<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social-Engineer.Org &#187; Blog</title>
	<atom:link href="http://www.social-engineer.org/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.social-engineer.org</link>
	<description>Security Through Education</description>
	<lastBuildDate>Thu, 19 Aug 2010 15:14:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Cyber Stalking and Smart Phones &#8211; Making Social Engineering Easier</title>
		<link>http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/</link>
		<comments>http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 15:12:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/?p=1274</guid>
		<description><![CDATA[Smart phones embed the longitude and latitude of the location in the meta data of the picture making it much easier for cyber stalking and social engineers.]]></description>
			<content:encoded><![CDATA[<p>It seems that every month we are <a href="http://twitter.com/humanhacker">tweeting</a>, blogging or writing in our newsletter something about the amazing world of <a href="http://www.social-engineer.org/newsletter/SocialEngineerNewsletterVol01Is03.htm">social media</a>.  Something just came across our desks that will really blow your mind. All about how smart phones are a cyber stalking dream tool.</p>
<p><a rel="attachment wp-att-1275" href="http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/attachment/stalkingsign/"><img class="alignleft size-full wp-image-1275" title="Stalking" src="http://www.social-engineer.org/wp-content/uploads/2010/08/stalkingsign.jpg" alt="stalkingsign Cyber Stalking and Smart Phones   Making Social Engineering Easier" width="300" height="297" /></a>What if I told you that there was a way to create a profile on you that could reveal<br />
•	Where you live<br />
•	Who else lives there<br />
•	Your commuting patterns<br />
•	Where you go for lunch each day<br />
•	Who you go to lunch with</p>
<p>And all I need you to do is use a <a href="http://www.social-engineer.org/newsletter/SocialEngineerNewsletterVol02Is07.htm">social media site</a> or two and post a picture or two here or there?</p>
<p>Most phones when used for taking pictures will embed certain data in the meta-tag.  Meta data is often used by software to help process the picture and open it correctly.  Yet there is so much space this is also often used to store the photographer’s name, date and other juicy bits of info about the picture.</p>
<p>One of the juiciest bits is geo-location.  Yes the age of the smart phone has opened up this flaw and allows a person to see the exact location of an individual when that picture was taking.  Smart phones actual embed the longitude and latitude of the location in the meta data of the picture.</p>
<p>Then when the user (you) posts it to twitter, facebook,  and the world begins to awe at your photographic prowess malicious social engineers are finding out the location seeing if you are near home, near a good spot to be abducted, profiling you for id theft or home invasion… pick your poison and although I sound sarcastic, this is very serious.</p>
<p><span id="more-1274"></span></p>
<p>This is a stalkers dream, enter the age of digital stalking.  And a brand new website<a href="http://icanstalku.com/"> http://icanstalku.com/</a></p>
<p>The folks at http://icanstalku.com/ scrap the Twitter feeds for people posting pictures, locate if it has metadata, scrap out the location and data and post it there for all to see.  YIKES.</p>
<p><strong>What Can You Do?</strong><br />
Well for one, stop sharing photos of your kids, your wife, yourself, your sandwiches, your clothing, your car, your new tattoo, your whatever with the whole universe.  Stop showing the world every time something funny, dumb or weird happens.</p>
<p>But if you are one of those people that must do this, then disable geolocation information in your smart phone.  For example in your iPhones it is under Settings &gt; General &gt; Location Services from there you can tell it what apps can access location data.</p>
<p>In your BlackBerry &#8211; Go into picture-taking mode (via HomeScreen, click icon &#8220;Camera&#8221;), press the Menu button and choose &#8220;Options&#8221;. Set the &#8220;Geotagging&#8221; setting to be &#8220;Disabled&#8221;. Finally, save the updated settings.</p>
<p>In Android go to the camera &gt; Settings &gt; GPS and make sure the check box is off.</p>
<p>That’s all you need to do, stop showing everyone where you are in the world.  This is not a light matter, when a criminal knows where you are they can more easily plan an attack.  <a href="http://www.social-engineer.org/">Security Through Education</a>.  Understand how the bad guys think and what methods they use and you can combat against it.</p>
<p>Till next time, stay safe.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;title=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;title=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;t=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cyber%20Stalking%20and%20Smart%20Phones%20-%20Making%20Social%20Engineering%20Easier%22&amp;body=Link: http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Smart%20phones%20embed%20the%20longitude%20and%20latitude%20of%20the%20location%20in%20the%20meta%20data%20of%20the%20picture%20making%20it%20much%20easier%20for%20cyber%20stalking%20and%20social%20engineers." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;title=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;title=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/&amp;title=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cyber+Stalking+and+Smart+Phones+-+Making+Social+Engineering+Easier+-+http://b2l.me/ajf26f&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/cyber-stalking-and-smart-phones-making-social-engineering-easier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A New Era of Security Awareness Training</title>
		<link>http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/</link>
		<comments>http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 15:52:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=1110</guid>
		<description><![CDATA[Our goal is to change the way people think, making them own a personal security policy that carries over from their personal life to their professional life.]]></description>
			<content:encoded><![CDATA[<p>Each year companies lose millions in security breaches. As these breaches wreak havoc on companies and people we feel that high quality Information Security Awareness is probably one of the most important remedies. The whole<a href="http://www.social-engineer.org/framework/"> social-engineer framework</a> is geared toward our thought that the human element is the weakest link in the chain, and the Social Engineering <a href="http://www.social-engineer.org/blog/se-ctf-scoreboard/">CTF at Defcon 18 </a>really drove that point home.</p>
<p><a href="http://www.offensive-security.com/">Offensive Security</a> and <a href="Social-Engineer.Org">Social-Engineer.Org</a> have joined forces to launch a new era in security awareness programs.  This course is different than everything on the market today. It is a one day, managerial security awareness training program, geared to expose the threats of modern day attackers.<br />
