cyberguypr wrote: » Please, no matter what you do DO NOT impersonate any legitimate company, agency, etc. Repercussions can be serious. I've seen this go wrong way too many times.
SteveLavoie wrote: » USB key drive dropping is very effective too. I did it in one of my last pentest. Very effective and fast:) 7h AM, dropped the key, 8h20, root shell
TheFORCE wrote: » I will need to kick off the social engineering exercise in a few weeks. Any ideas on good topics to go after?
TechGromit wrote: » You mean just for practice purposes? If your consulting for a company and this is part of testing there security is one thing, but to "practice" it on a company without permission is quite another. If you get arrested as a consultant doing social engineering when working for a company, a call to the right people can clear matters up and get you released without charges. If your doing it for fun or practice, are you prepared to get arrested and possible charged? What you going to tell the judge, I'm really not a criminal, I do this for a living?