HomeSecurity"I know I can't hack a bank, but I can hack...

"I know I can't hack a bank, but I can hack a person," says an ethical hacker

The idea that social engineering counters direct attacks on systems has been around for a long time, but it was presented at DTEXPO today by an ethical hacker who shared examples of his work.

"The role of a social engineer is a super specialized role, which only very capable people can manage to infiltrate a company," said the hacker.

hacker

“Sometimes, it takes a little effort to penetrate a company, I really don’t feel like I can hack a bank, even though I’ve been in three scenarios in job that involved banks. I know I could never hack a bank, but I know that if we hack the real people, we can get to the business. It’s very important to identify the weak points.”

The hacker shared examples of "physical penetration" to easily gain access to systems that were vulnerable beyond a human security process.

“In one job, we were forced to recreate the scenario of blowing up a chemical tank in a terrorist act,” the hacker said. “I looked at the site and tried to prepare or survey the building and the pressure was on us to climb into the silo.

“I didn’t know how I was going to do it, and the tank investigation came up. We had been informed about a special floor valve that was unique to this tank. So then we had something to talk about and use as a pretext to the officials we would meet.”

With only two people guarding this dangerous site, the hacker found that proper attire (jackets and boots) was enough to allow him to enter the workforce.

Similarly, the hacker found that his friend in a work area outside the smoking area was enough to accompany him to the emergency entrance. The hacker had the time he needed to perform task in the resulting confusion.

In another scenario, the hacker simply walked into an office holding a keylogger device, but the office was not empty, as initially expected.

“I found myself being the ‘keylogger guy’ – a fictional role that doesn’t even exist in the security industry – and I said, ‘Hi, I’m the keylogger guy.’ But someone from the back of the officeasked me, ‘What’s a keylogger?’,” giving me the chance to explain.

At the end of the day, the hacker explained, often in cybersecurity, " It's often just one person and we can defend ourselves against it if we all work together."

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS