SE

DON'T post new tutorials here! Please use the "Pending Submissions" board so the staff can review them first.
Post Reply
ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

SE

Post by ebrizzlez »

Ok, What is an essential or even required skilled for begin a hacker? Simple, Soical Engineering, and no, its not taking a hammer and trying to fix someone's teeth. (Thats a doctors job.) Social Engineering is the Art of Deception. Its the technique of deluding your target into doing a task or splurring out secretive or useful information. In this tutorial or gudieline I will refer to Social Enginneering as SE.

1.Lets start with "What We Can Get?"
You maybe asking what can we benefit off of from SE? Well, you can get almost anything you wish if your as skilled to do so. From anything to passwords to even credit card numbers! I myself have used SE to socialize Bad_Brains password! :twisted: His password is:

Code: Select all

EbrizzleIsLeet#1
jk. Well, you can actually get other users passwords using this method, you must remember the first rule, set by my hommie Albert Smartdude "Somthing as infinite as the universe is human stupidity"... and that factor will be exploited.

2.Now, "Building the Trust"
Before asking for an users password, you must build up the trust. After you build up the trust, then you can exploit the user. Simple questions about there daily life and trying to actually get to "know" and "understand" the user is easy towards building the trust. You need to put your postion into a high ranked person if you wish to exploit a company. Thats where part two comes in.

3. "SEARCH"
Simple, yet life saving words:"GOOGLE! GOOGLE! GOOGLE!"
You must do research before any SE attack! Some companys are prepared for SE attacks so be prepared!

4."Questions"
Now you will try to ask those questions to get the information you want. Try to make them indirect rather then direct. And make up a good execuse for why you would need the information, such as begin a suvery.

"SE by example."
This is how I obtain a users password.
Hey, I have been recieveing some werid packets while using my Airsnort on my Linux console. It gave me some password hashed packets that I believe came from your computer. If so, I need the character length of your password and the first and last letter of your password. If I get this info, I can match it up and warn the company about this "bug" that which it captures such high information.
Of course that example above was preformed on a friend, and worded differnetly, it worked perfectly.

To get IPs this one always works:
Hello there, well, I need a favor from you, I got this new server and its been picking up werid IPs and logging them into a log file. This can mean either I am getting hacked, or it picks up my IMs. I need you go onto www.whatismyip.com and tell me whats your IP so I can match them up and make sure my server isnt in danger.
Or
Hey, I tried to send you somthing but it gave me an error saying this persons port been blocked. So I read up on this and I found out you may have a new type of virus! It blocks all incoming and outgoing connections towards certain ports. It also slows down your computer! You gotta go onto www.nmap-online.com and tell me what the results are so I can see if your infected and give you this software I found that will fix this.
Now, the example above is another thing. You can trick a user into downloading a "patch" or so, and it is actually a keylogger you compiled your self! Be creative!


Now you are ready to go SE Bad_Brain on the IRC! I would recommend reading the book made by my most fav orite person and hacker , Kevin Mitnick (Besides Bad_Brain of course!) The Art of Deception, the book specializes on actual SE attacks.

P.S. Bad_Brain, please dont delete my accout for telling everyone your password. :wink:

Please post any comments or ideas, and any SE attack examples you have done.
[img]http://i81.photobucket.com/albums/j205/ebrizzlez/4lsint1.jpg[/img]

User avatar
sternbildchen
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 421
Joined: 26 Apr 2006, 16:00
17
Location: Germany

Post by sternbildchen »

For me social engineering is important for everything! Even beside hacking. Manipulating people can always grant you benefits not only over the internet. Some "hacker" even walk into big offices to look over someones shoulders while they type their PWs. (Haven't gonne so far by myself. But it surely works.)

But there is a big difference between someone telling you his IP or bis password. When you ask for a PW nearly everyone will get suspicious even if your are his "friend".

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Normally it would take days/weeks/months! to social engineer someone with some brains, because try to place yourself in the situation where someone airsnorts parts of your password then asks for the rest of it to warn the company =/ if someone uses airsnort they usually know what they are doing and doesn't need to ask for it ^^, so social engineering let's say an oldschool sysadmin might take sometime.

