The Experts below are selected from a list of 12 Experts worldwide ranked by ideXlab platform
Johnny Long - One of the best experts on this subject based on the ideXlab platform.
-
No Tech Hacking a guide to social engineering dumpster diving and shoulder surfing
2008Co-Authors: Johnny Long, Jack WilesAbstract:Johnny Long's last book sold 12,000 units worldwide. Kevin Mitnick's last book sold 40,000 units in North America. As the clich goes, information is power. In this age of TechNology, an increasing majority of the world's information is stored electronically. It makes sense then that we rely on high-Tech electronic protection systems to guard that information. As professional hackers, Johnny Long and Kevin Mitnick get paid to uncover weaknesses in those systems and exploit them. Whether breaking into buildings or slipping past industrial-grade firewalls, their goal has always been the same: extract the information using any means necessary. After hundreds of jobs, they have discovered the secrets to bypassing every conceivable high-Tech security system. This book reveals those secrets; as the title suggests, it has Nothing to do with high TechNology. Dumpster Diving Be a good sport and dont read the two D words written in big bold letters above, and act surprised when I tell you hackers can accomplish this without relying on a single bit of TechNology (punny). Tailgating Hackers and ninja both like wearing black, and they do share the ability to slip inside a building and blend with the shadows. Shoulder SurfingIf you like having a screen on your laptop so you can see what youre working on, dont read this chapter. Physical Security Locks are serious business and lock Technicians are true engineers, most backed with years of hands-on experience. But what happens when you take the age-old respected profession of the locksmith and sprinkle it with hacker ingenuity? Social Engineering with Jack WilesJack has trained hundreds of federal agents, corporate attorneys, CEOs and internal auditors on computer crime and security-related topics. His unforgettable presentations are filled with three decades of personal "war stories" from the trenches of Information Security and Physical Security. Google Hacking A hacker doesnt even need his own computer to do the necessary research. If he can make it to a public library, Kinko's or Internet cafe, he can use Google to process all that data into something useful. P2P HackingLets assume a guy has No budget, No commercial Hacking software, No support from organized crime and No fancy gear. With all those restrictions, is this guy still a threat to you? Have a look at this chapter and judge for yourself. People Watching Skilled people watchers can learn a whole lot in just a few quick glances. In this chapter well take a look at a few examples of the types of things that draws a No-Tech hackers eye. Kiosks What happens when a kiosk is more than a kiosk? What happens when the kiosk holds airline passenger information? What if the kiosk holds confidential patient information? What if the kiosk holds cash? Vehicle Surveillance Most people dont realize that some of the most thrilling vehicular espionage happens when the cars aren't moving at all!
-
No Tech Hacking
2008Co-Authors: Johnny LongAbstract:The chapter discusses that hackers are certainly a Technical bunch, but in this day and age, it pays to think simply. No-Tech attacks are simple to pull off, but the effects can be devastating to your facility's security posture. Learning to think like a hacker is Not necessarily as difficult as it may seem. You should pay attention to the little things and keep a vigilant watch for the opportunities you are offering a No-Tech hacker. The key to No-Tech Hacking is to think simply, be aware, and travel eyes open, head up. It focuses on tailgating. It describes the act of gaining unauthorized access to a restricted area by following closely an authorized individual. The chapter also explores lock picking. It is a fairly Technical exercise. It requires kNowledge of lock mechanics and internals, and perfecting the Technique takes quite a bit of practice. Lock bumping, on the other hand, falls firmly into the No-Tech Hacking category. The Technique involves the use of bump keys, or 999 keys, which are the keys that are made by cutting a key blank, so each cut is made to a maximum depth, and the tip and the shoulder are filed down by approximately half a millimeter.
-
Google Hacking Showcase
No Tech Hacking, 2008Co-Authors: Johnny Long, Jack Wiles, Scott Pinzon, Kevin D. MitnickAbstract:This chapter focuses on what can go drastically wrong when the Google Hacking threat is igNored. A decent No-Tech hacker can accumulate a library of significant data just by observing the world around him. But often that data is completely useless on its own. Arguably the most well kNown of No-Tech Hacking Techniques among hackers in the kNow, Google Hacking has become a standard weapon in every attacker's arsenal. A self-respecting Google hacker spends hours trolling the Internet for juicy stuff. Firing off search after search, they thrive on the thrill of finding clean, mean, streamlined queries and get a real rush from sharing those queries and trading screenshots of their findings. Google Hacking Showcase consists of screenshots of wild Google hacks the author had witnessed. Borrowing from the pool of interesting Google queries he had created, along with scores of queries from the community. The author snagged screenshots and presented them one at a time, making smarmy comments along the way. It makes sense to include the showcase in the edition of Google Hacking .
