Thursday, 22 January 2015

SOCIAL ENGINEERING

Social Engineering 

Social engineering – Social engineering is a technique used by attackers to take advantage of the
natural trusting nature of most human beings. Criminals often pose as an
insider or other trusted person to gain information they otherwise wouldn’t
be able to access

Passive test –   the passive test is  way of getting the information from the network by the use of search engine ..

So here are some queries  you can directly search from a search engine –

site: your~public~host~name/IP keywords to search for

Look for keywords such as wireless, address, SSID, password, .xls (Excel
spreadsheets), .doc (Word documents), .ppt (Power Point slides), .ns1
(Network Stumbler files), .vsd (Visio drawings), .pkt (sniffer packet captures), and so on.

 site: your~public~host~name/IP filetype:ns1 ns1
This searches for Network Stumbler files that contain wireless network
configuration information. You can perform this query on any type of
file, such as .vsd, .doc, and so on.

 site: your~public~host~name/IP inurl:”h_wireless_11g.html”
or inurl:”ShowEvents.shm”

This searches publicly accessible APs  such as D-Link and Cisco
Aironet for wireless setup pages and event logs,

But you will be surprised out of the information you will get out of it ….

Google is an amazing tool to get the information for different servers , so you must know how to use it for your benefit

Now if you are like me .. You would like more automated tools .. So here is one

www.foundstone.com/resources/freetools.htm

This site allow us to run various prepackage queries  .. And help to know the information

Active tests –  active test is more of a in personal way of hacking rather technical .. As you  try to get the information through the personal contact through phone , email or in person  ..

In hacking it is not just about getting the password but also any other type of information .. So think of it as finding a way to get these files ..


No comments:

Post a Comment