21
Jen Fox @j_fox

Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Jen Fox

@j_fox

Page 2: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM
Page 3: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Sr. Security Consultant

DEF CON 23 Uber Badge winner, SECTF

Page 4: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Objective• Network credentials and/or sensitive information

• Provide value for the client!

Scope• Contact names provided

(My) Problem• Don’t get to pick and

choose

• Need something credible and effective

• Limited time

Page 5: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM
Page 6: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Goals &

Requirements

Research &

Recon

Analysis

Attack!

Pwn / Fail

Pivot

Page 7: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Company site

Inappropriately exposed docs

Vendor case studies

News

Page 8: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Growth through merger / acquisition• News

Lack of integration• Email addresses

• Service providers

Page 9: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Back to scope – people provided across

depts and levels

What does everyone care about?

+ lack of integration …

Page 10: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

(Company Logo)

Company

PayrollCo PayrollCoService

PayrollCo, a payroll company

Copyright © 2014 PayrollCo

Page 12: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

[email protected]

company.com

Company,

Payrollco.net/company

Dude-

Page 13: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Other phone calls• Why pretext chosen

Vendor case study

LinkedIn info re: head of HR

Page 14: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Goals &

Requirements

Research &

Recon

Analysis

Attack!

Pwn / Fail

Pivot

Page 15: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM
Page 16: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Technology Physical security / process Routines – payday, breaks Case studies Org structure / phone

numbers

Page 17: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

From IT about upgrades, changes, etc.

Reminders that passwords will never be requested from help desk or IT department

Do it often – make it normal to hear from IT / InfoSec

Page 18: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Reduces uncertainty

Reduces snap decision making for

important transactions

However…• Procedures must reflect and support the actual

process

• Procedures must be applied consistently

Page 19: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Not stressed Not stressedStressed!

Page 20: Jen Fox @j fox - IASA...How I Got Network Creds Without Even Asking: A Social Engineering Case Study Author Jen Created Date 4/10/2017 1:58:16 PM

Rules don't help people respond well under pressure

Give people permission to say no

Provide examples of what to say or do

Assure them they will be supported when they say "no" to someone