, 11:44:33 PM »
I am new to this webcast thing.
Does it require me to pay to attend the webcast?
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #6 on:
February 24, 2009, 11:54:16 PM »
No sir. It's free... just like everything else on EH-Net.
Welcome to the community,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
alan
Newbie
Offline
Posts: 48
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #7 on:
March 07, 2009, 11:23:29 PM »
will this be recorded? would be interested to check it out but wont be able to watch it live
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #8 on:
March 10, 2009, 12:34:18 PM »
Thanks everyone for the compliments on and offline. There were many questions we just couldn't get to, even though we allowed about another 10 - 15 minutes of Q&A. Then again, that's why we have this thread.
Here are a few more questions for the guys:
1. What are some ways that I can convince my boss that we should add SE into our normal pen tests both internally and externally?
2. How can I measure ROI for the SE portion of pen testing?
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
cnickerson
Newbie
Offline
Posts: 7
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #9 on:
March 10, 2009, 12:43:33 PM »
#1 here is my linked in profile.. Go there to look for the reading List.
http://www.linkedin.com/in/nickersonlares
Logged
cnickerson
Newbie
Offline
Posts: 7
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #10 on:
March 10, 2009, 01:19:39 PM »
DAMNIT.. I wrote a resp for about 20 min.. and the site timed me out F%$#^%#
ok.. Ill go backwards.
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Its hard to show you everyhting without going over the whole class, but I can tell you some things. The outline is about 10 pages of bullets. Each section from intel collection to - gigging for information comes with training, examples, tools, practical exercise, and scnarios to make you put it all into play.
And what the hell.. don knows I am a liability... so heres a lil 0day.
(part of outline)
Determining Tests
Types of testing
o Direction of attacks
o External
Electronic
Phishing
Client-side / browser side exploitation
Metasploit
Core
By hand
Malicious attachments
Person to Person
Phone
Written
Social Networks/IM
Public Manipulation
o Internal
Person to Person
Gaining access to physical credentials
Solicitation
Direct interaction
Creating spies / information leak sources
o Methods (al mamalik,qulaam, kgb,cia,others)
o Trading information
Becoming an employee
Electronic
CD/Key drops
Authentication bypass
Key /perimeter bypass
Falsification of credentials
RFID/ HID copying
if u need more info... pm me.. =o)
Don
[/quote]
Logged
jakx
Newbie
Offline
Posts: 14
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #11 on:
March 10, 2009, 01:27:14 PM »
Was this video recorded by chance? I was not able to make it and would love to see it.
Logged
timmedin
Sr. Member
Offline
Posts: 469
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #12 on:
March 10, 2009, 01:48:56 PM »
Quote from: don on March 10, 2009, 12:34:18 PM
Thanks everyone for the compliments on and offline. There were many questions we just couldn't get to, even though we allowed about another 10 - 15 minutes of Q&A. Then again, that's why we have this thread.
Here are a few more questions for the guys:
1. What are some ways that I can convince my boss that we should add SE into our normal pen tests both internally and externally?
2. How can I measure ROI for the SE portion of pen testing?
3. I know you mentioned Core IMPACT and Maltego. Can you expand on some of the more technical components that will be in the class?
Don
Question #1 is what I was wonder. A corollary to that is, how do I get him to pay for my training?
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #13 on:
March 10, 2009, 01:57:16 PM »
The webcast was recorded in a video format. I am reviewing it now. Give me a little bit to review, clips the start and ending, convert, etc. But it will be made available soon for those who didn't catch the coupon code for basically half off the ChicagoCon training.
w00t!!
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
«
Reply #14 on:
March 10, 2009, 03:11:47 PM »
It is if you believe it to be.
Here are some more questions for Chris & Mike that didn't get answered during the live event:
Q: On a PenTest team, what is the best way to collaborate what you have found? I pentest and I have found that communication break down is one of the biggest problems within the PT team social context.
Q: It seems to me that there is not an orgnaization out there that would not fall for a client side attack. There is always at least one person that will click on a malicious link. Would a failure of such a test be the user clicking on a link, or lack of a safeguard such as A/V to prevent the malicious code from doing its thing?
To combine a bunch of questions... how does someone get into pen testing? What are your general thoughts on certs like CISSP? What foundational training would you recommend as a starting point?
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Pages: [
1
]
2
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCaseฎ Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News from the Outside World
: Google Dropping Windows For Internal Use
(10) by
Loyatoitada
Special Events
: [Article]-Video: Deep Dive into Red Teaming with the Metasploit Framework
(4) by
BeecyGorror
Security
: christian louboutin cheap artic5843
(0) by
fufig388
Special Events
: [Article]-Survey of Hacking Movies: Framing the Debate on the Gateway Drug into the H...
(14) by
BeecyGorror
/root
: [Article]-Course Review: CPT by InfoSec Institute
(1) by
BeecyGorror
Ethical Hacktivism
: Paranoid parents messing with routers
(21) by
BeecyGorror
Compliance, Regulations & Standards
: SABSA - Sherwood Applied Business Security Architecture
(1) by
BeecyGorror
News Items and General Discussion About EH-Net
: What does EthicalHacker.net bring you?
(12) by
BeecyGorror
News Items and General Discussion About EH-Net
: Burberry UK,2013 Burberry Safety-valve Online Available in London
(13) by
BeecyGorror
News Items and General Discussion About EH-Net
: louis vuitton handbags mhf
(0) by
Vamscoora
Calendar Of Events
: ChicagoCon 2008f
(3) by
BeecyGorror
News Items and General Discussion About EH-Net
: "Free Monthly Giveaways" - Details
(22) by
BeecyGorror
ChicagoCon 2007
: s going to be critical to have universal identity in order for these systems to talk ...
(0) by
Loyatoitada
Malware
: New zero-day exploit for Internet Explorer 7, 8, and 9 on Windows XP, Vista & 7
(13) by
BeecyGorror
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
BeecyGorror
News Items and General Discussion About EH-Net
: but it needs more help: they Sac Louis Vuitton
(0) by
Loyatoitada
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 The Wild West Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.