Information Security Blog

Social Engineering In My Free Time

Social Engineering In My Free Time

I was recently at an entertainment event that was part concert, part story-telling, part presentation, and all fun. I had purchased my ticket for this event the very day they went on sale, just to make sure I’d get a great seat. And the seat really was perfect: center-stage in the front section.

TicketsSome of my friends were also attending, but they either hadn’t had the spare cash to buy the great ticket, or had waited too long to get one. Instead, they volunteered to work the merchandise tables for the artists that were performing/presenting in exchange for admission. It meant that I wasn’t able to hang out with my friends during the show, but it opened up an entirely different opportunity for me: meeting the entertainers socially.

After the event was over, my friends were doing their work,cleaning up their merchandise areas and accounting for their sales. I made it a point to keep conversations with them active and kept moving around while security did their job of clearing the theater, escorting the stragglers outside, and locking the doors. Soon, I was locked in the building with everyone else on staff, with no actual permission to be there. I had successfully passed the first barrier: building security believed I was supposed to be there.

At that point, I did whatever I could to make myself useful. I carried boxes and moved equipment as though it was what I was there to do all the time. This allowed me to pass the second barrier: I was just accepted as another volunteer with those around me, even without the necessary credentials.

At the very end of the night, I ended up being one of three people not on the paid staff that was invited out for drinks with the entertainers and crew. I was going to spend the rest of my evening with some of my favorite stage and screen celebrities (some of whom you’ve probablynever heard of, and some of whom you almost definitely have heard of).

So, the deck was definitely stacked in my favor, and it’s highly unlikely that I would have been able to accomplish any of this if Ihadn’t already had friends “on the inside.” But, it does show how hard it can be to combat social engineering when a member of your organization actively assists an outside party. Perhaps you have a disgruntled low- or mid level employee with an idea about how they can raise their own privileges by vouching for the legitimacy of an outside party, and getting that outside party access above their own.

Make sure all levels of your organization, and any contractors you have, understand which sources they should trust, and which they shouldn’t.



Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

About the Author:

Bob Gorski - Senior Security Consultant

Add a Comment