because we are just humans

50
Because We Are Just Humans EHB Keynote - April 2014 - Xavier Mertens

Upload: xavier-mertens

Post on 26-May-2015

899 views

Category:

Technology


4 download

DESCRIPTION

Introduction to social engineering performed for EHB students @ Erasmus Hogeschool Brussels

TRANSCRIPT

Page 1: Because we are just humans

Because We Are Just Humans

EHB Keynote - April 2014 - Xavier Mertens

Page 2: Because we are just humans

TrueSec

$ whoami

• Xavier Mertens (@xme)

!

• Consultant @ day

!

• Blogger, Hacker @ night

!

• BruCON co-organizer���2

Page 3: Because we are just humans

TrueSec

The InfoSec World…

���3

Page 4: Because we are just humans

TrueSec

$ cat disclaimer.txt

“The opinions expressed in this presentation are those of the speaker and do not necessarily reflect those of past, present employers, partners or customers.”

���4

Page 5: Because we are just humans

TrueSec

Agenda

���5

• Introduction

• Historical examples

• Why and how?

• In our digital world

• Conclusion

Page 6: Because we are just humans

TrueSec

“Social What?”

���6

“Social engineering (SE) is the use of techniques to manipulate people into performing actions or divulging confidential information, rather than by

breaking in or using technical hacking techniques”

!

OR !

“A fancier way of lying”

Page 7: Because we are just humans

TrueSec

Attackers Are Lazy!

���7

Why make it complicated?

Page 8: Because we are just humans

TrueSec

First in the analog life

���8

Vendors: “It’s the last one, hurry up!” !

Headhunters: “I’m Alice from Marketing, May I speak to Bob, please?”

!

Kids: “May I go to this party?” !

… Women of course! (Maybe the wickests! ;-)

Page 9: Because we are just humans

TrueSec

Sand in the gears

���9

Page 10: Because we are just humans

TrueSec

Really?

���10

Page 11: Because we are just humans

TrueSec

$ man 3 human• People aren’t stupid (…well, only some :-])

• But they are…

• Kind

• Naive

• Trustful

• Voluntary

• Scared

���11

Page 12: Because we are just humans

TrueSec

People VS. Computers

���12

Page 13: Because we are just humans

TrueSec

Agenda

���13

• Introduction

• Historical examples

• Why and how?

• In our digital world

• Conclusion

Page 14: Because we are just humans

TrueSec

The Trojan Horse

���14

Page 15: Because we are just humans

TrueSec

Victor Lustig

���15

Page 16: Because we are just humans

TrueSec

Bernie Madoff

���16

Page 17: Because we are just humans

TrueSec

Christophe Rocancourt

���17

Page 18: Because we are just humans

TrueSec

Agenda

���18

• Introduction

• Historical examples

• Why and how?

• In our digital world

• Conclusion

Page 19: Because we are just humans

TrueSec

Why?

���19

… Because it works!

Page 20: Because we are just humans

TrueSec

How?

���20

… Sometimes being a good guy, sometimes being evil!

Page 21: Because we are just humans

TrueSec

It’s Cheap!

���21

Page 22: Because we are just humans

TrueSec

A nice target

• People know useful information (passwords, procedures, paths, phone numbers)

• People have access to

• Files

• Papers

• Badges

���22

Page 23: Because we are just humans

TrueSec

A “Swiss Army Knife”

• People can interact with systems or people

• Download a file

• Disconnect a system

• Introduce to someone else

• Send a mail or fax

• Get personal info

���23

Page 24: Because we are just humans

TrueSec

Attacks

• Physical

• Tailgating

• Shoulder surfing

• Trashing

���24

• Technical

• Phishing

• XSS

• Human DoS

Page 25: Because we are just humans

TrueSec

Our toolbox• Mail → Easy, anonymous and free

• Phone → Quick and direct access to the target

• Fax → Don’t under estimate the power of a fax in 2014!

• Snail mail → A stamp or nothing…

���25

Page 26: Because we are just humans

TrueSec

Psychology

• Fear

• Credulity

• Desire

• Solidarity

���26

Page 27: Because we are just humans

TrueSec

The Process

• The target

• The objective

• The plan

���27

Page 28: Because we are just humans

TrueSec

The Target• People

• Age, sex, social status, studies, …

• Company

• Open hours

• Jargon

• Procedures

• “Names”

���28

Page 29: Because we are just humans

TrueSec

The Objective

• Which info are we looking for?

• Which questions to ask?

• Cross-check

���29

Page 30: Because we are just humans

TrueSec

The Plan

• Write down a scenario

• Work below the radar

• Reminders, lexique, …

• Path

• “B” Plan!

���30

Page 31: Because we are just humans

TrueSec

Train Yourself

• Challenge your friends!

• It’s a game!

���31

Page 32: Because we are just humans

TrueSec

Agenda

���32

• Introduction

• Historical examples

• Why and how?

• In our digital world

• Conclusion

Page 33: Because we are just humans

TrueSec

A fact…

���33

“We located the problem: It is located between the keyboard and the chair”

Page 34: Because we are just humans

TrueSec

Pwn3d!

���34

This is a mass-pwnage device!

Page 35: Because we are just humans

TrueSec

The new OSI-model

���35

Layer 1 - 6

Layer 7

Layer 8 (“user” or “political”)

Over used

Getting better defended

Can’t be patched! ;-)

(Source: @jaysonstreet)

Page 36: Because we are just humans

TrueSec

You’ve been “Doxed”

���36

Page 37: Because we are just humans

TrueSec

Your Footprint

• In our modern life, we are 24x7 online

• We like to share

• We like to contribute

• Want an example?

���37

Page 38: Because we are just humans

TrueSec

At Home?

���38

Page 39: Because we are just humans

TrueSec

Maltego

���39

Page 40: Because we are just humans

TrueSec

B. Van Rillaer

���40

Page 41: Because we are just humans

TrueSec

B. Van Rillaer

���41

• bert.van.rillaer(at)ehb(dot)be

• vanrillaer(at)gmail(dot)com

• +32 2 559 15 xx

• +32 486 33 xx xx

• Study @ KUL 1999-2003 (License in Computer Science)

• Clarinet player?

Page 42: Because we are just humans

TrueSec

B. Van Rillaer

���42

• Twitter: @bvanrillaer

• 72 followers, last tweet 22/03

• Tweet most between 11:00 - 17:00

• Tablet Acer A200

• Mobile Samsung Galaxy S3 (GT-I9300)

• Active on G+, sell/buy on Kapaza

Page 43: Because we are just humans

TrueSec

B. Van Rillaer

���43

Page 44: Because we are just humans

TrueSec

Classic IT requests

• Could you give me the password?

• Could you power on/off this device

• Could you “<put your idea here>”

���44

Page 45: Because we are just humans

TrueSec

Interested?

���45

Page 46: Because we are just humans

TrueSec

Interested?

���46

• SET (https://www.trustedsec.com/downloads/social-engineer-toolkit/)

• Maltego (https://www.paterva.com/)

• Your own toolbox!

Page 47: Because we are just humans

TrueSec

Conclusions

���47

Page 48: Because we are just humans

TrueSec

Conclusions

���48

Page 49: Because we are just humans

TrueSec

Conclusions

���49

“You don’t know what you can get away with until you try.”

!

- Colin Powell

Page 50: Because we are just humans

TrueSec

Thank you! More info?

@xme

[email protected]

http://blog.rootshell.be

https://www.truesec.be

���50