<span id="more-1110"></span><br />
This course is very unique in the as it is highly informative and entertaining, leaving attendees both engaged and committed to their personal and corporate security. Our goal is to change the way people think, making them own a personal security policy that carries over from their personal life to their professional life.  Join us as we launch the <a href="http://www.information-security.com/">New Era of Security Awareness Training</a>.</p>
<p>For more information about the course, as well as free Security Awareness posters, visit our new Information Security Awareness website.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;title=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;title=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;t=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22A%20New%20Era%20of%20Security%20Awareness%20Training%22&amp;body=Link: http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Our%20goal%20is%20to%20change%20the%20way%20people%20think%2C%20making%20them%20own%20a%20personal%20security%20policy%20that%20carries%20over%20from%20their%20personal%20life%20to%20their%20professional%20life." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;title=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;title=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/&amp;title=A+New+Era+of+Security+Awareness+Training" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=A+New+Era+of+Security+Awareness+Training+-+http://b2l.me/ahyyyp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/a-new-era-of-security-awareness-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social-Engineer Breaks a Defcon Record</title>
		<link>http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/</link>
		<comments>http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 13:13:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=1095</guid>
		<description><![CDATA[The Social-Engineer.Org CTF took off with a bang that I think was heard around the world. We have counted just a tad under 100 articles that have been printed about the CTF in magazines, newspapers and media journals around the globe.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.social-engineer.org/wp-content/uploads/2010/08/SEDefconSign.jpg"><img class="size-full wp-image-1096 alignleft" title="Defcon 18   Social-Engineer CTF" src="http://www.social-engineer.org/wp-content/uploads/2010/08/SEDefconSign.jpg" alt="SEDefconSign Social Engineer Breaks a Defcon Record" width="277" height="211" /></a>Defcon is over and after the long treks home we take some time to review the past few days and there is so much to say it seems like I have to write a book to get it all out. Most of it can be summed up by saying, &#8220;Security Through Education.&#8221;</p>
<p><a href="http://www.social-engineer.org/blog/social-engineering/social-engineer-org-ctf-update-awareness-abounds/">The Social-Engineer.Org CTF </a>took off with a bang that I think was heard around the world.  We have counted just a tad under 100 articles that have been printed about the CTF in magazines, newspapers and media journals around the globe.  Companies, people and governments are very curious about the results of the contest and the report that is soon coming.<br />
<span id="more-1095"></span><br />
To recap some of the highlights:</p>
<ul>
<li>We had about 15-17 contestants that stuck with it, out of the 45 that signed up.  Many had to quit the competition due to pressure from their companies, some even being threatened with being fired if they competed.</li>
<li>Every company that was called and had a real human answer besides ONE failed.  The only reason the one did not fail is because at the time the call was placed there was no one on staff to help.</li>
<li>The <a href="http://www.social-engineer.org/framework/Successful_Pretexting">pretexts</a> used ranged from being a very technical person who needed help to a user that had zero technical skill at all.  All where successful.</li>
<li>The data collected will be very useful as companies see that the risk is real and the information was easily obtained.</li>
<li>In the end, we learned a lot and had a great time.</li>
</ul>
<blockquote>
<blockquote>
<blockquote>
<blockquote></blockquote>
</blockquote>
</blockquote>
</blockquote>
<p>We held <a href="http://www.social-engineer.org/framework/Social-Engineer.org_In_The_Media">two press conferences</a> while at Defcon as there were some 30 news reporters that wanted coverage on the event.  We worked hard to make sure that none of the target companies or their employees where named next to flags they fell for.  This was to keep the targets and their employees from feeling victimized.</p>
<p>Many of the reports where excellent truly representing what the CTF was all about.  All the press, all the attention and all the good information obtained surely made for an exciting weekend at Defcon.</p>
<p>The end results will be put into the Social-Engineer.Org report that will be posted hopefully in 3-4 weeks.  The Defcon weekend really blew us away.</p>
<p>From the first day we didn’t know what to expect when it came to the contestants as well as the room and the audience.  We were given a smaller room, but as we set it up it looked huge to us.  Just a short time after starting, we were amazed to see the room filling up.  By mid-day there was standing room only.  Not only where we shocked, but humbled to see how many stuck out through out the day.</p>
<p>Then on Saturday it was even fuller. The room was packed all day long, even a line forming outside before we arrived. On Sunday, the same thing but the <a href="http://www.social-engineer.org/framework/Podcast">podcast</a> went great.  We will be editing that and getting it online soon.</p>
<p>After a short break we went to the closing ceremonies.  Never before have we seen so many people packed into a room. They had such overflow they had to set up an auxiliary room.</p>
<p>In the end, the <a href="http://www.defcon.org">Defcon</a> staff told us they wanted to do something that hasn’t been done in 18 years of Defcon history – Give a first year contest a <a href="http://defcon.stotan.org/faq/convention2.htm#ques7">coveted black badge</a>.  The black badge which gives the holder free access to Defcon for life, as well as the honor and prestige of winning one of the few that are given away, is usually only given to popular contests once they are around for 2 or 3 or more years.  Defcon does this to ensure the contest will have longevity and not give it away to contests that will disappear quickly.</p>
<p>There was a catch though; Defcon didn’t want to break the rules without seeing what the audience thought.  The end result was that they were going to ask the audience if they thought social-engineer.org and the CTF deserved one to be given away to its winner.  After our introductions, Pyr0 asked the audience what they thought.  The response was truly an amazing and humbling experience.  Horns where blown, people clapped, screamed, hooted, hollered, stomped their feet and yelled in support.  After about 20-30 seconds of that from both rooms, the Defcon staff said, “You have your answer” and for Defcon, as well as Social-Engineer.Org history was made.</p>
