<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shades of Gray Security &#187; social engineering</title>
	<atom:link href="http://shadesofgraysecurity.com/category/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>http://shadesofgraysecurity.com</link>
	<description>Because security isn't always black &#38; white</description>
	<lastBuildDate>Thu, 17 Mar 2011 07:20:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Social Networking/Engineering Sites</title>
		<link>http://shadesofgraysecurity.com/social-networking-engineering-sites/</link>
		<comments>http://shadesofgraysecurity.com/social-networking-engineering-sites/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 15:33:37 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[mashable]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[web 2.0]]></category>
		<category><![CDATA[worms]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=64</guid>
		<description><![CDATA[I was discussing social networking sites with a friend the other day and a slip of my tongue revealed the strongest weakness of these sites, I called them social engineering sites. I know, I know, yet another SE article. Not so, I&#8217;m going to discuss the growing trend of social networking and the inherent weaknesses [...]]]></description>
			<content:encoded><![CDATA[<p>I was discussing <a href="http://shadesofgraysecurity.com/tag/social-networking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social networking">social networking</a> sites with a friend the other day and a slip of my tongue revealed the strongest weakness of these sites, I called them <a href="http://shadesofgraysecurity.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">social engineering</a> sites. I know, I know, yet another SE article. Not so, I&#8217;m going to discuss the growing trend of <a href="http://shadesofgraysecurity.com/tag/social-networking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social networking">social networking</a> and the inherent weaknesses found in them.</p>
<p>Everyone always hears what &#8220;they&#8221; say about them, social networking sites are dangerous, they are vulnerable, people can hack your computer through them, viruses spread through them, etc. Immediately, the site in question gets smeared. Interestingly, to me anyway, is it doesn&#8217;t seem to slow the acceptance and use of these sites at all. New contenders spring up out of no where, exploding onto the scene like the first time you see Jaws break the surface. There is no question, <a href="http://shadesofgraysecurity.com/tag/web-2-0/" class="st_tag internal_tag" rel="tag" title="Posts tagged with web 2.0">Web 2.0</a> (I really dislike buzz words, especially that one for some reason) has radically changed the Internet.</p>
<p>That being said, what makes these sites more vulnerable than any other site you visit? Nothing, really. At least at their core. The only thing that really makes them more vulnerable is the fact that so many people use them they become highly prized targets. I said at their core though. That&#8217;s where things get tricky. Most of these sites are not really all that bad when standing alone. This is where Web 2.0 and <a href="http://shadesofgraysecurity.com/tag/mashable/" class="st_tag internal_tag" rel="tag" title="Posts tagged with mashable">mashable</a> buzz words start reeking havoc. At it&#8217;s core, most of the sites are not bad, but opening up an API to allow extensions, or applications to be installed on the profile starts to become a problem. Some sites that offer too much control to the user (hi <a href="http://myspace.com" target="_blank">MySpace</a>) also present problems. If nothing else, giving novices access to design their own completely tasteless site to look like some horrid thing from the early 90&#8242;s is just plain wrong. More often than not, I come across profiles that don&#8217;t even load right, at least I hope they don&#8217;t. I&#8217;d hate to think someone intentionally wanted their profile to scroll a mile to the right to see the second column of the page. At least it appears we are trending away from this, first <a href="http://www.facebook.com" target="_blank">FaceBook</a> restricted users to a basic template so all profiles are uniform, and now <a href="http://www.twitter.com" target="_blank">twitter</a> doesn&#8217;t allow a user much of anything other than basic update functionality and a hand full of backgrounds from which to choose.</p>
<p>Don&#8217;t believe me? Look at <a title="TwitPwn month of twitter bugs" href="http://twitpwn.com" target="_blank">twitpwn.com</a> and the <a title="month of twitter bugs" href="http://www.twitpwn.com/labels/MoTB.html" target="_blank">Month of Twitter Bugs</a> going on over there. we are at day 8 and so far, all the vulnerabilities are from vendors using the API and messing things up. This isn&#8217;t to say <a href="http://www.twitter.com" target="_blank">Twitter</a> is not without it&#8217;s problems, but the trend of mashable applications integrating with a wide variety of other applications far outweighs the problems a single source may have. This is only natural.</p>
