Slashdot Mirror


The Art of Deception

MasterSLATE writes "One of the weakest links to the most secured computer systems are the humans that operate them. No matter how well secured a computer, network or information may be, there are always people that will have contact with them from the inside. This is what the social engineer exploits in order to gain access. In The Art of Deception, Kevin Mitnick writes about the human element and how it can be manipulated and exploited to gain access to computer systems or 'secure' information." Read on for the rest of Masterslate's review. The Art of Deception author Kevin Mitnick (& William L. Simon) pages 346 publisher Wiley Publishing, Inc. rating 9 reviewer MasterSLATE ISBN 0471237124 summary Geared toward the company security guy, but a good read for anyone interested in security, especially social engineering What's to Like?

The Art of Deception is extremely easy to understand and actually fun to read.

The first part of the book, Behind the Scenes contains the first chapter, Security's Weakest Link, which describes through many examples how and why the social engineer is able to so easily manipulate people to get what he wants.

Part 2, The Art of the Attacker, contains chapters 2-9, which describe various ways a social engineer can manipulate people over the phone. Each chapter tells of a different method that could be used to gain information. Each chapter also contains at least one example.

Part 3, Intruder Alert, contains chapters 10-14, which tell about different ways a social engineer can get inside a company, whether physically or through an internal contact. Each chapter contains at least one example.

Part 4, Raising the Bar, contains chapters 15 and 16, which explain how a company should create their security policies and training to prevent the social engineer from gaining access to sensitive information. These chapters are definitely more geared toward the executive, security analyst, or other specialist, as they contain specifics on what new policies should be implemented and why.

The last section in the book, Security at a Glance, contains some charts and information which should be read over by a more general audience, such as employees and other people that may be contacted by a social engineer.

And one sidenote: there's a nice little foreword by Woz (Steve Wozniak).

The Summary Although this book is geared toward the company security expert, this book also has appeal to anyone with an interest in social engineering. I found it to be a quick and fun read. As a social engineer, this book taught me new tactics to try as well as ways that my targets might be prevented from giving me information I seek.

Table of Contents

Foreword
Preface
Introduction

Part 1 Behind the Scenes
* Chapter 1 Security's Weakest Link
Part 2 The Art of the Attacker
* Chapter 2 When Innocuous Information Isn't
* Chapter 3 The Direct Attack: Just Asking for It
* Chapter 4 Building Trust
* Chapter 5 "Let Me Help You"
* Chapter 6 "Can You Help Me?"
* Chapter 7 Phony Sites and Dangerous Attachments
* Chapter 8 Using Sympathy, Guilt and Intimidation
* Chapter 9 The Reverse Sting
Part 3 Intruder Alert
* Chapter 10 Entering the Premises
* Chapter 11 Combining Technology and Social Engineering
* Chapter 12 Attacks on the Entry-Level Employee
* Chapter 13 Clever Cons
* Chapter 14 Industrial Espionage
Part 4 Raising the Bar
* Chapter 15 Information Security Awareness and Training
* Chapter 16 Recommended Corporate Information Security Policies

Security at a Glance
Sources
Acknowledgments
Index

You can purchase The Art of Deception from bn.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.

27 of 236 comments (clear)

  1. Protecting people via DCMA by eaddict · · Score: 5, Interesting

    Doesn't the US DCMA NOT allow for tools that bypass security? I wonder how soon it will be before someone tries to use the DCMA against someone who used social engineering.

    --
    "If you are on fire you can just stop, drop, and roll. If you fall into Lava you are just dead." - my 5yr old daughter
  2. Is this always true? by chrisseaton · · Score: 4, Interesting

    there are always people that will have contact with them from the inside

    Can't you get cryptographic keys that are sealed inside a black box device so that no-one can access them? Couldn't this sort of thing be done for at least some hardware?

    Oh dear, I think I've just justified security through obfuscation.

    1. Re:Is this always true? by God!+Awful+2 · · Score: 5, Funny


      It's called a KEY, Eisenstein. You can find them at the hardware store.

