Social Engineer Challenge - Convince a fellow player
My task for this was to convince a fellow player that I am proficient in a language that I am really not proficient in.
I didn't have a time to work on this task since i had to leave class early last Tuesday.
My plan was to arrive early to class today and I was going to target AgentBlueRaven since she told me one day that she has some Italian in her family. I was going to practice a few sentences and words in Italian and try to have a conversation with her in Italian, but i was not able to get it done because I was late for class and by the time I got to class everyone was already here.
Mission Failed....
Tuesday, April 21, 2015
Social Engineering #6 Covincing or No?
My challenge last week was to convince a fellow player that a famous person is related to me. I knew this would be challenging but I figured if I stuck to it I might be able to make it work. I originally started on Inspector Green and told him that my cousin is J. Alvarez he was skeptical but I continued by saying I have tickets to his concert this weekend. I asked him if he wanted to go because I had plans this weekend. I had a pair of tickets that I saved from an event I went to two years ago and showed them to him to prove it and a part of me noticed that he reached for them as if he would take them.
I put them away and continued to prod if he wanted to go to MY COUSIN'S concert and he was reluctant but never said that he did not believe that he did not believe me. By the time class was over he said no he didn't want the tickets and I think it was because he thought my task was to give someone something. I am not sure whether he believed it or not.
This task I think was considerably hard because mostly everyone in this class knows my name knows about me and we have been in this class for months already social engineering each other and learning things about each other. This task would have been easier towards the beginning of the class. As for the morals of this task I could see where someone could trick someone by using this lie. If I could convince a stranger that Steven Tyler was my uncle I could ask them for their contact information and guarantee a letter from him. There is so much that can be done with a small lie with someone that is gullible enough to believe it.
I put them away and continued to prod if he wanted to go to MY COUSIN'S concert and he was reluctant but never said that he did not believe that he did not believe me. By the time class was over he said no he didn't want the tickets and I think it was because he thought my task was to give someone something. I am not sure whether he believed it or not.
This task I think was considerably hard because mostly everyone in this class knows my name knows about me and we have been in this class for months already social engineering each other and learning things about each other. This task would have been easier towards the beginning of the class. As for the morals of this task I could see where someone could trick someone by using this lie. If I could convince a stranger that Steven Tyler was my uncle I could ask them for their contact information and guarantee a letter from him. There is so much that can be done with a small lie with someone that is gullible enough to believe it.
Social Engineer Challenge 9
My task this week was to find out what CaptainBlack X31 does on Tuesdays after class.
Well since i needed help on a lab that i needed to turn in tuesday after class, i asked him if he would be available after class to help me. (legit request)
I told him i would not be home until around 7pm. He said sure i'll be available. So around 7:30pm i texted him letting him know i was logging on and if he was still able to assist and he responded sure!
I started the lab and worked my way through. By 8pm I reached and completed the part i had a problem with. I then texted him and let me know that i figured it out and thanked him for standing by.
We then continued on via text discussing next week's presentation and what we have left for the rest of the semester. This went on for another hours or so.
Looks to me like CaptainBlack X31is usually relaxing at home after class on tuesdays, unless i call him to ask for help :-)
Thanks CaptainBlack X31!
Well since i needed help on a lab that i needed to turn in tuesday after class, i asked him if he would be available after class to help me. (legit request)
I told him i would not be home until around 7pm. He said sure i'll be available. So around 7:30pm i texted him letting him know i was logging on and if he was still able to assist and he responded sure!
I started the lab and worked my way through. By 8pm I reached and completed the part i had a problem with. I then texted him and let me know that i figured it out and thanked him for standing by.
We then continued on via text discussing next week's presentation and what we have left for the rest of the semester. This went on for another hours or so.
Looks to me like CaptainBlack X31is usually relaxing at home after class on tuesdays, unless i call him to ask for help :-)
Thanks CaptainBlack X31!