-
TechNo Security's Guide to Managing Risks for IT Managers, Auditors and Investigators
2007Co-Authors: Jack Wiles, Johnny Long, Russ RogersAbstract:"This book contains some of the most up-to-date information available anywhere on a wide variety of topics related to TechNo Security. As you read the book, you will Notice that the authors took the approach of identifying some of the risks, threats, and vulnerabilities and then discussing the countermeasures to address them. Some of the topics and thoughts discussed here are as new as tomorrow's headlines, whereas others have been around for decades without being properly addressed. I hope you enjoy this book as much as we have enjoyed working with the various authors and friends during its development." --Donald Withers, CEO and Cofounder of TheTrainingCo. · Jack Wiles, on Social Engineering offers up a potpourri of tips, tricks, vulnerabilities, and lessons learned from 30-plus years of experience in the worlds of both physical and Technical security. · Russ Rogers on the Basics of Penetration Testing illustrates the standard methodology for penetration testing: information gathering, network enumeration, vulnerability identification, vulnerability exploitation, privilege escalation, expansion of reach, future access, and information compromise. · Johnny Long on No Tech Hacking shows how to hack without touching a computer using tailgating, lock bumping, shoulder surfing, and dumpster diving. · Phil Drake on Personal, Workforce, and Family Preparedness covers the basics of creating a plan for you and your family, identifying and obtaining the supplies you will need in an emergency. · Kevin O'Shea on Seizure of Digital Information discusses collecting hardware and information from the scene. · Amber Schroader on Cell Phone Forensics writes on new methods and guidelines for digital forensics. · Dennis O'Brien on RFID: An Introduction, Security Issues, and Concerns discusses how this well-intended TechNology has been eroded and used for fringe implementations. · Ron Green on Open Source Intelligence details how a good Open Source Intelligence program can help you create leverage in negotiations, enable smart decisions regarding the selection of goods and services, and help avoid pitfalls and hazards. · Raymond Blackwood on Wireless Awareness: Increasing the Sophistication of Wireless Users maintains it is the TechNologist's responsibility to educate, communicate, and support users despite their lack of interest in understanding how it works. · Greg Kipper on What is StegaNography? provides a solid understanding of the basics of stegaNography, what it can and can't do, and arms you with the information you need to set your career path. · Eric Cole on Insider Threat discusses why the insider threat is worse than the external threat and the effects of insider threats on a company. *Internationally kNown experts in information security share their wisdom *Free pass to TechNo Security Conference for everyone who purchases a book--$1,200 value *2-HOUR DVD with cutting edge information on the future of information security
Jack Wiles - One of the best experts on this subject based on the ideXlab platform.
-
No Tech Hacking a guide to social engineering dumpster diving and shoulder surfing
2008Co-Authors: Johnny Long, Jack WilesAbstract:Johnny Long's last book sold 12,000 units worldwide. Kevin Mitnick's last book sold 40,000 units in North America. As the clich goes, information is power. In this age of TechNology, an increasing majority of the world's information is stored electronically. It makes sense then that we rely on high-Tech electronic protection systems to guard that information. As professional hackers, Johnny Long and Kevin Mitnick get paid to uncover weaknesses in those systems and exploit them. Whether breaking into buildings or slipping past industrial-grade firewalls, their goal has always been the same: extract the information using any means necessary. After hundreds of jobs, they have discovered the secrets to bypassing every conceivable high-Tech security system. This book reveals those secrets; as the title suggests, it has Nothing to do with high TechNology. Dumpster Diving Be a good sport and dont read the two D words written in big bold letters above, and act surprised when I tell you hackers can accomplish this without relying on a single bit of TechNology (punny). Tailgating Hackers and ninja both like wearing black, and they do share the ability to slip inside a building and blend with the shadows. Shoulder SurfingIf you like having a screen on your laptop so you can see what youre working on, dont read this chapter. Physical Security Locks are serious business and lock Technicians are true engineers, most backed with years of hands-on experience. But what happens when you take the age-old respected profession of the locksmith and sprinkle it with hacker ingenuity? Social Engineering with Jack WilesJack has trained hundreds of federal agents, corporate attorneys, CEOs and internal auditors on computer crime and security-related topics. His unforgettable presentations are filled with three decades of personal "war stories" from the trenches of Information Security and Physical Security. Google Hacking A hacker doesnt even need his own computer to do the necessary research. If he can make it to a public library, Kinko's or Internet cafe, he can use Google to process all that data into something useful. P2P HackingLets assume a guy has No budget, No commercial Hacking software, No support from organized crime and No fancy gear. With all those restrictions, is this guy still a threat to you? Have a look at this chapter and judge for yourself. People Watching Skilled people watchers can learn a whole lot in just a few quick glances. In this chapter well take a look at a few examples of the types of things that draws a No-Tech hackers eye. Kiosks What happens when a kiosk is more than a kiosk? What happens when the kiosk holds airline passenger information? What if the kiosk holds confidential patient information? What if the kiosk holds cash? Vehicle Surveillance Most people dont realize that some of the most thrilling vehicular espionage happens when the cars aren't moving at all!
