exploitAtion 179
desk employee over the phone could result in a cornucopia of valuable
nonpublic information.
To be successful, attackers often need to use these tactics and oth-
ers to gain enough information and access to complete their tasks. In
Ira Winkler’s 1997 book Corporate Espionage, he describes a social-
engineering penetration test he conducted completely by phone that
gave him complete access to a corporation’s systems.
52
ey completed
the task by using pieces of nonpublic information to gain the trust of
humans in the company. Each piece of information gave them the
ability to get slightly more information. Winkler gains the key pieces
in the following order:
1. An executive’s name and the company’s phone number (from
an annual ...