Draft Post: Hacker's Loyalty
Adrian
Lamo is an ex-hacker who was also known as the “Homeless Hacker”. He was called
the “Homeless Hacker” because he accessed hotspots in various locations
to penetrate internal networks of high profile companies and alerted them of
their vulnerabilities. He offered his services to fix it because he felt he was doing the right thing by notifying them of this security
breach and the potential harm it can do to their system if it got into the
wrong hands. Most companies took him up
on his offer and did not press charges. It
wasn’t until 2002 when one of the companies, NY Times, he hacked didn’t think
so kindly of Lamo’s actions. Instead they notified the U.S. Attorney’s office
who started an investigation on Lamo and his actions. He would later be found
guilty and be placed on 6 months probation and also having to pay restitution.
While on probation, he cleaned up his act and attended school to become a
Threat Analyst.
In
2010, a U.S. Soldier by the name of Bradley Manning contacted Adrian Lamo via
AOL chat room. During their chat, the two discussed Lamo’s past hacking
history, Manning awaiting to be discharged due to his gender identity
issue, both their experience in the IT world. As the
conversation progressed, Manning eventually confided that he has been
penetrating the U.S. classified network and forwarding classified information to
Wikileaks. This information he believed the public needed to know. Not believing
what he was hearing, Lamo asked Manning for specific stories and Manning supplied. Lamo
contacted the U.S. military and informed them of his conversation with
Manning. Manning was later arrested and
charged with several offenses, with one being “aiding the enemy”, which led to
a 35 year sentence.
Lamo
claimed that his action for turning manning in was to help the nation, "Mr Manning's well being was not as
important as the security of our armed forces. I had never considered myself
particularly patriotic, but when push came to shove the wellbeing of the nation
was of paramount importance to me." (excerpt from http://www.theguardian.com/world/2011/dec/15/hacker-adrian-lamo-bradley-manning-wikileaks)
I think that Lamo is a hypocrite, just as he thought that he was doing good exposing the companies whose systems he penetrated and then offering to fix it instead of doing ill will, Manning felt the same way about his actions; he felt as though the classified information needed to be known by the public so the truth would be out. According to Wired article, there are three different types of Hackers: whitehats (employed with companies in which they hack within the law), Blackhats (penetrate networks illegally for fun), and Grayhats (hackers who protect security holes from vandals). It would seem as though Lamos is regarded as a Grayhat. Since when is a grayhats loyalty to the law enforcement?
to be continued....
Final Draft for Final Post:
Albert Gonzalez – T.J Maxx
It is so much
easier to pay with a credit/debit card.
Most of us have one, or a few of them. A lot of people don’t like to carry
cash with them anymore, and if you need cash, you can easily find an ATM close
by, since there are so many around. We also love shopping, and a lot of us use our
credit/debit cards to pay for the items we purchase. In order to obtain a
Credit/Debit card you have to provide your name, address, social security
number, among other personal information to the Bank. So since it’s your
personal information, wouldn't you want Companies to protect it when you use
your Credit/Debit card to purchase items from them? I would like them to keep
my information secure, I hope you would too. But unfortunately when it comes to
information security, not all companies and industries are alike.
Albert Gonzalez was accused of
masterminding the combined credit card theft and subsequent reselling of more
than 170 million cards and ATM numbers from 2005 through 2007. The biggest such
fraud in history. He stole card information from TJX Companies like T.J Maxx,
BJ’s Wholesale Club, DSW, Office Max, Boston Market, Barnes & Nobles, and
Sports Authority. He hacked stores in different states like New York,
Massachusetts, and New Jersey. Gonzalez was arrested on May 7, 2008 and On
March 25, 2010, he was sentenced to 20 years in federal prison.
I believe that Albert Gonzalez actions
were wrong, and he is guilty as charged, but I have to ask, do you think Albert
Gonzalez was the only one at fault? Many would say yes, he is, but
I would argue the opposite.
One of the Companies he hacked was T.JX Companies,
T.J Maxx and Marshals s are clothing store owned by T.JX that sells designer
clothes for a discounted price. Therefor a lot of customers walk in to theirs
stores and purchase their items. I am not talking about a Mommy and Daddy owned
store, I am talking about a very big company that is making a very good amount
of money. But surprisingly they were using out of date and vulnerable security
encryption for their machines and networks. I believe that if a person uses their
Credit/Debit card at a store for instance, it is the store’s responsibility to
keep the information safe. Once I swipe my card thought your credit machine, my
card information is stored, so it becomes your property. Probably more than 90%
of the customers affected were not aware that their Credit/Debit card information
was compromised.