-
Google Hacking Showcase
No Tech Hacking, 2008Co-Authors: Johnny Long, Jack Wiles, Scott Pinzon, Kevin D. MitnickAbstract:This chapter focuses on what can go drastically wrong when the Google Hacking threat is igNored. A decent No-Tech hacker can accumulate a library of significant data just by observing the world around him. But often that data is completely useless on its own. Arguably the most well kNown of No-Tech Hacking Techniques among hackers in the kNow, Google Hacking has become a standard weapon in every attacker's arsenal. A self-respecting Google hacker spends hours trolling the Internet for juicy stuff. Firing off search after search, they thrive on the thrill of finding clean, mean, streamlined queries and get a real rush from sharing those queries and trading screenshots of their findings. Google Hacking Showcase consists of screenshots of wild Google hacks the author had witnessed. Borrowing from the pool of interesting Google queries he had created, along with scores of queries from the community. The author snagged screenshots and presented them one at a time, making smarmy comments along the way. It makes sense to include the showcase in the edition of Google Hacking .
-
TechNo Security's Guide to Managing Risks for IT Managers, Auditors and Investigators
2007Co-Authors: Jack Wiles, Johnny Long, Russ RogersAbstract:"This book contains some of the most up-to-date information available anywhere on a wide variety of topics related to TechNo Security. As you read the book, you will Notice that the authors took the approach of identifying some of the risks, threats, and vulnerabilities and then discussing the countermeasures to address them. Some of the topics and thoughts discussed here are as new as tomorrow's headlines, whereas others have been around for decades without being properly addressed. I hope you enjoy this book as much as we have enjoyed working with the various authors and friends during its development." --Donald Withers, CEO and Cofounder of TheTrainingCo. · Jack Wiles, on Social Engineering offers up a potpourri of tips, tricks, vulnerabilities, and lessons learned from 30-plus years of experience in the worlds of both physical and Technical security. · Russ Rogers on the Basics of Penetration Testing illustrates the standard methodology for penetration testing: information gathering, network enumeration, vulnerability identification, vulnerability exploitation, privilege escalation, expansion of reach, future access, and information compromise. · Johnny Long on No Tech Hacking shows how to hack without touching a computer using tailgating, lock bumping, shoulder surfing, and dumpster diving. · Phil Drake on Personal, Workforce, and Family Preparedness covers the basics of creating a plan for you and your family, identifying and obtaining the supplies you will need in an emergency. · Kevin O'Shea on Seizure of Digital Information discusses collecting hardware and information from the scene. · Amber Schroader on Cell Phone Forensics writes on new methods and guidelines for digital forensics. · Dennis O'Brien on RFID: An Introduction, Security Issues, and Concerns discusses how this well-intended TechNology has been eroded and used for fringe implementations. · Ron Green on Open Source Intelligence details how a good Open Source Intelligence program can help you create leverage in negotiations, enable smart decisions regarding the selection of goods and services, and help avoid pitfalls and hazards. · Raymond Blackwood on Wireless Awareness: Increasing the Sophistication of Wireless Users maintains it is the TechNologist's responsibility to educate, communicate, and support users despite their lack of interest in understanding how it works. · Greg Kipper on What is StegaNography? provides a solid understanding of the basics of stegaNography, what it can and can't do, and arms you with the information you need to set your career path. · Eric Cole on Insider Threat discusses why the insider threat is worse than the external threat and the effects of insider threats on a company. *Internationally kNown experts in information security share their wisdom *Free pass to TechNo Security Conference for everyone who purchases a book--$1,200 value *2-HOUR DVD with cutting edge information on the future of information security
Russ Rogers - One of the best experts on this subject based on the ideXlab platform.
