Social Engineering: the Fine Art of BS, Face to Face

Social Engineering expert Chris Nickerson reveals what criminals are looking for when it comes vulnerabilities in building security.

By Joan Goodchild
Mon, June 08, 2009

CSO — Chris Nickerson is willing to push it about as far as a person can go when it comes to security assessments. The founder of Lares, a security consultancy in Colorado, Nickerson conducts what he calls "Red Team Assessments" for clients. (See: Red Team, Blue Team.) He is paid to try and dupe a client, and the client's employees, to give them a clear picture of the weak spots in their security plan. He then advises them on how to shore up defenses more effectively in the event a real criminal comes knocking.

In his line of work, Nickerson has to play the part of the criminal to its maximum potential (See: Anatomy of a Hack). When I say he is willing to push it as far as it can go in the interest of finding security holes, I mean he is even willing to be arrested and taken to jail. Nickerson said in a worse case scenario, if he is caught and arrested, even then he will not give up on his assessment. He tells police he is conducting the assessment for a client and gives them a fake number where they can call to verify he is telling the truth. On the other end, a member of his team, who poses as the client, will vouch for Nickerson.

If the cops buy it, Nickerson continues his work. Only as a very, very last resort will Nickerson have law officials call the actual client to get him off the hook in the event he has been caught. So far, that hasn't been necessary.

CSO got to experience Nickerson's ease at dealing with people in an assessment when we looked around one of the buildings in our area (Check out the video of his assessment). Nickerson pointed out areas of weakness for us that a criminal might look for when sizing up a facilities potential for breach. (See our walkthrough of the facility grounds and the list of problems in 5 Security Holes at the Office.)

Through a Social Engineers Eyes

Social Engineering expert Chris Nickerson reveals what criminals are looking for when it comes vulnerabilities in building security.

This player will be used for any in-article video treatment. This is a single video player.

"Normally when you are walking around a facility, someone should be stopping you," he noted "They should be questioning why you are cruising around the dirt of their building."

And they did. The staff at the building we examined does get credit for being observant. While Nickerson said none of the interrogation we dealt with during our time there would have deterred him in the slightest from getting his job done, we weren't completely unnoticed. The facilities manager did come out and ask us what we were doing.

Continue Reading

Lares

Loading...
Most Recent Technology Topics Stories
Batch Application Integration allows you to process critical transactions, such as payment authorizations, in real-time, and cue fulfillment (such as packaging and shipping) or other lower priority actions for batch processing. Learn more about Batch Application Integration, and how BMC CONTROL-M makes it possible.
Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective workload automation (WLA). But without tight integration and orchestration capabilities, you cannot truly achieve the benefits of WLA. Enterprise Management Associates share 5 critical steps to smarter WLA in this valuable white paper.
With the right workload automation solutions, business can take much greater advantage of cloud computing, achieving faster time-to-market, reduced costs, and more flexible operations. Learn how sending the workload into the cloud can provide faster processing while also reducing capital equipment expenditures inside the data center in this white paper.
This whitepaper by Marc Staimer, Dragon Slayer Consulting, reviews urgent issues facing organizations such as the inability to recover and restore data when required and mounting financial and legal risks. It also covers an on-demand approach that instantly and cost-effectively solves these issues.
Discover how Citrix Delivery Center provides an efficient and secure architecture for virtual workforce success.
This whitepaper provides a technical and commercial comparison of Citrix® XenServer" and VMware® vSphere", two of the leading server virtualization products on the market.
This Webcast discusses the highly scalable, superior IT optimization and workload consolidation that System z deliv...
Join Lee Weiner, Director, Support and Collaboration Technologies, LogMeIn, and guest speaker Ben Grey, Senior Anal...
Virtualization is not just for large enterprises. This expert video roundtable explains how to get started with a c...
The Fast Track to Windows 7
Users are demanding faster access to business applications and want devices that have the latest features that they...
Determining the Best Way to Virtualize
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center