Started By
Message

re: Is the whole hacker / IT security / upgrade loop just a system to keep people employed?

Posted on 8/6/18 at 10:11 am to
Posted by GrammarKnotsi
Hammond
Member since Feb 2013
10172 posts
Posted on 8/6/18 at 10:11 am to
quote:

Hacking an individual is as easy as creating a fake automotive header and telling someone they have a recall on their vehicle and they need to click a link to see where to take it.


one of my most successful campaigns is an Amazon email that says "If you DID NOT order this, click and sign in here"
Posted by Centinel
Idaho
Member since Sep 2016
46687 posts
Posted on 8/6/18 at 10:11 am to
quote:

The biggest threat in IT/IS will always lie between the seat and the keyboard..The Id10t malware will always exist


aka, the Layer 8 problem.
Posted by ell_13
Member since Apr 2013
88419 posts
Posted on 8/6/18 at 10:11 am to
Twice a year, our company sends out its own phishing email just to see how many people still don't get the message about clicking links. All it takes is telling someone they need to address a certain PO that was uploaded to sharepoint. At least 20% of people get fooled every time.
Posted by 50_Tiger
Arlington TX
Member since Jan 2016
43534 posts
Posted on 8/6/18 at 10:14 am to
quote:

Twice a year, our company sends out its own phishing email just to see how many people still don't get the message about clicking links. All it takes is telling someone they need to address a certain PO that was uploaded to sharepoint. At least 20% of people get fooled every time.



This happened last quarter. Always starts the conversation in the restaurant about what retard opened the email up

I know with respect to telecom and our Packet Core, carriers are always looking for IPSec gurus. I have much respect for those guys because it requires more abstract thought than analytical, but most these guys are masters of both.
Posted by GrammarKnotsi
Hammond
Member since Feb 2013
10172 posts
Posted on 8/6/18 at 10:14 am to
quote:

All it takes is telling someone they need to address a certain PO that was uploaded to sharepoint.


I send out one called "Updated Holiday Hours" from an addy that appears to be internal and have users download it
Posted by Centinel
Idaho
Member since Sep 2016
46687 posts
Posted on 8/6/18 at 10:15 am to
Hell we run quarterly campaigns. And have been doing so for two years now. We also have annual mandatory cybersecurity training, along with training for all new employees.

We STILL have a 10-15% click rate, with some quarters being as high as 30%.

And it's not the administrative assistants or staff. It's the fricking attorneys...supposedly the smartest people in the room.
Posted by GrammarKnotsi
Hammond
Member since Feb 2013
10172 posts
Posted on 8/6/18 at 10:16 am to
quote:

And it's not the administrative assistants or staff. It's the fricking attorneys...supposedly the smartest people in the room.



lol..see my previous comments..These guys keep many of us in business
Posted by ell_13
Member since Apr 2013
88419 posts
Posted on 8/6/18 at 10:18 am to
quote:

We also have annual mandatory cybersecurity training, along with training for all new employees.

We STILL have a 10-15% click rate, with some quarters being as high as 30%.

And it's not the administrative assistants or staff. It's the fricking attorneys...supposedly the smartest people in the room.
Spot on. We find that it correlates mostly to age. If you're over 50, there's a 40% chance you will click the link.
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:18 am to
quote:

Network+ is ok. Was my first cert back in 2002. But if you are going for the CCNA, i'd skip it. First test for the CCNA is basically the Network+ applied to cisco. If you have a CCNA, Network+ is understood. Kind of redundant.


Well i've been studying on an off to either take the ICND1 and 2 or the CCNA full exam. I just got off track during the summer. I heard they were retiring the N+ exam at the end of this month, so I figured why not. Otherwise I would just skip that. I haven't decided whether I will take the two part ccna, or the 1. I guess it depends on how I feel about it.
Posted by GrammarKnotsi
Hammond
Member since Feb 2013
10172 posts
Posted on 8/6/18 at 10:21 am to
quote:

We find that it correlates mostly to age


I was honestly working on a paper based on this topic before I left my last job..We never see those kinds of details from our clients, but based on the feedback I had with them, it was a definitely a commonality..