<p>Handing the black badge to the winner was a joyful experience because he was as shocked as we were.  Our top two winners where amazing in skill and really showed what can be accomplished through social engineering.  Congrats to Scott and Wayne and thanks to Defcon, <a href="http://www.offensive-security.com/">Offensive Security</a> and <a href="http://www.continuumww.com/">CWC</a> for their support. Thank you again to the <a href="http://www.eff.org/">EFF</a> for the constant advisement, and thank you to the FBI for not judging without all the facts and treating social-engineer.org and the CTF event with such respect.</p>
<p>This is not the end however, but rather just the beginning. With the live recording of the one-year anniversary of the social-engineer.org podcast, the ever growing framework, a much talked about newsletter, and the forthcoming report detailing the analysis of the CTF, we have our hands full.</p>
<p>Thank you everyone for playing a part, supporting us, and the constant words of encouragement.  There will be plenty more news as we get closer to releasing the report.</p>
<p>Thank you for standing with us. And just keep thinking, &#8220;Security Through Education.&#8221;</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;title=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;title=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;t=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social-Engineer%20Breaks%20a%20Defcon%20Record%22&amp;body=Link: http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Social-Engineer.Org%20CTF%20took%20off%20with%20a%20bang%20that%20I%20think%20was%20heard%20around%20the%20world.%20We%20have%20counted%20just%20a%20tad%20under%20100%20articles%20that%20have%20been%20printed%20about%20the%20CTF%20in%20magazines%2C%20newspapers%20and%20media%20journals%20around%20the%20globe." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;title=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;title=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/&amp;title=Social-Engineer+Breaks+a+Defcon+Record" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social-Engineer+Breaks+a+Defcon+Record+-+http://b2l.me/ahukax&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/social-engineer-breaks-a-defcon-record/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Engineering &#8211; Fact versus Fiction</title>
		<link>http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/</link>
		<comments>http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 19:17:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Social Engineer Blog]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=1070</guid>
		<description><![CDATA[Despite all of our efforts to notify the public that we are not out for malicious gain it seems like this message is not getting through to many in the security industry.]]></description>
			<content:encoded><![CDATA[<p>Social-Engineer.Org started the idea for this years CTF without really knowing how much fear it would build into people and organizations.  From the beginning we have published our goals, rules and ideas to help squelch the fears of those who think our intent is malicious.</p>
<p>While it is true that social engineering will involve some deception as well as obtaining information about these companies, the information the contestants are trying to obtain is innocuous, NON-FINANCIAL and NON-PERSONAL.  At no time will we allow a contestant to make a call that will compromise a company or person&#8217;s financial, banking information or identity.</p>
<p>Despite all of our efforts to notify the public that we are not out for malicious gain it seems like this message is not getting through to many in the security industry.  For example, we have come across an email sent out by a large security firm to all their nationwide customers warning them about the CTF.</p>
<p>This email is posted below:<br />
<span id="more-1070"></span><br />
&#8212;&#8212;&#8211;</p>
<p><strong>Subject:</strong> <strong>Warning Regarding DEF  CON 18 Social Engineering Contest</strong></p>
<p>As you may know, DEF CON is the world&#8217;s longest  running and largest underground hacking conference with the 2010 event scheduled  in Las Vegas from July 30 &#8211; August 1. The 2010 conference may include a nationwide Social Engineering contest sponsored by a group called <a href="http://social-engineer.org/" target="_blank">social-engineer.org</a>.   This contest that could possibly affect your organization anytime between now and the end of the conference; although  due to recent publicity and subsequent security concerns directed to the  contest sponsor, it is unclear whether or not the contest will actually occur.  The official rules are posted at <a href="../defcon-social-engineering-contest/" target="_blank">http://www.social-engineer.org/blog/defcon-social-engineering-contest/</a></p>
<p>The contest targets an unknown list of &#8220;victim&#8221; organizations submitted by  contest participants and while there are associated &#8220;rules&#8221; posted for this  contest, we can assume some participants may not heed the direction.  Therefore,  we suggest DDI clients plan for any attack possible.</p>
<p>With  that in mind, DDI suggest you consider the following:</p>
<ul>
<li>All personnel associated with your organization should be aware of anyone attempting to solicit ANY  personal information at all.  This could include, userID&#8217;s, passwords, account information, name, address, social security number, information on your organizational IT systems or networks, or  anything that is not freely available on the Internet.  For example,  many organizations provide executive names on the external web site.  So an attacker  could say, &#8220;Mr. CEO_Name is expecting my call; he asked me to call and ask for him&#8221;.  In  another example, the attacker will ask the victim to logoff their computer to perform some maintenance, and then  ask for the victim&#8217;s userID and password to &#8220;test&#8221; the fix.</li>
</ul>
<ul>
<li>Be aware of anyone calling and asking for help with a virus, malware, or a  network issue.  This is a great way to develop rapport with the victim (asking someone for help appeals to the innate  desire to help others).</li>
</ul>
<ul>
<li>Beware that the caller will appear confident and friendly. They will provide as little information as  possible (This is Phil from IT Security, as an example). They will smile and  laugh on the phone, they may be a bit forceful, but most of the time they will  attempt to appeal to the desire to help or ask for help/assistance.</li>
</ul>
<ul>
<li>They may use veiled phrases such &#8220;we do not want to miss payroll&#8221;, &#8220;we cannot afford another outage&#8221;, &#8220;the  auditors are waiting for the information&#8221;, or something along those lines, which  would cause an employee to offer assistance.</li>
</ul>
<ul>
<li>Callers can imitate anyone they think might solicit information. Examples are an auditor, law enforcement, IT Security, a contractor or vendor, or anyone who might have a valid  reason to be associated with your organization.</li>
</ul>
<p>Please remember that you are dealing with skilled manipulators.  They  will be friendly, professional and polished.  We strongly suggest you remind your staff NEVER to give any personal or proprietary information to  anyone via the telephone. EVER!</p>
<p>Regards,</p>
<p>Digital  Defense</p>
<p>&#8212;&#8212;</p>
<p>We would once again like to reiterate that the CTF will not breach the lines of legality.  We have a professional team of ethical security specialists who are vigilant about maintaining a professional and legal environment during the CTF.  Our goal has been and always will be <a href="http://www.social-engineer.org">&#8220;Security Through Eduction.&#8221;</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;title=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;title=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;t=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social%20Engineering%20-%20Fact%20versus%20Fiction%22&amp;body=Link: http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Despite%20all%20of%20our%20efforts%20to%20notify%20the%20public%20that%20we%20are%20not%20out%20for%20malicious%20gain%20it%20seems%20like%20this%20message%20is%20not%20getting%20through%20to%20many%20in%20the%20security%20industry." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;title=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;title=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/&amp;title=Social+Engineering+-+Fact+versus+Fiction" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social+Engineering+-+Fact+versus+Fiction+-+http://b2l.me/ahukay&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/general-blog/social-engineering-fact-fiction/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Social-Engineer.Org CTF Update &#8211; Awareness Abounds</title>
		<link>http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/</link>
		<comments>http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 17:41:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=1050</guid>
		<description><![CDATA[Malicious social engineers never hold contests, never do press releases and never warn the world they will be calling, and they also never have rules. To some extent, we feel that our goal has been advanced already by this discussion, and we hope that with the information we will gather during the CTF we will be able to assist many companies to becoming more secure.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.social-engineer.org/wp-content/uploads/2010/07/se-ctf-eff-blogpost.png"><img class="size-full wp-image-1053 alignleft" title="Security Through     Education" src="http://www.social-engineer.org/wp-content/uploads/2010/07/se-ctf-eff-blogpost.png" alt="This is supposed to be fun" width="365" height="239" /></a></p>
<p>We are extremely excited about the <a href="http://www.social-engineer.org/blog/defcon-social-engineering-contest/">Social-Engineer.org CTF at Defcon 18</a>. However, in the excitement some have expressed concern that contestants might act improperly or that government, companies or individuals might be adversely impacted. We want to put these concerns to rest. Our jobs at Social-Engineer.Org are to ensure the security of our clients, and our reputation is built on that promise.</p>
<p>The purpose of the contest is to (1) raise awareness on the threat of social engineering, and (2) challenge contestants to come up with creative, legal ways of obtaining information from companies.  The contest is structured to be good, clean fun.  Our goal is to show how much information companies may inadvertently divulge to individuals making regular, legal inquiries using normal channels of communication. The type of information we will be asking for will be things like the number of restrooms in the building, and the sort of candy that sells out from the vending machines first.<br />
<span id="more-1050"></span><br />
We have been working with attorneys at the <a href="http://www.eff.org/">Electronic Frontier Foundation</a> to ensure that the rules make clear to contestants that their game play must be lawful:</p>
<p>•	Contestants may not ask for or obtain financial data, passwords, or personal identifying information such as social security numbers or bank account numbers;<br />
•	Contestants may not attempt to falsify or falsify employment records;<br />
•	The list of target organizations will not include any financial, government, educational, or health care organizations;<br />
•	Contestants must keep it clean, for example, use of any pornography is banned.</p>
<p>These are just a subset of the rules that we have reviewed with the EFF to ensure participants keep this contest above board. Contestants that do not follow the rules will be disqualified.</p>
<p>We hope our CTF will raise awareness and provide information that shows companies what they need to educate their workers about  malicious social engineering attacks. Malicious social engineers never hold contests, never do press releases and never warn the world they will be calling, and they also never have rules. To some extent, we feel that our goal has been advanced already by this discussion, and we hope that with the information we will gather during the CTF we will be able to assist many companies to becoming more secure. Since the beginning,<a href="http:// www.social-engineer.org"> www.social-engineer.org</a> has been all about “Security Through Education” and this CTF is an extension of that.</p>
<p>If there are any questions or concerns please feel free to <a href="http://www.social-engineer.org/contact/">contact us directly</a>. We would be happy to discuss this specific social engineering contest, or social engineering threats in general with you and your organization. We are here to help the community, please let us know how we can help you.</p>
<p>If you would like to discuss this please contact Chris Hadnagy at defcon@social-engineer.org</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;title=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;title=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;t=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social-Engineer.Org%20CTF%20Update%20-%20Awareness%20Abounds%22&amp;body=Link: http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Malicious%20social%20engineers%20never%20hold%20contests%2C%20never%20do%20press%20releases%20and%20never%20warn%20the%20world%20they%20will%20be%20calling%2C%20and%20they%20also%20never%20have%20rules.%20To%20some%20extent%2C%20we%20feel%20that%20our%20goal%20has%20been%20advanced%20already%20by%20this%20discussion%2C%20and%20we%20hope%20that%20with%20the%20information%20we%20will%20gather%20during%20the%20CTF%20we%20will%20be%20able%20to%20assist%20many%20companies%20to%20becoming%20more%20secure." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;title=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;title=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/&amp;title=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social-Engineer.Org+CTF+Update+-+Awareness+Abounds+-+http://b2l.me/ahukaz&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/social-engineer-org-ctf-update-awareness-abounds/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Defcon 18 Social Engineer CTF Update</title>
