I attended several great presentations during last week's BSides and Defcon. HD's VxWorks, egyp7's phpterpreter, and David Kennedy's SET talks were a few of my favorites, with great content and demos, but one that I found especially refreshing and fun was Jayson Street's "Deceiving the Heavens to Cross the Sea: Using the 36 Stratagems for Social Engineering."Jayson started the talk with a demo stating he could guess what you ate for dinner by simply asking five questions. Instead of guessing what the volunteer ate, he social engineered her into answering three of the questions that led to the compromise of Sarah Palin's Yahoo e-mail account last year. It was a great demo and not unlike so many examples we see in daily life, such as drawings for free gym memberships and e-mail asking you to sign up for a webinar with the chance to win an iPad.The talk went through some of the history surrounding the 36 stratagems, social engineering, and how social engineering techniques vary by the target's country. Jayson then dug into examples of how the stratagems can be applied to social engineering.
**Hidden Content: To see this hidden content your post count must be 1 or greater.**