Logo Image
Blog | Study | Writing | Tools | Contact | About | Syndication | Search

Social Engineering In The South vs. The North

By Daniel Miessler on August 15th, 2006: Tagged as Information Security | Musings | Penetration Testing | Security | Social Engineering

I’m starting to get more opportunities to use social engineering as part of penetration testing jobs, and after a recent success in the Southeastern United States I began pondering something:

Is it easier or harder to do social engineering in the South?

When you first think about it your gut reaction is that it’s easier, but it turns out that it’s all based on what type of attack is being performed. Getting information over the phone and such is most likely much easier, but attempting to physically access a building and roam around might actually be harder. Here’s why.

Southerners are very personable people. They want to know who’s working near them, who just got fired, who the new person is, etc. They don’t often work in close proximity to someone without having made contact with them in some way, shape, or form. This often manifests as extreme kindness, i.e. inviting new acquaintances to eat with their family, etc.
For a pentester trying to go unnoticed, this presents a problem. As I was on one of these engagements earlier this week I wondered if it would be easier in say, the Northeast, where, as I understand, people commonly don’t care at all who the people are around them.

But then I realized that while Southerners are more likely to be familiar with those around them, they’re also probably less likely to challenge someone who’s not supposed to be somewhere. I ran into this during this job as well; someone found me in their server room and didn’t say anything, most likely for fear of being rude.

Anyone have any additional anecdotal evidence to offer?

--

No Comments »

--




visitor stats

Twitter/danielrm26


    Security & Technology

    • XSS Explained
    • Security and Obscurity
    • The Diffie-Hellman Protocol
    • Not All SYN Packets Are Created Equal
    • The Birthday Attack
    • The Hyperlink Trailing Slash Debate
    • Understanding Subnetting
    • Why CISSPs *DO* Need to Be Technical
    • A tcpdump Primer
    • Understanding Network Ports
    • Windows is IE: OS X is Firefox
    • 10 Infosec Interview Questions
    • Security is Not a Technology Problem
    • Why You Should Encrypt *ALL* of Your Google Activities
    • An lsof Primer
    • Using find and xargs
    • A Guide to the tr Command
    • How UNIX/Linux Permissions Work
    • Proving the Monty Hall Puzzle in Python
    • An Infosec Prediction: More Human-Based Attacks
    • It's Time to Drop the "www"
    • How to Pronounce "Linux"
    • How to Pronounce "Ubuntu"
    • How to Pronounce "OS X"
    • The Pronunciation of "Rijndael"

    Philosophy & Science

    • Free Will: The Necessary Delusion
    • Logical Conclusions to the Lack of Free Will
    • Outrageous Beliefs Are NOT Equal to Claims They Are Preposterous
    • How Would *YOU* Prove Evolution?
    • An Atheist Debate Reference
    • Was the Last Time Your Last Time?
    • How I Became an Atheist
    • A Letter to Religious Moderates
    • What Does it Mean If We Have No Free Will?

    Culture & Society

    • The Nice Guy Paradox
    • Socialism, Anarchy and Ideal Government
    • What Every American Should Know About the Middle East
    • The Bimbo and the Caveman
    • Multiculturalism: Tested and Failed
    • Is it Wrong to Have Children Today?
    • A Logical Approach to CFR and NWO Conspiracies
    • Lifecasting: What It Is and How It Will Change Society
    • Why You Should Submit Your Own Content To Social Sites
    • Measuring The Quality Of A Society

    Blog Archives

    • 1996
    • 1997
    • 1998
    • 1999
    • 2000
    • 2001
    • 2002
    • 2003
    • 2004
    • 2005
    • 2006
    • 2007
     

    Copyright © | Daniel Miessler | 1999-2008 | All Rights Reserved