Skip the navigation
News

How to steal corporate secrets in 20 minutes: Ask

By Robert McMillan
July 30, 2010 08:59 PM ET

IDG News Service - A few companies in the Fortune 500 need to upgrade their Web browsers. And while they're at it, a little in-house training on social engineering wouldn't be a bad idea, either.

Social engineering hackers -- people who trick employees into doing and saying things that they shouldn't -- took their best shot at the Fortune 500 during a contest at Defcon Friday and showed how easy it is to get people to talk, if only you tell the right lie.

Contestants got IT staffers at major corporations, including Microsoft, Cisco Systems, Apple and Shell, to give up all sorts of information that could be used in a computer attack, including what browser and version number they were using (the first two companies called Friday were using IE6), what software they use to open pdf documents, their operating system and service pack number, their mail client, the antivirus software they use, and even the name of their local wireless network.

The first two contestants made it look easy.

Wayne, a security consultant from Australia who wouldn't give his last name, was first up Friday morning. His mission: Get data from a major U.S. company. (IDG News Service has chosen not to report which companies fell for which attacks because of possible security risks.)

Sitting behind a sound-proof booth before an audience, he connected with an IT call center and got an employee talking. Pretending to be a KPMG consultant doing an audit under deadline pressure, Wayne got him to spill details, big time.

Wayne ignored a request for an employee number and launched immediately into a story about how his boss was on his back, and how he really needed to get this audit finished. He worked his Aussie charm on the worker, who'd only been with his new employer for a month. Within minutes, it seemed he was willing to give Wayne pretty much any information he wanted -- at one point he even visited a fake KMPG Web page that Wayne had set up.

He ended the call promising to buy the employee a beer.

He ended the call promising to buy Ledoi a beer.

"What beer do you like?"

"Right now I'm on a Blue Moon kick."

In an interview after the call, Wayne couldn't believe his luck. "I was thinking they're a pretty big company and I know they did a lot of in-house security audits."

Later, contest organizers said his effort was the best of the day. But everyone who was targeted gave up information. Chris Hadnagy, one of the founders of the contest, believes the victims would have given away sensitive information such as passwords had they been asked. "They would have given pictures of their family if they'd asked for it," he said.

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.

DEFCON

Additional Resources
ESG - What's Needed for Cloud Computing
WHITE PAPER
Just what is cloud computing anyway? Skeptics might say it is nothing but industry hyperbole, visionaries might say it is the future of IT. In reality, both statements are true - cloud computing has been embellished by the tech industry but it does hold real potential for new types of on-demand dynamic IT services. This paper seeks to clarify the definition of cloud computing, identify how far along users are in terms of cloud deployment, and examine the role of the network in the cloud computing model.
Driving Storage Efficiency in SAN Environments
WHITE PAPER
This ESG paper outlines the considerations for architecting an efficient SAN data storage infrastructure with a focus on the NetApp solutions for increased utilization, improved performance and streamlined protection to reduce operational costs.
Get a Quick ROI from Being Green
WEBCAST
The menu of green initiatives is long, but how do you get an early win with a solid ROI? Enterprise Print Services address sustainability issues well beyond paper usage. Learn how you can get an assessment of enterprise printing to identify underutilized devices, reduce energy consumption, cut waste, and free-up valuable space.
What People Are Saying
Security White Papers
Backup and Disaster Recovery eGuide
As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
Read Now.
Windows 7 Migration Made Easier with Desktop Virtualization
Read Now.
Virtualization 2.0: The Desktop Revolution
Read Now.
Securing Data in the Cloud
This document is intended to give a broad overview of our security policies, processes and practices.
All Security White Papers
Security Webcasts
Desktop virtualization keys innovation drive
View now.
Survival Guide: Overcoming the Obstacles to Effective Risk Management
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
How to cut software management costs and avoid over-spending in the future
View now!
Get a $20 Amazon Gift Card - Just watch a Demo
View now!
All Security Webcasts
IT Jobs