{"id":936,"date":"2010-03-08T10:23:00","date_gmt":"2010-03-08T10:23:00","guid":{"rendered":"https:\/\/www-new.brucon.org\/2018\/2010\/03\/08\/announcing-brucon-training-3-social-engineering-for-pentesters\/"},"modified":"2010-03-08T10:23:00","modified_gmt":"2010-03-08T10:23:00","slug":"announcing-brucon-training-3-social-engineering-for-pentesters","status":"publish","type":"post","link":"https:\/\/archive.brucon.org\/2024\/2010\/03\/08\/announcing-brucon-training-3-social-engineering-for-pentesters\/","title":{"rendered":"Announcing BruCON Training #3: Social engineering (for pentesters)"},"content":{"rendered":"<p style=\"font-style: italic\">\n<blockquote style=\"font-style: italic\"><p>In 2007, one of the biggest diamond robberies ever found place. The thief used no violence. He used one weapon  &#8212;  his charm &#8212; to gain confidence. He bought chocolates for  the personnel, he was a nice guy, he charmed them, got the original of  keys to make copies and got information on where the diamonds were. You can have all the safety and security you want, but if someone  uses their charm to mislead people it won&#8217;t help.<\/p><\/blockquote>\n<p><span style=\"font-weight: bold\">Course abstract: <\/span>Social engineering attacks can have disastrous consequences, both  financially and reputationally.  You can have the best technical  security controls in the world, from the most expensive firewall to the  most sophisticated biometrics, but they will not protect you from a  social engineering attack.  In any security program, people are the  weakest link.  Social engineering tests can be used to evaluate and  strengthen this link. <\/p>\n<p>Like any penetration test, social engineering tests can help to  identify security weaknesses that could allow your IT systems to be  compromised.  Such tests can: <\/p>\n<ul>\n<li> Give a good indication of and even improve your staff\u2019s level  of security awareness <\/li>\n<li> Teach your staff how to identify and deal with social  engineering situations <\/li>\n<li> Provide valuable recommendations on both security awareness  and physical security <\/li>\n<\/ul>\n<p> However, it can be difficult to know how to conduct a social  engineering test.  This two-day training course will teach participants  how to conduct an ethical social engineering test, the theory behind  social engineering, as well as giving recommendations on how to defend  against social engineers.  The course will include practical exercises  and is open to anyone with an interest in social engineering.<\/p>\n<p><b><\/p>\n<blockquote><p>Sharon Conheady \u2013 Biography<\/p><\/blockquote>\n<p><\/b> <\/p>\n<p>Sharon Conheady is a Director at First Defence Information  Security in the UK where she specializes in social engineering.  She has  social engineered her way into dozens of organizations across the UK  and abroad, including company offices, sports stadiums, government  facilities and more.  She has presented on social engineering at  security conferences including Deepsec, Recon, Brucon, CONFidence, ISSE,  ISF, SANS Secure Europe and more. <\/p>\n<p>After inventing the Internet alongside Al Gore, Sharon moved on  to the development of security protocols that were used to crack 128 bit  encryption.  She holds a degree in Computer Science from Trinity  College Dublin and a MSc in Information Security from Westminster  University.  Three times winner of the Nobel Prize, Sharon enjoys belly  dancing and space travel. <\/p>\n<p>If you see Sharon around your office, she kindly requests that  you open the door to let her in.  <\/p>\n<p><b><\/p>\n<blockquote><p>Martin Law \u2013 Biography<\/p><\/blockquote>\n<p><\/b> <\/p>\n<p>Martin Law has over 19 years security expertise and has been  performing social engineering tests since 1994. He specializes in  accessing datacenters by using social engineering techniques and  bypassing physical security like a geeky James Bond. <\/p>\n<p>Martin also undertakes investigations into actual or suspected  security breaches, and specializes in the area of Information Warfare.  He attempts to breach not only the logical security of systems and  networks, but also the physical security of the infrastructure and  buildings, including the use of social engineering when engaged in an  \u201cAll-Out-Attack\u201d against an enterprise.<\/p>\n<\/p>\n<blockquote><p>\u201cIf you can&#8217;t go through the <em>firewall<\/em>, go through the  secretary\u201d <span style=\"font-weight: bold\">&#8212;<\/span><b><\/b> <em>Sharon Conheady<\/em><\/p><\/blockquote>\n<p><em><\/em> <\/p>\n<p>More information on the course can be found <a style=\"font-weight: bold\" href=\"http:\/\/2010.brucon.org\/index.php\/Training_3\">here<\/a><span style=\"font-weight: bold\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2007, one of the biggest diamond robberies ever found place. The thief used no violence. He used one weapon &#8212; his charm &#8212; to gain confidence. He bought chocolates for the personnel, he was a nice guy, he charmed them, got the original of keys to make copies and got information on where the diamonds were. You can have all the safety and security you want, but if someone uses their charm to mislead&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-936","post","type-post","status-publish","format-standard","category-training"],"menu_order":0,"_links":{"self":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts\/936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/comments?post=936"}],"version-history":[{"count":0,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts\/936\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/media?parent=936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/categories?post=936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/tags?post=936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}