<p>So let&#8217;s move forward in terms of what are some of the most dangerous aspects and weaknesses of social engineering, I mean networking, sites.</p>
<h3>CLASSIC SOCIAL ENGINEERING PITFALLS</h3>
<p>Let&#8217;s start here. How many people put a little too much data on their profile? How many of those people expose that profile to the general public, not just their friends. How many of those friends online are actually, you know, friends? Is it easy to find what high school you attended (hello <a href="http://www.facebook.com" target="_blank">FaceBook</a>)? Do you use the &#8220;What high school did you attend?&#8221; security question for your login to your bank? Really? So I can easily obtain most of those so called personal security questions just from browsing your profile(s)? Hmm, not too good.</p>
<p>Other problems may come of you tweeting too much information about your company. Having problems with a firewall? Planning a large roll out of network gear? Did you just tell the world there is a major shift in the topology of your network and it may be down, disrupted, and certainly may not be looked at as closely during the event? Tsk tsk. Revealing insider deals that could effect stock? Oops!</p>
<p>Have you been partying and posted pictures of you drinking heavily and acting less than professional? That could effect your current employment severely. It could hurt your employer&#8217;s relations with it&#8217;s clients. It could hurt your future employment when you get canned for it and the prospective employer finds it. If you&#8217;re going to stand a chance of being found by an employer or if you are mixing personal and business data on a profile, remember to keep it clean and that anyone can see it.</p>
<p>Knee-jerk comments are very difficult. People explode and in a fit of rage, post a status update, or tweet something. No amount of wishing is going to put the genie back in the bottle. This &#8220;new media&#8221; is incredibly dangerous when it comes to blurting things out. If they say friends don&#8217;t let friends drunk dial, how much worse is it to tweet drunk?</p>
<p>I&#8217;ll close this section with one more idea. I can&#8217;t tell you how many of my friends post messages on <a href="http://www.facebook.com" target="_blank">FaceBook</a> regarding their upcoming vacation, post what they are currently doing on vacation, and finally let us know when they are coming home. While I enjoy seeing pictures of you all enjoying yourselves in Hawaii while I sit suffering the oppressive heat of Louisiana, those pictures can wait until you come back.</p>
<p>This is only worsened by accepting anyone who wants to be your friend. I know it&#8217;s hard to ask for proof you know someone and you don&#8217;t want to be rude and not reciprocate a follow on <a href="http://www.twitter.com" target="_blank">Twitter</a>, but please consider what you are saying and whom you are saying it too. Even if you personally know and trust everyone in your friend list, maybe it&#8217;s a bad idea to say it anyway. After all, do you know all their friends? How many times have you seen a picture of a friend posted on <a href="http://www.facebook.com" target="_blank">FaceBook</a>, went to comment, and then realized you couldn&#8217;t because it was on someone else&#8217;s profile who is not your friend. Comments spread people. Loose fingers sink much more than the ship, much much faster.</p>
<h3>Passw0rds, P@ssw0rds, P@$$words</h3>
<p>With all the sites nowadays you have to login to, that&#8217;s a lot of passwords to remember. Are you using the same password for all your social networking sites? Come on, admit it. Do all those sites use encryption, or are you sending your credentials in clear text? In other words, do you see https instead of http in te address bar? Look at <a href="http://myspace.com" target="_blank">myspace.com</a> next time you log in and tell me what you see. If you are using the same password at all these sites, and one of them gets compromised by either an attack against the site itself dumping all the account data, or something that attacked you, there is considerable damage to be had. Now you stand the <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> of disinformation and malware being sent out from all your accounts without your knowledge. Do you use the same password to bank with? Tell me you don&#8217;t! Please!</p>
