Penetration Testing mailing list archives
Re: Email Pen-testing
From: "Al Smolkin" <UnODir () hotpop com>
Date: Sun, 21 Mar 2004 18:37:07 -0500
It is your job as a pen-tester to completely outline to the higher staff exactly what and where you will be doing, and that includes social engineering. It is the management of the bank's job to educate their employees (or hire you to do so) prior or after the pen-test. Be forewarned, though. Make sure that you go over every detail with the management. Don't forget in describing the test to dot the "I"s and cross the "T"s, otherwise, your butt could easily end up in the proverbial sling. as far as the social engineering goes overall, remember, Kevin Mitnick made a career out of it. Al Smolkin CEH, CCNA On 20 Mar 2004 16:22:18 -0000, Blake wrote:
Wanted to get your opinion on something... Doing a pen-test for a small bank which was proving very difficult to get it. A friend of mine suggested I send a backdoor trojan attachment via an email. If
they clicked on it, the backdoor performs maybe a boxscan, grab passwords, and connects out to the Internet. --Much like a virus.
I think this type of testing is becoming more relevant nowadays, especially with whats out there. It reinforces properly configured antivirus software and
user awareness.
I spoke with a previous customer of mine about the idea. He said he would be very upset if he was not told prior to that type of test as part of normal pen-
testing.
Generally speaking, my code of ethics doesn't allow me to social engineer. I don't like lying and misleading people. Also people tend to hate you after
they've been punk'd.
What's your ideas on the email pen-tesing? -Blake --------------------------------------------------------------------------- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------------
--------------------------------------------------------------------------- You're a pen tester, but is google.com still your R&D team? Now you can get trustworthy commercial-grade exploits and the latest techniques from a world-class research group. www.coresecurity.com/promos/sf_ept1 ----------------------------------------------------------------------------
Current thread:
- RE: Email Pen-testing, (continued)
- RE: Email Pen-testing Chris Hurley (Mar 23)
- RE: Email Pen-testing AJ Butcher, Information Systems and Computing (Mar 23)
- RE: Email Pen-testing Frank Knobbe (Mar 24)
- Re: Email Pen-testing Michael Richardson (Mar 24)
- RE: Email Pen-testing Rob Shein (Mar 23)
- RE: Email Pen-testing Brad . Murray (Mar 23)
- Re: Email Pen-testing Michael Richardson (Mar 23)
- RE: Email Pen-testing R. DuFresne (Mar 23)
- Re: Email Pen-testing Rainer Duffner (Mar 23)