Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Friday, July 17, 2009

Baby Pictures and Social Engineering

Creative Commons attribution licensed image courtesy of The Consumerist

The Times Online covers a study by Edinburgh psychologists who found that a wallet with baby pictures was the most likely to be returned. The study showed that only 10% of wallets with baby pictures were not returned, a far higher rate than any other wallet and picture combination. The article notes that a related study found a hardwired response pattern in the brain to baby pictures, meaning that some elements of our reactions might be hard to overcome.

The flaw in the study - at least for those security practitioners who are now pondering putting baby pictures on all of their possessions? The wallets didn't contain any items of real value - no cash or credit cards, meaning that their return rates were likely higher than might have been seen with wallets with a reward for those who don't return them.

As for cute kittens chewing on wallets? I'm not sure if it guarantees more hits...

Friday, February 6, 2009

Parking Tickets and Social Engineering


(not the actual ticket - Creative Commons attribution licensed image courtesy singsing_sky)

Lenny Zeltser of the ISC reports that he recently investigated malware that was spread after victims visited a URL that was included on a parking violation flyer on their car. The BBC picked up the story, meaning copycats are far more likely as this hits major news media. Make sure you check out Lenny's article, as his malware analysis is always worth a read.

The bigger question is if we'll see more of this - I suspect yes. We've seen penetration testers use "lost" thumbdrives in parking lots to get into secure networks and the US military has banned thumb drives on some of their networks due to possible threats.. Now we've gone to the next level and rely on users typing in a URL to compromise their own machines. This would be particularly easy on college campuses or other venues during game days or other events, when many people receive parking tickets because they are unfamiliar with the parking rules, or may have parked in the wrong location.

The best technical fix for organizations is likely a combination of border URL filtering (or DNS blackholing), a good centrally managed AV solution, and strong host level anti-malware software. I've seen a lot of good results with Malwarebytes recently, particularly when removing trojans that the major AV companies miss or are unable to properly clean, and that's what I will be recommending to end users.

Wednesday, April 2, 2008

Followup: Craigslist whole house looting

The Craigslist based looting I mentioned a few posts back resulted in a subpoena of Craigslist records, and the arrest of the couple who had posted the ad - apparently to cover the theft of saddles and other items. The Smoking Gun has mugshots and more details.

Investigators were lucky this time - the couple didn't use an anonymizing proxy or otherwise cover their tracks well enough to avoid being discovered. If this becomes a more common event, we'll likely see better concealment in the future.

Tuesday, March 25, 2008

Listing: the Craigslist attack vector


Most of us don't worry about people looting our homes while we're at work - but a new form of attack can create more than a nuisance. A recent Craigslist hoax resulted in large numbers of people taking possessions from Robert Salisbury's Jacksonville, Oregon home. KGW.com's article on the event is worth a read.

This is somewhat similar to the "SWATters" who fake 911 calls using callerID spoofing, social engineering, and other tactics. In each case, the attack is reasonably easy to conduct anonymously, can cause great damage, and uses third parties to conduct the actual attack. In many ways, this is a physical manifestation of what security professionals are used to seeing from botnets and zombies conducting an attack.

Will we see a new term for Craiglist lootings and other attacks - Listing, perhaps?

Other events, such as the massive out of control party in England after it was announced online and by a radio DJ point to the power of broadcast media. Normal social controls are often ignored when people feel that they were invited to take advantage of a situation - and damages can be hard to calculate.

Have you updated your home inventory recently?

Creative Commons licensed Flickr image credit to user blmurch

Wednesday, February 27, 2008

Social engineering the deliveryman


Sometimes life gives you a great example of a vulnerable system - here's my recent exposure to an everyday system with a reasonably significant vulnerability.

We've all heard of cases of packages being left on doorsteps, or mis-delivered. This one is a bit different...

I recently ordered a new phone, and had it shipped to my apartment. As most apartment dwellers are used to, over the course of my time there any delivery that arrived when I wasn't around was taken to the complex office and a note was left on my door. That's actually quite convenient, and the complex staff require signatures and, better, recognize me.

In this case, however, something a bit different happened. First, the delivery person was told by my neighbors that I wasn't around, and carried on with his deliveries. On his way back, he saw someone outside of the apartment and stopped. The person claimed to be me - and according to the delivery person, they knew my name, and claimed to be waiting for the package. A forged signature later, and my new phone was gone.

If you ship with FedEx, DHL, or UPS, you've likely never been asked to present ID. If you're around the residence, know the person's name, and act reasonably sure of yourself, packages are free for the taking.

A hole in the system? Yes. One I had never seen exploited before, but one that is pretty easy to tackle if you can get the resident's name. The solution is amazingly simple: allow packages to be sent with a "require ID" option. A photo ID would have prevented the entire issue.

I'll post a follow up, as further investigation is ongoing. Sadly, in cases like this the value of the stolen item isn't sufficient to change policy, and is below the threshold to make any sort of police investigation likely.

Creative Commons licensed image credit to Flickr user StarMama

Wednesday, April 4, 2007

Social engineering in the workplace: avoiding the "evil security guy" tag.

Security is evil. We say no (that's "default deny" to you), we enforce policies, and we make life difficult.

We ask hard questions, we poke holes in the beautiful software that you just wrote, and worst of all, we take up your time that could be spent on more important things than doing security assessments and configuration checks.

Really, we just get in the way.

Or, at least, that's how it feels a lot of the time. Then, a security event happens, and suddenly the security guy has a new shine!

Sadly, that's not the best way to work with IT staff. Security needs to work effectively with IT staff and the organizational community all of the time, not just during emergencies. What can we, as security professionals, do to build ties with the administrators, staff, and other employees? I have a few favorite tactics to make security staff more available to the rest of the organization.

Lunch with the security guys

Every few weeks, I eat lunch with a group of systems administrators from across the organization. It isn't a formal meeting, just a meeting of fellow geeks. Often, more useful information is exchanged at these lunches than in a week of meetings - and more happens as a result of them.

The real security benefit, however, is that I'm available as a resource in a non-formalized environment. Questions that never come up elsewhere are brought up, discussed - and often I don't have to provide an answer. The others in the group will already know it, or they've heard it from me before.

The key here is being approachable - the same ideas work for CISOs and other security management professionals - up to a point. Define a line of professionalism, but make yourself available.

Housecalls

In larger organizations, security staff may only heard of when they're bringing trouble to your door. It helps to build ties before the event. I've made a habit of getting out periodically and chatting with various contacts across campus. They tend to refer things to me, and it helps me keep my finger on the pulse of the IT community.

There is a balance here - at some point, being heads down working on security projects is more useful, but making these contacts can be an effective part of a security outreach program.

Lures

We all like to read about social engineering - why not do some of your own. If you walk into my office, you'll find a bright yellow 1960's Civil Defense Geiger counter, magnetic building toys, and a selection of candy all out and easy to get to. Why?

They lure in IT staff.

I've had more conversations because of someone wandering down the hall and spotting the Geiger counter through my open door than I can count. The candy means that people make a stops, ask a question, grab a handful, and meander back out. The building toys give engineering types something to play with as they explain their problems.

Simply taking the time to chat with the folks you work with is a valuable security tool. Yes, the "evil security guy" image is useful at times, but having an IT community that willingly comes to you before the problem becomes an issue is worth the trade.