Tuesday, May 22, 2012 Register
Start Your Tech Media Search Here

or Browse Any of the Tech Media Categories Below
 
Subscribe to the IT Specialist Newsletter
Thank you!
List Your Subscriptions

Please enter your email address and select the IT Specialist newsletter(s) that you wish to subscribe to. You will then receive our e-mail messages when we send to that list.




Select an IT Specialist newsletter(s) below to subscribe.

IT Specialist Newsletter - The IT Specialist Newsletter is our main source for news and information about our IT Specialist.com Web site and Career Center (IT Specialist.info). The newsletter is published once per month.
CAPTCHA image
Enter the code shown above in the box below
Subscribe

Thank you!

You are here Home Feature Tech Review
   
Main Media Hub
IT Resource Listings
IT Specialist Career Center

Searching for a Job or Seeking Career Advice? Visit or join our newly revamped IT Specialist Career Center!



Click here or on the image above to join now or learn more!

Feature Tech Review

 

Hackers Play "Social Engineering Capture The Flag"

Robert Siciliano
Contributed 1 years 315 days ago
by Robert Siciliano

Like: 1 Pass: 0

  • Currently 5.00/5 Stars.

Tags: defcon hackers social engineering
Categories: categoryInfoSec categoryOperations Security categoryInfrastructure Security
Views: 1508
Print Bookmark and Share

Social engineering is a fancier, more technical form of lying. An alternative to traditional hacking, it is the act of manipulating others into performing certain actions or divulging confidential information. Social engineering or “social penetration” techniques are used to bypass sophisticated and expensive hardware and software in a corporate network. Smart organizations train their employees to identify and resist the more common attempts to trick them into letting down their guard. Criminal hackers use social engineering as a very effective tool and as part of their strategy when gathering information to piece together the parts of their scams. They often target company executives via phone and email. Once they have extracted some data from the top, accessing networks or whatever end game they had in mind is much easier.

Social engineering has always been a “person to person” confidence crime. Once the con man gains the mark’s trust, the victim begins to provide all kinds of information, or to fork over cash and credit. Trust seems to be an inherent trait we all have from birth. I suppose we would need to be able to trust one another in order to survive as an interdependent communal species, otherwise fear would prevent us from relying on others to nurture us until we are tossed out of the nest.

Defcon is a conference for hackers of all breeds. There are good guys, bad guys, and those who are somewhere in between, plus law enforcement and government agents. All kinds of inventive people with an intuition for technology decend on Las Vegas to learn, explore, and hack. InfoWorld reports, “This year’s Defcon gathering in Las Vegas will feature a contest in which participants will compete to gather nuggets of information from unsuspecting target companies — over the telephone instead of the Internet.”

Defcon is known for its antics but it’s also an event where hackers of all flavors improve their skills. The game they are playing this year is a social engineering fun-o-rama called Social Engineering CTF, referencing the game “Capture the Flag.” “This contest will borrow elements from the convention’s traditional computer-based CTF tournaments, but with a few variations. Prior to the conference, participants will receive an email with the name and URL of a target company. Participants will be permitted to gather preliminary information about the company using Google searches and other passive techniques. Contestants are banned from contacting their target directly via email or phone, and they get points for information gathered. Competitors then use that data during the actual tournament to fuel their social engineering attack. They have twenty minutes to call unsuspecting employees at their target companies and obtain specific bits of (nonsensitive) information about the business for additional points. Participants aren’t allowed to make the target company feel at risk by pretending to represent a law enforcement agency.”

Recognize that online predators use these tactics to get what they want. They consider you, the innocent computer user, their natural prey.

So always question authority, or the appearance of authority. Don’t automatically trust or give the benefit of the doubt. When you are contacted via phone or email, or approached in person, proceed with caution. Always be suspect of external or internal communications, and consider that you could be the target of a phishing scam. Never click on links in the body of an email, and if an email prompts you to divulge a username and password, pick up the phone to verify the legitimacy of the request. The best defense is effective policies coupled with ongoing awareness training.

Robert Siciliano, personal security and identity theft expert adviser to Just Ask Gemalto, discusses credit and debit card fraud on CNBC. (Disclosures)





No Comments


Please register here to comment.

Hackerville: The Epicenter of Romanian Hackers
Scammers and hackers often originate from Ghana, Nigeria, Romania, Korea, Israel, Columbia, Argentina, Philippines, Malaysia, and, of course, China and the good old USA. These developing countries breed MIT-like hackers who spend all their days targeting consumers and Internet users like you and me.
Published: 1 years 51 days ago | Views: 911 | Comments: 0


Top 5 Business Security Risks
1. Data Breaches: Businesses suffer most often from data breaches, making up 35% of total breaches. Medical and healthcare services are also frequent targets, accounting for 29.1% of breaches. Government and military make up 16.2%, banking, credit, and financial services account for 10.5%, and 9.2% of breaches occur in educational institutes.
Published: 1 years 2 days ago | Views: 726 | Comments: 0


Facebook + Hackers – Privacy = You Lose
I’m as sick of writing about it as you are sick of reading about it. But because Facebook has become a societal juggernaut: a massive inexorable force that seems to crush everything in its way, we
Published: 1 years 352 days ago | Views: 709 | Comments: 0


Women Proved “Securest” in the Defcon Social Engineering Game
In a recent post (Hackers Play “Social Engineering Capture The Flag” At Defcon), I pointed to a game in which contestants used the telephone to convince company employees to voluntarily cough up
Published: 1 years 227 days ago | Views: 707 | Comments: 0


Adobe a Target for Criminal Hackers
We all know and love Adobe products. Their PDFs have become as ubiquitous as .DOC, .TXT and .XLS. Most PCs include Adobe Reader as a bundled software. The Adobe Flash media player is the easiest most
Published: 1 years 311 days ago | Views: 703 | Comments: 0

comment Just a quick fix...I have a note regarding CentOS ...more
 
email email::delicious.com delicious.com::digg digg::technorati technorati::reddit reddit::stumbleupon stumbleupon::facebook facebook::google bookmarks google bookmarks::ask ask::live live::twitter twitter::linkedin linkedin

ITSN Banner Ad Campaign





Social Media Sites and Communities for the IT Professional

Privacy StatementTerms Of UseCopyright (c) 2008-2012 Acadian Media, Inc.

BorderBoxedBlueBoxedGrayBlue Small width layoutMedium width layoutMaximum width layoutMaximum textMedium textSmall textBack Top!