ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Mitnick teaches 'social engineering'

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 18 Jul 2000 11:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Would you trust Kevin Mitnick? Dozens of administrators, security personnel and phone operators did. That, he says, was one reason he succeeded as a hacker. In the early 90s, Mitnick had the run of many phone systems. On Sunday, the celebrity hacker told hackers, wannabes and activists who packed two rooms at Hacking on Planet Earth 2000 how he did it.

"Through social engineering, I gained the ability to obtain any number, listed or unlisted," Mitnick said in a speech delivered by phone from Los Angeles. "This really came easy to me -- manipulating the telephone company."

Social engineering is basically pulling a con job, hacker-style. The object is to get information or access to systems that are normally only used by privileged users.

"[As] the media characterises social engineering, hackers will call up and ask for a password," Mitnick said. "I have never asked anyone for their password."

It was the first talk Mitnick has given since his probation officer gave him permission to lecture on hacking, work as a security consultant and write articles on security.

Mitnick, 36, served almost five years behind bars for breaking into computers, stealing data and abusing electronic communication systems. Upon his release in January, Mitnick denied the charges against him, claiming he had been railroaded into a plea bargain by the authorities.

Mitnick is nothing, if not persuasive. The California resident chatted with H2K attendees about how he would build trust with administrators, security personnel, and anyone else who might have the information or access he needed.

"You try to make an emotional connection with the person on the other side to create a sense of trust," he said. "That is the whole idea: to create a sense of trust and then exploiting it."

As an introduction to the session, Eric Corley -- also known as Emmanuel Goldstein, the publisher of the hacker magazine 2600 -- called AT&T's internal security to inquire about a memo that warned employees about the social engineering session.

Corley, who had a copy of the memo, posed as an AT&T employee who wanted to know more about the memo and the "hacker threat". He talked to an alleged security employee and confirmed the existence of the memo, though no other privileged information was gained.

While the example seemed benign, it showed how willing people are to trust someone on the other end of a phone call.

"I used to do a lot of improvising," Mitnick said. "I would try to learn their internal lingo and tidbits of information that only an employee would know."

Mitnick also offered advice to businesses afraid that spies and hackers may gain access to their internal systems using social engineering. "On the corporate side, as an employee, it all comes down to user awareness and education," Mitnick said.

Proactively recording calls could increase security as well, he added.

"The 'monitoring this call for quality assurance' is really a deterrent because you don't know whether they are listening to you," he said.

Take me to the Summer of Hacking Special

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
43 out of 97 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Experienced Clinical Research Associate Career Growth Exceptional!

The role will involve regular interaction with International management and external committees as well as colleagues from various functions globally ...

Major Energy Franchise Market Risk specialist sought

Due to the stature of this organisation this is a much sought after opportunity therefore we are seeking personnel with commercial market risk ...

Procurement Manager, Cost Control, Bid Management, Telecoms, London

You will report to the Director of Supplier Management & he must be able to trust to you, as he will delegate some of his work to you e.g.meeting new ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal