[64] Goal-Based Social Engineering Pretexts

Поделиться
HTML-код
  • Опубликовано: 8 июл 2024
  • In this video I show you my main method for creating a goal based social engineering pretext

Комментарии • 31

  • @PocketWomen
    @PocketWomen 3 года назад +7

    That was very interesting. I would never have thought of a broken key, very clever, cheers

  • @seanb3516
    @seanb3516 3 года назад +6

    2) Tailgating. Easier than you think. Pretend to be injured or crippled. If people are hesitant to let you through the door make them feel like crap. Or rather encourage them to make themselves feel like crap. Then give them a chance for redemption by opening the door for you. Hoomuns are 2EZ, GG WP.

    • @malkav_ils
      @malkav_ils 2 года назад

      Would not work if the security culture is high enough that the employees only hold dors open for people they recognize.

    • @seanb3516
      @seanb3516 2 года назад

      @@malkav_ils I'm working construction in a high security site and the people who work here are very afraid of...probably nothing. It seems the more security you provide the more you make people frightened. One guy almost ran away from his own skin when he saw me standing in the elevator. I was wearing hi-viz and the whole outfit so he knew I was a construction worker. But nope, they are very afraid even with guards around the place.

    • @klausstock8020
      @klausstock8020 Год назад +1

      Ah, brings back fond memories. Was caught tailgating. "You don't belong here."
      Me: "I do belong here."
      Guy: "Okay." - and holds the door open for me and four other guys he's never ever seen before.
      And people still believe "these aren't the droids you are looking for" requires some Jedi mind trick...

  • @ryanwilson_canada
    @ryanwilson_canada 3 года назад +8

    Honestly? Perhaps it's just because I live in Atlantic Canada, just talking with people is usually enough to get me into bank vaults, server rooms etc... I've only been asked to show my credentials once, that was to enter a police evidence vault. (All legal entries of course, I had to do work in them) for the most part, taking a minute Or two and talking to the gate keeper (and also a subject of one of your previous videos) and looking the part has been enough for me.
    Hope everyone is staying safe. Take care.

    • @seanb3516
      @seanb3516 3 года назад +2

      Atlantic Canada? I lived even further East in Cape Breton. That's beyond the Maritime Provinces! Yeah. Talking and also drinking with people will get you into places you wouldn't normally be able to.

    • @ryanwilson_canada
      @ryanwilson_canada 3 года назад

      @@seanb3516 New Brunswick, I spent a week all over Cape Breton on vacation. Beautiful place once you get used to gearing down your automatic vehicle so you don't burn your brakes out down the hills. Lol

    • @amihirata
      @amihirata  3 года назад +7

      Honestly it depends on the office culture, some places are much more friendly than others. Small towns for example are a nightmare for external consultants to breach since everyone knows each other

    • @ryanwilson_canada
      @ryanwilson_canada 3 года назад +2

      @@amihirata such is true. I have found though, even in small towns, talking the part and looking the part plays a huge role. Not a pen job at all. But three massive concerts (before covid obviously) U2 being one, I forgot I had my fold out utility knife on my belt. Security waved me through without wanding me, but they did everyone else before me. Yet I was the only one with a technical weapon on my person. Now. They were correct in assuming I wouldn't use it, as I simply forgot it was there because it always is. Blending in and "looking harmless" can actually get you a fair amount of access.

    • @seanb3516
      @seanb3516 3 года назад +1

      @@ryanwilson_canada I was 10 in Breton and living in a log cabin miles off the grid in a remote location between 2 small mountains. No electricity, running water, or flushing toilets. Winter was brutal. Having said that...the office environment in your area would be difficult to penetrate as everyone knows each other. I suppose you could introduce yourself as Mr. McKinnon...and then blend in with everyone else. :D [at least in Nova Scotia]

  • @traditionaltools5080
    @traditionaltools5080 Год назад

    A forgotten key is the best excuse. Youd be surprised how many people leave pass cards to high security buildings at home. In general, people want to let you in. Especially if you go right at the start of the day.

  • @indigosix6511
    @indigosix6511 3 года назад +2

    I always just acted like I was on the phone or carried envelopes or boxes. Never had an issue

  • @tacocin
    @tacocin 3 года назад

    Salute!

  • @j.g4104
    @j.g4104 3 года назад

    @NotSoCivialEngr hey I have a question for you about your tubular lock video...
    You'd mentioned that you can get the Bin numbers off a impression kit/tubular lockpick by using Calipers instead of using a Tubular lock pick decoder , I was wondering if you might be able to help me out with understanding how to use calipers instead of me needing to buy a decoder?

