Black Hat 2007 No-Tech Hacking with Johnny Long
posted Aug 2nd 2007 6:48am by Will O'Brienfiled under: cons, misc hacks

[J0hnny]’s at Blackhat and Defcon this year with his talk on “No-Tech Hacking”. It’s a fun talk that boils down to this: loads of information can be gathered using low tech methods. A small digital (or film) camera is ideal for shoulder surfing, identifying weaknesses, and assessing strengths.
The talk is pretty amusing – the commentary on the example shots is priceless. The concept has gone over so well at the cons that [J0hnny] has contributed a chapter to a book on risk management. You can grab a sample chapter here. It looks like he’ll be running his talk at 8pm on Friday at Defcon. From the sample chapter, I’d say that the book should be pretty good. It looks like a good introduction to social engineering and using your wits to defeat obstacles (like corporate security).

The DoD also does penetration testing of its own facilities with similar results. Restricted area badges being worn in plain sight are susceptible to photography (telephoto photography of smoking areas is a favorite target) and counterfeiting. Social engineering goes a long way, and idiot users are always a weak link (passwords and usernames written on sticky notes…)
Posted at 1:46 pm on Aug 2nd, 2007 by Mike