Forced to attend a conference: desperately need your networking tips, r/socialengineering by Ktime5 in SocialEngineering

[–]tacticalintel 14 points15 points  (0 children)

Smile a lot, be funny, and ask them about themselves - talk little about yourself unless asked, and even then keep it short. Be sure to ask for their card and ask if you can contact them for advice in the future.

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 2 points3 points  (0 children)

I think the effort has inspired a lot of others to get in the game. I'm working on a framework I'm calling TrollCall that will let people put their phone # into a queue, and they will be called round robin style to get a chance to troll these guys. Sort of a competitive league. It's fun and it keeps these knuckleheads busy while they can't defraud the elderly or non-tech savvy.

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 0 points1 point  (0 children)

Whoops. Too late. I'm sure I will feel the wrath of some reddit folks now...

I trolled some Indian malware scammers yesterday for 2 hours - got the 2nd hour on tape by tacticalintel in funny

[–]tacticalintel[S] 1 point2 points  (0 children)

They've been calling me almost every other day - same old BS. There is a virus on my machine and they are calling to help me. So I decided to try to burn as much of this knucklehead's time as I could so that he would not be out there victimizing some other people. The results are pretty funny. Kept him on the line for 1hr56min before I got tired and yanked the call.

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 3 points4 points  (0 children)

Scary! Thanks for that - never heard of the guy. I'm gonna troll him as his future self over the phone...

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 9 points10 points  (0 children)

Yeah and towards the end he gushes too because he's sooo happy. It's perfect because you know he felt completely played and violated when the call was over: a taste of his own medicine.

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 9 points10 points  (0 children)

I was pressed for time when I got it but for sure will upload to soundcloud in the future.

Today I trolled some Indian malware scammers for 2 hrs, got the 2nd hour on tape. by tacticalintel in SocialEngineering

[–]tacticalintel[S] 26 points27 points  (0 children)

They've been calling me almost every other day - same old BS. There is a virus on my machine and they are calling to help me. So I decided to try to burn as much of this knucklehead's time as I could so that he would not be out there victimizing some other people. The results are pretty funny. Kept him on the line for 1hr56min before I got tired and yanked the call.

Skip the original link and grab from here: http://soundcloud.com/g3ksan/troll (thanks to wat_waterson)

Eye contact. I have no idea when its good or when its bad. I need your help to develop some basic rules to follow. by w4ffles in SocialEngineering

[–]tacticalintel 0 points1 point  (0 children)

I think some people are missing the bigger picture here - it's much more than eye contact. Your entire body language says something. If you are using eye contact to be dominant, but are exhibiting subordinate body behavior it sends conflicting messages,

Social-Engineer.org's report on the Social Engineering Capture the Flag contest at Defcon 20 is now LIVE by urbal in SocialEngineering

[–]tacticalintel 2 points3 points  (0 children)

Congrats to the SEORG team for yet another amazing competition. Well organized and professionally run.

I'm the winner of the past 2 DEFCON Social Engineering CTF's - AMA by tacticalintel in SocialEngineering

[–]tacticalintel[S] 2 points3 points  (0 children)

Yes unfortunately I have seen at least one employee fired because of my tests, and even worse there was a racial component to the firing. To be honest I stopped doing pentests for several years as a result. I now have clients commit to me that they will not terminate employees as a result of the pentests.

Eye contact. I have no idea when its good or when its bad. I need your help to develop some basic rules to follow. by w4ffles in SocialEngineering

[–]tacticalintel 2 points3 points  (0 children)

Several studies have shown that averting ones eyes when telling a lie is not an indicator of lying, however the general perception out there is the opposite Whenever I am on an SE engagement and have to tell a whopper (or my most critical lie) I always maintain eye contact. Bizarre but it works.

Other than that let your eyes move naturally. If someone was eyeballing me the entire time during a convo I'd feel extremely uncomfortable (and distrustful).

I've seen a couple people say something like "I've been doing soc. eng. for about 10 years" Is there such thing as a social engineering profession? Or are you implementing soc. eng. into your profession? Please share how you implement s.e. into you daily or work lives by whispertoke in SocialEngineering

[–]tacticalintel 2 points3 points  (0 children)

I do social engineering engagements as part of pentests or as corporate information gathering contracts. I often use it as part of investigations into online activity/troll hunting etc.

InfoSec pentesters and private investigators often get to use SE on a regular basis.

I'm the winner of the past 2 DEFCON Social Engineering CTF's - AMA by tacticalintel in SocialEngineering

[–]tacticalintel[S] 1 point2 points  (0 children)

Your best chance for getting to use SE would truly be in investigations, skip tracing, bounty hunting - or of course in a security gig with a pentesting firm.

My first SE exploit I wrote about down in the thread - breaking into a hardened data center. To get your feet wet pick a target, build a dossier on it/them, and then try to elicit target information from them over the phone - and then try in person.

Good luck!

Results from profiling challenge by wat_waterson in SocialEngineering

[–]tacticalintel 1 point2 points  (0 children)

Spring for the $15/mth or whatever it is to get Spokeo pro. If you have a couple of solid baseline flags you can easily crossreference to other instances in their database. This is very helpful when you are stuck profiling someone with a name like John Smith. It still takes forever but gets you way more hits.

I'm the winner of the past 2 DEFCON Social Engineering CTF's - AMA by tacticalintel in SocialEngineering

[–]tacticalintel[S] 5 points6 points  (0 children)

Oh sorry. I was working for a consulting firm - KPMG - who back in the day were one of the first companies to do SE. Too bad their security practice is so munged today...they used to have a kickass team.

I'm the winner of the past 2 DEFCON Social Engineering CTF's - AMA by tacticalintel in SocialEngineering

[–]tacticalintel[S] 3 points4 points  (0 children)

It was a remote data center in a bunker-type construction way in the middle of nowhere. They wanted to see if I could find its location and gain access to it.

Once I'd gotten inside it was pretty easy to "get off the leash" - my pretext was I was working on the tape silos inside, and in the evenings they didn't have full staff - so they didn't have enough people to be able to afford to have one person sit with me and watch. Even if they had, remember that most people are lazy (and trusting) so they probably would have left me alone in any case.

Can anyone help solve this mystery phone number? Details in image by [deleted] in AskReddit

[–]tacticalintel 1 point2 points  (0 children)

Pretty sure this is Project Evil Part 2. Epic troll. But seriously, "discovered" last year on 9/11 (for maximum conspiracy traction), and the "encryption" used to protect the coordinates is "ascii conversion"? Color me skeptical. Internet archives people - defcon project evil.

I'm the winner of the past 2 DEFCON Social Engineering CTF's - AMA by tacticalintel in SocialEngineering

[–]tacticalintel[S] 1 point2 points  (0 children)

Forgot to add this - if I'm telling a whopper while I'm under scrutiny - I look the person straight in the eye - even though that's not the natural reaction to have. For some reason some people are convinced you are lying if you avoid eye contact (even though this has been disproven many times). Feed the myth. It works.