Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests online
 
Advertisement

You are here: Home arrow Columnsarrow Hadnagyarrow [Article]-An Insider`s Look at the Social-Engineer.Org SE CtF at DEFCON
EH-Net
May 21, 2013, 09:13:29 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-An Insider`s Look at the Social-Engineer.Org SE CtF at DEFCON  (Read 3683 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: May 25, 2012, 12:14:51 PM »

Hard to believe that BH and DEFCON are only 2 months away. In gearing up for the annual trek to Sin City, here's a cool expose on the SE CtF. I'm sure this will generate some questions on your end. Please ask away as Chris would be happy to answer what he can.

Permanent link: [Article]-An Insider`s Look at the Social-Engineer.Org SE CtF at DEFCON

Quote

By Chris Hadnagy

I want you to picture this scene:  It is a warm day in sunny Maryland, my phone rings.  I answer it.
   
   Me – “Chris speaking…”
   Voice – “Hello Sir, this is Special Agent Smith (name changed) from the FBI, I would like to speak to you about this social engineering contest…”
   Me – “Nice Dave, not falling for it.  Good try sucker!”
   Voice – “Sir, I already mentioned my name is Special Agent Smith, not Dave.  It is important that we…
   Me – “Blah, Blah Blah.. right Dave.  You are always trying to get me.  Nice one, almost sounds real.  Later loser…”
   Moments after the phone was hung up it rings again…
   Me – “Hello?”
   Voice – “I would ask that you listen sir and do not hang up.  Call me back at this number… And ask for Special Agent Smith.”
   
This was the birth of the very first Social-Engineer.Org’s Social Engineering Capture the Flag Contest (SE CtF) at DEFCON over 2 years ago.


Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #1 on: May 27, 2012, 03:21:32 AM »

Social-Engineering is great and as CEH presentation says there is no patch for human stupidity!!!!! that was cool.
Logged

ICS Academy Network Security Certified
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #2 on: May 28, 2012, 08:56:17 AM »

Its not necessarily stupidity that is the flaw but the need to be helpful.  You can get very intelligent people to disclose information if you know how to work the discussion.  If you can get the mark to relate to you or vice versa, then you develop a sort of bond that makes them feel they could trust you.  You are essentially finding exploits in humans as you would find in applications.  The only real patch to this is education and awareness.  In the case of the CtF, better classification of company information as well as educating the employees would probably help reduce the numbers show in the report.  Eventually a good SE will find the proper way to pull the information they require. 

For instance reading the DEFCON 18 report and looking at the flags, I figured to get something like "On Site Wireless" and "ESSID" I could pose as a new employee at a remote site (provided the target has remote sites).  Use the pretext that I am at my new office but no company phone has been installed so I am reduced to my cell phone to make all my calls.  Then lead into "they didn't even set my laptop up all the way..." and proceed to ask for Wireless information.   Giving the mark signs of stress and frustration, they may think, hey I was new once and man I feel for this guys...

Knowing all this about SE, I think back to my earlier years in IT and wonder if I may have fallen for these tactics ever.  I am sure I may have since I tend to like being helpful.  But now-a-days I am much more aware.
Logged

Certs: GCWN
(@)Dewser
loganWHD
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #3 on: June 01, 2012, 08:48:04 PM »

Excellent story and comments.  Thanks for sharing.  It is amazing how much information people release to total strangers... isn't it?

Thanks and keep reading.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.083 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.