<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Black Hat 2007 No-Tech Hacking with Johnny Long</title>
	<atom:link href="http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Wed, 25 Nov 2009 22:35:23 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dumspterdiver</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27524</link>
		<dc:creator>dumspterdiver</dc:creator>
		<pubDate>Sat, 18 Aug 2007 00:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27524</guid>
		<description>If you are interested in no tech hacking you should check out Johnny&#039;s new book from Syngess (Kevin Mitnick is the technical editor)</description>
		<content:encoded><![CDATA[<p>If you are interested in no tech hacking you should check out Johnny&#8217;s new book from Syngess (Kevin Mitnick is the technical editor)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M3talhead</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27523</link>
		<dc:creator>M3talhead</dc:creator>
		<pubDate>Mon, 06 Aug 2007 10:02:04 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27523</guid>
		<description>Ditto on the idiot comment by Mike. He really needs to do a little more homework before he opens his mouth.</description>
		<content:encoded><![CDATA[<p>Ditto on the idiot comment by Mike. He really needs to do a little more homework before he opens his mouth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: strider_mt2k</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27522</link>
		<dc:creator>strider_mt2k</dc:creator>
		<pubDate>Sun, 05 Aug 2007 17:06:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27522</guid>
		<description>social engineering ftw!</description>
		<content:encoded><![CDATA[<p>social engineering ftw!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred Thompson</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27521</link>
		<dc:creator>Fred Thompson</dc:creator>
		<pubDate>Sat, 04 Aug 2007 08:39:15 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27521</guid>
		<description>mike, you really don&#039;t know what you&#039;re talking about. Poser.</description>
		<content:encoded><![CDATA[<p>mike, you really don&#8217;t know what you&#8217;re talking about. Poser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stevew</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27520</link>
		<dc:creator>stevew</dc:creator>
		<pubDate>Sat, 04 Aug 2007 08:16:52 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27520</guid>
		<description>The TV series Mission Impossible (&#039;66-&#039;73) predominant hack was looking like they knew what they were doing, van, orange cones, coveralls, a hard hat, or a coat and tie where expected, just looking professional works wonders.  Show up with a metal clipboard, step ladder, an electrician&#039;s tool belt, a spool of Cat5 and ask security where the presidents office is because you&#039;ve got a work order here to install a new secure line...  In fact many remodeling subs are often required to do their work after normal hours, so you have security holding the doors open for you as you carry in your drop cloths and paint buckets right at closing time.</description>
		<content:encoded><![CDATA[<p>The TV series Mission Impossible (&#8216;66-&#8217;73) predominant hack was looking like they knew what they were doing, van, orange cones, coveralls, a hard hat, or a coat and tie where expected, just looking professional works wonders.  Show up with a metal clipboard, step ladder, an electrician&#8217;s tool belt, a spool of Cat5 and ask security where the presidents office is because you&#8217;ve got a work order here to install a new secure line&#8230;  In fact many remodeling subs are often required to do their work after normal hours, so you have security holding the doors open for you as you carry in your drop cloths and paint buckets right at closing time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: srilyk</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27519</link>
		<dc:creator>srilyk</dc:creator>
		<pubDate>Fri, 03 Aug 2007 18:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27519</guid>
		<description>Social engineering is actually the staple of the most dangerous hackers. They&#039;re the ones who can penetrate organizations and make off with all sorts of stuff.&lt;br&gt;&lt;br&gt;Heck, I think it was on slashdot a while ago (and in the news) about some girl who &quot;attended&quot; harvard or stanford or one of those big name schools. She lived in the dorms, had the books... oh, one thing - she wasn&#039;t ever enrolled in the school.&lt;br&gt;&lt;br&gt;Social engineering is where it&#039;s at! (To be fair, they did use some of that on Oceans 11...)</description>
		<content:encoded><![CDATA[<p>Social engineering is actually the staple of the most dangerous hackers. They&#8217;re the ones who can penetrate organizations and make off with all sorts of stuff.</p>
<p>Heck, I think it was on slashdot a while ago (and in the news) about some girl who &#8220;attended&#8221; harvard or stanford or one of those big name schools. She lived in the dorms, had the books&#8230; oh, one thing &#8211; she wasn&#8217;t ever enrolled in the school.</p>
<p>Social engineering is where it&#8217;s at! (To be fair, they did use some of that on Oceans 11&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27518</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Fri, 03 Aug 2007 01:50:36 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27518</guid>
		<description>of course you aren&#039;t going to get through a card reader with a photo of a card.  card readers are going to require a better hack.  i am referring to &quot;red team&quot; penetration testing of actual dod facilities, some of which do not have additional authentication of credentials.  successful penetration tests have been done on restricted areas such as aircraft maintenance facilities, flightline access, munitions areas, and working areas with siprnet access, any of which can provide access to secret, and secret-noforn material.  i haven&#039;t run across results from higher classification levels, but they aren&#039;t going to share those reports with me.  read johnny long&#039;s sample chapter, this is real stuff, not not some oceans 11 fantasy or just wishful thinking.</description>
		<content:encoded><![CDATA[<p>of course you aren&#8217;t going to get through a card reader with a photo of a card.  card readers are going to require a better hack.  i am referring to &#8220;red team&#8221; penetration testing of actual dod facilities, some of which do not have additional authentication of credentials.  successful penetration tests have been done on restricted areas such as aircraft maintenance facilities, flightline access, munitions areas, and working areas with siprnet access, any of which can provide access to secret, and secret-noforn material.  i haven&#8217;t run across results from higher classification levels, but they aren&#8217;t going to share those reports with me.  read johnny long&#8217;s sample chapter, this is real stuff, not not some oceans 11 fantasy or just wishful thinking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred Thompson</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27517</link>
		<dc:creator>Fred Thompson</dc:creator>
		<pubDate>Thu, 02 Aug 2007 21:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27517</guid>
		<description>Yeah, that&#039;s a great idea. Try passing through a card reader with a photo of a security badge in a truely secure DOD area and see what happens. &quot;Jacked up&quot; doesn&#039;t just mean being on steroids.</description>
		<content:encoded><![CDATA[<p>Yeah, that&#8217;s a great idea. Try passing through a card reader with a photo of a security badge in a truely secure DOD area and see what happens. &#8220;Jacked up&#8221; doesn&#8217;t just mean being on steroids.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://hackaday.com/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/comment-page-1/#comment-27516</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 02 Aug 2007 20:46:14 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2007/08/02/black-hat-2007-no-tech-hacking-with-johnny-long/#comment-27516</guid>
		<description>The DoD also does penetration testing of its own facilities with similar results.  Restricted area badges being worn in plain sight are susceptible to photography (telephoto photography of smoking areas is a favorite target) and counterfeiting.  Social engineering goes a long way, and idiot users are always a weak link (passwords and usernames written on sticky notes...)</description>
		<content:encoded><![CDATA[<p>The DoD also does penetration testing of its own facilities with similar results.  Restricted area badges being worn in plain sight are susceptible to photography (telephoto photography of smoking areas is a favorite target) and counterfeiting.  Social engineering goes a long way, and idiot users are always a weak link (passwords and usernames written on sticky notes&#8230;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
