Social Engineering Blogs

An Aggregator for Blogs About Social Engineering and Related Fields

The Episteme Blog November 4, 2009

Return-to-Barry-White Human Exploitation

Spent a weekend in early October hanging out with Tom and Kim at their rapport and anchoring bootcamp.  And I was talking in email with my friend Cris Neckar afterward where we were talking about the large number of pre-existing anchors that exist within someone’s already vast consciousness.

Cris’s comment was that using pre-existing material for anchors is “sort of like exploiting around DEP” – basically, the idea of a “Return-to-libc” exploit.  You have pre-existing functions that perform the task that you’re hoping to do.

This reminded me of something that Tom did to me during the weekend.  Tom walked up to me this weekend and said:

“So, you’re a hypnotist right?  You’ve been in trance before, you know what that feels like, don’t you?” And, as soon as I think about it (which I have to do to understand his question), he achors it.

Tom then proceeded to spend the rest of the weekend enjoying firing off the trance anchor at opportune times.

So, in our email conversation, Cris and I were talking about some good elicitations to anchor that many people would already have:

“Hey… remember that scene from Say Anything where John Cusack was standing outside with the boom-box on his head?  How romantic was that?  What was the most romantic movie scene you remember… one that just made your heart melt?”

Or: “As you wish” (for anyone who has seen the Princess Bride).

Or: “What’s the song that gets you most in the mood?”

In other words, the “Return-to-Barry-White” exploit. 

Note: I’m well aware that this isn’t at all new.  Neither’s ret2libc, really.  But it’s a great example that hopefully drives some new ideas and new thinking.


Filed Under: Security

The Episteme Blog October 5, 2009

NLP for Social Engineers

Anybody in the industry who has talked to me about NLP has understood my utter frustration about the state of NLP learning and its application to social engineering. It got me riled up enough to do a post on NLP and science a few months ago.

And, for the past few months, I’ve been pondering the idea of doing a free education series for the industry on what NLP is and how to use it as a social engineer. But, as anybody who knows me knows, I’ve been a bit busy. Foreground is taking off, having made the INC 5000 due to the phenomenal amount of growth (and corresponding amount of work for each of us). And my own projects (Connected Career, Information Security Leaders, and the projects we do through Michael Murray and Associates) have added an even bigger load.

But I got really riled up when I read the NLP section of the new Social Engineering framework. Because, while true, it doesn’t teach the reader anything useful about how to use NLP in SE. (That shouldn’t be taken as a criticism – I believe strongly in the project and will be helping to edit and correct deficiencies and gaps over the coming months… the guys over there are doing the community a phenomenal service).

So, I sat down and started recording the material I had been putting together over the previous months. It’s going to come out to about 10 hours of audio, video and a whole pile of exercises. I even did a video to explain what you’re going to get.

Check out the video and sign up here.

Technorati Tags: Hypnosis, NLP, social engineering, social-engineer.org


Filed Under: Hypnosis, Social Engineering

The Episteme Blog September 28, 2009

Hacker Halted Redux

I had a blast at Hacker Halted last week, and I did a talk that I was incredibly excited about. It was the first time I was going to talk about some of the new research I’ve done and, while I didn’t plan to give out a huge number of details on the methods, I hoped that the talk was going to be well received.

Well, I’m sure that it would have been, had it actually finished. Because I didn’t read the program nearly closely enough, and I prepared a normal 80 minute talk, only to realize that my speaking slot was 45 minutes.

So, I only got about 1/2 way through my slides, and much of the meat was lost. A couple of audience members talked to me afterwards and seemed a bit disappointed, so I promised I’d provide the talk another way.

I do like to keep promises. So I sat down at my computer this morning and recorded the slides and the audio. The entirety of the talk that the audience would have seen is below.

@ Yahoo! Video

Let me know your thoughts and opinions and ask questions if you have them (since I didn’t get to take audience questions at the conference, either).

Technorati Tags: hacker halted, social engineering


Filed Under: Hacking

  • « Previous Page
  • 1
  • …
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • Next Page »

About

Welcome to an aggregator for blogs about social engineering and related fields. Feel free to take a look around, and make sure to visit the original sites.

If you would like to suggest a site or contact us, use the links below.

Contact

  • Contact
  • Suggest a Site
  • Remove a Site

© Copyright 2025 Social Engineering Blogs · All Rights Reserved ·