Re: Papers on Sex as an audit tool?

From: Raven Alder (raven@oneeyedcrow.net)
Date: Thu Mar 11 2004 - 04:29:33 EST


Hiya --

Quoth Sriram Lakshmanan (Wed, Mar 10, 2004 at 02:17:07PM +0530):
> Really interesting Point. In my limited audit experience, yet to come
> across "fairer sex" being used to ferret info from clients.

        It is a definite factor. I am both female and a pen-tester.
Even if I'm not trying to social-engineer, I find that being a
reasonably attractive woman can be immensely helpful. People tend to
bend over backwards to be charming and helpful, try to impress you with
their knowledge, talk more freely than they would to some unknown guy,
or vastly underestimate your technical skill level. There are times
when it's actually an advantage to be dealing with a sexist jerk.
[grin] "Wow, that looks really *difficult*, you must be so *smart*."
"Well, let me show you, little lady..." "Oh, that's so cool!" [mentally
records details of login challenge-response...]

        While I normally focus much more on the technical aspects of
pen-testing than the social ones, I have had co-workers ask me on
multiple occasions to be the one to try the social engineering tactics.
They (correctly) estimated that my chances of success would be much
greater, simply by virtue of looking like the girl next door. And if
the specs of your pen-test contract include social engineering and
physical security, a savvy female with both social engineering skills
*and* technical know-how can do really well. Get in the door, find the
machine, FIRE CD, ba da bing. Corporate security desks tend not to
search purses, either.

        I haven't authored any formal papers on the subject, but
probably could. (More of a case study of my own experiences than
anything statistical/canonical, but still.) I'll add it to the "Things
to do in my Copious Spare Time" list. [grin]

Cheers,
Raven

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:50 EDT