Add to Google

False Requests for Information - Watch out for posers

Pages: 1, 2
free web hosting

Read Latest Entries..: (Post #18) by football123213 on Jan 1 2005, 12:05 AM. (Line Breaks Removed)
I just dont get how u could fall for that kind of stuffthis is admin can i have your pass lolbut what ever
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Open Discussion > Have your say > General Talk

False Requests for Information - Watch out for posers

Spectre
The single biggest threat in security is the human element. Methods such as social engineering are one of the easiest ways for an intruder to gain access to information they shouldn't know.

It is important that everyone watch out for false claims of authority, and requests for sensitive information - especially passwords. If you receive a private message or email from someone claiming to have permission from an administrator, or that they are in a position to rightfully have access to such information, then it is strongly recommended that you check that what they are saying is true, with either myself, or another administator.

One example might be:
QUOTE
The admin just told me to check your account for any problems, but I need your password to do it.


Or another:
QUOTE (Guest)
Hey, its me, the admin. For some reason, I can't login to my account, and it's not letting me reset my password. Could someone please change it to X for me, so I can log back in?


Properly structured and planned social engineering attempts will generally be much more clever and sneaky than this, and often seem valid enough that the user is fooled into complying with whatever the attacker is requesting.

Anyway, my point is just to be careful if someone starts asking for something that seems a little bit suspicious. If you see something that you don't trust, then report it to an administrator as soon as possible.

 

 

 


Comment/Reply (w/o sign-up)

Too_Hot
kk thanks for the heads up, i'll be more vigilant rolleyes.gif

Comment/Reply (w/o sign-up)

odomike
thanks sauron...i will be much more careful from now onwards

Comment/Reply (w/o sign-up)

Bash
QUOTE
The admin just told me to check your account for any problems, but I need your password to do it.


lol, i dont think anyone's gonna fall for that

Comment/Reply (w/o sign-up)

EricDrinkard
Thanks for the infomation. I'll keep a sharp eye out.


Thanks
Eric Drinkard

Comment/Reply (w/o sign-up)

Spectre
You would be suprised what people would 'fall for', Bash. Especially if you appear to be coming from a position of authority.

As I said, a real attempt to gain information would most likely sound much more convincing. I don't want to give anyone any material to work with, so I am keeping it simple here.

Comment/Reply (w/o sign-up)

odomike
thats good sauron. it is better to prevent something than to try healing it when it has inflicted someone.

Keep doing the good work.

Comment/Reply (w/o sign-up)

X3r0X
Yeah, i cant believe people realy would do something like that. Evil has infested these forums, search and destroy tongue.gif lol, just watch out everyone

Comment/Reply (w/o sign-up)

NeXDesigns
hey Genocide i am going to need your password and your credit card number for account verification. dry.gif
lol i just dont get where some would fall for it, forum admins never need users password unless for troubleshooting, even then the admins can control user accounts from the acp
(this may not be true with IPB but it is with phpbb)

Comment/Reply (w/o sign-up)

Shackman
Good one there.

I would like to add that usually the only reason the admin needs your password is when he need to modify your account or troubleshoot it.

So far, admin has never asked me for my cpanel or forum password although I have been with Trap17 for quite some time already.

admin usually won't ask you for your account password unless you approach him about something like say maybe something wrong has gone wrong withy our account and you approached him to help you. Other than that, he won't ask you for it.

Yes, properly structured and planned 'social engineering' attacks can be seem very real. Thousands of people have fallen for it before on bigger issues such as credit card passwords. These people are generally wealthy adults who are very smart. And yet, they fall for these tricks. Don't look down on these atackers. They are smarter than you think!

Comment/Reply (w/o sign-up)

Latest Entries

football123213
I just dont get how u could fall for that kind of stuff
this is admin can i have your pass lol

but what ever

Comment/Reply (w/o sign-up)

OpaQue
Right said, The people who carry out such practices are very much cleaver and should not be underestimated. They are extermely smart and know about the human psycology. They know what your thinking and usually attack your emotions ... in other words, play with your emotions.

Clarification about your Doubts regarding Cpanel and Forums : I won't require your forum password because I can directly access your account.

As for the Hosting account, I can also access you Cpanel without your permission. this usually helps in debugging the errors and changing various other settings. However, your DATA in database, Your mySQL tables etc. are all beyond my reach.

The Data is Safe and believe me, I am like managing more than 200 clients (including clients from other network sites ). And the only thing I lookup for the statistics is for invalid downloads and activity. I have never even thought about sneaking into others files or folders. First of all, trap17 is a professional Company. We do not sneak into files as this is against the ethics. And we try our best to protect data. Trap17's hosting is maintained on secure servers and since we are hosted along with one of the toppest sites. Look at this page for the protection stuff we have for the servers.. http://www.theplanet.com/datacenter.html

Comment/Reply (w/o sign-up)

Triple X
I was mostly kidding dude, I know how convincing people can be in scams for passwords on any place because...uhm I've heard storys, lets go with that.

Comment/Reply (w/o sign-up)

Spectre
Just because you fall victim to a cleverly crafted social engineering attack doesn't make you stupid. It is human nature to trust other people, especially people in a position of authority - which is a very exploitable trait.

I've listened into, and been apart of, some very, very convincing social eningeering attempts, which even the smartest person who wasn't intentionally on their gaurd could fall for. If you put enough thinking and preperation into constructing a story line to play someone, then it can be very easy to fool them.

Of course, social engineering attacks aren't generic, and it most definately helps to do some research on your target first. That generally makes it easier to sound like you know what you're talking about. Knowing what area they work in (assuming this is where you want to exploit them), what an average day would consist of in such a job, what typically happens in such an environment, what lingo is generally used by staff, and the names of some of the colleagues - as well as the target - can make you sound like the real thing. Dropping names and other such information that would usually only be known by a person in the position that you are claiming to be in is an invaluable asset when trying to extract information from people.

