Using trusted insiders as attack vectors
An attack vector is how can attack is delivered.
How can I, the attacker, get my attack delivered to the target, it is a problem. First I need an accessible exploitable vulnerability, so I first need entry (access). Employees all have access, if I can somehow get an employee to deliver the attack, my problem shrinks considerably. Social engineering is about exploiting human vulnerabilities to get a person to do something, like read a malicious email. If I contact an employee and offer softcopy of a white paper if they will do something simple and I deliver the paper in an email or on a USB drive along with a bit of malware my problem shrinks more. My malware infects their home computers when the drive is inserted or the email read and it migrates to the employer when they remotely access their office network, viola! My attack has been delivered. Of course the malware must avoid the employer's defenses but that seems to be easily solved.

0 Comments:
Post a Comment
<< Home