• On CHOW: Why is ginger ale so popular on planes?
advertisement
July 31, 2010 10:53 AM PDT

Contest finds workers at big firms handing data to hackers

by Elinor Mills

LAS VEGAS--Hackers competing in a social engineering contest at the Defcon conference here on Friday were able to trick random employees at 10 major U.S. tech, oil, and retail companies into giving them sensitive information over the phone that could be used in targeted computer attacks on the companies.

"Every single company, if it was a security audit, would have failed," Christopher Hadnagy, operations manager for Offensive Security, a training and penetration testing company, told CNET after the first day of the contest, which wraps up Saturday and targets BP, Shell, Google, Proctor & Gamble, Microsoft, Apple, Cisco, Ford, Coke, and Pepsi. "Not one company shut us down, although certain employees within the company did. But we (participants) were able to call right back and get another employee that was more willing to comply."

The organizers declined to offer specific comments about any one of the companies targeted by the contest or say which companies are faring better or worse than the others. But they said they'd release a report with aggregated information in a few weeks.

"The point isn't to shame anyone. It's to bring awareness to this attack vector, which is probably the easiest way to hack a corporation today," said Mati Aharoni, lead trainer at Offensive Security. "We really don't want to see anyone get harmed or get in trouble."

Social engineering is a hacking technique that involves simply tricking people into offering up sensitive information, rather than using technical means--such as breaking into computer systems--to get such data. The contest's organizers said companies put a lot of emphasis on buying security software and building technological defenses for their information, but they ignore their Achilles heel: the people who work for them.

"The human resources are the weakest and softest spot of the whole organization," Aharoni said. "The most used vector by hackers today is the easiest route, and that's usually the human element."

Each of the 10 contestants was assigned one of the target companies a week or so before the event and allowed to do "passive" Web research to gather intelligence on the target and figure out a plan of attack. They were not allowed to make social engineering calls or use phishing or other online methods to extract this information.

The social engineering contest at Defcon targeted 10 major companies to see how easily a stranger could get information out of them.

The social engineering contest at Defcon targeted 10 major companies to see how easily a stranger could get information out of them.

(Credit: Social-Engineer.org)

At Defcon the contestants have 25 minutes to make calls to try to get as many bits of information from a predetermined list as they can. The calls are broadcast over a sound system. The contestant with the most items at the end of the event wins.

Contestants are asked to get "innocuous information" about the corporations, such as what company provides dumpster service, whether it has a cafeteria, and what browser its employees use, contest organizers said.

None of the employees at the companies was asked for or gave out any financial information, credit card details, personal data, or other sensitive information barred from the contest, according to the contest organizers, whose Web site is dedicated to educating people about the dangers of the social engineering technique.

Only three people out of 50 or more employees who answered the phone calls, were skeptical and hung up without providing information, and all three were women, said Hadnagy.

"One woman said 'this question sounds fishy to me' and hung up within the first 20 seconds," Hadnagy said. "We all clapped."

In another case, one hacker got answers to nearly every question on the list of 30 to 40, plus information that wasn't part of the official list, according to Hadnagy.

"People went as far as opening up their e-mail clients, Adobe Reader, versions of Microsoft Word, and clicking on 'Help/About' and giving the exact version numbers of their software," said Aharoni. "For an attacker, the exact version number would provide a much higher level of success," allowing an attack to be tailored to exploit a vulnerability in that exact program.

The contest made ripples even before it officially began. After hearing about plans for the event, the FS-ISAC (Financial Services-Information Services Analysis Center) issued warnings to companies to be alert during Defcon. The contest organizers reached out to the agency and offered to work with it to educate and train people about recognizing and preventing social engineering attempts.

Meanwhile, several agencies in the U.S. federal government have expressed interest in the group's report when it's done, according to Hadnagy. He declined to identify the agencies.

"We will share information with law enforcement as they've asked of us," Aharoni said.

Updated at 12:50 p.m. August 4 to correct that Proctor & Gamble, not PG&E, was a target company in the contest.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from InSecurity Complex
Facebook adds new remote log-out security feature
China requires cell phone subscriber IDs
Cars: The next hacking frontier?
'LOL is this you?' spam spreading via Facebook chat
Bad flash drive caused worst U.S. military breach
Windows DLL bug hits dozens of apps
With McAfee deal, Intel to bake in security
Critical Adobe Reader hole to be patched Thursday
Add a Comment (Log in or register) (10 Comments)
  • prev
  • next
by chidera01 July 31, 2010 11:14 AM PDT
too true ...
Reply to this comment
by n3td3v July 31, 2010 11:25 AM PDT
They've obviously run out of new things to fill the slot at Defcon... this isn't news. Social engineering is as old as the invention of the wheel.

