![]() |
|
SE Explained - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge) +--- Thread: SE Explained (/Thread-SE-Explained) |
RE: SE Explained - mothered - 01-15-2018 Allow me to clarify a few things here with social engineering. There's a lot people who do In fact completely overlook the SEing side of It, and only take the "end result" Into account hence deem It as no relevance to social engineering. Simply put and In general terms, SEing Is manipulating the person on the other end Into doing something they're not supposed to do. The end result Is Immaterial. It's the methodology used to achieve the end result that's classed as social engineering. For example: (1). You obtain personal Information and credentials such as family names, given names, addresses, date of births, phone number,s bank account name & numbers, merchant Ids, Inter-company codes, usernames & passwords, CC numbers, CC account holder, expiration dates, CVV numbers and the list goes on. This was performed via person-to-person contact over the phone. The methodology used to obtain this Information, Is social engineering. Not the end result. (2). You've been authorized access to a restricted building, bypassing the building's entry code. This was performed by assuming the role of an employee, dressed accordingly In a suit, wearing (what appeared to be) an authenticated ID and as such, another employee left the door ajar for you and you've walked Into the building. The methodology used to gain access to the restricted building, Is social engineering. The end result Isn't. (3). In the case of "Amazon" on this board. The methodology used to steal the Item In question, Is classed as social engineering. The end result Is not. Yes (where applicable), I agree It Is stealing there's no question about It, but Identifying the vulnerability(s) of the person on the other end, exploiting those vulnerabilities (hence circumventing the human firewall) and getting the person to do something they're not supposed to do (refund/replace the Item) Is social engineering. The end result Is not. As you can see, the results of all analogies above have a different outcome. However, the key element Is the methods used to get the result- all of which pertain to social engineering. RE: SE Explained - DarkMuse - 01-15-2018 (01-15-2018, 05:36 AM)mothered Wrote: Allow me to clarify a few things here with social engineering. There's a lot people who do In fact completely overlook the SEing side of It, and only take the "end result" Into account hence deem It as no relevance to social engineering. Very well said. To me SE is supposed to be used to identify these exploits. The majority of posts here as of right now are people using these exploits over and over by several several people. There's identification and there's usage. In other words, there are bug hunters who find the bugs, and report them, moving on afterwards. And then there's the skids who use weaponized and whored-out scripts with little to no understanding of what they're doing and choose to use them for their own game. Skids and Hunters. RE: SE Explained - mothered - 01-15-2018 (01-15-2018, 06:15 AM)DarkMuse Wrote: To me SE is supposed to be used to identify these exploits. The majority of posts here as of right now are people using these exploits over and over by several several people. There's identification and there's usage. Precisely. Pertaining to Identifying vulnerabilities In web applications and security systems In place, I perform It each and every day both via technical and social engineering gateways. The result Is, I gain unauthorized access. What I do with that result, has no relevance to how I attained It. Of course, there's no malicious Intent whatsoever. In terms of the SEing side of It, my SEing method granted the result. I report vulnerabilities thereby help to fend off future attacks. The moral Is, If users wish to use their SEing methods for stealing, that's their prerogative. It doesn't change the fact that they've social engineered but, they're the ones who'll need to live with the crime they've committed. On the other hand, If they use their SEing methods solely for the purpose to enhance their skill set and report all vulnerabilities to help secure the organization In question, all for the better. RE: SE Explained - Jiggly - 01-15-2018 (01-15-2018, 06:55 AM)mothered Wrote:(01-15-2018, 06:15 AM)DarkMuse Wrote: To me SE is supposed to be used to identify these exploits. The majority of posts here as of right now are people using these exploits over and over by several several people. There's identification and there's usage. I'm with you there. I feel like many people begin amazon SE before they've developed their personal moral codes or views. RE: SE Explained - sah4jt3 - 02-28-2018 Very clean post now understood difference between those both ![]() Edit- what is skids? @mothered RE: SE Explained - Bish0pQ - 02-28-2018 @sah4jt3 skids is short for script kiddies. Term used for people who aren't really interested in technology, but just want to create simple scripts/viruses... In order to do damage to computers, people, companies... They don't want to learn/help. There is a thread here somewhere explaining the difference between blackhats, whitehats and skids. RE: SE Explained - sah4jt3 - 02-28-2018 Okay got it. And what about you? Blackhat whitehat....? @Bish0pQ RE: SE Explained - Bish0pQ - 02-28-2018 (02-28-2018, 12:07 PM)sah4jt3 Wrote: Okay got it. And what about you? Blackhat whitehat....? I wouldn't consider myself a hacker but if I'd need to class myself it'd be grayhat which is basically in between. RE: SE Explained - sah4jt3 - 02-28-2018 (01-15-2018, 05:36 AM)mothered Wrote: Allow me to clarify a few things here with social engineering. There's a lot people who do In fact completely overlook the SEing side of It, and only take the "end result" Into account hence deem It as no relevance to social engineering. (02-28-2018, 12:18 PM)Bish0pQ Wrote:(02-28-2018, 12:07 PM)sah4jt3 Wrote: Okay got it. And what about you? Blackhat whitehat....? Oh yes good to know that
RE: SE Explained - Blink - 02-28-2018 (01-14-2018, 12:53 PM)Jiggly Wrote:(01-14-2018, 12:33 PM)Skryptec Wrote: You can see it as people stealing stuff in real life. Why do people steal? Because they can't afford it or want to make money. This is the same reason why people do this online. That is, until they start stealing from random Ebay sellers... |