Skip to Content
Unauthorised Access: Physical Penetration Testing For IT Security Teams
book

Unauthorised Access: Physical Penetration Testing For IT Security Teams

by Wil Allsopp
September 2009
Intermediate to advanced
307 pages
7h 46m
English
Wiley
Content preview from Unauthorised Access: Physical Penetration Testing For IT Security Teams

4.2. Tactical Approaches to Social Engineering

Having discussed in general the overall philosophy of the social engineer, this section provides tips and hints for social engineers. It looks at the specific tactics that can be employed within conversations to achieve your goals (or at least speed up the process). After reading each section, think about people you know and how you think they would respond to each approach. This is actually a lot easier than you might imagine. For example, acting belligerent and imperious with middle management is going to get you nowhere fast (unless you can convince your victim you are upper management), similarly don't expect to carry out a successful IT-based attack against IT staff. You will find this kind of mental templating very useful.

4.2.1. Acting Impatient

Acting with impatience when someone is moving too slowly or appears to be considering verifying your story can be effective in derailing some people's adherence to accepted security protocols. Usually you can expect one of three responses:

  • The flustered target – This is when people panic because they're out of their depth and feel expected to handle a situation they're not trained to deal with. People who don't know what to do are easily manipulated. If this kind of reaction occurs, you should immediately change tack – become reassuring but at the same time firm. Adopt an alpha personality that implies that you know what needs to be done and you will take charge of the situation to ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Hack I.T.: Security Through Penetration Testing

Hack I.T.: Security Through Penetration Testing

T. J. Klevinsky, Scott Laliberte, Ajay Gupta
Penetration Testing and Network Defense

Penetration Testing and Network Defense

Andrew Whitaker, Daniel P. Newman

Publisher Resources

ISBN: 9780470747612Purchase book