Slashdot Mirror


Pen Testers Break Into Gov't Agency With Fake Social Media ID

itwbennett writes "Security experts used fake Facebook and LinkedIn profiles to penetrate the defenses of an (unnamed) U.S. government agency with a high level of cybersecurity awareness. The attack was part of a sanctioned penetration test performed in 2012 and its results were presented Wednesday at the RSA Europe security conference in Amsterdam. The testers built a credible online identity for a fictional woman named Emily Williams and used that identity to pose as a new hire at the targeted organization. The attackers managed to launch sophisticated attacks against the agency's employees, including an IT security manager who didn't even have a social media presence. Within the first 15 hours, Emily Williams had 60 Facebook connections and 55 LinkedIn connections with employees from the targeted organization and its contractors. After 24 hours she had 3 job offers from other companies."

18 of 109 comments (clear)

  1. Pen testers? by Anonymous Coward · · Score: 5, Funny

    What does the average slashdotter know about penetration?

  2. Security? by Anonymous Coward · · Score: 5, Insightful

    Forget security, the real headline should be "How to get 3 job offers in 24 hours". She must have had some serious (fake) qualifications and/or a smoking hot profile pic.

    1. Re:Security? by Joining+Yet+Again · · Score: 4, Insightful

      Yeah, I imagine by "job offer" they mean "recruiter spam".

      And by "high level of cybersecurity awareness" they mean that some cunt installed Norton on the desktops.

  3. What else do we expect to do? by Anonymous Coward · · Score: 5, Funny

    And yet when I accuse people I just met at the company of being Chinese spies, I am the one who is sent to HR. There is some kind of double standard here.

    1. Re:What else do we expect to do? by Minwee · · Score: 4, Insightful

      They look just like us but like bad beer and hockey.

      And the ones who like good beer stay in Canada.

  4. Re:Job offers? by Anonymous Coward · · Score: 3, Insightful

    Probably just headhunters. I get those all the time through Linkedin.

  5. Because they used an attractive woman. by EMG+at+MU · · Score: 5, Interesting

    The IT world article explains that the fake account was an attractive woman. The victims who exposed their organizations to attack were men who were trying to "help" this attractive woman in her new position.

    New security measure: male employees are castrated upon hire. They tried the same attack with a male profile and received no hits.

    Aside from that interesting bit, we have heard this story over and over again: Large organizations contain at least a few stupid people. Those stupid people, who are mostly well intentioned, work around security measures and run Java applets to see the company Christmas card, a card that is actually an attack.

    1. Re:Because they used an attractive woman. by jsepeta · · Score: 5, Insightful

      so really the title should be "attractive women more likely to get job offers." move along, no story here.

      --
      Remember kids, if you're not paying for the service, YOU ARE THE PRODUCT THAT IS BEING SOLD.
    2. Re:Because they used an attractive woman. by Zontar_Thing_From_Ve · · Score: 4, Informative

      The IT world article explains that the fake account was an attractive woman. The victims who exposed their organizations to attack were men who were trying to "help" this attractive woman in her new position.

      Executive summary:
      Fake Facebook and Linkedin accounts created for a non-existent attractive 28 year old female who was supposedly a new employee. Apparently the account sent out a lot of friend invitations which were accepted by (seemingly mostly) men who never questioned the invitation or why they had never met this person in real life. The men fell all over themselves to "help" this new employee with some even offering to bypass official channels to get her working sooner. So basically lonely nerds take a shot that friending and helping a hot new chick at work might get them something down the road. The fact that she got job offers means nothing as everybody I know who uses Linkedin (for the record I do not use it) gets job offers all the time. One more thing - they made some fake postings from her so that an internet search would seem to indicate she was a real person. And her Facebook account had a link to an external site with a Java security attack that got some suckers to click on it.

  6. Re:Since when ... by quietwalker · · Score: 5, Informative

    (and then I read the article)

    Okay, the point where they then use the connections to send out xmas cards linked to an attack site which people went to, and how they somehow scammed someone into sending her a work laptop and network access credentials.

    That might be better to lead with the actual attacks in the summary, and not just some sort of information gathering setup.

  7. Curious... by the_skywise · · Score: 3, Insightful

    "The attack used built-in Java functionality to get the shell instead of exploiting a vulnerability and required user interaction, but despite these technical limitations, it was very successful, according to Lakhani."

    I'm curious what the "required user interaction" was...

    I'm pretty tech secure savvy - run noscript, only use the computer with condoms on, etc; But I wonder if I would've fallen for this as well...

