Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 3 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Social Engineeringarrow How to prepare the "Human OS" for a malware scan???
EH-Net
May 19, 2013, 03:54:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How to prepare the "Human OS" for a malware scan???  (Read 5168 times)
0 Members and 1 Guest are viewing this topic.
johnnekar
Newbie
*
Offline Offline

Posts: 11

Information Revolution


View Profile WWW
« on: April 02, 2010, 01:37:57 AM »

Well there are loads of AVs that not only alert you of some threats but also provide online security. Securing your computer/OS to some extent(No machine is completely secure, never) is easy but what about the OS that is installed on our brain? The biggest vulnerability of the Human OS (HOS) is "trust". So we can define Social Engg as "The clever manipulation of the natural human tendency to trust".

Well the biggest questions over here are:
1) Though AVs, firewalls and IDSs keep the networks perimetere secure, how can we train the HOS to identify any mischief?

2) People who are naive to the internet will never know that they are becoming a victim of a phishing attack. Even after warning the population to check the URL, the SSL favicon, the padlock symbol to ensure the authencity of a websit, how many bother to check that?

3) Techniques like email spoofing add to the nuisance. Who bothers to check the headers of an email to verify the origin if the message?

4) Can there never be a security solution to Social Engg?

I as a script-kiddie had launched quite a few phishing attacks. But being a White Hat I only grabbed email a/cs, no bank accs. Though I never misused them, but merely accessing those accounts gave enormous information about that person including bank & credit card details.

Will we ever have a solution??

j0hnn3k4r
http://techkranti.blogspot.com
Logged

Your tomorrow should be better than your today.. j0hnn3k4r
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #1 on: April 02, 2010, 08:57:44 AM »

Educate your workers. of course not everyone is going to be patched, but if some understand they can protect each other.

http://www.seas.ucla.edu/security/social_eng.html
http://www.windowsecurity.com/articles/Social_Engineers.html
http://www.bestsecuritytips.com/xfsection+article.articleid+126.htm
http://schaumburgcomputers.com/?p=15
Logged

Knowledge Resource is Power.
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #2 on: April 06, 2010, 03:29:05 AM »

security awareness trainings should be standard within every organization atleast once a year. there are many do's and dont's for giving these trainings, but the fact should be that people think before they act. If the budget doesnt let you perform a simple phising scam (with authorization from your manager) and calculate the results to a simple chart showing how many people "clicked the wrong button". even this is effective in educating people for such attacks.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #3 on: April 06, 2010, 04:45:00 AM »

http://www.youtube.com/user/mindfulsecurity#grid/user/EC5CB2F0B9123BF6 
found this last night.
Logged

Knowledge Resource is Power.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.