Contribuez à SecuObs en envoyant des bitcoins ou des dogecoins.
Nouveaux articles (fr): 1pwnthhW21zdnQ5WucjmnF3pk9puT5fDF
Amélioration du site: 1hckU85orcGCm8A9hk67391LCy4ECGJca

Contribute to SecuObs by sending bitcoins or dogecoins.

Chercher :
Newsletter :  


Revues :
- Presse
- Presse FR
- Vidéos
- Twitter
- Secuobs





Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- USBsploit
- Commentaires


Revue Presse:
- Tous
- Francophone
- Par mot clé
- Par site
- Le tagwall


Top bi-hebdo:
- Ensemble
- Articles
- Revue
- Videos
- Twitter
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Twitter :
- Tous
- Par mot clé
- Par compte
- Le tagwall


Commentaires :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS/XML :
- Articles
- Commentaires
- Revue
- Revue FR
- Videos
- Twitter


RSS SecuObs :
- sécurité
- exploit
- windows
- attaque
- outil
- microsoft


RSS Revue :
- security
- microsoft
- windows
- hacker
- attack
- network


RSS Videos :
- curit
- security
- biomet
- metasploit
- biometric
- cking


RSS Twitter :
- security
- linux
- botnet
- attack
- metasploit
- cisco


RSS Comments :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS OPML :
- Français
- International











Revue de presse francophone :
- Appaloosa AppDome nouent un partenariat pour accompagner les entreprises dans le déploiement et la protection des applications mobiles
- D-Link offre une avec un routeur VPN sans fil AC
- 19 mai Paris Petit-Déjeuner Coreye Développer son business à l'abri des cyberattaques
- POYNTING PRESENTE LA NOUVELLE ANTENNE OMNI-291, SPECIALE MILIEU MARITIME, CÔTIER ET MILIEU HUMIDE
- Flexera Software Les utilisateurs français de PC progressent dans l'application de correctifs logiciels, mais des défis de tailles subsistent
- Riverbed lance SD-WAN basé sur le cloud
- Fujitsu multi-récompensé VMware lui décerne plusieurs Partner Innovation Awards à l'occasion du Partner Leadership Summit
- Zscaler Private Access sécuriser l'accès à distance en supprimant les risques inhérents aux réseaux privés virtuels
- QNAP annonce la sortie de QTS 4.2.1
- Une enquête réalisée par la société de cyber sécurité F-Secure a décelé des milliers de vulnérabilités graves, potentiellement utilisables par des cyber criminels pour infiltrer l'infrastru
- Trouver le juste équilibre entre une infrastructure dédiée et cloud le dilemme de la distribution numérique
- 3 juin - Fleurance - Cybersécurité Territoires
- Cyber-assurances Seules 40 pourcents des entreprises françaises sont couvertes contre les violations de sécurité et les pertes de données
- Des étudiants de l'ESIEA inventent CheckMyHTTPS un logiciel qui vérifie que vos connexions WEB sécurisées ne sont pas interceptées
- Les produits OmniSwitch d'Alcatel-Lucent Enterprise ALE gagnent en sécurité pour lutter contre les cyber-attaques modernes

Dernier articles de SecuObs :
- DIP, solution de partage d'informations automatisée
- Sqreen, protection applicative intelligente de nouvelle génération
- Renaud Bidou (Deny All): "L'innovation dans le domaine des WAFs s'oriente vers plus de bon sens et d'intelligence, plus de flexibilité et plus d'ergonomie"
- Mises à jour en perspective pour le système Vigik
- Les russes ont-ils pwn le système AEGIS ?
- Le ministère de l'intérieur censure une conférence au Canada
- Saut d'air gap, audit de firmware et (in)sécurité mobile au programme de Cansecwest 2014
- GCHQ: Le JTRIG torpille Anonymous qui torpille le JTRIG (ou pas)
- #FIC2014: Entrée en territoire inconnu
- Le Sénat investit dans les monnaies virtuelles

