Archive for the 'Kevin Mitnick' Category

Controlling the Human Element of Security
KEVIN D. MITNICK
& William L. Simon
Foreword by Steve Wozniak

We humans are born with an inner drive to explore the nature of our
surroundings. As young men, both Kevin Mitnick and I were intensely curious
about the world and eager to prove ourselves. We were rewarded often in our
attempts to learn new things, solve puzzles, and win at games. But at the same
time, the world [...]

st1\:*{behavior:url(#ieooui) }
Some hackers destroy people’s files or entire hard drives; they’re called crackers
or vandals. Some novice hackers don’t bother learning the technology, but simply
download hacker tools to break into computer systems; they’re called script
kiddies. More experienced hackers with programming skills develop hacker
programs and post them to the Web and to bulletin board systems. And [...]

This book contains a wealth of information about information security and social
engineering. To help you find your way, here’s a quick look at how this book is
organized:
In Part 1 I’ll reveal security’s weakest link and show you why you and your
company are at risk from social engineering attacks.
In Part 2 you’ll see how social [...]

A company may have purchased the best security technologies that money can
buy, trained their people so well that they lock up all their secrets before going
home at night, and hired building guards from the best security firm in the
business.
That company is still totally Vulnerable.
Individuals may follow every best-security practice recommended by the experts,
slavishly install [...]

st1\:*{behavior:url(#ieooui) }
What do most people think is the real threat from social engineers? What should
you do to be on your guard?
If the goal is to capture some highly valuable prize–say, a vital component of the
company’s intellectual capital – then perhaps what’s needed is, figuratively, just a
stronger vault and more heavily armed guards. Right?
But in [...]

st1\:*{behavior:url(#ieooui) }
Many social engineering attacks are intricate, involving a number of steps and
elaborate planning, combining a mix of manipulation and technological knowhow.
But I always find it striking that a skillful social engineer can often achieve his
goal with a simple, straightforward, direct attack. Just asking outright for the
information may be all that’s needed – as [...]

Some of these stories might lead you to think that I believe everyone in business
is a complete idiot, ready, even eager, to give away every secret in his or her
possession. The social engineer knows isn’t true. Why are social engineering
attacks so successful? It isn’t because people are stupid or lack common sense.
But we, as [...]

We’re all grateful when we’re plagued by a problem and somebody with the
knowledge, skill, and willingness comes along offering to lend us a hand. The
social engineer understands that, and knows how to take advantage of it.
He also knows how to cause a problem for you.., then make you grateful when he
resolves the problem.., and [...]

st1\:*{behavior:url(#ieooui) }
You’ve seen how social engineers trick people by offering to help.Another
favorite approach turns the tables: The social engineer manipulates by pretending
he needs the other person to help him. We can all sympathize with people in a
tight spot, and the approach proves effective over and over again in allowing a
social engineer to reach his [...]