Clients biggest issues are what to do with these people..If Andy shows up on that chart, has a Mitnick video to watch and then shows back up next quarter, what do you do ?
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:22 am to
quote:

why can't this kind of user error be prevented?


Because older people in the workforce generally lack common sense, and let curiosity get the better of them. In my case, it's a lot of accounting/AR/AP people. They get these cryptic emails about invoices and they think oh hey, this is legit. But if they just take a second, to scan over the email, they'd realize the sender is bogus and so is the email. I tell everyone here as a rule of thumb, if you don't trust a sender, or you think the email might be bogus.....delete it. If its important or legit, they will either send you another, or call you about if you got it or why you haven't replied.
Posted by GrammarKnotsi
Hammond
Member since Feb 2013
10172 posts
Posted on 8/6/18 at 10:23 am to
quote:

If its important or legit, they will either send you another, or call you about if you got it or why you haven't replied.




we preach this on physical security too..If someone needs to get into your server room, the person there to do the work, shouldn't be the first time you've heard about it
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:24 am to
quote:

My question is more about why can't email threats be screened more effectively?

Phishing is a different animal, but clicking a malicious link seems preventable by the system.


We get a lot of bullshite emails that have PDF's as the attachment. I guess that is the new ploy by hackers or malware coders. Since everything is scanned to email in pdf form, or emailed in pdf's or zip files. Makes it easy to pass through filters, or have some idiot open them.
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:25 am to
quote:

Layer 8 problem.


That's the transport layer right? Were routers are? lol
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:26 am to
quote:

We STILL have a 10-15% click rate, with some quarters being as high as 30%.


Our most recent one was 45%. our CIO who is really heavy on security lost his shite in a meeting.
Posted by ell_13
Member since Apr 2013
88419 posts
Posted on 8/6/18 at 10:28 am to
quote:

If someone needs to get into your server room, the person there to do the work, shouldn't be the first time you've heard about it
This has become the "new" approach that was recently covered by the WSJ. Companies aren't just being directly targeted anymore. Their vendors are (who are less regulated). And those hacked vendors allow the hackers to create more realistic phishing attempts.

In other words, if I have a vendor who has approved remote access to my system and their employees have their accounts hacked, how do I know it's really my vendor contacting me about scheduling their next remote session?
This post was edited on 8/6/18 at 10:30 am
Posted by 50_Tiger
Arlington TX
Member since Jan 2016
43534 posts
Posted on 8/6/18 at 10:28 am to
Layer 8 is you personally


Here's an image for the non IT folks.

This post was edited on 8/6/18 at 10:30 am
Posted by slackster
Houston
Member since Mar 2009
91871 posts
Posted on 8/6/18 at 10:29 am to
quote:

We get a lot of bullshite emails that have PDF's as the attachment. I guess that is the new ploy by hackers or malware coders. Since everything is scanned to email in pdf form, or emailed in pdf's or zip files. Makes it easy to pass through filters, or have some idiot open them.


Is it feasible/possible to have external emails opened on a different server/network? I might be using the wrong terminology, so apologies.
Posted by ell_13
Member since Apr 2013
88419 posts
Posted on 8/6/18 at 10:30 am to
quote:

Is it feasible/possible to have external emails opened on a different server/network?
Emails and their contents can be scanned before delivery, yes. But the scanning server/software... get this... has to be updated/patched, too.
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
42502 posts
Posted on 8/6/18 at 10:31 am to
quote:

In other words, if I have a vendor who has approved remote access to my system and their employees have their accounts hacked, how do I know it's really my vendor contacting me about scheduling their next remote session?


Saw this happen to a company I use to work for. They had their own web servers etc so their customers could monitor drilling jobs in real time. Someone hacked into the customers network, and in turn found a backdoor into the company providing the portal. They took over both's entire network and stole and ransomed both company's batch of file/web servers.
first pageprev pagePage 4 of 6Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram