From: ctg (plumme@gmail.com)
Date: Tue Nov 23 2004 - 12:17:53 EST
Hello Mr. Bones,
Best resource what can you get for the social engineering is the
PR/Sales related people, because it's down to their line of work. What
you need to learn from social engineering is that people are rather
stupid and you need to find a way to get what you need by manipulating
the people.
In the simple terms the social engineering aiming point in the
penetration test is to gather as much of the information by using
'sweet talk' etc methods. You must understand that in the attacker
point of view is to get know how easy those people are, if you
understand what I mean.
There is no good better practice then trying to do social engineering.
Just be adventurous and make some practical jokes with the people, by
using 'sweet talk', 'bribe' etc. When you get it, you can use those
same skills to pen. test your client.
Just think about how the people make frauds.
- ctg. -
This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:08 EDT