Revue de presse internationale :
- VEHICLE CYBERSECURITY DOT and Industry Have Efforts Under Way, but DOT Needs to Define Its Role in Responding to a Real-world Attack
- Demand letter served on poll body over disastrous Comeleak breach
- The Minimin Aims To Be The Simplest Theremin
- Hacking group PLATINUM used Windows own patching system against it
- Hacker With Victims in 100 Nations Gets 7 Years in Prison
- HPR2018 How to make Komboucha Tea
- Circuit Bender Artist bends Fresnel Lens for Art
- FBI Director Suggests iPhone Hacking Method May Remain Secret
- 2016 Hack Miami Conference May 13-15, 2016
- 8-bit Video Wall Made From 160 Gaming Keyboards
- In An Era Of Decline, News Sites Can t Afford Poor Web Performance
- BeautifulPeople.com experiences data breach 1m affected
- Swedish Air Space Infringed, Aircraft Not Required
- Why cybercriminals attack healthcare more than any other industry
- Setting the Benchmark in the Network Security Forensics Industry

Annuaire des videos
- FUZZING ON LINE PART THREE
- Official Maltego tutorial 5 Writing your own transforms
- Official Maltego tutorial 6 Integrating with SQL DBs
- Official Maltego tutorial 3 Importing CSVs spreadsheets
- install zeus botnet
- Eloy Magalhaes
- Official Maltego tutorial 1 Google s websites
- Official Maltego tutorial 4 Social Networks
- Blind String SQL Injection
- backdoor linux root from r57 php shell VPS khg crew redc00de
- How To Attaque Pc With Back Track 5 In Arabique
- RSA Todd Schomburg talks about Roundup Ready lines available in 2013
- Nessus Diagnostics Troubleshooting
- Panda Security Vidcast Panda GateDefender Performa Parte 2 de 2
- MultiPyInjector Shellcode Injection

Revue Twitter
- RT @fpalumbo: Cisco consistently leading the way ? buys vCider to boost its distributed cloud vision #CiscoONE
- @mckeay Looks odd... not much to go on (prob some slideshow/vid app under Linux)
- [SuggestedReading] Using the HTML5 Fullscreen API for Phishing Attacks
- RT @BrianHonan: Our problems are not technical but cultural. OWASP top 10 has not changed over the years @joshcorman #RSAC
- RT @mikko: Wow. Apple kernels actually have a function called PE_i_can_has_debugger:
- [Blog Spam] Metasploit and PowerShell payloads
- PinkiePie Strikes Again, Compromises Google Chrome in Pwnium Contest at Hack in the Box: For the second time thi...
- @mikko @fslabs y'all wldn't happen to have lat/long data sets for other botnets, wld you? Doing some research (free/open info rls when done)
- RT @nickhacks: Want to crash a remote host running Snow Leopard? Just use: nmap -P0 -6 --script=targets-ipv6-multicast-mld #wishiwaskidding
- An inexpensive proxy service called is actually a front for #malware distribution -

Mini-Tagwall
Revue de presse : security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone

+ de mots clés pour la revue de presse

Annuaires des videos : curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit

+ de mots clés pour les videos

Revue Twitter : security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall

+ de mots clés pour la revue Twitter

Top bi-hebdo des articles de SecuObs
- [Ettercap – Partie 2] Ettercap par l'exemple - Man In the Middle et SSL sniffing
- [Infratech - release] version 0.6 de Bluetooth Stack Smasher
- [IDS Snort Windows – Partie 2] Installation et configuration
- [Infratech - vulnérabilité] Nouvelle version 0.8 de Bluetooth Stack Smasher
- Mises à jour en perspective pour le système Vigik
- USBDumper 2 nouvelle version nouvelles fonctions !
- EFIPW récupère automatiquement le mot de passe BIOS EFI des Macbook Pro avec processeurs Intel
- La sécurité des clés USB mise à mal par USBDUMPER
- Une faille critique de Firefox expose les utilisateurs de Tor Browser Bundle
- Installation sécurisée d'Apache Openssl, Php4, Mysql, Mod_ssl, Mod_rewrite, Mod_perl , Mod_security

Top bi-hebdo de la revue de presse
- StackScrambler and the Tale of a Packet Parsing Bug

Top bi-hebdo de l'annuaire des videos
- DC++ Botnet. How To DDos A Hub With Fake IPs.
- Comment creer un server botnet!!!!(Réseau de pc zombies)
- Defcon 14 Hard Drive Recovery Part 3

Top bi-hebdo de la revue Twitter
- RT @secureideas: I believe that all the XSS flaws announced are fixed in CVS. Will test again tomorrow if so, release 1.4.3. #BASESnort
- Currently, we do not support 100% of the advanced PDF features found in Adobe Reader... At least that's a good idea.
- VPN (google): German Foreign Office Selects Orange Business for Terrestrial Wide: Full
- @DisK0nn3cT Not really, mostly permission issues/info leak...they've had a couple of XSS vulns but nothing direct.
- Swatting phreaker swatted and heading to jail: A 19-year-old American has been sentenced to eleven years in pris..
- RT @fjserna You are not a true hacker if the calc.exe payload is not the scientific one... infosuck.org/0x0035.png

Top des articles les plus commentés
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Microsoft !Exploitable un nouvel outil gratuit pour aider les développeurs à évaluer automatiquement les risques
- Webshag, un outil d'audit de serveur web
- Les navigateurs internet, des mini-systèmes d’exploitation hors de contrôle ?
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- CAINE un Live[CD|USB] pour faciliter la recherche légale de preuves numériques de compromission
- Nessus 4.0 placé sous le signe de la performance, de l'unification et de la personnalisation
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- [IDS Snort Windows – Partie 1] Introduction aux IDS et à SNORT
- Origami pour forger, analyser et manipuler des fichiers PDF malicieux

Social Hacking of Support and Implementation Teams

Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]

