Wednesday 13 November 2013

See How Social Engineering Duped a Security-aware Organization

That’s recent news from IDG News Service, which states that some penetration testers faked their social identity over a network to break-in through government agency; the one having strong cyber security defenses.

So, some security experts tried to penetrate with the defenses of a U.S. government agency. Faking as an attractive young woman, the security experts tend to show the levels of effective social engineering attacks now-a-days.

Said attack was a part of some penetration test performed in 2012. The results to this penetration test were released by the cyber-defense specialist, Aamir Lakhani. Aamir Lakhani represented the test results at the RSA Europe security conference held in Amsterdam.

The team handling this penetration test claimed Emily Williams (the faked identity) was a 28-year-old; MIT graduate with 10 years experience. The social profiles over Facebook and Linkedin were maintained to set her identity with as much real information as possible. To make it more realistic, an image of a real woman was used over these social profiles.

The test went successful when this fake identity over social profiles started receiving skill endorsements on Linkedin and friend lists on Facebook. However, Lakhani and his team wanted to see how far the social media deception could be taken.


Well, as time went on men working for the targeted agency offered to help Emily Williams, get started faster in her alleged new job within the organization by going around the usual channels to provide her with a work laptop and network access. The level of access she got in this way was higher than what she would have normally received through the proper channels if she had really been a new hire, Lakhani said.

Windows 8.1 Would Be Capable of Protecting Systems against Pass the Hash Attacks

It’s of great efforts that lead to successful blocks for Pass the Hash attacks on the new Windows OS, i.e. Windows 8.1 . Microsoft has blocked the most critical cyber-attacks for this new version of Operating System.

Microsoft states, “Pass the hash is one of the most popular types of credential theft and rescue attacks”. These cyber attacks are mainly known for their efficient ability of filtering networks in a matter of minutes, making havocs along the way.

With the release of Windows 8.1 on past October 1, Microsoft ensured an enhanced level of security improvements in the OS. They said, some major security improvements are added to block hackers from further use of these attacks.

This recent release has gone a step ahead with the evolution of cyber security. Following few steps would surely enhance your password practices, listed below:-
  1. Maintain administrator accounts separately with care.
  2. Lock down Domain Administrator passwords at a shared place where system administrator can easily access them whenever needed.
  3. Change domain Administrator passwords after each use.
So stay protected and be safe from pass the hash attacks with Windows 8.1 . Still facing issues? Call our tech experts at +1-888-703-9488