So I ask, why weren't they protecting
their costumer’s private information with up to date security?
T.JX was using WEP security encryption for their network. Almost every hacker
out there likes a challenge, but when the security is outdated and weak is like
a day at the park for them. I believed that T.JX should have done a better job
at securing their networks and customers information.
Sources:
Social engineering challenge: Stop!
My challenge for the past week was to have a fellow player fail their challenge due to my efforts. I had no definite plan on how to go about doing this, so i just had to keep my eyes open for when i saw someone openly trying to accomplish their task. the only open attempt was made by Raven Blue when she stuck the piece of tape to MzQueens water bottle. It all happened do fast i couldn't process anything she managed to stick tape on the bottle before I could even get up to intercept, so that was a fail. Before that, when i saw CaptianBlack take his challenge card from the bag, there were only two card in there. When i picked mine, it was the same challenge i had in a previous week, so i put it back. That left two cards in the bag, one of which i knew what it was so that was a 50-50 chance he'd pick that card. when he opened his card, i noticed the color of the writting and it was the same as the one i had, so i knew what his challenge was before he even finished reading it. for the whole class period, i tried to keep my eye on CaptianBlack to try and watch out for his attempt at his challenge so i can stop him. unfortunately, i didnt see him attempt his challenge, so that was a fail. looking back, i probably should have just said out loud to everyone what his challenge was, that way everyone would be suspicious of him trying to trade anything with them.
Final blog post first draft: The Hacks on the PSN (2011)
The Sony PlayStation
Network (PSN) has had a handful of hacks and incidences since its release in November
of 2006 from jail broken PS3s to a mass intrusion of privacy, but the hacks
that took place in April and June of 2011 were two for the record books. In
April, Sony said it discovered that between the 17th and 19th, an "illegal and unauthorized person"
got access to 77 million PSN users names, addresses, email address, birthdates,
usernames, passwords, logins, security questions and more. At
first, Sony and the rest of the world believed it to be George Hotz, the hacker
that made public instructions on how to jailbreak your PS3. Come to find out
that the splinter hacktivist group of Anonymous known as Lulzsec was
responsible by using a DDoS attack on the network, deliberately flooding the
PSN server with traffic causing a loss of income for a company that does
business online. Jake Davis (20), Mustafa Al-Bassam (18), Ryan Ackroyd (26) and
Ryan Cleary (21) from Lulzsec all claimed responsibility and plead guilty. This
hit Sony big time, shutting them down for nearly a month to try to recover and
costing just about $171.1 million in damages. A few months later, a separate
attack on the PlayStation Network, Sony Online Entertainment and Sony's
Qriocity media-streaming service led to the theft of private data pertaining to
more than 100 million user accounts, including credit-card numbers. All three
services were offline for more than three weeks. Anonymous later came forward
and took credit for the attack, saying that it was unintentional that they
obtained the information of all PSN’s users. Using a basic SQL injection attack to
expose millions users' personal data, 3.5 million digital coupons and 75,000
music codes.
A couple questions that
I ask Sony are:
- Why were PSN passwords apparently stored in plain, human-readable text?
- Why were email addresses, personal details, and credit card details also stored in unencrypted form?
While it might be
impossible to fully prevent unauthorized access to a system, it’s very simple
to encrypt data in a way that both secures user privacy, and makes it almost
valueless to any hacker with an intent to use that information for their own
personal gain, profit or otherwise.
Some questions that I have
for the hacktivist groups are:
- Why make user accounts public? Users aren’t the ones at fault so they shouldn’t be the ones that are punished.
- Instead of hacking a big league company like Sony, why not simply inform them that their security was not as tightly secured as they claimed it to be? Why was the result of your hacking necessary?
I
was in either of the hacktivist’s shoes, I would probably have the same ideals
in terms of trying to make being online safe for all users. As I mentioned in
one of my questions to the hacktivists, I would simply inform a company that
did business online that the security that they claim to be fool proof, isn’t. I
wouldn’t put any of the users at risk because that isn’t my goal.
Sources:
Subscribe to:
Posts (Atom)