Perimeter
3/17/2015
04:00 PM
Sara Peters
Sara Peters
Slideshows
Connect Directly
Twitter
RSS
E-Mail
100%
0%

The 7 Best Social Engineering Attacks Ever

Seven reminders of why technology alone isn't enough to keep you secure.
Previous
1 of 9
Next

Image, via Wikipedia: Maquette Trojan Horse, used in the movie Troy, a gift from Brad Pitt to the Turkish town Canakkale
Image, via Wikipedia: Maquette Trojan Horse, used in the movie Troy, a gift from Brad Pitt to the Turkish town anakkale

Social engineering is nothing new.

In 1849, Samuel Williams, the original "confidence man," as the newspapers named him, engineered gullible strangers out of their valuables simply by asking "Have you confidence in me to trust me with your watch until tomorrow?" Through the late 19th and early 20th century Joseph "Yellow Kid" Weil ran a variety of scams, including conning Benito Mussollini out of $2 million by selling him phony rights to mining lands in Colorado. And of course in the 1960s, Frank Abagnale, subject of the movie Catch Me If You Can, made a living faking identities and passing bad checks.

While technology has made some kinds of fraud more difficult to commit, it's created all sorts of new opportunities for adaptable fraudsters. And even the very strongest security technology can be overcome by a clever social engineer. That's part of the reason security awareness training for end users is so essential.

"Executives 'get it' right away," says Wombat Security president and CEO Joe Ferrara, about awareness training. "The people who are harder to convince are...the die-hard technologists who don't want to leave [anything] in the hands of the user." 

So for you die-hard technologists out there who need convincing, here are a few examples of social engineering prevailing over security technology. A few are my own personal favorites, and a few are Ferrara's, who will be presenting a session on the topic at the Interop Las Vegas conference.

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
baller188
100%
0%
baller188,
User Rank: Apprentice
3/14/2017 | 6:00:19 AM
Forex security and vulnerabilities
Great post as always. Technology advances every day, new vulnerabilities arise all the time. Security is everyones main priority and rightly so. For any site owner nowadays you need a dedicated security team to make sure you and your customers are safe. Its a scary world out there.
Sincee
50%
50%
Sincee,
User Rank: Strategist
10/2/2015 | 4:56:47 AM
thank's for post
system security in any country is the future !
MichaelH91401
50%
50%
MichaelH91401,
User Rank: Apprentice
10/1/2015 | 3:18:11 PM
Re: name required
The post refers to "Ferrara" repeatedly, but never describes who he is or what he does. 
AnonymousC493
50%
50%
AnonymousC493,
User Rank: Apprentice
5/9/2015 | 9:41:21 AM
Social Engineering examples
Here's another example:

https://engineering.social/2015/05/02/sinkholing-script-kiddies/

It's not one of 'the best social engineering attacks' ever, but shows that anyone can be a target.

 

 
mithoon
0%
100%
mithoon,
User Rank: Apprentice
3/28/2015 | 2:37:41 AM
Re: name required
great post
delllphi
50%
50%
delllphi,
User Rank: Apprentice
3/24/2015 | 7:21:23 AM
Confidence Man
The name of the "confidence man" was "William Thompson" and not "Samuel Williams". The article "Arrest of the Confidence Man" (New-York Herald, July 8, 1849) can be found online.
xmarksthespot
50%
50%
xmarksthespot,
User Rank: Strategist
3/19/2015 | 4:24:22 AM
Good examples
Great article!  Periodic User awareness training to reduce social engineering is of paramount importance.  Some phishing emails are so good that high trained security people can fall for them.  The examples in the article effectively demonstrate the issue.


The rule I use for my own emails is not click links in emails, including unsubscribe, unless the email is expected, such as one as confirmation during new account setup. Of course, never click on attachments either unless they are expected.  I have within Spyshelter (anti-keylogger) where I can save an attachment, right click the file and on the pop-up menu click 'Spyshelter-> Check it on VirusTotal'; it uploads to virustotal.com .   It's then scanned by over 50 antivirus software products. 

I think this rule is probably the most important security measure I use for computers at my home.
Thomas Claburn
0%
100%
Thomas Claburn,
User Rank: Ninja
3/18/2015 | 6:45:32 PM
name required
Can we all agree to ignore any email that isn't addressed by name?
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.