RE: Email Pen-testing

From: Kevin (kevin_at_kevincomputers.com.sg)
Date: 03/21/04

  • Next message: hwertz_at_voltron.homelinux.org: "Re: Email Pen-testing"
    To: <pen-test@securityfocus.com>
    Date: Mon, 22 Mar 2004 01:07:25 +0800
    
    

    Well, human are the weakest link in the security ring.. and social
    engineering is always the easiest (if not the best) technique to open up
    loopholes in a security system.

    Although it's an area which requires most emphasizes and concern, it is
    also the most sensitive area where security managers get stuck often in.

    If the company is ok with social engineering in the pen test, then I
    suppose it's ok.. It's ethical as long as you're doing it for a cause
    not malicious and harmful.

    -----Original Message-----
    From: Blake [mailto:netspan@hotmail.com]
    Sent: Sunday, March 21, 2004 12:22 AM
    To: pen-test@securityfocus.com
    Subject: Email Pen-testing

    Wanted to get your opinion on something...

    Doing a pen-test for a small bank which was proving very difficult to
    get it. A friend of mine suggested I send a backdoor trojan attachment
    via an email. If they clicked on it, the backdoor performs maybe a
    boxscan, grab passwords, and connects out to the Internet. --Much like a
    virus.

    I think this type of testing is becoming more relevant nowadays,
    especially with whats out there. It reinforces properly configured
    antivirus software and user awareness.

    I spoke with a previous customer of mine about the idea. He said he
    would be very upset if he was not told prior to that type of test as
    part of normal pen-testing.

    Generally speaking, my code of ethics doesn't allow me to social
    engineer. I don't like lying and misleading people. Also people tend to
    hate you after they've been punk'd.

    What's your ideas on the email pen-tesing?

    -Blake

    ------------------------------------------------------------------------

    ---
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off
    any course! All of our class sizes are guaranteed to be 10 students or
    less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of
    in-the-field
    pen testing experience in our state of the art hacking lab. Master the
    skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.
    www.coresecurity.com/promos/sf_ept1
    ----------------------------------------------------------------------------
    

  • Next message: hwertz_at_voltron.homelinux.org: "Re: Email Pen-testing"

    Relevant Pages

    • REVIEW: "Security Warrior", Cyrus Peikari/Anton Chuvakin
      ... get around to stating that the book focuses on security ... tools for reverse engineering are listed in chapter two, ... Overflow attacks, in chapter five, explains buffer and other overflow ... Part three lists attacks against specific platforms. ...
      (comp.security.misc)
    • REVIEW: "Security Warrior", Cyrus Peikari/Anton Chuvakin
      ... get around to stating that the book focuses on security ... tools for reverse engineering are listed in chapter two, ... Overflow attacks, in chapter five, explains buffer and other overflow ... Part three lists attacks against specific platforms. ...
      (alt.computer.security)
    • Re: Shame on Microsoft
      ... The problem is POOR ENGINEERS AND POOR MANAGEMENT. ... engineering testing requirements. ... Microsoft has been VERY aware of the basic flaws with Microsoft system - ... ANYTHING until ALL security testing is performed. ...
      (microsoft.public.security)
    • Re: test #1: black ice
      ... > desperately slow, however, but that's my fault, not BI. ... > Passed option 1 security scan and the privacy scan with flying colors. ... > This site installs software on the host machine, ... > This time also I was also very verbose on my technique. ...
      (comp.security.firewalls)
    • [Full-disclosure] XCon 2008 Call for Paper
      ... XCon 2008 Call for Paper ... Anyone who loves information security, ... hacker technique fans, etc. ... The speakers will be provided with: ...
      (Full-Disclosure)