Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

9/3/2014
07:15 PM
Connect Directly
Google+
Twitter
RSS
E-Mail

Home Depot, Other Retailers Get Social Engineered

Famed annual contest reveals how many retailers lack sufficient defenses against social engineering.

(Source: Social-Engineer.org)
(Source: Social-Engineer.org)

Comment  | 
Print  | 
Comments
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
SteveMorlan
100%
0%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 2:52:06 PM
Ease of Access
Thank you for the mention of Schmooze Operators. Stephanie and I had a lot of fun participating in the competition. Perhaps the most concerning part, was the ease at which information was acquired from all of the companies. 

Social Engineering training ought to be implemented as part of the security training at all major companies. Regardless of how many millions of dollars are spent on security devices and services, the weakest link will always be the person that speaks to the public. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 2:58:54 PM
Re: Ease of Access
Hi Steve--thanks for your note. I'm curious -- from your perspective, which flags were the most difficult to capture? 
SteveMorlan
50%
50%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:18:00 PM
Re: Ease of Access
Kelly,

From what I viewed and experienced, antivirus was one of the hardest to acquire, simply because the information was hidden from the employee, not because the employee was not willing. I watched multiple teams acquire phone system info, os version and service pack, computer make and model, vendor information, etc. Once the employee starts giving information, your trust with them builds and they happily hand over information. 

One of the most entertaining flags was asking the individual to navigate to a website. All the teams used the seorg.org address. In many cases, the individual actually went to the site more than once on the same call. What is so funny about this, is that the site says "What is Social Engineering?" in bold font on the top of the page. 

Most importantly, it is not the employees' fault. The majority of these individuals have simply not been trained to handle social engineering. The folks that run the contest do an excellent job of reporting their findings and protecting the individuals involved. I hope that more companies implement training for these types of attacks. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:25:47 PM
Re: Ease of Access
Thank you for sharing this insight, Steve. So you were the substitute team member/volunteer for the audience when the other Schmooze Operator member got sick? How hard was that--jumping in?
SteveMorlan
100%
0%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:36:11 PM
Re: Ease of Access
Haha. So, it was very surprising. I have never competed before or used Social Engineering in any professional environment. I had roughly one hour to prepare for the contest before joining Stephanie in the booth, so I didn't. She wrote a script ahead of time, which I glanced at, but none of it flowed nicely with my personality. Consequently, I chose to wing it. She also provided me with a list of flags, which is what I went off of. 

In the booth she initiated the call by grabbing non-tehnical information and then transferring to me, a member of the security team, which was brilliant on her part because it played to stereotypical gender roles. My experience with tech support, sales, and system administration took over from there. 

I was very nervous before sitting down in the booth, but the laughter and cheers from the crowd made it much easier. 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:43:48 PM
Re: Ease of Access
Really, really interesting. It sounds like you two were a good balance of personalities and perspectives.

So--are you thinking you'll form a team for next year?
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:43:48 PM
Re: Ease of Access
Really, really interesting. It sounds like you two were a good balance of personalities and perspectives.

So--are you thinking you'll form a team for next year?
SteveMorlan
50%
50%
SteveMorlan,
User Rank: Apprentice
9/4/2014 | 3:54:28 PM
Re: Ease of Access
Unfortunately, we likely won't. Chris has not released how the competition will be run next year. Moreover, this year teams were assigned randomly so that experienced individuals were placed with new individuals. 

If I am allowed, I would love to participate again. I found the entire experience rewarding and enjoyable. Moreover, it gives me examples of attacks that could be leveraged against the company I currently work for; allowing us to make changes to our training to incorporate new concerns. 
Kelly Jackson Higgins
100%
0%
Kelly Jackson Higgins,
User Rank: Strategist
9/4/2014 | 3:55:53 PM
Re: Ease of Access
It's great that you can take back to your company the firsthand experience of what can happen to employees in social engineering situations.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
9/4/2014 | 4:06:03 PM
fascinating thread
Wow! This a great thread. Thanks @SteveMorlan for sharing your experience on the winning team at Social Engineering Capture the Flag (SECTF) competition at DEF CON. Love the details. It really brings the competition to life..
Page 1 / 2   >   >>
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...