Wednesday, March 4, 2015

Social Engineering Week 4 "Orange in the bag"

My task for this week was: “Get an object larger than an orange into a fellow player’s bag.”

Previously I prepared a fake social engineer task card similar to the once used by the professor in class (same note card and marker), I wrote on it a task week 4 from class 2014 that I found on this blog in the 2014 section. I prepared the card to show it to someone to get them to trust me. 

When I picket the real task I realized that I only have two object larger than an orange, my tablet (no way I will use it for this task) and my ice tea can. I decided to use the can.

Next step scan the class for a potential target (Admiral Aquamarine ;) ) ,  there were only two targets that had open bags on the table; Agent Raven Blue and Pink Mystery. I first wanted to target Agent Raven Blue and just sneak behind her and put the can in her bag but it was going to be too obvious and wanted to see if I can find a better way to execute my task. It was clear that if I approach her and ask for any request, it will be too obvious, at this point I knew that I will have a better chance by targeting my very very good friend Pink Mistery. I had a two step plan:
1)      Get Pink Mistery to trust me Knowing that she will be suspicious with any request that I will ask her,  I tried focus her attention on something else and I decided to use my secret weapon ( the fake card), I told her that my task is a little hard and that I need to know who has a car, I said I can show you my card if you show me yours ( I just wanted to make sure that she will not target me and also it will look suspicious if I don’t ask her to see her card), I showed her my fake card which sais “ Get a plate number for a student Car ” and she showed me hers. First step of my plan was accomplished.
2)      In the second part I wanted to ask her to hide my ice tea in her bag from the help disk guy since we are not allowed to have drinks in the labs and IT classes, I wanted to make the request seems like a spontaneous idea that I had on the spot just to make sure that she will not suspect me,  I waited for the help-desk guy to go in the storage room in front of the class and I dropped my can in the floor and picked up quickly to hide it and said “the help-desk guy is out side I don’t want him to see me through the window” tried to put it in my small bag did not work and I turned to Pink Mistery and asked her if she can hide my ice tea can in her bag because of the help disk outside, she accepted and put the can in her bag.

I think my plan was effective, I am happy that I didn’t go with my first plan because both Pink Mistery and Agent Raven Blue did not leave the classroom, also I think that without the fake card I would never been able to convince Pink Mistery to help me with anything since she was on the defensive.

Since I did not put the object on my targets’s bag myself, I don’t think I Brock any privacy laws but I did break a lot of moral once by laying and betraying her trust.


I felt horrible to target my friend, laying to her and betraying her trust was a really hard think to do, I told her that she can take the Ice Tea at the end to make me feel a little bit better. I was happy to accomplish my task but I did not feel good about what I had to do to get it done.

2 comments:

  1. This is impressive! I give you 5 points for how you accomplished what was an easier task.

    ReplyDelete
  2. This is impressive! I give you 5 points for how you accomplished what was an easier task.

    ReplyDelete