<p>This brings us to the next major section of the article. Actual attack vectors on these sites. We need to look at client side attacks, vulnerable &#8220;applications,&#8221; and <a href="http://shadesofgraysecurity.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>. It all comes back to the user. The term &#8220;click happy&#8221; I think aptly defines our society. Especially on these sites. My friend posted it, so it must be safe for me to click that link right? Really? Maybe he thought that too before getting hacked by Mary, who thought that of Tom, who thought that of Steve, who said Jan would never mess with him and then&#8230; well&#8230; Jan was just plain stupid. It happens. We all know it. Someone at the office always invariably opens the email attachment excited to see the ecard they were sent. It doesn&#8217;t matter how often it happens. After that, it spreads as if coming from you. Don&#8217;t be so quick to click! Do I need to mention <a href="http://tinyurl.com" target="_blank">tinyurl</a> and the likes? All the URL shortening are absolutely perfect for funneling malicious links to unwitting click happy victims.</p>
<h3>Vulnerability Plugins</h3>
<p>The growing mashable market allows for all sorts of disasters to be creep in. As I stated earlier, look no further that the <a title="month of twitter bugs" href="http://www.twitpwn.com/labels/MoTB.html" target="_blank">Month of Twitter Bugs</a>. Sites such as <a href="http://www.facebook.com" target="_blank">FaceBook</a> and now <a href="http://myspace.com" target="_blank">myspace</a> are allowing third parties to write applications that can be added to your profile. The more functionality applied to an application, the more likely vulnerabilities will be introduced. I grew up in a different time in the computer world apparently and I&#8217;m only in my mid-thirties. We were drilled with a few basic ideas in college, one of which was KISS. Keep It Simple, Stupid! What happened to that? Has it become Mashup Extremely Susceptible Systems? Sorry for my lack of creativity there. It&#8217;s certainly a MESS anyway.</p>
<h3><a href="http://shadesofgraysecurity.com/tag/spyware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spyware">Spyware</a>, Worms, and Woes<strong><br />
</strong></h3>
<p>People always hear these sites are dangerous, but don&#8217;t hear why. This informational gap is ripe for popup ads for spyware claiming to protect you. The same old tricks on any other websites, but now targeted to the perceived threats of social networking.</p>
<p>Just like you have heard a million times before with email, your friends list can be used to spread worms. <a href="http://www.google.com" target="_blank">Google</a>&#8216;s own social networking site <a href="http://www.orkut.com" target="_blank">Orkut</a> had a <a href="http://blog.trendmicro.com/orkutgoogle-worms-compromise-over-400000-accounts/" target="_blank">worm problem</a> that hit the news a while back. It&#8217;s really no different on these sites than on your email system. In fact, worms here are probably a little easier in that they will effect all users in as much as allowing it to spread if not directly affecting the user&#8217;s machine. Meaning, say I run linux and Thunderbird is my email client, well a worm hitting Windows and Outlook probably won&#8217;t mess up my system nor will it be able to use my contact list to spread. Not so in social networking contacts. The worm can still spread on the site, harvest your data there and move through your contacts list. In fact, it can do all that without even needing you to log on. I am quite stunned there haven&#8217;t been more.</p>
<h3>Cross-Site Scripting (<a href="http://shadesofgraysecurity.com/tag/xss/" class="st_tag internal_tag" rel="tag" title="Posts tagged with xss">XSS</a>)</h3>
<p>Don&#8217;t ask me why it&#8217;s XSS, not CSS. CSS was taken already I suppose. Anyway, this is a common attack vector effecting all web applications. The major difference here is again, these attacks are coming from a perceived trusted source. Why would Billy try to steal my cookies? A simple injection onto a blog, or profile that then get&#8217;s replayed every time someone looks at it could be devastating.</p>
<h3>Air Flashes in the Silverlight</h3>
<p>I&#8217;ve saved the final frontier for last. Adobe Air, Flash, and <a href="http://shadesofgraysecurity.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with microsoft">Microsoft</a> Silverlight are common technologies that increase the attack surface of any site. They are becoming increasingly popular. Naturally, the prolific use of Flash is one of the evolutions that make <a href="http://www.facebook.com" target="_blank">Facebook</a> and <a href="http://myspace.com" target="_blank">MySpace</a> so lucrative to attackers. As anyone with a profile knows, these technologies are extremely pervasive, as well as fun, when doing social networking. Unfortunately, a recent exploit in Adobe Flash has become a huge security threat. Experts say that so far hundreds of thousands of Websites have been compromised, including thousands of networking site pages, as the result of the Flash exploit loose in the wild. These technologies and there increasing use for their eye candy factor have naturally drawn the attention of attackers.</p>
<h1>Conclusion</h1>
