Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Home Depot, Other Retailers Get Social Engineered
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
SteveMorlan
100%
0%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 2:52:06 PM
Ease of Access
Thank you for the mention of Schmooze Operators. Stephanie and I had a lot of fun participating in the competition. Perhaps the most concerning part, was the ease at which information was acquired from all of the companies. 

Social Engineering training ought to be implemented as part of the security training at all major companies. Regardless of how many millions of dollars are spent on security devices and services, the weakest link will always be the person that speaks to the public. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 2:58:54 PM
Re: Ease of Access
Hi Steve--thanks for your note. I'm curious -- from your perspective, which flags were the most difficult to capture? 
SteveMorlan
50%
50%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:18:00 PM
Re: Ease of Access
Kelly,

From what I viewed and experienced, antivirus was one of the hardest to acquire, simply because the information was hidden from the employee, not because the employee was not willing. I watched multiple teams acquire phone system info, os version and service pack, computer make and model, vendor information, etc. Once the employee starts giving information, your trust with them builds and they happily hand over information. 

One of the most entertaining flags was asking the individual to navigate to a website. All the teams used the seorg.org address. In many cases, the individual actually went to the site more than once on the same call. What is so funny about this, is that the site says "What is Social Engineering?" in bold font on the top of the page. 

Most importantly, it is not the employees' fault. The majority of these individuals have simply not been trained to handle social engineering. The folks that run the contest do an excellent job of reporting their findings and protecting the individuals involved. I hope that more companies implement training for these types of attacks. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:25:47 PM
Re: Ease of Access
Thank you for sharing this insight, Steve. So you were the substitute team member/volunteer for the audience when the other Schmooze Operator member got sick? How hard was that--jumping in?
SteveMorlan
100%
0%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:36:11 PM
Re: Ease of Access
Haha. So, it was very surprising. I have never competed before or used Social Engineering in any professional environment. I had roughly one hour to prepare for the contest before joining Stephanie in the booth, so I didn't. She wrote a script ahead of time, which I glanced at, but none of it flowed nicely with my personality. Consequently, I chose to wing it. She also provided me with a list of flags, which is what I went off of. 

In the booth she initiated the call by grabbing non-tehnical information and then transferring to me, a member of the security team, which was brilliant on her part because it played to stereotypical gender roles. My experience with tech support, sales, and system administration took over from there. 

I was very nervous before sitting down in the booth, but the laughter and cheers from the crowd made it much easier. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:43:48 PM
Re: Ease of Access
Really, really interesting. It sounds like you two were a good balance of personalities and perspectives.

So--are you thinking you'll form a team for next year?
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:43:48 PM
Re: Ease of Access
Really, really interesting. It sounds like you two were a good balance of personalities and perspectives.

So--are you thinking you'll form a team for next year?
SteveMorlan
50%
50%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:54:28 PM
Re: Ease of Access
Unfortunately, we likely won't. Chris has not released how the competition will be run next year. Moreover, this year teams were assigned randomly so that experienced individuals were placed with new individuals. 

If I am allowed, I would love to participate again. I found the entire experience rewarding and enjoyable. Moreover, it gives me examples of attacks that could be leveraged against the company I currently work for; allowing us to make changes to our training to incorporate new concerns. 
Kelly Jackson Higgins
100%
0%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:55:53 PM
Re: Ease of Access
It's great that you can take back to your company the firsthand experience of what can happen to employees in social engineering situations.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
9/4/2014 | 4:06:03 PM
fascinating thread
Wow! This a great thread. Thanks @SteveMorlan for sharing your experience on the winning team at Social Engineering Capture the Flag (SECTF) competition at DEF CON. Love the details. It really brings the competition to life..
Page 1 / 2   >   >>


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5615
PUBLISHED: 2020-08-04
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5616
PUBLISHED: 2020-08-04
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] fre...
CVE-2020-5617
PUBLISHED: 2020-08-04
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.
CVE-2020-11583
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-11584
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.