      LOL... if sarcastically calling someone Einstein implies that they are stupid, does sarcastically calling someone Eisenstein imply that they are spouting propaganda?

      -a

  3. Letter.. by grub · · Score: 5, Funny


    Dear Amazon.com,

    I would like to get a copy of "The Art of Deception", however my grandmother needs surgery and I can't spare any money at the moment. If you'd like to lend me a copy please feel free to email for shipping information.

    I, and my grandmother, thank you.

    grubby

    --
    Trolling is a art,
    1. Re:Letter.. by Scratch-O-Matic · · Score: 5, Funny

      Dear Mr. Grub...

      Hi, it's Scratch at Amazon. The suits here would never think of sending you something for free, but your story touched my heart, and I'd like to help. If you could send me the username and password of your Amazon account, I'd be happy to slip the order in for you, without charging your credit card.

      --


      Evil is the money of root.
  4. The lost first chapter to the book.... by Ami+Ganguli · · Score: 5, Informative

    The Register ran a review, along with the original first chapter of the book (which was cut by the editors).

    The first chapter is (or rather, was) a short bio and history of the Mitnik case. Interesting to read Kevin's side in his own words.

    The lost chapter

    --
    It is tempting, if the only tool you have is a hammer, to treat everything as if it were a nail. - Abraham Maslow
  5. Innocuous by jfreis · · Score: 4, Insightful

    "Chapter 2 When Innocuous Information Isn't"

    All the little bits and pieces of info can sure add up to a major security hole if they are collected by the right person...

  6. small typo in the review by Anonymous Coward · · Score: 4, Funny

    As a social engineer, this book taught me new tactics to try as well as ways that my targets might be prevented from giving me information I seek.

    You misspelled "criminal".

  7. Human factors ... again ... by beanerspace · · Score: 5, Insightful
    Wasn't it just yesterday we read an article here on /. that pointed out human factors being the weak link in the chain? In the case of yesterday's news, human factors in programming and today's, human factors in physical security.

    I mean look at an article on TechTV as far back as October 2001 that point out such human blunders as "Default installs of operating systems and applications" or "Accounts with no passwords or weak passwords" ... human mistakes which make it as easy a pie for someone who socially engineers their way into the back office to penetrate your secure systems.

    Perhaps this quote from a Oct '02 SANS/FBI article point out the worth of this book where they say:
    The majority of the successful attacks on operating systems come from only a few software vulnerabilities ...
    Which is why I think books such as "The Art of Deception" are as needed as biometric identification systems to secure your computer facilities.

  8. Where's the review? by awch · · Score: 5, Insightful

    This isn't a review. It's a Table of Contents! Was the book even read?

  9. Security's Weakest Link by phorm · · Score: 5, Interesting

    Is generally the users. Excluding those who run open mail relays, most servers/sysadmins have enough brains not to run the file in their email coming with a message:
    This iz a very fun game
    I hope you anjoy it
    I made this just for u


    How users manage to continually fall for this idiocy is beyond me, but they do. My family is a prime example of this (they refer to me when something dies, but never listen to my "do not open attachments" rant): thus, they now get Mozilla and I'll probably block emails with .exe/.vbs/etc entirely.

    Just based on the chapter titles, I think tricks such as the "Let me help you", etc are probably some of the nastiest. Considering the many people who seem to know shiat about progamming and come for help, it wouldn't be hard to slip something cruel into your "sample code."
    It's amazing how, after helping somebody directly with something for 30 minutes or so, they're suddenly willing to let me
    a) Have root access to their machine ('nix)
    b) Control their PC (netmeeting/etc windows)

    Luckily I'm a nice person, but not everybody is so helpful as they appear. Social engineering is definately an increasing trend, which is leading to user pananoia. I still don't think that the statement "One of the weakest links to the most secured computer systems are the humans that operate them."
    A good sysadmin will block a lot of things that lead to exploitation (unused ports, etc), and perhaps notice odd happenings/traffic. It's the operators of the less-secure systems (clients) that are at risk most often.

  10. Somewhat disappointing by knobmaker · · Score: 4, Insightful

    I read this recently, and although it's a pretty good introduction to the conman profession, I was a little disappointed in the lack of actual examples of clever hacking.

    The book is primarily about social engineering. Most of the example crimes in this book could have been perpetrated by folks who had no more than a casual acquaintance with the inner workings of computers. In other words, Mitnick tells you how to exploit the stupidity of human beings in large organization, and not how to exploit weaknesses in operating systems and security software.

    Part of this is probably due to court-ordered vagueness; the court obviously didn't want Mitnick spreading dangerous knowledge.

    On the other hand, Mitnick is probably correct in his contention that the greatest factor leading to compromised systems is the naivete of the folks who work with them.

  11. Table of Contents? by mmThe1 · · Score: 4, Informative

    May seem like a nitpick, but isn't this "review" more of a "Table of Contents with brief description of chapters"?

    Slashdot Book Review Guidelines

  12. It's a knack. by caluml · · Score: 4, Insightful

    It's a knack, social engineering.
    I've read the book, and just like some people couldn't sell food to a starving man, only a few people can pull it off.

    Get one tiny piece of information from one person, another from another, and after a while, enough of those pieces make you sound like you are an employee. And we all help our fellow downtrodden, overworked employees, don't we.

    EG. If you have an intranet at work, I bet you have a nickname for it. And if someone asked you for something from it, and said "I can't get to the XXXX today, not sure why, it seems to be down..." you'd probably go and find the info for them.

  13. A more informative review by phr2 · · Score: 5, Informative
    Here's a review by Rob Slade that's quite a bit more detailed than MasterSLATE's review.

    Before seeing Slade's review, I read most of The Art of Deception at the bookstore and decided not to buy it. I agree with most of what Slade says. The book is mostly aimed at PHB types and doesn't say all that much useful to techies. However, as a security implementer, I don't think trying to install paranoia in PHB's is such a bad thing. They are often completely unrealistic about vulnerabilities, so it's good to open their eyes a little.

  14. Excellent Book and Some Resources by webword · · Score: 5, Informative

    I'm reading this book now. Surprisingly, it isn't so much about technology and security. Instead, it is more about understanding humans. Despite the sterotype that geeks have for being socially incompetent, to be a truly good hacker using social engineering, you have to be good socially. Maybe not great, but pretty good. And, you need to know the right language and the right people to communicate with. Mitnik does a great job with this stuff and I am really enjoying the book. (However, I'm not so sure his tactics will work as well as they did a few years ago.)

    Here are some pretty good resources for learning more about social engineering:

    Social Engineering: What is it, why is so little said about it and what can be done?

    Social Engineering Fundamentals, Part I: Hacker Tactics

    Social Engineering: The Human Side Of Hacking

  15. Re:Already done, only better by Bastian · · Score: 5, Interesting

    SmartCard security, ATM cards, and a host of other security solutions (not just along the card theme) already employ the "Something you have, something you know" security scheme in which sensitive things can only be accessed if you have both a device (usually containing some sort of identifier) as well as a password.

    Another interesting version of this system involves a keychain or some similar device that contains a computer whose only job is to take some encryption key and scramble it every n time interval. The central sever is doing the same thing. The end result is that the user has to know two passwords - his normal password, plus a key that changes every minute or what have you.

  16. On Mitnick by Anonymous Coward · · Score: 4, Insightful

    Am I the only participant to this forum who thinks that any admiration on Mitnick is admiration on a crook? As this book clearly seems to illustrate, the basis of his success as a cracker was his ruthlessness and willingness to lie and deceive people, rather than his technical prowess.

    I.e. Mr. Mitnick is a criminal, who may or may not have extraordinary technological savvy; all those years in jail, and post-jail constraints, were surely well-deserved.

    1. Re:On Mitnick by DrMaurer · · Score: 5, Insightful

      Perhaps he's trying to turn his life around and teach people lessons that can help thwart people like he used to be. He's out of prison, served his time, give him a chance to turn around and give him the benefit of doubt. He knows what he knows, and the information he can provide can help security.

      Of course, don't answer any of his questions about your network, either.

      There are plenty of ex-criminals that went on to give plenty of good to society or to hold positions of power. Have you seen 'catch me if you can'? Based on a true story/book, the guy who went on to work for the check fraud division of the FBI. Is that another ex-criminal who should be working at some grocery store bagging groceries instead of lending their talents later to banks to help prevent fraud?

      That attitude (once a con, always a con) is part of the problem of recivitism (sp); if convicts could make a decent living like most people, they wouldn't have to go back to crime.

      I thought the "Free Kevin" stuff was kind of silly once he was charged with a crime. I don't know much about this particular case, anyway, so.

      --
      Dan
    2. Re:On Mitnick by kubrick · · Score: 4, Insightful

      The whole point about democratic freedoms and human rights is that they should apply to scum like Mitnick as well as to you and I. Compelling someone to give up those rights doesn't give me a lot of confidence that they are being respected in the more general case.

      Besides, all that time spent before his plea counted toward his sentence. He just got it over with early.

      Shouldn't a suspect be considered innocent until proven guilty in a court of law?

      --
      deus does not exist but if he does
  17. Not Sufficient by nosilA · · Score: 5, Interesting

    One of the anecdotes in this book exploits a SecurID, using a well-meaning 3rd party. Basically a caller poses as an employee when talking to an operator during a snowstorm. He says he needs to get some work done, but he left his SecurID on his desk. The operator doesn't want to go to the desk to get it, so instead he gives his own SecurID number and PIN to the caller. This was probably one of the most clever manipulations in the book.

    Fundamentally, any time you have a human involved in a process, you have a potential security hole.

    -Alison

    1. Re:Not Sufficient by nosilA · · Score: 4, Interesting

      I have no contempt for humanity. Our goal is never security for security's sake. We could theoretically make a security system that was completely free of any holes, but it would undoubtedly be far to complex to actually accomplish the true goal of our organization. So we let security be a little more lax than that by means of calculated risks.

      It is true that organizations that are very security conscious will have security guards who memorize everyone's face, name, and purpose, rather than using IDs that can be defeated. However, for most organizations security by this method is too expensive, and either there would be a way to bypass this security or communicating from this organization would be too cumbersome to accomplish one's job.

      The point of this book is to make us aware of the potential security holes around us, not necessarily to eliminate them. The final part of the book focuses on how to identify information that demands a higher level of security and implement appropriate security procedures. It establishes a 4-level classification scheme (although 3 or 5 would be okay too). At the highest levels of security, a face-to-face or other strong identification method would be required. At the lower levels, something as simple as verifying a name would be acceptable. In the middle, one may verify a story by a third trusted party, for example.

      The point is not that humanity is bad, just that one of our best qualities, desire to help others, can be turned into a weakness.

      -Alison

  18. A donkey laden with gold...... by Savage-Rabbit · · Score: 5, Insightful

    ....can scale any fortress wall.

    Philip of Macedon said that (I seem to remember) 2300 year ago. To put it short more codes have been cracked and more defenses of any kind have been breached by exploiting simple human weakness than any clever hacking/engineering ever has and ever will. It usually is the easyest way. Take the Enigma code, it was cracked, partly, because of the simplistic and repetitive choices of code key words made by the Wehrmacht communications personnel. It never ceases to amaze me how deeply this fact disappoints the tech freaks of this world. If I had to guess all the nerds at CIA-Langley with all their cool equipment will not contribute even half as much to catching Osam Bin Landen or determining his fate as simple traitors within Al Quaeda will do.

    --
    Only to idiots, are orders laws.
    -- Henning von Tresckow
  19. I read it... by Hanashi · · Score: 5, Informative
    This article wasn't much of a review, so I thought I'd chime in. I read this book recently, and here are some of my thoughts.

