- Sleeping Sheep Hackers… - http://sleepingsheephackers.org -

The SEVER Methodology

Dieser Eintrag stammt von tugrik Am 31.1.2012 @ 19:35 In opinion | Keine Kommentare

The “Social Engineering Vulnerability Evaluation and Recommendation (SEVER)” methodology, located at [1] http://www.kgb.to/SEVER_Instructions_Final.pdf , was recently highlighted to me, and also appeared in the darknet.org.uk blog in December 2011, although the document appears to date from April 2011.
The SEVER project hopes to

  1. Provide the fastest means of training novices about complex social engineering concepts.
  2. Provide penetration testers with a methodology that minimizes their effort while increasing their chance of success.

The truth is far from this, and the detail is unnecessary - I started writing references and in the end realised I was referencing at least every page, if not every paragraph.

In summary, the document is an “eighties text file” style rant about the author’s personal irritants; it doesn’t really detail a methodology at all, and concentrates on how to attack a single person rather than an organisation or other goal.  For example as part of a Social Engineering engagement the author appears to advocate the exploitation of phobias, use of lighting to induce migraines in the target, gaining rapport with the target through mutual use of illegal drugs, and torture.  I strongly suggest reading for entertainment purposes only.

In stating the above I’m presuming that Penetration Testers all obey the law, their job being to simulate the effect of criminal acts rather than commit them; also their intention is to show the customer that they are can be trusted with the information and access they’ve been granted. Also that as part of the engagement a Penetration Tester is not permitted nor willing to cause permanent physical and/or psychological damage to their client’s employees. The legal liability incurred by trying out many of the techniques listed would be “interesting.”


Dieser Artikel wurde ausgedruckt ab Sleeping Sheep Hackers…: http://sleepingsheephackers.org

URL zum Artikel: http://sleepingsheephackers.org/2012/01/31/the-sever-methodology/

URLs in this post:
[1] http://www.kgb.to/SEVER_Instructions_Final.pdf: http://www.kgb.to/SEVER_Instructions_Final.pdf

Klicken hier zum Drucken.