		<link>http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/</link>
		<comments>http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 16:02:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Social Engineer Blog]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=997</guid>
		<description><![CDATA[The How Strong Is Your Schmooze contest is on it's way.  The targets have been chosen, the dossier's have been sent and the social engineering talent has bloomed.  The team at social-engineer.org wanted to give a few updates to the CTF.]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.social-engineer.org/wp-content/uploads/2010/05/contest-2.png"><img class="size-full wp-image-814 aligncenter" title="Social Engineering CTF" src="http://www.social-engineer.org/wp-content/uploads/2010/05/contest-2.png" alt="How Strong is Your Schmooze" width="375" height="197" /></a></p>
<p style="text-align: left;">The<a href="http://www.social-engineer.org/blog/defcon-social-engineering-contest/"> How Strong Is Your Schmooze</a> contest is on it&#8217;s way.  The targets have been chosen, the dossier&#8217;s have been sent and the social engineering talent has bloomed.  The team at social-engineer.org wanted to give a few updates to the CTF.</p>
<p style="text-align: left;">1)   There has been a lot of &#8220;fear&#8221; in the market about our contest.  In one way this is great as it is raising awareness about social engineering.  We have been sent anonymous reports about banks, credit agencies and other organization pasting posters warning of the threats of malicious social engineers.  One report we received told us that many of these organizations even mention social-engineer.org by name and warn of attempts.</p>
<p><span id="more-997"></span></p>
<p style="text-align: left;">2)  Defcon was kind enough to give us a room for the CTF event.  Things worked out to get us into a great spot to host the CTF.  We have the room for Friday, Saturday and Sunday.</p>
<p style="text-align: left;">On Friday and Saturday we will be listening in as the contestants make their calls.  We are all excited to see what they come up with.</p>
<p style="text-align: left;">Then on Sunday we have a special event scheduled.  At 10:00am we will be hosting a live podcast.  Well, what we are calling a &#8220;Zombie&#8221; <a href="http://http://www.social-engineer.org/framework/Podcast">podcast</a>.  It will be live with community support and all of you there, but not broadcasted live.</p>
<p style="text-align: left;">The topic for this podcast will be all about <a href="http://www.social-engineer.org/framework/">Social Engineering</a>, <a href="http://www.social-engineer.org/newsletter/SocialEngineerNewsletterVol02Is10.htm">Neuro-Linguistic Hacking</a>, <a href="http://www.social-engineer.org/framework/Psychological_Principles:_Micro-Expressions">Microexpressions</a> and <a href="http://www.social-engineer.org/framework/Psychological_Principles:_Instant_Rapport">Body Language</a> usage in social engineering.  What we want is for the community to submit questions or other items you want to discuss.  Submit your questions to defcon@social-engineer.org.</p>
<p style="text-align: left;">During the podcast mING will be fielding the questions and getting people lined up for the mic.  Make sure you get there early.</p>
<p style="text-align: left;">After the podcast we will be hosting a public peer review.  We will discuss some of the things we learned from the CTF as well as some of the great attacks used.</p>
<p style="text-align: left;">3)   The room we have been given is awesome, but it is not huge.  We are limited to about 80 people, and that will be tight.  If you want to get in for the CTF, if you want in for the Podcast and if you want if for the peer review &#8211; GET THERE EARLY.  We will be packed solid, so make sure you get there to get your spot.</p>
<p style="text-align: left;">We will not be able to record any of the days (except the podcast) or broadcast any of the days over icecast or anything.  If you want to hear what is going to be going on, get there early.</p>
<p style="text-align: left;">If you can&#8217;t get in, make sure to tell Defcon about it so next year we get a bigger room. <img src='http://www.social-engineer.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' title="Defcon 18 Social Engineer CTF Update" /> </p>
<p style="text-align: left;">The contestants have been hard at work now for a week and we are looking forward to seeing the results.  till the next update, we will talk soon.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;title=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;title=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;t=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Defcon%2018%20Social%20Engineer%20CTF%20Update%22&amp;body=Link: http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20How%20Strong%20Is%20Your%20Schmooze%20contest%20is%20on%20it%27s%20way.%20%20The%20targets%20have%20been%20chosen%2C%20the%20dossier%27s%20have%20been%20sent%20and%20the%20social%20engineering%20talent%20has%20bloomed.%20%20The%20team%20at%20social-engineer.org%20wanted%20to%20give%20a%20few%20updates%20to%20the%20CTF." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;title=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;title=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/&amp;title=Defcon+18+Social+Engineer+CTF+Update" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Defcon+18+Social+Engineer+CTF+Update+-+http://b2l.me/ahuka3&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/defcon-18-social-engineer-ctf-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Pizza Delivery Man is a Social Engineer</title>
		<link>http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/</link>
		<comments>http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 17:56:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=968</guid>
		<description><![CDATA[The other day I had a pizza delivered to my home using my Visa. When the pizza arrived, however, the driver refused to give it to me unless I either gave him my social security number or let him write down my driver's license number. I refused because of identity-theft and general privacy concerns. I offered to show him my driver's license and the Visa card I'd used to order the pizza, but he said he had to write down one or the other number.]]></description>
			<content:encoded><![CDATA[<p>Everyone knows I am a stickler when it comes to the <a href="http://www.social-engineer.org/framework/">free pizza</a> but this story just takes free pizza to a new level for social engineers, scam artists and con-men.</p>