S'abonner au fil RSS global de la revue de presse



Social Hacking of Support and Implementation Teams

Par Netsparker Web Application Security Scanner
Le [2014-11-06] à 12:39:10



Présentation : Support, customer service and implementation teams are the human gateways into many systems. Because they are human, with regular access to some of the most sensitive information for a business, they pose a special security risk from two kinds of behaviour malicious behaviours, intended to exploit the system in some way, and innocent behaviours, which place the system at risk as a by-product, rather than a goal. In this article, we will focus on malicious behaviours and how to defend against them. Social Engineering Customer Facing and Operations Teams ------------------------------------------------------- The dangers of malicious behaviour initiated purposely by an employee of customer facing and operations teams are obvious but they are not unique to them. It is the high risk of being tricked into these behaviours by a second party social engineering hacks that makes these teams a special security weak point, as they have more direct contact with users than members of any other team and so present tempting targets. They also expect to be contacted by strangers, whereas other teams may become suspicious as soon as they are approached and be on guard for every unexpected interaction. So while general engineering techniques such as fake surveys can be used against all teams, user-targeting hacks - an attempt to hack a single user s account - are most likely to utilize these customer facing teams. Social engineering takes advantage of support and implementation employees to hack user accounts without investing in it technologically. Sometimes, hackers take advantage of errors in the rules that these teams are following sometimes the rules are correct, but team members bend them out of a desire to help or through being manipulated and talked or pressured into a mistake. Why the Rules Do Not Always Protect You --------------------------------------- As an example of rules failing,Scott Hanselman's hacker got Amazon to send Mr Hanselman a new Kindle, and then changed the shipping address away from Mr Hanselman. The address change should not have been possible and was refused several times, but the hacker called again and again until he found a representative more eager to help than to follow the rules. Mr Hanselman also notes that the hacker was not asked to log onto Amazon to prove he had access to the account, nor did some of his suspicious requests such as trying to eliminate a paper trail raise a red flag. Sometimes, the problem isn t with one company s rules or behaviours, so much as with the way that different companies reveal or request different information. Contradictory rules were at the base of the Mat Honan and Gizmodo hack from 2012, one of the best known examples of this sort of hacking. As Mr Honan puts it, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification. His hacker used two companies by-the-book actions to gain access to two accounts, based on the differences in what these companies considered private and hard-to-get information. Both of these hackers used some information they had about their victim, and a lot of information about which rules can be exploited and which can be overcome with enough effort. That is the essence of social engineering. How Implementation Teams can Be Socially Engineered --------------------------------------------------- You might think that implementation, as it is on-site and often face-to-face with users, cannot be exploited by social engineering as it relies on impersonating a stranger. But since implementation workers are often away from the office and moving between different sites, it can be quite easy for a hacker to pretend to be not an anonymous user but a fellow-employee, or an employee of the client, who has simply not met the implementation worker before. Using supposed familiarity can help the hacker lower the implementation worker s defences. Additionally, real employees that are well known to implementation teams may gain access to information they should not be able to see, and then pass it on for profit. Defending Against Social Engineering Attacks -------------------------------------------- So we can see that avoiding social engineering hacks requires two things correct rules, and a willingness to follow them even when the user sounds distressed or simply very innocent and convincing, and especially when the user is known to the customer facing teams. What forms a correct rule, or set of rules At its base, exploitation of employees uses the inherent difficulty of verifying a person s right to access information. The two sides of the equation, then, are the identity of the person and the information supplied to that person. A correct set of rules would seek to reveal as little information as possible, in exchange for as much identifying information as feasible. Keep three assumptions in mind at all times you cannot really predict what hackers may find beneficial in the information your employees disclose no single piece of identifying information is proof of identity and some of the things you consider to be separate pieces of identity are all discoverable from a single source. But the rules, as we said, are not enough. Employees must also stick to the rules despite the pressures or apparent distress of the user. And most of all, employees should use their common sense and pay attention to suspicious behaviour. If they flag a user, they may be able to prevent that user taking advantage of a fellow employee. In Mr Hanselman s case, it took the hacker several tries to change the shipping address on the order. Any one of those tries could have flagged the hacker as behaving suspiciously, and a string of these flags should have stopped the shipment. Similarly, in Mr Honan s case, the hacker made two calls one to supply a new credit card number, one to use that number to verify his identity and so gain access to the account. Paying attention to this string of calls could have prevented the hack. Employees should also feel confident that if they stick to the rules, they will receive backing from their bosses even if the user is not a hacker and complains about the lack of assistance. And, if you are measuring your employees by how many calls they handle, you should be aware that the time pressure makes it more likely that they will make mistakes such as give the hacker hints about security questions, reveal too much information before verifying identity and agree to perform actions that break the rules. Summary ------- This post provided only a glimpse of social engineering. There are multiple techniques for this form of hacking, and multiple goals, from hacking your company to hacking your users accounts. Defending against all of them is difficult, but educating yourself and your support, customer service and implementation teams about social engineering especially the need to be critical and on guard is a good place to start.

Les mots clés de la revue de presse pour cet article : social implementation
Les videos sur SecuObs pour les mots clés : social implementation
Les mots clés pour les articles publiés sur SecuObs : social
Les éléments de la revue Twitter pour les mots clé : social implementation



AddThis Social Bookmark Widget



Les derniers articles du site "Netsparker Web Application Security Scanner" :

- Web Application Security Basics - Keeping All Your Software Up To Date
- Security Weekly Talks About Web Application Security Automation with Netsparker CEO
- April 2016 - Netsparker Cloud Update
- April 2016 - Netsparker Desktop Update
- Scanning Parameter-Based Navigation Websites for Vulnerabilities
- VIDEO What is Netsparker An Interview with Ferruh Mavituna
- Excluding Parameters from a Web Security Scan
- Netsparker Cloud Updated with New Security Checks and Several Other Service Improvements
- Netsparker Desktop Updated with DROWN SSL TLS Security Check and More
- Infographic Statistics About the Security Scans of 396 Open Source Web Applications




S'abonner au fil RSS global de la revue de presse

Menu > Articles de la revue de presse : - l'ensemble [tous | francophone] - par mots clé [tous] - par site [tous] - le tagwall [voir] - Top bi-hebdo de la revue de presse [Voir]



Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail




SecuToolBox :

Mini-Tagwall des articles publiés sur SecuObs :

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :

Mini-Tagwall des Tweets de la revue Twitter :