Social engineering is generally done by phone or email. Obviously, going with the telephone can get very sticky at times. You also have to expect the unexpected - things don't always go as you plan, so sometimes you have to think on your toes and make sure you are ready with a response in case they ask something you aren't ready for. People might get suspicious, but you have to be able to shrug it off, and not sound like you're nervous. If people ask you something, you have to have an answer - or if you don't, then you have to weave it so it sounds like you do know what you are talking about.

Often the pitch of your voice changes dramatically when you're nervous, or lying - which is a dead giveaway. You have to control things like that when you're trying to sound like the real deal.

Anyway, I don't encourage the use of such practises for obtaining any illegal information, or information that you are going to use illegaly. So be straight, stay cool, and keep your nose clean.

Comment/Reply (w/o sign-up)

Triple X
*wouldn't give his p/w out to anyone for any reason ever* I'm not stupid as some people can be rolleyes.gif

Comment/Reply (w/o sign-up)



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

Pages: 1, 2
Similar Topics

Keywords : Requests Information Posers

  1. Questions Regarding Copy Right Laws And Information - (3)
  2. Can The Internet Make You Stupid ? - truth & information vs. lies & dis-information (54)
    Hi all, How does the internet affect your thinking ability?? There's little real
    "accountability" out there on the net. Anybody can post just about anything ... I you take what
    someone says on the net at "face value" ... and believe it. ..then the "wrong" idea gets inside
    your head .. and can make you "stupid". Some associated questions to think about: Who do you believe
    as an authority on a subject ???? Who do you trust?? How do know when to trust them? How many "blind
    alleys" have you been led down by mis-informed ppl, lying ppl, or just plain stupid ppl with no r...
  3. Information Privacy - am I paranoid? (9)
    Hi everybody, I ran into an interesting situation the other day, and I want to see what you guys
    think. One day I found an abandoned computer case and monitor sitting next to the dumpster at my
    apartment complex. Being the compassionate computer lover that I am I couldn't just leave it
    sitting there all alone awaiting its doom, so I wrapped it in swaddling clothes (okay, not really)
    and brought it back home to live with me. Inside I found a hard drive, floppy drive, motherboard,
    modem, graphics card, RAM, CD-ROM, processor, power supply, internal cables, etc.--all...
  4. Forums Rules & Important Information ~ Updated 12/03/05 - (0)
    Welcome To Free Nuke Hosting Index 1. Forum Rules 2. Terms of Service 3. Music Rules
    4. FAQs 5. Trading Market
    ******************************************************************** Please read carefully so that
    you do not get in trouble with the site staff.
    ********************************************************************* 1. Forum Rules
    You are not allowed to Post: Links To: Child Pornography Adult Content Torrents files
    Warez (P2P) Illegal Content Posts Should Not Include: Spam Cracks Or Ser...
  5. Information - (2)
    Hello: I enjoy FNH I wish I could help in some way... Can I Be an account creator? Or a
    modorator? -- Mike...
  6. My Space band requests - (0)
    I think my space is a great way to get your band heard, I don't think they are annoying....
  7. Spreading Firefox, place an information bar in IE - (13)
    If you are using IE to browse the web you may be seeing the information bar pops up and tell you to
    switch to Firefox. It's very cool, I think many Firefox fans here will admire it. So I post my code
    here for you Firefox fans. It is free to redistribute or modifying as long as you keep the credits.
    It is multilingual and will show the language that you are currently using. It now has 6+ languages
    and I expect to have more. CODE Credits: HTML & CSS code by Martin Ng PHP code by
    Ching Yonghan English message by Lim Chee Aun modified by Ching Yonghan Mal...
  8. .Info Information - (0)
    I tryed doing the .info lstnight and when I sent in for my RIN# I got this for a responce A
    response has been made by Karen Hedrick in service request ID 45962. - - - - - - - - - - - - - -
    - - - - - - - - - - - - - - - - - - - Time........: 1/31/2005 9:16 P.M. Response....: Karen
    Hedrick Our free RIN offer for 25 free .info domains expired at midnight on 12/31/04. If we
    can be of any further assistance to you, please contact us. Karen Hedrick Customer Support #1
    Domain Names International, Inc. in otherwords, you can nolonger get the .info f...
  9. JS HTTP XML Requests - (2)
    Alright. This script, when complete, will use javascript to request the contents of a page on any
    server, then update the current page, placing the new content into a div somewhere on the page.
    With a little modification, you can use it for your sites, provided that your site is not very
    complicated. If you want me to help you implement this on your site, or would like me to do it, PM
    me. You can view a demo of the technology at
    http://codefx.titaniumhosting.com/jstest/index.php I spent very little time on the graphics and
    content, so it won't look very pretty...
  10. Some information about administration - (16)
    Is there another way to root a site in this hosting ? Do you only have a Cpanel ? Don't you have
    any solution using just an https connection. I ask this before register because I'm always away from
    home and I often need to use some computer with too security and a lot of closed port. As, until
    now, I have notice that the https port is always open, I want to know if you have a https solution
    to root my site if a get host by you ? Thanx in advance....
  11. Order of the requests is wrong, I think... - (24)
    The order of the posts in the request for free host is the tipical: last post date To the
    admin(s): If you go to the admin panel, then forum admin, then edit that forum, you can set the
    order the forum should be displayed. I think you should select topic date, and not last post date
    (as predefined). I saying this, because I was the first guy to request and I'm still waiting...
    please see this topic ....



Looking for false, requests, information, watch, posers

Searching Video's for false, requests, information, watch, posers




advertisement



False Requests for Information - Watch out for posers