<p>The main thing to realize is that regardless of the method of attack, you should always be aware that your profile can be exposed. Responsible disclosure of your personal and company data is crucial. Always assume that your data will be stolen and that the worse possible person to see it will eventually see it. If you think your boss will get mad if they read something, its probably best you not post it. If you wouldn&#8217;t invite that stranger into your home, you probably don&#8217;t want to invite him into your profile either. If you don&#8217;t put out a neon sign in your front lawn announcing you&#8217;re on vacation, you probably don&#8217;t want to put it on your profile either.</p>
<p>Go on, have fun on that vacation, we can wait to see the pictures.</p>
<p>Sleep well kiddies.</p>
<p>-Twisted</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 589px; width: 1px; height: 1px;">http://www.twitpwn.com/labels/MoTB.html</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fsocial-networking-engineering-sites%2F&amp;title=Social%20Networking%2FEngineering%20Sites" id="wpa2a_2"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Social Networking/Engineering Sites"  title="Social Networking/Engineering Sites photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/social-networking-engineering-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Killing bugs, a Social Engineering Odyssey</title>
		<link>http://shadesofgraysecurity.com/killing-bugs-social-engineering-odyssey/</link>
		<comments>http://shadesofgraysecurity.com/killing-bugs-social-engineering-odyssey/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 03:25:19 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[ips social engineering]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=36</guid>
		<description><![CDATA[I sat in the parking lot, trying to maintain my composure. &#8220;What the hell do I know about pest inspection?&#8221; My palms were sweating, My gear bag was sitting on the seat next to me. My outfit was complete with knee pads, safety goggles, work boots, cover alls. My nervousness certainly helped the disheveled look. [...]]]></description>
			<content:encoded><![CDATA[<p>I sat in the parking lot, trying to maintain my composure. &#8220;What the hell do I know about pest inspection?&#8221; My palms were sweating, My gear bag was sitting on the seat next to me. My outfit was complete with knee pads, safety goggles, work boots, cover alls. My nervousness certainly helped the disheveled look. I had forgotten to shave or clean my nails. I certainly looked to part, but &#8220;what the hell do I know about pest inspection?&#8221; The question repeated over and over in my head. It wasn&#8217;t like it was the first time I walked into a job I didn&#8217;t know much about. Just needed to walk in, look around, ask a few questions, maybe lay a few traps or something, then done. &#8220;Well, the client needs me to go take a look inside and see what I can find, maybe I can do this. Besides, what does any bank teller know about pest control?&#8221;</p>
<p>I walked in the front door and up to the first desk I saw. &#8220;Welcome to First National FCU, can I help you?&#8221;</p>
<p>&#8220;Yes ma&#8217;am, I&#8217;m here to do a walk through inspection. Is Ms. Doe available?&#8221; No way she is, why would she be?</p>
<p>&#8220;No sir, she&#8217;s out for lunch, but I can help you.&#8221; Oh perfect, the manager isn&#8217;t here, how did I know that was going to happen? Fortunately this lady, a loan officer perhaps, is going to help me. She proceeded to tell me she was in charge while the manager was out and told me of numerous locations reported to have ants. In my career, I have found that ants are a very big problem in filing rooms for some reason. Anyway, sure, let&#8217;s take a tour and look at those ants.</p>
<p>After taking me on an extensive tour of the facility showing me locations of reported problems, she excused herself and let me get after measuring rooms to get the cubic footage because my employer charges by that and all.</p>
<p>Rounding a corner, I walked into the filing room, again, the person at the computer in this room reported bad ant problems. &#8220;Do you need me to step out so you can work?&#8221; he asked. &#8220;If you don&#8217;t mind, I can go ahead and take care of this ant problem for ya right now,&#8221; I replied. He quickly excused himself and shut the door on the way out.</p>
<p>Did I mention, I&#8217;m not a pest inspector? &#8220;What do I know about pest control?&#8221;</p>
<p>&#8220;What do ya know, he left the computer unlocked. Looky here, account data.&#8221; A local printer and Ctrl-P, thanks for the help. Now let&#8217;s dig through these filing cabinets and look for some hot files to photograph. &#8220;Why it&#8217;s Ms. Doe&#8217;s account.&#8221; Click. &#8220;Here&#8217;s a few large business accounts, I&#8217;m sure these are worth some money.&#8221; Click click click. Oh, almost forgot, just for a nice touch, I brought canned air. Better make sure I spray it from time to time to sound like I&#8217;m spraying for bugs to avoid suspicion. I later learned the showboating wasn&#8217;t so important, but this was my first assignment as a pest inspector, and what do I know about pest control?</p>