<div id="attachment_969" class="wp-caption alignright" style="width: 394px"><a href="http://www.social-engineer.org/wp-content/uploads/2010/06/freepizza.jpg"><img class="size-full wp-image-969" title="Free Pizza - Real or Myth?" src="http://www.social-engineer.org/wp-content/uploads/2010/06/freepizza.jpg" alt="Free Pizza"  width="384" height="287" /></a><p class="wp-caption-text">&nbsp;&nbsp;&nbsp; Free Pizza - Real or Myth?</p></div>
<p>Most of us have probably done this:</p>
<p>You are hungry, so you call your local pizza place, realize you have no cash, so you tell the guy on the phone you need to pay with your credit card.</p>
<p>You read off the numbers tell him to put a few dollars on there for tip then chill a couple beers and wait.</p>
<p>This is what Brent did too.  He called his local Dominoes and ordered a pizza&#8230; here is his story:</p>
<p>&#8220;The other day I had a pizza delivered to my home using my Visa. When the pizza arrived, however, the driver refused to give it to me unless I either gave him my social security number or let him write down my driver&#8217;s license number. I refused because of <a href="http://www.social-engineer.org/framework/Podcast/008_-_The_Social_Engineering_Zero_Day_Revealed">identity-theft and general privacy concerns</a>. I offered to show him my driver&#8217;s license and the Visa card I&#8217;d used to order the pizza, but he said he had to write down one or the other number.</p>
<p>When I called the local Domino&#8217;s about this, I was told that drivers are now required to get the information because, she said, people have been ordering pizzas with stolen credit cards. Why showing that my license and Visa matched wasn&#8217;t sufficient, she couldn&#8217;t say.&#8221;</p>
<p>Fortunately, this guy knew well enough to forgo the hunger pangs and not give out his social security number.  There is a good lesson there, I am not personally sure if Dominoes Corporate says this is their policy or not, but what I do know is that this is definitely a dangerous policy.</p>
<p>Anytime someone asks for our social security number to complete a purchase we should be leery.  At most a company may require a drivers license or some other ID to prove you are who you say you are, but considering you can go online and buy almost anything with any credit card it seems odd that a pizza guy would want a social security number.</p>
<p>The lesson:  <a href="http://www.social-engineer.org/framework/Newsletter">Stay Educated</a>, be cautious, think ahead and never give out person details too easily.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;title=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;title=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;t=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22The%20Pizza%20Delivery%20Man%20is%20a%20Social%20Engineer%22&amp;body=Link: http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20other%20day%20I%20had%20a%20pizza%20delivered%20to%20my%20home%20using%20my%20Visa.%20When%20the%20pizza%20arrived%2C%20however%2C%20the%20driver%20refused%20to%20give%20it%20to%20me%20unless%20I%20either%20gave%20him%20my%20social%20security%20number%20or%20let%20him%20write%20down%20my%20driver%27s%20license%20number.%20I%20refused%20because%20of%20identity-theft%20and%20general%20privacy%20concerns.%20I%20offered%20to%20show%20him%20my%20driver%27s%20license%20and%20the%20Visa%20card%20I%27d%20used%20to%20order%20the%20pizza%2C%20but%20he%20said%20he%20had%20to%20write%20down%20one%20or%20the%20other%20number." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;title=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;title=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/&amp;title=The+Pizza+Delivery+Man+is+a+Social+Engineer" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=The+Pizza+Delivery+Man+is+a+Social+Engineer+-+http://b2l.me/ahuka4&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/the-pizza-delivery-man-is-a-social-engineer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering CTF Update</title>
		<link>http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/</link>
		<comments>http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 11:48:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=961</guid>
		<description><![CDATA[The awareness that has been raised is just amazing. There has been many stories written and podcasts  discussing the contest and what the rules are. People are wondering and very curious about what it will entail. There has been numerous alerts issued from various agencies about the contest. I will post one of them below.]]></description>
			<content:encoded><![CDATA[<p>It has been only a week since we launched the registration for the Social-Engineer.Org First Social Engineering CTF &#8211; <a href="http://www.social-engineer.org/blog/defcon-social-engineering-contest/">How Strong is Your Schmooze</a>. What has happened in over a week?</p>
<p>The awareness that has been raised is just amazing.  There has been many stories written and <a href="http://www.social-engineer.org/framework/Podcast">podcasts</a> discussing the contest and what the rules are.  People are wondering and very curious about what it will entail.  There has been numerous alerts issued from various agencies about the contest.  I will post one of them below.</p>
<p><a href="http://www.social-engineer.org/wp-content/uploads/2010/05/contest-2.png"><img class="alignright size-full wp-image-814" title="Social Engineering CTF" src="http://www.social-engineer.org/wp-content/uploads/2010/05/contest-2.png" alt="How Strong is Your Schmooze" width="358" height="188" /></a>We are very happy with all the awareness this is raising for social engineering threats.  At the end of the contest we are going to release a detailed report that will help all who are interested see what attacks worked.</p>
<p>Our Contest registration is full 100% and there is even a small overflow list. We are excited to see how the contest progresses and we wish all the contestants good luck.  We are giving points for this things that you probably never even thought of gathering during normal <a href="http://www.social-engineer.org/blog/how-tos/how-to-prevent-social-engineering-attacks-chosing-the-right-security-auditor/">social engineering gigs.</a></p>
<p>Stay tuned for more information.</p>
<p>As promised here is one of those warnings below:</p>
<p>Advisory ID: 2010-06-016<br />
Date/Time Reported (GMT): 6/7/2010 8:14 PM<br />
Title: DEFCON Social Engineering Capture The Flag Contest</p>
<p>Risk: 2<br />
Audience: Analysts<br />
Core Members<br />
Premier Members<br />
Standard Members</p>
<p>Type of Threat: Social Engineering</p>
<p>Summary: Hacker Conference DEFCON is hosting a Capture The Flag (CTF) contest that aims to test participants&#8217; social engineering skills. The contest&#8217;s specific ground rules state that participants must legally socially engineer their way into a target company, and they are not allowed to get credit card numbers, social security numbers, passwords, involve porn, or<br />
make the target feel &#8220;at risk.&#8221; Participants cannot use government agencies, law enforcement, or legal entities as a ruse to get inside, nor can they contact relatives of the targeted firm&#8217;s employees.<br />
