itt3 its social engineering

Download Itt3 its social engineering

If you can't read please download the document

Upload: morten-nielsen

Post on 25-May-2015

324 views

Category:

Technology


0 download

TRANSCRIPT

  • 1. Social engineering Servers and network 2012 Autumn Morten Bo Nielsen [email protected]

2. Old schoolIts all about themoney Hustling ScamsExampleNetworks and servers - [email protected] 3. Psychology of scamscognitive and motivationalprocesses trust and authority visceral triggers human desires and needs greed, fear, avoidance of physical pain, or the desire to be likedNetworks and servers - [email protected] here for full story 4. Inducing judgement errors Scarcity cues Unique opportunity Induction of behaviouralcommitment Start small and get them rolling Extreme cost/benefit Lack of emotional control A psychological trait of victimsNetworks and servers - [email protected] 5. ExamplesWho needs spam, when we have this linkhttp://www.urbanmillionaires.com/Question: Is it true? Is it trustworthy? Puts words on it from the previous slides. Still think it is trust worthy?Networks and servers - [email protected] 5 6. ExamplesEmotional distresssteal a womans hand bagQuestion: Is this possible? Is she gullible?Networks and servers - [email protected] 7. Still old school Gaining access to places you are not allowed http://www.youtube.com/watch?v=kOEWd_M5m44 The secret: Look as if you belong.Networks and servers - [email protected] 7 8. Relation to security No security withphysical access Why go through thefirewall, if you maywalk past?Networks and servers - [email protected] 9. People on the moveSteal the laptop (covertly) laptops in airportsNetworks and servers - [email protected] 9 10. People on the moveUse their telephones against them for profit reading the calendar, mails, SMS As a bugNetworks and servers - [email protected] 10 11. People on the moveMobile IT A security nightmare Too many variablesIs this ok to use?Could it be fake?Networks and servers - [email protected] 11 12. People at the office Make them tell you their passwords. Teachers recurring story this time with an external reference.... from the BBCQuestion: Is this realistic? In Denmark?Networks and servers - [email protected] 12 13. People at the office Spam Check your mailboxNetworks and servers - [email protected] 13 14. People at the office Receptionists are acrucial part of security Educate people Like this?Networks and servers - [email protected] 14 15. Closing wordWhich on to use? Technical vs. socialAnswer: BothTo read more, see thisNetworks and servers - [email protected]