Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
7 Ways To Charm Users Out of Their Passwords
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
JulietteRizkallah
100%
0%
JulietteRizkallah,
User Rank: Ninja
7/28/2016 | 11:43:51 AM
Re: Wow...
Well, i hope you use unique password because many times hackers will test the password they obtain - by theft, bribe or money - against many other systems until they get into the one they want access to.  You may think you can just chnage your password as soon as revealed and all is safe but hackers are not that stupid, they usually do not ask for the password of the system they wnat access to, they want to study your passwords, test them against other corporate systems until they get their way in.  And be worried, there is always one app you forget that will let them in!
T Sweeney
100%
0%
T Sweeney,
User Rank: Moderator
7/28/2016 | 10:21:40 AM
Re: Wow...
Ha! Thanks, Whoopty... that's a better title, actually: 7 Ways to Bribe Users! I'll admit I was surprised at how many ways there were to get users to give up the goods. Some little treat is actually a great conversational opener for a social engineer, provided they're willing to try it in person and forego the anonymity of the phone.

The other surprise: How many users will give up their passwords just by being asked... no incentive required. What's up with that?
Whoopty
100%
0%
Whoopty,
User Rank: Ninja
7/28/2016 | 8:02:00 AM
Wow...
I thought this piece would be about legitimate social engineering techniques, not outright bribery of people! I'm shocked so many would give up information for a pen.

A cookie I can understand but still...

I might be tempted by the cash, but only because I would immediately change my password after they gave it to me. 
<<   <   Page 2 / 2


More SolarWinds Attack Details Emerge
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/12/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-35128
PUBLISHED: 2021-01-19
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. ...
CVE-2020-35129
PUBLISHED: 2021-01-19
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on th...
CVE-2020-23342
PUBLISHED: 2021-01-19
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
CVE-2020-20950
PUBLISHED: 2021-01-19
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable li...
CVE-2020-23522
PUBLISHED: 2021-01-19
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.