PS: to be honest i can't see what i am writing right now so please bare with my spelling if it's bad. Not wearing glasses and the text is tiny :<
"The best place to hide a tree, is in a forest"

ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

Post by ebrizzlez »

well.. thats why you need to do research, like I said, this example was done on a friend. So they hadnt known a thing I said and was willingly to give me high case parts of the password so I can later Brute Force. This is just an outline towards what SE would be like. And SE is a quicker method appose to actually brute forcing or using airsnort, if the user is advance then make up a program name or somthing. :wink: And my syntax and spelling maybe just as horid for I type late at night and in the dark.

EDIT: To be honest, if your good enough in SE, you could probley SE any company. I SE Adobe claming that I bought their product and the serial wasnt working, so they gave me a serial to use, and then I installed a free trail and then activated the product. So SE can take you places, its depending on whom is your target. If its a company you need work and research, if its a friend, then its a matter of what they can trust you with. Also, in my postion, I am still young and my friends have trouble finding the off switch on a computer, so anything with a big word or two will work. But if its a company, then you need work. But it can always be pulled off if you know how. And most in most SE attacks, the research might take longer then the actual attack. Depending on how big the company is of course!
[img]http://i81.photobucket.com/albums/j205/ebrizzlez/4lsint1.jpg[/img]

ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

Post by ebrizzlez »

sternbildchen wrote:For me social engineering is important for everything! Even beside hacking. Manipulating people can always grant you benefits not only over the internet. Some "hacker" even walk into big offices to look over someones shoulders while they type their PWs. (Haven't gonne so far by myself. But it surely works.)

But there is a big difference between someone telling you his IP or bis password. When you ask for a PW nearly everyone will get suspicious even if your are his "friend".
Well it isnt a matter of asking "can i get your password?" its a matter of what trust they can put into you. I asked for only pieces so I could Brute Force the rest later on. There are many methods, find the best that fits you and use it!
[img]http://i81.photobucket.com/albums/j205/ebrizzlez/4lsint1.jpg[/img]

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

*changes his password to Ebrizzlezsucks* [-(

:lol:


good post, man... :wink:

ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

Post by ebrizzlez »

Thanks, but if you continuously change your password how is the public going to be able to login into your account and band and delete other users. :twisted: jk. :wink:
[img]http://i81.photobucket.com/albums/j205/ebrizzlez/4lsint1.jpg[/img]

User avatar
Lyecdevf
cyber Idi Amin
cyber Idi Amin
Posts: 1222
Joined: 16 Mar 2006, 17:00
18
Location: In between life and death.
Contact:

Post by Lyecdevf »

bad_brain wrote:*changes his password to Ebrizzlezsucks*
Damn it! The pass does not work are you sure this is the right one? :wink:

Let's not forget that Timothy McVeigh has always considered him self more of social engener. I think that once I get the necessary hacker skills I am going to go off one lovelly day create an account on some forum where you would not expect to find the computer sort of people and create havoc.
We will either find a way, or make one.
- Hannibal

ebrizzlez
Kage
Kage
Posts: 732
Joined: 31 Mar 2007, 16:00
17
Location: Hidden in a Buffer Protection.
Contact:

Post by ebrizzlez »

Well going on a random board in which doesnt have tech salvi people on it would make you seem like a goddest, and it also intrust them with information and they would rely on you for certain information. Once you correctly uptain this information, you can easily cause havoc. You can use one of the oldest trick of the book, but it seems that it isnt flawless, you can claim how your a whitehat and hate blackhats, and how if you got your targets password, you could protect them from theses evil hackers. This tricked work well on a forum made by my friend, I got there password through SE, caused havoc and removed there board. But you have to remember SE is an Art. It musnt be abused at careless times. :wink:
[img]http://i81.photobucket.com/albums/j205/ebrizzlez/4lsint1.jpg[/img]

Post Reply