DEFCON 18 will take place July 30th &#8211; August 1, 2010 at the Riviera Hotel &amp; Casino in Las Vegas, Nevada. Financial institutions should be aware of this upcoming contest, and should brief their personnel, especially call centers and legal departments regarding this event.</p>
<p>Business Impact: Social Engineering</p>
<p>Severity: 1 &#8211; Informational (Normal)</p>
<p>Urgency: 1 &#8211; Information Only</p>
<p>Credibility: 3 &#8211; Single Source</p>
<p>Description:<br />
The CTF Rules<br />
&lt;our rules where posted here&gt;</p>
<p>Recommendations: Financial Institutions are recommended to proactively brief their personnel, especially call centers and legal departments regarding this event.</p>
<p>Legal reminders for Financial Institutions: Any attempt to solicit information about an FI customer/client is considered an attempt at unauthorized access to customer information under</p>
<p>GLBA and Bank Secrecy Act provisions and may require submission of a Suspicious Activity Report.</p>
<p>Regulatory guidance: <a href="http://www.ffiec.gov/ffiecinfobase/resources/retail/frb-sr-01-11-identity_theft_pretext_calling.pdf">http://www.ffiec.gov/ffiecinfobase/resources/retail/frb-sr-01-11-identity_theft_pretext_calling.pdf</a><br />
<a href="http://www.fdic.gov/news/news/financial/1998/fil9898.html">http://www.fdic.gov/news/news/financial/1998/fil9898.html</a></p>
<p>In New York State criminal impersonation is a misdemeanor: S 190.25 Criminal impersonation in the second degree: A person is guilty of criminal impersonation in the second degree when he:<br />
1. Impersonates another and does an act in such assumed character with intent to obtain a benefit or to injure or defraud another; or<br />
2. Pretends to be a representative of some person or organization and does an act in such pretended capacity with intent to obtain a benefit or to injure or defraud another; or<br />
3. (a) Pretends to be a public servant, or wears or displays without authority any uniform, badge, insignia or facsimile thereof by which such public servant is lawfully distinguished, or falsely expresses by his words or actions that he is a public servant or is acting with approval or authority of a public agency or department; and (b) so acts with intent to induce another to submit to such pretended official authority, to solicit funds or to otherwise cause another to act in reliance upon that pretense.</p>
<p>Criminal impersonation in the second degree is a class A misdemeanor.</p>
<p>Source(s):<a href="http://www.social-engineer.org/blog/DEFCON-social-engineering-contest/"> http://www.social-engineer.org/blog/DEFCON-social-engineering-contest/</a><br />
<a href="http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=225400253">http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=225400253</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;title=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;title=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;t=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social%20Engineering%20CTF%20Update%22&amp;body=Link: http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20awareness%20that%20has%20been%20raised%20is%20just%20amazing.%20There%20has%20been%20many%20stories%20written%20and%20podcasts%20%20discussing%20the%20contest%20and%20what%20the%20rules%20are.%20People%20are%20wondering%20and%20very%20curious%20about%20what%20it%20will%20entail.%20There%20has%20been%20numerous%20alerts%20issued%20from%20various%20agencies%20about%20the%20contest.%20I%20will%20post%20one%20of%20them%20below." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;title=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;title=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/&amp;title=Social+Engineering+CTF+Update" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social+Engineering+CTF+Update+-+http://b2l.me/ahukgc&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/social-engineering-ctf-update/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Engineering being used by Child Predators</title>
		<link>http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/</link>
		<comments>http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 11:40:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Social Engineer Blog]]></category>
		<category><![CDATA[Interesting SE Articles]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=925</guid>
		<description><![CDATA[Predators are using MS Live Game system to attack unknowing children and use malicious social engineering to entrap them.]]></description>
			<content:encoded><![CDATA[<p>I can remember as a child the PSA’s (see below for an example) about keeping your kids safe from predators. Times surely have changed in the recent years.  There are plenty of laws that are supposed to keep our kids safe.  Yet it seems that those who desire to hurt our children are coming up with more and more malicious ways using <a title="Maliciious Social Engineers" href="http://www.social-engineer.org/framework/">social engineering</a> to lure children into the dark corners of their depravity.</p>
<div id="attachment_927" class="wp-caption alignleft" style="width: 310px"><a href="http://www.social-engineer.org/wp-content/uploads/2010/06/button_abuse_cycle.jpg"><img class="size-full wp-image-927 " style="margin-right: 4px; margin-left: 4px; border: 2px solid black;" title="Sexual Abuse Cycle" src="http://www.social-engineer.org/wp-content/uploads/2010/06/button_abuse_cycle.jpg" alt="Malicious Social Engineering" width="300" height="231" /></a><p class="wp-caption-text">Malicious Social Engineers May Use This</p></div>
<p>When the stories never cease to amaze you and you think you have seen it all, there comes a story that just seems to defy all logic.  Enters our present story.</p>
<p>Prosecutors in New Jersey USA says that Jonathan Prime, a 20-year old man convinced a 13 and 14 year old boy to send him pictures of their genitals.  How?</p>
<p>The two young men where frequent players of the game Call of Duty: World at War on MS Live.  It seems that Jonathan was able to convince the two young boys that it was a condition of the clan he was starting.</p>
<p>This wasn’t a lone incident, he did this to many children.  Many who rejected him but he was able to convince at least four of them by grooming them, getting them to comply and even getting one to call him and have phone sex.</p>
<p>Despite the inherent WTH factor here.  How could these kids fall for this?  How could they believe that this really was a term of the contract?</p>
<p>Those questions are above our scope of our site.  What we will cover is what could parents do to keep safe?  How is it possible to keep your children safe without having to unplug the television and disconnect the Internet?</p>
<p>There are certain things that can be done, but the reason many fall short is these steps don’t involve a plug in or device to keep you safe, but there are two steps that can keep your family safe.</p>
<ol>
