Go Back   Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum > Support > Internet Security

Reply
 
LinkBack Thread Tools Display Modes
  #16 (permalink)  
Old 07-17-2006, 07:29 PM
kev woodman's Avatar
Premium Member
 
Join Date: Jul 2006
Location: Newport, Wales, UK.
Posts: 1,494
Default Social Engineering on MySpace?

Are social engineering attacks a particular problem on MySpace. When the term is used in IT security it is usually in the context of attackers gaining access to systems by exploiting human weakness e.g. by collecting usernames and passwords by ringing up and pretending to be from the IT department (a depressingly succesful tactic).

I suppose that this could be used to gather MySpace account details but it's hard to know what real advantage would be gained by an attacker being able to access some 14 year olds page (unless they re-wrote all the text speak into legible English, that might be worth doing).

Children being put at risk by the actions of predatory adults is certainly a concern on sites like MySpace and Bebo but I don't think that counts as social engineering.
__________________
homo sum: humani nil a me alienum puto ... ( just Google it )
Reply With Quote
  #17 (permalink)  
Old 07-19-2006, 06:40 AM
Junior Member
 
Join Date: Jul 2006
Posts: 17
Default

kev,

well as myspace is such a popular service, i know exactly what i would use it for if i was engineering an attack. You might know that someone in a company that you're planning on attacking uses myspace. Rather than trying to fake your way in through ringing them up at work or something, you could target them on myspace as their deffence wouldn't be so high.

It's just another approach. It's like cracking message boards to get password lists. The majority of users use the same passwords that they use for message boards as well as work.
Reply With Quote
  #18 (permalink)  
Old 07-19-2006, 08:00 AM
kev woodman's Avatar
Premium Member
 
Join Date: Jul 2006
Location: Newport, Wales, UK.
Posts: 1,494
Default

That's a suspisciously good idea mate
__________________
homo sum: humani nil a me alienum puto ... ( just Google it )
Reply With Quote
  #19 (permalink)  
Old 07-19-2006, 04:46 PM
paul's Avatar
Senior Member
 
Join Date: Apr 2006
Location: Norway
Posts: 1,641
Default

Quote:
Originally Posted by scream
well i would have to disagree. If social engineering wasn't anything to do with security, then it wouldn't be covered in security topics. As i've mentioned, the key to stop such attacks, is knowledge. It's having a policy that users keep too and having checks every so often to see if such policies are working.

The fact that the very nature of social engineering is used to break into systems, clear puts it within the security topic for a security person. Speaking from experience. Whenever i've done penetration tests i've used social engineering to gain access to their network. From this i would then tell the client how such attacks can be prevented.
__________________________________________________ ________________

I am not talking whether it is covered in security topics or not, but I am still firm at my earlier comment, my point is that "few" people just misuse it by finding the weakest link to exploit people, I have came across with a renowned CRM company, they gathered datas and personal information of people but their few employees has misused it for their personal benifit, even though it is clearly mentioned in their TOS that they are not going to reveal it to any third party. In your case for performing penetration test can not be considered part of social engineering to gain access to your client network, as most of the client provide usually their login detail/root password and other details to get remotely access by a service providers complying to their TOS or NDA.

Last edited by paul; 07-19-2006 at 04:48 PM.
Reply With Quote
  #20 (permalink)  
Old 07-19-2006, 05:06 PM
kev woodman's Avatar
Premium Member
 
Join Date: Jul 2006
Location: Newport, Wales, UK.
Posts: 1,494
Default

So are we all agreed that by any usual definition MySpace can't be considered 'safe' although how insecure it is and why may be open to debate?
__________________
homo sum: humani nil a me alienum puto ... ( just Google it )
Reply With Quote
  #21 (permalink)  
Old 07-21-2006, 06:49 AM
Junior Member
 
Join Date: Jul 2006
Posts: 17
Default

Paul in my case the client doesn't know this is happening. I'm effectively cold calling an employee in that company and pretending to be someone, either within that company or a contractor. THAT is social engineering to gain accesss. All companies have the policy of not to hand out their username and passwords, even to their own IT staff, but people still do it. That's why social engineering is so effective, and why it's such a big security problem.
Reply With Quote
  #22 (permalink)  
Old 07-31-2006, 03:28 PM
Junior Member
 
Join Date: Jul 2006
Posts: 23
Default

i myself dont thing myspace has a good security and they need 2 work on the loop hole they created themself...
Reply With Quote
  #23 (permalink)  
Old 08-03-2006, 11:46 AM
paul's Avatar
Senior Member
 
Join Date: Apr 2006
Location: Norway
Posts: 1,641
Default

Possibly that is the reason that US plan to ban social networking site, by inforcing DOPA Act, Children in the US could be banned from using social networking sites in schools and libraries by a new law; http://news.bbc.co.uk/2/hi/technology/5230506.stm
__________________

Reply With Quote
  #24 (permalink)  
Old 08-04-2006, 05:56 PM
kev woodman's Avatar
Premium Member
 
Join Date: Jul 2006
Location: Newport, Wales, UK.
Posts: 1,494
Default Not sure if legislation is the right way...

They are doing this in Ireland as well but I'm not convinced that's the right way to go about it.

Firstly I'd argue that local authorities are probably the agencies that should be enforcing any ban in schools/public libraries. I'm sure that public institutions like these already operate filtering software so adding social networking sites shouldn't be a problem.

Secondly I'd suspect that misuse of these sites is not taking place in libraries or schools but at home. The high profile cases of teenagers posting nude/semi-nude photographs of themselves highlight this. I'm guessing that these children didn't take the photographs on their school webcam, they did it in their bedrooms.

Surely it is up to parents to ensure that they know what their children are doing on the 'net and, most importantly, that 'net enabled computers are in areas of the house where they can be monitored.
__________________
homo sum: humani nil a me alienum puto ... ( just Google it )
Reply With Quote
  #25 (permalink)  
Old 08-05-2006, 11:34 AM
paul's Avatar
Senior Member
 
Join Date: Apr 2006
Location: Norway
Posts: 1,641
Default

Let us see how US people are going to react on this.
__________________

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 12:37 PM.
Copyright 2002-2007 WebHosting.uk.com. All rights reserved.
Web Hosting UK Forum