<p>For grins, I opened all the filing cabinet drawers, stood on the desk, and took a few pictures of the room. Now let&#8217;s move on.</p>
<p>After packing back up, I slipped quickly out the door. My helpful evacuee was not to be seen but the ladies outside looked up at me. I had forgotten the goggles and dust mask I had donned in case someone busted in while I had those drawers open. &#8220;Oh, better tell him not to go back in there for at least 30 minutes, but that ant problem you have is solved.&#8221; Yeah that&#8217;s right, that would give the evilest of criminals a good thirty minutes to get away before the explosives go off. Scary, ain&#8217;t it?</p>
<p>That was one of several frighteningly similar <a href="http://shadesofgraysecurity.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">social engineering</a> engagements I have been on across the country over the past few years. I have been in several organizations such as this, too many to count. As I mentioned, I learned the extra touches were not needed. No one cares. If they do, they don&#8217;t question it anyway. I have never failed. Not once. I&#8217;m not bragging on my skills, it&#8217;s just that bad.</p>
<p>Even on an engagement where they set me up to fail, I won. Well, won is not appropriate. Let&#8217;s just say, they failed. The client had said a pest inspector wouldn&#8217;t work because they were in a shared space and that was controlled by the property management. That makes no sense, I had done plenty like that. In fact they are easier because the employees don&#8217;t care who the property management sends to do these jobs. Customer is always right of course so we decided on a phone guy. What do I know about phones? Perhaps, surprisingly little. I should know more, but I don&#8217;t. I could certainly mess up your lines with the equipment I bought at Home Depot though! I asked if they had their own phone guy, and was told no. They also wanted to test piggybacking and when asked if they had any sort of uniform or anything I was told no and they dress business casual. I show up and I&#8217;m escorted by, you guessed it, their internal phone guy. He wasn&#8217;t letting me do anything because they had so many problems with their phones. OK, FAIL. Now back to the hotel, a quick shave and fixing of my hair, the donning of a suit to dress over them and I returned. I was stopped by someone who I could have sworn was reading off a teleprompter with her speech about not letting me in. They did all wear the same company logo emblazoned golf shirts by the way. That was nice. So there was FAIL two. My first defeat. So I thought. I returned to the vehicle, got my computer gear bag and returned to do some pen testing. The receptionist had her head below the counter, I quickly turned into a different room. The mail room FTW. Oh look, a box full of accounts with socials and such was in there. Click click click. The client called foul, that the box wouldn&#8217;t be there normally. When I say given a long enough timeline you can get in anywhere, sometimes that timeline is much shorter than you would imagine.</p>
<p>I think it goes without saying that&#8217;s not the name of the bank and Ms. Doe did not manage it. Although, I&#8217;m sure I&#8217;ve been in a bank with a similar name. I don&#8217;t believe I&#8217;ve ever met a Doe though.</p>
<p>What can we learn from this? I&#8217;m not sure really. Invest in coffee cans? Certainly burying your money in the back yard would make it much harder for me to get a hold of your data. That&#8217;s not practical. What needs to be done is of course, <a href="http://shadesofgraysecurity.com/tag/awareness/" class="st_tag internal_tag" rel="tag" title="Posts tagged with awareness">awareness</a> training. People are the weakest link in security. They always will be. You can&#8217;t firewall stupid. In my time in this field, I have found that it simply doesn&#8217;t matter what you as a security engineer does. Why come through the network and <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> <a href="http://shadesofgraysecurity.com/tag/ids/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ids">IDS</a> sensors lighting me up when your employees give me the keys to your data center? No seriously, that DID happen. Come back for a future post with some tips on what to do. Or google it, I&#8217;m sure the Internet is ripe with tips on stopping this and you believe everything you see on the internets right? This article isn&#8217;t another social engineering attempt is it?</p>
<p>Sleep well kiddies.</p>
<p>-Twisted</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fkilling-bugs-social-engineering-odyssey%2F&amp;title=Killing%20bugs%2C%20a%20Social%20Engineering%20Odyssey" id="wpa2a_4"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Killing bugs, a Social Engineering Odyssey"  title="Killing bugs, a Social Engineering Odyssey photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/killing-bugs-social-engineering-odyssey/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>No Firewalls for Stupid</title>