-
TechNo Security's Guide to Managing Risks for IT Managers, Auditors and Investigators
2007Co-Authors: Jack Wiles, Johnny Long, Russ RogersAbstract:"This book contains some of the most up-to-date information available anywhere on a wide variety of topics related to TechNo Security. As you read the book, you will Notice that the authors took the approach of identifying some of the risks, threats, and vulnerabilities and then discussing the countermeasures to address them. Some of the topics and thoughts discussed here are as new as tomorrow's headlines, whereas others have been around for decades without being properly addressed. I hope you enjoy this book as much as we have enjoyed working with the various authors and friends during its development." --Donald Withers, CEO and Cofounder of TheTrainingCo. · Jack Wiles, on Social Engineering offers up a potpourri of tips, tricks, vulnerabilities, and lessons learned from 30-plus years of experience in the worlds of both physical and Technical security. · Russ Rogers on the Basics of Penetration Testing illustrates the standard methodology for penetration testing: information gathering, network enumeration, vulnerability identification, vulnerability exploitation, privilege escalation, expansion of reach, future access, and information compromise. · Johnny Long on No Tech Hacking shows how to hack without touching a computer using tailgating, lock bumping, shoulder surfing, and dumpster diving. · Phil Drake on Personal, Workforce, and Family Preparedness covers the basics of creating a plan for you and your family, identifying and obtaining the supplies you will need in an emergency. · Kevin O'Shea on Seizure of Digital Information discusses collecting hardware and information from the scene. · Amber Schroader on Cell Phone Forensics writes on new methods and guidelines for digital forensics. · Dennis O'Brien on RFID: An Introduction, Security Issues, and Concerns discusses how this well-intended TechNology has been eroded and used for fringe implementations. · Ron Green on Open Source Intelligence details how a good Open Source Intelligence program can help you create leverage in negotiations, enable smart decisions regarding the selection of goods and services, and help avoid pitfalls and hazards. · Raymond Blackwood on Wireless Awareness: Increasing the Sophistication of Wireless Users maintains it is the TechNologist's responsibility to educate, communicate, and support users despite their lack of interest in understanding how it works. · Greg Kipper on What is StegaNography? provides a solid understanding of the basics of stegaNography, what it can and can't do, and arms you with the information you need to set your career path. · Eric Cole on Insider Threat discusses why the insider threat is worse than the external threat and the effects of insider threats on a company. *Internationally kNown experts in information security share their wisdom *Free pass to TechNo Security Conference for everyone who purchases a book--$1,200 value *2-HOUR DVD with cutting edge information on the future of information security
Kevin D. Mitnick - One of the best experts on this subject based on the ideXlab platform.
-
Google Hacking Showcase
No Tech Hacking, 2008Co-Authors: Johnny Long, Jack Wiles, Scott Pinzon, Kevin D. MitnickAbstract:This chapter focuses on what can go drastically wrong when the Google Hacking threat is igNored. A decent No-Tech hacker can accumulate a library of significant data just by observing the world around him. But often that data is completely useless on its own. Arguably the most well kNown of No-Tech Hacking Techniques among hackers in the kNow, Google Hacking has become a standard weapon in every attacker's arsenal. A self-respecting Google hacker spends hours trolling the Internet for juicy stuff. Firing off search after search, they thrive on the thrill of finding clean, mean, streamlined queries and get a real rush from sharing those queries and trading screenshots of their findings. Google Hacking Showcase consists of screenshots of wild Google hacks the author had witnessed. Borrowing from the pool of interesting Google queries he had created, along with scores of queries from the community. The author snagged screenshots and presented them one at a time, making smarmy comments along the way. It makes sense to include the showcase in the edition of Google Hacking .
Scott Pinzon - One of the best experts on this subject based on the ideXlab platform.
-
Google Hacking Showcase
No Tech Hacking, 2008Co-Authors: Johnny Long, Jack Wiles, Scott Pinzon, Kevin D. MitnickAbstract:This chapter focuses on what can go drastically wrong when the Google Hacking threat is igNored. A decent No-Tech hacker can accumulate a library of significant data just by observing the world around him. But often that data is completely useless on its own. Arguably the most well kNown of No-Tech Hacking Techniques among hackers in the kNow, Google Hacking has become a standard weapon in every attacker's arsenal. A self-respecting Google hacker spends hours trolling the Internet for juicy stuff. Firing off search after search, they thrive on the thrill of finding clean, mean, streamlined queries and get a real rush from sharing those queries and trading screenshots of their findings. Google Hacking Showcase consists of screenshots of wild Google hacks the author had witnessed. Borrowing from the pool of interesting Google queries he had created, along with scores of queries from the community. The author snagged screenshots and presented them one at a time, making smarmy comments along the way. It makes sense to include the showcase in the edition of Google Hacking .