<li><a title="Communication is Key" href="http://www.social-engineer.org/framework/Communication_Models">Communication</a>:  Nothing can beat just sitting your kids down and talking with them.  Telling them what is going on in the world and how malicious people think.  Telling them what signs to look for and being involved in their lives.  This can keep them safe.</li>
<li>If kids are going to play online, consider muting all the other players. It is normally possible to only talk to people that are known friends, instead of random strangers. Gaming can be a social event, but best to keep it social to those you know. Parents can use gaming as a chance to do something with their kids. If parents sit down and play games with the kids, they will better understand the potential issues that could be encountered. This will put them in a better situation to provide guidance to the kids in a manner that is truly helpful.</li>
<li><a title="Education is Key" href="http://www.social-engineer.org/blog/resources/">Education</a>:  Right along with communication, teach your kids about the world and what is going on.  If they are aware of the malicious attacks and how these people think they can be aware of their tactics.  This doesn’t mean you need to tell them all the gory details but keeping them aware can go a long way in a good protection plan.</li>
</ol>
<p style="text-align: left;">We always strive to learn something from the attacks we analyze, but truly in this one there are no redeeming qualities.  All we can say, it is one of those attacks that is pure evil and malicious and there is not much to learn except, keep your kids safe.</p>
<p style="text-align: center;">Its 10:pm Do you know where your children are?</p>
<p style="text-align: center;"><a href="http://www.youtube.com/watch?v=0dAWFQEj470">In the 1980&#8242;s before Social Engineers were using the Internet to Trap Children</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;title=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;title=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;t=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social%20Engineering%20being%20used%20by%20Child%20Predators%22&amp;body=Link: http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Predators%20are%20using%20MS%20Live%20Game%20system%20to%20attack%20unknowing%20children%20and%20use%20malicious%20social%20engineering%20to%20entrap%20them." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;title=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;title=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/&amp;title=Social+Engineering+being+used+by+Child+Predators" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social+Engineering+being+used+by+Child+Predators+-+http://b2l.me/ahukge&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/general-blog/social-engineering-being-used-by-child-predators/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Social Engineering CTF &#8211; How Strong is Your Schmooze</title>
		<link>http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/</link>
		<comments>http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 20:45:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.social-engineer.org/blog/?p=821</guid>
		<description><![CDATA[We are inviting those of you who think you can use ethical social engineering skills to stretch your limits as a social engineer. A unique blend of information gathering, planning and attack vector execution will challenge the very core of every participant.]]></description>
			<content:encoded><![CDATA[<p>Are you looking for a real social engineering CTF challenge?  Tired of  the usual, “IT Tech Guy” pretext?  If you have the skills that make up a  real social engineer, we challenge you to come and prove it.</p>
<p><center><br />
<img title="The Social Engineering CTF" src="http://www.social-engineer.org/wp-content/uploads/2010/05/contest-2.png" alt="The Social Engineering CTF" width="361" height="192" /><br />
</center></p>
<p>Join <a title="Social Engineering " href="../../">Social-Engineer.Org</a> and <a title="Information Security Training" href="http://www.offensive-security.com/">Offensive Security</a> in the  Official Social Engineering CTF hosted at <a title="Defcon 18" href="http://www.defcon.org/">Defcon 18</a>.</p>
<p>We are inviting those of you who think you can use ethical social  engineering skills to stretch your limits as a social engineer. A unique  blend of information gathering, planning and attack vector execution  will challenge the very core of every participant. This will be a different SE challenge as our focus is not on who can &#8220;get&#8221; the target the worst, but a true display of SE talents. Each participant will be given a target company and there will be point system.  Full rules coming on the registration page.</p>
<p><strong><br />
<img src="http://www.social-engineer.org/wp-content/themes/i-blog/images/1st.png" alt="The First Prize" style="float:left;" title="The Social Engineering CTF   How Strong is Your Schmooze" /><br />
</strong> &#8211; Your choice between an <a title="Wifu Online" href="http://www.offensive-security.com/online-information-security-training/backtrack-wifu/"> Offensive  Security Wifu Course</a> or a 16GB iPad, Winners  Plaque and a spot on the <a title="The Social Engineers Podcast" href="../../framework/Podcast">Social-Engineer.org  Podcast</a></p>
<div style="clear:both; width:100%;">
</div>
<p><strong><br />
<img src="http://www.social-engineer.org/wp-content/themes/i-blog/images/2nd.png" alt="The Second Prize" style="float:left;" title="The Social Engineering CTF   How Strong is Your Schmooze" /><br />
</strong> -<a title="Wifu Online" href="http://www.offensive-security.com/online-information-security-training/backtrack-wifu/"> Offensive  Security Wifu Course</a> and 2nd Place Winners Plaque</p>
<div style="width:100%; clear:both;">
</div>
<p>Registration will begin on June 3rd so stay tuned and be the first in line to sign up for this exciting new contest.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;title=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;title=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;t=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22The%20Social%20Engineering%20CTF%20-%20How%20Strong%20is%20Your%20Schmooze%22&amp;body=Link: http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A We%20are%20inviting%20those%20of%20you%20who%20think%20you%20can%20use%20ethical%20social%20engineering%20skills%20to%20stretch%20your%20limits%20as%20a%20social%20engineer.%20A%20unique%20blend%20of%20information%20gathering%2C%20planning%20and%20attack%20vector%20execution%20will%20challenge%20the%20very%20core%20of%20every%20participant." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;title=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;title=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/&amp;title=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=The+Social+Engineering+CTF+-+How+Strong+is+Your+Schmooze+-+http://b2l.me/ahukgg&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.social-engineer.org/social-engineering/the-social-engineering-ctf-how-strong-is-your-schmooze/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