    First, what's in this book? The bulk of the book is given over to scenarios of different types of social engineering attacks. This includes things like acting helpless, offering help and guilting your victim into "owing you something", and pushing certain psychological buttons designed to make the victim feel whatever emotions you want. There's also some stuff about how to create a good security policy for your organization, but you can skip that. There are much better references for this sort of thing.

    What did I like? The scenarios sure are entertaining! The book covers a wide variety of different situations and goals, from tricking someone into telling you their password to gaining physical access to "secure" facilities. The authors tell the story of each attack both from the victim's point of view and from the attackers, then provide an analysis of why it worked and how it could have been prevented. Very valuable!

    What did I dislike? There's a substantial amount of repetition in the scenarios, but some may view that as useful reinforcment, so it's not necessarily a bad thing. As I said, I think the security policy section isn't very good, and it could easily have been left out.

    My overall impression is good, and I highly recommend this to anyone responsible for physical or information security in their organization.

    --
    Check out my eclectic infosec blog at InfoSecPotpou
  20. So... The solution is... by einhverfr · · Score: 5, Insightful

    1) Ideally build security around "what you have/what you know" to the greatest extent possible.

    2) Train, train, train!

    3) Just like you do a network security audit from time to time, do mock attacks! Call up an employee and use something like the following script (modified each time)

    "Hi, my name is Joe Angstrom. I work over in IT."

    "We are investigating a potential security problem on our network and need to ask you a few questions. Have you noticed anything strange about your computer recently?"

    "Thank you, this has been very helpful. There is one more thing. So that we can be sure of this, could you verify your username and password?"

    Just make sure that it is approved of before you do it ;) If the employee gives out their login info, you send them an email letting them know that they should NEVER give out login information to ANYONE for ANY REASON, and tell them to change their password. Explain that passwords are not accessible to anyone, and that login information is available to anyone who would be investigating security problems. If it happens again, send an email to their manager as well ;-)

    The point is-- human factors can be mitigated by training, but no one puts that effort into things.

    --

    LedgerSMB: Open source Accounting/ERP
  21. Sorry but no by Inexile2002 · · Score: 5, Interesting

    A HUGE part of my job is preventing social engineering type stuff (or if you want to be specific - evaluating the degree to which a client has successfully implemented good risk management and security management). I interview people all the time, and I assure you that waving $100 is the most sure fire way to not get what you want.

    People are more afraid of getting caught, of loosing their job or of getting in trouble than I think you realize. That said, it is amazing the things people do, if they think they're supposed to do them.

    I'll routinely call people at a client and just start asking questions to total strangers. I've been in server rooms interviewing people and I'll ask questions like, "How does a visitor get access to this room?" When they answer, I'll ALWAYS follow up with, "Why was I not subjected to that procedure?" I'm legitimately supposed to get access to the information I get, and I sign NDAs and get approval for everything I do. Not once have I ever been challenged to provide that information. (For some reason, if you call the manager of a department and tell him that you'll be talking to his employees and why - they assume you're legitimate.)

    Show up, talk the talk and look like you belong there and people will tell you anything. Wave around $100 and people call security.

  22. Admiration? by GuyMannDude · · Score: 4, Insightful

    Am I the only participant to this forum who thinks that any admiration on Mitnick is admiration on a crook?

    Actually, I haven't really seen too many posts here glorifing Mitnick so I don't know where your incredulous attitude is coming from. I agree that he is not someone to be admired. I'm guessing that a large number of slashdotters do too. However, we are interested in what he has to say, regardless of whether he was a decent person or not. He did manage to pull off quite a few feats. There are a lot of people here saying things like "Oh, that's obvious" and "He has no technical skill." So what? He has shown us that technical skill is really not required. As technical/science/engineering types here, we are interested in discovering the truth -- even if the truth is underwhelming when we finally get to it.

    I.e. Mr. Mitnick is a criminal, who may or may not have extraordinary technological savvy; all those years in jail, and post-jail constraints, were surely well-deserved.

    True enough. But there is something to be learned from his book (I'm guessing here -- I haven't read it). That's why the review is here on slashdot. That, in an of itself, doesn't imply that we're all Mitnick fanboys around here.

    GMD