How to Run Social Engineering Tests Safely

629 views
November 29, 2011
by
RSAC Cybersecurity
YouTube video player
How to Run Social Engineering Tests Safely

TL;DR

Social engineering tests should be authorized, carefully scoped, and designed to avoid operational disruption, legal trouble, and embarrassment for the client. Seemingly clever tactics, such as forging badges, resetting active users’ passwords, impersonating regulators, entering facilities, or examining discarded records, can trigger police involvement, interrupt business, expose sensitive information, and damage trust in security practitioners.

Transcript

Thanks. Hi there. Is the mic o-- yeah, it is. Well, I'm echoing myself. Um, let's see. Okay, have the title. Okay. Let me-- There's always stories behind my things, and, I mean, I've had a bunch of... I mean, this one, I don't know where to start with the stories because it was, like, about time people said, "You gotta start telling people how not ... Read More

Key Insights

  • Social engineering is often applied too broadly to nearly any attack that extends beyond purely technical activity. Treating every persuasive email or human interaction as sophisticated social engineering hides the distinct methods involved and encourages practitioners to act without training in the relevant underlying sciences.
  • Authorization is not sufficient protection when assessors use reckless tactics. A consultant who created a fake badge and asked the target’s guards to laminate it still prompted police involvement, emergency confirmation with contract personnel, removal from the site, and forced departure from the area.
  • Forged institutional correspondence can create consequences far beyond the intended target. Consultants testing a credit union used a document associated with the National Credit Union of America, causing the recipient to report it and triggering warnings to members around the country.
  • Password-reset attacks can disrupt legitimate business operations. If an assessor persuades a help desk to reset an operational user’s password, the real employee may lose access, which can be especially damaging when that employee handles hundreds of thousands or millions of dollars in daily transactions.
  • Physical intrusion can expose credentials without complex technical exploitation. During one office entry, assessors noticed a small piece of paper under a monitor, found the word “tourist,” and used it to access the account of a human resources vice president at a very large company.
  • Casual disclosure can turn questionable conduct into evidence against the practitioner. A hacker who described getting a janitorial job later identified the targeted company while speaking near FBI personnel, illustrating the risk of discussing potentially felonious conduct or sensitive client work too freely.
  • Dumpster diving can reveal highly sensitive corporate information. The talk cites discarded administrator credentials that enabled compromise of telephone infrastructure, as well as credit card records and boxes of bank documents left in trash, showing why disposal practices belong within security assessments.
  • Poorly executed social engineering harms clients and the security industry. Public incidents can make executives reluctant to approve legitimate assessments, damage confidence in practitioners, and expose organizations to disruption or embarrassment even when the original goal was to evaluate security weaknesses.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can social engineering tests be conducted safely?

Social engineering tests should begin with clear authorization, defined methods, and safeguards against operational harm. Assessors must consider how targets, guards, help desks, police, regulators, and other outside parties could react. A tactic should not merely prove that deception works. It should produce useful findings without locking out employees, provoking public warnings, or creating an apparent crime that requires emergency contract verification.

Q: Why can a forged employee badge cause legal trouble?

A forged badge can appear to security personnel and police as direct evidence of attempted unauthorized access. In the example provided, a consultant took a fabricated company badge to the corporate security office and requested lamination. Guards recognized the forgery, contacted police, and required contract administrators to confirm the engagement before the consultant was escorted away and told to leave on the next flight.

Q: What went wrong in the credit union social engineering test?

Consultants testing a credit union forged correspondence associated with the National Credit Union of America while attempting to place spyware inside the institution. The recipient noticed that the material looked suspicious and contacted the named organization. That organization then warned members around the country, creating a cascade of attention that affected confidence in similar security assessments and potentially embarrassed the client.

Q: Why is resetting an employee password during a test risky?

Resetting a password proves that a help desk can be manipulated, but it can also prevent the legitimate employee from accessing the account. The operational impact depends on the employee’s responsibilities. The transcript highlights a trader handling hundreds of thousands or millions of dollars in transactions each day, whose unexpected lockout could disrupt important business activity and create consequences unrelated to the test’s learning objective.

Q: What activities are described as social engineering?

The talk describes telephone deception, help desk manipulation, gaining entry to facilities, walking through company spaces, observing passwords stored near monitors, obtaining employment that provides physical access, and searching discarded materials. It also questions the tendency to label every minimally nontechnical attack as social engineering, because broad terminology can conceal meaningful differences in methods, risks, and required expertise.

Q: How can physical access expose corporate passwords?

Physical access lets an assessor inspect workspaces for credentials that employees have written down or poorly concealed. In one example, assessors could not guess a password but noticed a small strip of paper protruding from beneath a monitor. The paper contained the word “tourist,” which allowed them to log into the account of a vice president of human resources at a very large company.

Q: Why is dumpster diving valuable in a security assessment?

Dumpster diving can uncover credentials, credit card numbers, internal printouts, and boxes of sensitive records that organizations discard without adequate protection. The talk describes a hacking group finding printed administrator user IDs and passwords outside a telephone company, which enabled compromise of telephone infrastructure. It also references banks losing data because papers and boxes were left in dumpsters rather than securely destroyed.

Q: How does irresponsible testing damage the security industry?

Irresponsible testing makes executives question whether authorized assessments are worth the operational, legal, and reputational risk. After the credit union incident became widely known, a customer considering another engagement hesitated because its executives had heard about the case. Such incidents do not only embarrass individual consultants. They reduce trust in practitioners and can prevent clients from receiving useful security evaluations.

Summary & Key Takeaways

  • Security practitioners can create serious problems when they treat social engineering as an easy or exciting exercise. One consultant brought a forged corporate badge to the target company’s security office for lamination, prompting police involvement, contract verification, removal from the property, and an order to leave on the next available flight.

  • A credit union assessment escalated when consultants forged correspondence associated with the National Credit Union of America and attempted to introduce spyware. The suspicious recipient contacted the organization, which warned members around the country. The resulting attention made other executives question similar testing and harmed the reputation of the security assessment industry.

  • Social engineering includes telephone deception, physical entry, observation of exposed passwords, dumpster diving, and manipulation of support processes. These methods can reveal valuable information, but careless execution can lock out operational users, disrupt high-value work, alert law enforcement, expose clients publicly, and transform an authorized assessment into a damaging incident.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