    • @alabamalockpicking
      @alabamalockpicking 3 года назад

      Funny thing is my tubular lock impression tool comes in on march the 5th I can't want to learn how to use it

  • @kilometrekm
    @kilometrekm 3 года назад +1

    But wouldn't the target employee simply shrug because now the keyhole is stuck, therefore blocking the only entrance to the lab? Even if (s)he wanted to let you in -- (s)he couldn't because of the broken key is stil in the key hole, right?

    • @mr.grumpy3683
      @mr.grumpy3683 2 года назад

      You have to have both parts of the key in your hand. It snapped before it was pushed all the way.

  • @Feldscher1039
    @Feldscher1039 3 года назад +1

    How would you break your key though without half of it being stuck in the lock, requiring me to call maintenance by which time you would have sorted out your key problem anyway?

    • @ehrichweiss
      @ehrichweiss 3 года назад

      Not all key breaks require a special extractor. It's possible that a little bit of the key was sticking out just enough to get a fingernail on it and pull it out. Nobody but a security-minded individual is going to worry about that.

    • @Feldscher1039
      @Feldscher1039 3 года назад +2

      @@ehrichweiss gotta be prepared for that semi-security-minded individual asking a question that pops up in their head though. Might want to bring a broken key that sort of looks like the real key, which means you will have to know what make the key is, if it has a tag or other marking and it's rough profile so that the key carrying individual doesn't look at your broken key and immediatelly know somethings fishy.

    • @alexandrezani
      @alexandrezani 3 года назад

      Get a key with the right profile in, break it such that it will be easy to pull out by hand and let the person who comes next fish it out.

    • @klausstock8020
      @klausstock8020 Год назад +1

      You don't need a broken key. Just like you don't actually call maintenance.
      All you need is someone who lets you in, and it's sufficient that the broken key and the maintenance guy on the phone exist in the perception of that person.

    • @Feldscher1039
      @Feldscher1039 Год назад

      @@klausstock8020 It's rather important not to put yourself into a corner. You want to get in. You need someone to let you in. If you approach someone for that specific reason, you need a sympathetic cause that makes the other person feel impolite to decline. However, that cause needs to be non-checkable and fitting. "I broke my key, can you let me in" "you did? How did you do that?" "Oh, never mind, I don't want to get in anymore, bye"..... yeah, that's a call to security. You can wing it like that if you are doing a no-stakes game where if you get apprehended there are no consequences, but for any real usage this approach is way to dangerous. "I broke my key" means you have a physical key with you that is broken, you work in this place and should be known to someone, you know where you are going etcppp. Any questioning whatsoever will destroy this pretext in 2 seconds flat and you are absolutely relying on the person you encounter to be a mindless drone who couldn't be bothered by anything. That is a very thin plank to tie your operationl success to.

  • @crattor3849
    @crattor3849 3 года назад

    Hey my friend i watch your videos all the time they are awesome. I just want to ask for your help if you may know what this could be. My neightbor has this device in a box he uses his cell phone with it and also a flashing light in the phone or device. Ill tell you what it does. It makes my lights flicker inside my house inhad to replace the bulbs numerous of times

    • @crattor3849
      @crattor3849 3 года назад

      , it also changes the clocks on my micwave, tv amd stove yea weird, thats not all, sometimes it drains my vehicle battery aswell it manages to turn off the street light bulbs. Its really strange this device. He uses it at night time where it cannot be seen. Do you know what this could be? I do not think its an emp. Definately. Not. Sometimes i feel these pulse waves too. Its really strange man. Can you help out?

    • @alexseguin5245
      @alexseguin5245 3 года назад +2

      lol wtf

  • @crattor3849
    @crattor3849 3 года назад

    , it also changes the clocks on my micwave, tv amd stove yea weird, thats not all, sometimes it drains my vehicle battery aswell it manages to turn off the street light bulbs. Its really strange this device. He uses it at night time where it cannot be seen. Do you know what this could be? I do not think its an emp. Definately. Not. Sometimes i feel these pulse waves too. Its really strange man. Can you help out?

    • @klausstock8020
      @klausstock8020 Год назад

      It's called a blackjack. He hits you on the head, and the lights go out and if you wake up, the time displayed on your appliances has changed.
      More advanced tools would indeed be the EMP or a microwave transmitter, preferably one with a directional antenna. You can also do strange things with a directional ultrasound transmitter.

  • @seanb3516
    @seanb3516 3 года назад +10

    Young Black Physically Handicapped Lesbians would be the greatest Pen-Testers of all time. Doors would fly open and alarms would self-destruct in shame. Social Engineering would be more like Social ThermoNuclear War.