Published on Security Management (http://www.securitymanagement.com)
Security Pros Get Scammed by Black Hat Hackers
By Matthew Harwood
Created 08/08/2008 - 12:32



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
08/08/2008
By Line: 
By Matthew Harwood
Teaser: 

By posting fake profiles of prominent computer security professionals, two hackers showed Black Hat hacking conference attendees how even skeptical security experts can get scammed.

The ruse was simple.

Shawn Moyer, chief information security officer for Agura Digital Security, and Nathan Hamiel, senior consultant for Idea Information Security, created fake profiles of prominent computer security professionals, posted them to various social networking sites, and then sent out plenty of friend requests to other security experts.

They were so astounded by the results they presented to the Black Hat hacking conference [1] yesterday in Las Vegas, according to the Associated Press [2]:

Moyer and Hamiel said they did it three times, each time impersonating a different person. Each time they lured in more than 50 new friends within 24 hours. Some of those people were chief security officers for major corporations and defense industry workers, they said. They declined to identify any of those people.

According to the AP, security professionals are known for their skepticism, some say paranoia, but even these knowledgeable denizens of the net fell for the same scams they warn the average Web surfer to avoid, especially on social networking sites.

Accepting friends on social networking sites you haven't authenticated as real is dangerous, says the AP. Cybercriminals and hackers masquerading as friends can then post malicious code on a person's profile page or simply post links to malicious Web sites.

Related Resources: 

"The Jihadist MySpace [3]," by Matthew Harwood, Today's Headlines,  Jan. 17, 2008

"MySpace for Spooks [4]," by Matthew Harwood, Today's Headlines, Aug. 22, 2007

"Antisocial Networking Sites [5]," by Peter Piazza, Security Management, Nov. 2006

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 35,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters USA, 1625 Prince Street, Alexandria, Virginia 22314-2818
703-519-6200 | fax 703-519-6299 | www.asisonline.org

ASIS

Copyright © 2009 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/security-pros-get-scammed-black-hat-hackers-004495

Links:
[1] http://www.blackhat.com/
[2] http://ap.google.com/article/ALeqM5h0kjo2fb-7rSiDOlZHMgkTrEJURgD92DM7OO1
[3] http://www.securitymanagement.com/news/jihadist-myspace
[4] http://www.securitymanagement.com/news/myspace-spooks
[5] http://www.securitymanagement.com/article/antisocial-networking-sites-0