Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Monday, January 4, 2016

That is not hacking ...

Lately I have been doing a couple of social engineering attacks . One of the attacks I did was fairly simple. I had access to a big screen showing me a nice typical Windows background.

When I checked out the back of the screen I found a USB port so as one does when something is in scope, you start having fun with it. I plugged in a USB keyboard and hit the Windows+R combination. A nice window popped up and I opened a notepad so I could write a nice little message to the system administrator with my contact details. I unplugged the keyboard and continued what I was doing.

Later in the afternoon when the message got enough attention I took the message down. It had had the attention of the managers and I was already looking with the infosec-team for solutions.

Funny enough one person from the IT staff came up to me and said that it wasn't a hack since it required physical access to the machine. I pointed out that to a threat agent it doesn't really matter how it gets done, the only thing that matters to a threat agent is that his or her job gets done.

Friday, March 28, 2014

VIP Social Engineering

Yesterday there was this big commercial vendor security event in Belgium with a VIP area. I was offered VIP entrance tickets but at the time offered I wasn't even sure I wanted to go and now I had regular tickets.

The thing was thus that a number of people I knew were VIP and I wanted access to the area were I was not supposed to come.

The first time I stopped at the lady checking the badges with my phone next to my ear, totally ignoring her and having a conversation with somebody who was actually inside. It was funny because I was describing the area loudly like "I see this banner, and to the left that poster and ... ok now I see you" and just walked right in like I belonged there without getting challenged.

The second time I wanted a different approach and got challenged. I showed my badge, she said I couldn't enter I asked why not so she had the feeling she was doing her job. Then I said, I really needed to talk to my colleague and pointed at a guy who was going to sit down. He was actually my colleague but I could have pointed at anybody just far away enough to make sure she couldn't leave her desk. Since she was alone, she had no way of going to check my story. She said ok, but I couldn't have any drinks or snacks ... sure, I said I needed a chat with that guy, no drinks, no snack.

One of the guys going in with me, piggy backed on my excuse and did not even have to speak a word, he just smiled.

Yes, we did this for fun and giggles but social engineering is daily used by bad people.

Sunday, March 9, 2014

SMS Scam

Hello,

I want to tell you about a scam I received last Friday on my phone. I got during the evening a text message which was a nice piece of Social Engineering. The text message said "Appelle moi urgent 0010664112011".

The text was in French, a language spoken in my social circle, so I could have been tempted to call back. It is a classic in Belgium that people without any calling credit can send you a message that looks similar to this. This is for a lot of youngsters the way they communicate with their parents over the phone since they are most of the time out of credit.

The form that it is written in is interesting too. "Appelle moi" means "call me" so that is an instruction and if you would still hesitate it says that it is urgent and thus trying to take away any resistance. It uses the feeling of guilt that we have if we don't help somebody in need.

When I researched the number online it was immediately obvious that I was not the only one and there are number of variations. The best illustration of this is anruf-info.de. They collected some data which is interesting. If you look at the 7th, the evening I got the message there are quite a lot of Belgians reporting it, when a time stamp is given it was in the evening, just like mine. This could be an indication of some form of automatization. As we can see the day after on the 8th the scam just goes on.

Unfortunately I don't have any knowledge about how to trace the origin of this number but it would be very interesting.


Monday, August 19, 2013

Playing with Social Engineering at a music festival

It is summer in the Northern hemisphere of planet earth and this means that we have music festivals. Traditionally at the festival area you have two checkpoints, one for the entrance bracelet and one to inspect the backpacks for drinks.

The funny part is that people smuggle in drinks because it is kind of a challenge.  My theory was if the man that would check my backpack would find something he would be happy and stop looking through the rest of my backpack.

I packed my bag with 2 glass bottles of Belgian beer, put them inside my sweater and put all the rest of my bicycle gear in my backpack. The thing I had planted for the man to discover was a deodorant spray. When you just pad the backpack it feels kind of like a can of coke when you are unexperienced.

I stood in the queue and when it was my turn, I presented the backpack and opened it cooperatively. I showed that I had my gear like my helmet and everything what you need to bike in a city,  and the guy started padding the backpack. He found the deodorant and he asked me immediately what it was. Instead of answering him I opened up the backpack showed him the spray and he was happy with the answer.

I gave him a frame of "the guy on his bike" so the big backpack made sense.

As expected the man had a flow in his mind:
1. look into the bag, when no bottle visible goto 2 otherwise confiscate bottle
2. pad the bag, when nothing let through, when something ask question

The security problem was clearly in this last part, he knew he had to confront me with the fact that he had found something but when he was given an explanation that was different from "shit, bottle found". He was happy because he had the positive feeling he had done his job.

For your information, my friends and I still buy our beers at the festivals, but as I said before it is kind of a challenge to see if you can beat the system.

Wednesday, July 14, 2010

Welcome to big hotel

I recently had to visit the office of a customer just outside of Brussels. I knew approximatly where it was. Since I didn't get any GPS signal, I had to ask for directions and I stopped at a hotel near by my destination just to ask for final directions.

The hotel where I stopped is part of a big international chain. I walked up to the front desk where a lovely young lady called Marielle (Dutch accent, the ring on her left hand on the ring finger indicated that she is most probably married) according to her name tag greeted me. I explained my problem. She didn't knew where my customer was located so I social engineered her by simply asking if she had Internet access on her computer and if she had access to a website like Google maps. While she was typing I noticed that on every screen in the left corner there was a post-it with the magic words user: username, password: password.

Suddenly my mind started working in a different way and just for fun I asked if I could come behind the desk to have a look at the Google map and by looking at the screen I noticed that it was an Internet Explorer.

So lets have a look at what we got:
- a name for name dropping
- a target who is susceptible to social engineering
- a browser, which has a good track record of being vulnerable
- a user name and password for something which will be most probably the application for managing the rooms

To say it with the words of Louis Armstrong ... What a wonderful world.