<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Should Social Engineering be a part of Penetration Testing?</title>
	<atom:link href="http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sun, 08 Nov 2009 07:15:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: RichB</title>
		<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-1243</link>
		<dc:creator>RichB</dc:creator>
		<pubDate>Wed, 17 May 2006 19:56:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-1243</guid>
		<description>SE &lt;strong&gt; absolutely&lt;/strong&gt; should be part of a pen test.  It can serve to pinpoint organizational failures in applying and/or enforcing security policies--and lack of adequate employee security awareness training.  

All too often, organizations download stacks of security policies from the web and shove them in a binder... &lt;i&gt;having&lt;/i&gt; a policy is not the same as &lt;i&gt;following&lt;/i&gt; a policy.</description>
		<content:encoded><![CDATA[<p>SE <strong> absolutely</strong> should be part of a pen test.  It can serve to pinpoint organizational failures in applying and/or enforcing security policies&#8211;and lack of adequate employee security awareness training.  </p>
<p>All too often, organizations download stacks of security policies from the web and shove them in a binder&#8230; <i>having</i> a policy is not the same as <i>following</i> a policy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HTNet</title>
		<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-74</link>
		<dc:creator>HTNet</dc:creator>
		<pubDate>Tue, 07 Mar 2006 07:33:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-74</guid>
		<description>&lt;strong&gt;Data Security for the Enterprise: The Human Factor...&lt;/strong&gt;

	When the subject of corporate data security comes up in any board meeting, chances are, the topics will straight away dive into complicated things such as firewalls and IDP systems. And when this happens, it&#8217;s obvious that the meeting participan...</description>
		<content:encoded><![CDATA[<p><strong>Data Security for the Enterprise: The Human Factor&#8230;</strong></p>
<p>	When the subject of corporate data security comes up in any board meeting, chances are, the topics will straight away dive into complicated things such as firewalls and IDP systems. And when this happens, it&#8217;s obvious that the meeting participan&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ubourgeek</title>
		<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-67</link>
		<dc:creator>Ubourgeek</dc:creator>
		<pubDate>Sun, 05 Mar 2006 10:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-67</guid>
		<description>I&#039;ll be brief for once - the short answer is &quot;YES - ABSOLUTELY&quot;. 

As I&#039;ve told people I&#039;ve presented to regarding SEng, &quot;Once you realize that 70% of helpdesks will do anything to help, 80% of SysAdmins are lazy and 90% of users are stupid, you&#039;ll begin to understand the impact wetware hacking can have.&quot;.

Cheers,

U.</description>
		<content:encoded><![CDATA[<p>I&#8217;ll be brief for once &#8211; the short answer is &#8220;YES &#8211; ABSOLUTELY&#8221;. </p>
<p>As I&#8217;ve told people I&#8217;ve presented to regarding SEng, &#8220;Once you realize that 70% of helpdesks will do anything to help, 80% of SysAdmins are lazy and 90% of users are stupid, you&#8217;ll begin to understand the impact wetware hacking can have.&#8221;.</p>
<p>Cheers,</p>
<p>U.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Your Employees Don&#8217;t Care About Your Data &#187;</title>
		<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-66</link>
		<dc:creator>Your Employees Don&#8217;t Care About Your Data &#187;</dc:creator>
		<pubDate>Sat, 04 Mar 2006 04:51:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-66</guid>
		<description>[...] As we discussed in the article on Social Engineering in Penetration Testing, it&#8217;s not that the employees don&#8217;t care as such, it&#8217;s that they don&#8217;t know. They haven&#8217;t been educated, they are ignorant, their awareness of best practise is low. An experiment carried out within London&#8217;s square mile has revealed that employees in some of the City&#8217;s best known financial services companies don&#8217;t care about basic security policy. [...]</description>
		<content:encoded><![CDATA[<p>[...] As we discussed in the article on Social Engineering in Penetration Testing, it&#8217;s not that the employees don&#8217;t care as such, it&#8217;s that they don&#8217;t know. They haven&#8217;t been educated, they are ignorant, their awareness of best practise is low. An experiment carried out within London&#8217;s square mile has revealed that employees in some of the City&#8217;s best known financial services companies don&#8217;t care about basic security policy. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: backbone</title>
		<link>http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-60</link>
		<dc:creator>backbone</dc:creator>
		<pubDate>Thu, 02 Mar 2006 11:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/should-social-engineering-a-part-of-penetration-testing/#comment-60</guid>
		<description>Social enginnering should be part in the penetration test... why should you try it in the hard way, if it&#039;s posibile in the &quot;tricky&quot; way... this is why Kevin Mitnick is one of the best hackers that are still alive...</description>
		<content:encoded><![CDATA[<p>Social enginnering should be part in the penetration test&#8230; why should you try it in the hard way, if it&#8217;s posibile in the &#8220;tricky&#8221; way&#8230; this is why Kevin Mitnick is one of the best hackers that are still alive&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