		<link>http://shadesofgraysecurity.com/no-firewalls-for-stupid/</link>
		<comments>http://shadesofgraysecurity.com/no-firewalls-for-stupid/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 05:20:01 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=5</guid>
		<description><![CDATA[I received the following email while working an assignment. This email was passed through a very close chain from the source. Read the email, my analysis of why this was bad follows. The names of been changed to protect the innocent (and the guilty), and some comments are added in [brackets] by myself. All, The [...]]]></description>
			<content:encoded><![CDATA[<p>I received the following email while working an assignment. This email was passed through a very close chain from the source. Read the email, my analysis of why this was bad follows. The names of been changed to protect the innocent (and the guilty), and some comments are added in [brackets] by myself.</p>
<blockquote><p>All,</p>
<p>The IT department has received information that there is a very complicated Virus that has been infecting computers worldwide and there is no 100% safeguard against it. This virus is capable of doing serious damage to your PC and it is very hard to remove once a PC is infected. We have had a few reported cases here at Pwned Industries that we detected and resolved immediately. We have also verified our virus scanners are up to date.</p>
<p>As always, please be very cautious of any email received, especially if it has an attachment. This could be sent by an external or internal person. If you do receive a suspicious email and aren&#8217;t sure what to do, please create a service request from your desktop icon, the helpdesk website http://omgyoureallyhaveapubliclyaccessiblehelpdesk.com or call Helpdesk @ Ext 1234 [seriously, I didn't change the extension, that's really it, what are the odds?].</p>
<p>*****Do not open the email or attachment till IT gives you instructions*****</p>
<p>Very Important &#8211; If you get an IE or Windows pop up on your desktop stating it is &#8220;Antivirus 2009&#8243; please do not do anything. Call the helpdesk @ Ext 1234 immediately. Thank you</p>
<p>Regards,<br />
Innocent Victim- Network Systems Admin<br />
Pwned Industries<br />
Phone: 123-123-1234<br />
Fax: 123-123-1235<br />
IVictim@PwnedIndustries.com</p>
<p>&#8220;Life itself is easy. Humans and their actions are what make it hard&#8221;</p></blockquote>
<p>What I have learned, is that Pwned Industries is infected with a Trojan and doesn&#8217;t have much confidence in their ability to detect it. They also think said Trojan is new which further sends shivers of joy up my hacker spine. How did I come about such sensitive information? Well you see, Johnny Looselips over there thought he would help his friend out by forwarding an email from his Network Admin warning about the Trojan.</p>
<p>In addition to sending the letter in its entirety, he also sent it from his corporate email address. Even if he had thought &#8220;gee, maybe it&#8217;s a bad idea to alert outsiders of a TROJAN running rampant in my employer&#8217;s network, maybe I should scrub identifying data,&#8221; he still sent it from his corporate email address.</p>
<p>Additional nuggets not to be overlooked in this prime harvest include the link to their publicly accessible helpdesk, and name and number of the admin. I&#8217;m betting I have two user names in their email addresses (the admin&#8217;s and Mr. Looselips&#8217; who forwarded this email out). I also have the number to the help desk. &#8220;Hi, I&#8217;m Johnny Looselips and I forgot my password to the helpdesk. I got this email about this Trojan and I think I&#8217;m infected. I tried running the AV2009 tool and my computer seems to be getting worse. Please help me reset the password so I can get it fixed!&#8221; The signature line of this unfortunate Network Systems Admin, tragically sums it up &#8220;Life itself is easy. Humans and their actions are what make it hard.&#8221; Touché, good sir, touché.</p>
<p>As the title of this article states, there are no fire walls for stupid. Users continue to be teh weakest point in your network. What are you doing to raise <a href="http://shadesofgraysecurity.com/tag/awareness/" class="st_tag internal_tag" rel="tag" title="Posts tagged with awareness">awareness</a> at your organization?</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fno-firewalls-for-stupid%2F&amp;title=No%20Firewalls%20for%20Stupid" id="wpa2a_6"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="No Firewalls for Stupid"  title="No Firewalls for Stupid photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/no-firewalls-for-stupid/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

