RE: Social Engineering Pentest



Look on this:

http://www.networkworld.com/newsletters/sec/2007/1029sec2.html

(no attachment are send with this e-mail)

Kind regards
Lorenz Kaminski

IT CC - Competence Center IT Security
----------------------------------------------------------------

Bundesdruckerei GmbH
Oranienstraße 91
10969 Berlin

GERMANY

Phone: +49 (0) 30 2598 2152
Fax: +49 (0) 30 2598 2139
lorenz.kaminski @bdr.de
www.bundesdruckerei.de

place of Business: Berlin
trade register: AG Berlin-Charlottenburg HRB 51900. Ust.-IdNr.: DE 165893405
supervisory board chairman: Heinz-Günter Gondert
COO: Ulrich Hamann (leader), Joachim Eilert

This message is intended only for the use of the individual or entity to which it is addressed, and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, or the employee or agent responsible for delivering the message to the intended recipient, we hereby give notice that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this message in error, please delete the message and notify us immediately.



-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On Behalf Of Joseph McCray
Sent: Tuesday, April 22, 2008 11:16 PM
To: pen-test
Subject: Social Engineering Pentest


I just got contacted by a customer that wants a pentest with the primary
focus being Social Engineering. We do a few things, but the SE portion
of our assessments isn't all encompassing by any means.

If you do a healthy amount of SE in your assessments give me a holla
because I'd really be interested in talking to you about developing a
more thorough social engineering attack framework that we can customize
for different customer verticals.


--
Joe McCray
Toll Free: 1-866-892-2132
Email: joe@xxxxxxxxxxxxxxxxxxxxxxx
Web: https://www.learnsecurityonline.com


Learn Security Online, Inc.

* Security Games * Simulators
* Challenge Servers * Courses
* Hacking Competitions * Hacklab Access

"The only thing worse than training good employees and losing them
is NOT training your employees and keeping them."

- Zig Ziglar

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • RE: A question for the list...
    ... There seems to be consensus that competence is part of the ... * ISP would block all ports for incoming traffic by default, ... Suitable procedures could be defined to protect a compentent customer ...
    (Incidents)
  • Re: A question for the list...
    ... > There seems to be consensus that competence is part of the ... Customer adds a platform and becomes incompetent. ... tunneling every protocol through port 80. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
    (Incidents)