These hacker conferences are supposed to be about cutting edge hacker techniques that are up-to-the-minute new, I don't see that here.
Reply to this comment 4 people like this comment
by drfillgood July 31, 2010 12:16 PM PDT
No, it's about exposing flaws in security systems. This just happens to be the oldest flaw of all. Even "impregnable" fortresses from medieval times got overrun using this type of attack (using inside information or help). This underlines an important weakness in security systems.
1 person likes this comment
by n3td3v July 31, 2010 12:22 PM PDT
It was underlined years ago, ... I feel as if I'm re-reading an article from the 1980s or something here.
1 person likes this comment
by txlakeside July 31, 2010 1:27 PM PDT
Ok ... so this is many years old ... it obviously is still relevant and a real threat! Do you think that just because you were aware of the threat that makes it any less of a threat? We all have known about viruses, worms and trojans ... does that make an infection tomorrow any less real!
Reply to this comment
by n3td3v July 31, 2010 1:51 PM PDT
The point is, *why* is this being showcased at Defcon, when the security industry is well aware of social engineering already.
1 person likes this comment
by Beeblebrux August 5, 2010 7:52 AM PDT
Why is it being showcased at Defcon? It doesn't matter if the security industry is already aware of it, it's obviously still a problem if they were able to get sensitive information using these techniques! I think Defcon should continue to showcase it. If nothing is being done about it, that's a good reason to keep doing it (until something IS done). If the problem is addressed, and they keep featuring it, then they have data showing how it has improved over time. It's not just about showcasing the latest and greatest technologies. It's about showing the evolution (or de-evolution) of security in our world today.
by gerrrg July 31, 2010 2:06 PM PDT
Every generation spawns a swarm of people that remain clueless to the risks of the most simple of techniques. Doesn't hurt to remind everyone that they exist. Well, unless you're cynical.
Reply to this comment
by SteveChicago August 1, 2010 7:51 AM PDT
I believe that con artists do the same thing.
by MrRetardo July 31, 2010 4:52 PM PDT
Yet Kevin Mitnick was prosecuted & jailed by the US Government for doing this sort of thing, while these people do it for "fun".
Reply to this comment 1 person likes this comment
(10 Comments)
  • prev
  • next
advertisement
CNET River
  • caro: Paired with a Dogfish Punkin Ale #TheRiseOfTheodoreRoosevelt http://bit.ly/bZQxMB

  • natalidelconte: Really people, you don't want to follow me on Ping. My music tastes are not that interesting.

  • caro: Also, the @blissspa itinerary that they send you post-booking looks so official that I'm tempted to send it to Tripit.

  • caro: Booking a massage to address aftereffects of this week's hill runs and hikes. Must say @blissspa's online reservation system is impressive.

  • raygun01: BTW if my out of warranty Mac Pro requires replacement, I might just punch myself in the face. It's only 2 years old!! http://bit.ly/988ozc

  • stshank: Spoiled by Netflix. In UK trying Lovefilm and already angry. 1. Plan descriptions opaque & misleading. 2. Is there no way to queue videos?

  • raygun01: My Mac Pro wont even stay alive long enough to boot from a CD. This sounds bad. And expensive.

  • cnetfalcone: Amazon VOD is already a strong iTunes competitor, but it needs to be supported on more devices. Android, Xbox, & PS3 would be a nice start.

  • jetscott: Bad timing on the white iPhone 4...this would have been the last day to use it.

  • loricnet: LOL RT @1001noisycamera: Last day to wear white cameras :)

  • jetscott: I'm Looking Through This Thin Slice of Nova #beatlejews

  • mollywood: I'm so shocked I blogged it. The AT&T third-party eBill verification process, in 50 easy steps. http://themolly.com/blog/?p=194

  • mollywood: I am absolutely flabbergasted at how hard AT&T makes it to sign up for online billing. It's taken weeks. Everyone else? You just. click.

  • loricnet: RT @planetMitch: Check this video out -- Richard Schleuning Of Zeiss Explains T-Stop Vs. F-Stop. http://t.co/L6N2wBO via @goforjared

  • loricnet: RT @sonyalpharumors (SR5) Firmware upgrade for NEX will deliver AF for SAM & SSM lenses! http://bit.ly/cA2Oq0

  • natalidelconte: How personal is too personal on social networking? I wrote an article about it for AOL's @mydailyuk: http://bit.ly/dAun0e

  • stshank: This looks quite handy esp w/varying screen sizes today. RT @paulrouget: CSS calc() coming in Firefox: http://dbaron.org/log/20100905-calc

  • jetscott: Hey Jets haters, shelve those fantasies: Revis is coming back.

  • caro: Just spotted Fish and Chips @ Liberal Cup on @Foodspotting http://bit.ly/b6qzu7

Chrome reshapes the browser market

The influence that Google's browser has had on the market is broader than its actual use. On Chrome's second anniversary, Google releases the sixth stable version.

Apple rolls out new iPods, social iTunes

A new version of Apple TV is also coming soon, as Apple follows its usual September playbook in refreshing its iPod lineup and the iTunes software.
• Roundup: New iPods, iTunes, TV?

About InSecurity Complex

Elinor Mills became fascinated with hacker culture when she was sent to Las Vegas to cover DefCon in 1995. Since then, script kiddies have given way to cyber criminals targeting bank passwords, and privacy risks are everywhere, from Google to Facebook and the iPhone. InSecurity Complex keeps tabs on the flaws, the foibles, and the fixes.

Add this feed to your online news reader

InSecurity Complex topics

advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right