    If I got a "Christmas Card" from somebody on my company's email I would've allowed the java applet to run. There's an automatic assumption of trust *inside the system* and I would've also assumed that the sandbox mode would be reasonably secure. Was the "user interaction" just allowing the applet to run or did it also ask for something like internet access, which would've thrown up a red flag?

    1. Re:Curious... by PPH · · Score: 3, Interesting

      If I got a "Christmas Card" from somebody on my company's email I would've allowed the java applet to run.

      When I worked for Boeing, one of the supervisors on my project was a fan of Asian male porn (use your imagination). More than a few e-mails supposedly from him contained malware. Given the firewalls we had, I have to think that the infection was hosted on his system. Probably a laptop he carried back and forth to work.

      Fortunatly, I ran a Linux desktop, so no Asian male porn popups for me.

      --
      Have gnu, will travel.
  8. Social Media by Bigbutt · · Score: 4, Interesting

    Well, I don't accept connections on Facebook from anyone at work. Too many folks who have distasteful lives (and I don't want them knowing my stuff either). I have received the occasional Facebook chick spam. I figure it's porn and I certainly don't need Facebook to find porn :)

    I deleted my Linkedin profile a week or two ago so no connections there either. Way too many headhunter spams ("we have a sysadmin job in New Jersey for 6 months for $20 an hour" or better "we are a temp agency, do you need any accounting people?"), marketing spams ("we have this awesome windows management tool" You do know I'm a Unix admin, right?), folks who have no idea of what I do who think I'm a great C programmer, and quite a few folks I have no idea who they are who want to link. So not seeing any benefit, I bailed.

    I also don't click on such attachments or Facebook posts. I have relatives sending me links to such Christmas or Birthday card sites and I choose not to click the link. Just a tad paranoid I guess.

    In reading the article:

    The experiment also shows that attractive women get special treatment in the male-dominated IT industry. The majority of individuals who went out of their way to help Emily Williams were men. The team actually tried a similar test in parallel with a fake male social media profile and got no useful connections.

    I wonder if they though to try it with a plainer woman. Since women are so underrepresented in IT, any woman might have received the "special treatment".

    In general though, I think it's true. Social Networking, either by Social Media or in person will certainly eventually gain you access. Folks are helpful. At work the Customer Service folks get the most awards for being helpful. Upper management even had a Customer Service demonstration for our last company wide meeting. I think it'll take a big change to get that sort of behavior changed.

    [John]

    --
    Shit better not happen!
  9. Re:Job offers? by tompaulco · · Score: 4, Interesting

    I have over 200 contacts and have never had a job offer from linkedin. Maybe it is because I don't accept connections from people I don't know.
    I do regularly get contacted by Indian firms via e-mail or even by phone, but as soon as they find out I am a citizen and not an H1b, then they lose interest.

    --
    If you are not allowed to question your government then the government has answered your question.
  10. Re:Job offers? by Austrian+Anarchy · · Score: 4, Insightful

    How good can a company be if they offer you a job solely on your so-called resume?

    No interview, no verification..

    I suspect they are grossly misusing the term "job offer." Could be an indication of just what sort of people they have working in their own organization.

    --
    Time Bomber the Book coming soon.
  11. Elaborate social engineering hack != "pen testing" by atom1c · · Score: 4, Interesting

    An elaborate multi-factored social engineering hack (commonly referred as a "heist") is quite different than a penetrate test. Anybody can commit fraud, be it a computer illiterate juvenile or a network security contractor (*cough*Snowden*cough*) by virtue of misleading or reconfiguring enough influential factors (people, systems) to pass whatever security measures are in place.

    The same outcome could have occurred by stealing an employee's security badge -- especially if there's an uncanny visual resemblance.

    In other words... no news here.

  12. Re:Job offer is not "break into" by Minwee · · Score: 3, Informative

    To "Break Into" you have to get hired, get past security clearance process and then get hired into position that has access to something valuable, then succeed at taking it. When you are willing to manufacture lies "job offer" is an easy part.

    Maybe you didn't read all of the article.

    [...] men working for the targeted agency offered to help her get started faster in her alleged new job within the organization by going around the usual channels to provide her with a work laptop and network access. The level of access she got in this way was higher than what she would have normally received through the proper channels if she had really been a new hire [...]

    If you read very carefully, you will see that "Emily Williams" was given access to the secure but unnamed organization's network without having to do any of those things.

  13. Re:Elaborate social engineering hack != "pen testi by neminem · · Score: 4, Insightful

    How is it *not* a penetration test? They were testing whether they could get in. They got in. How does it matter whether they got in because they tricked a computer into letting them in, or a person? Both avenues are equally important if you want your office to be secure.