Information Age: News, analysis & insight for IT & business leaders

Exploiting the human weak point

14 November 2011  

Author and consultant Ian Mann explains how he got the better of a SaaS provider's security precautions by outsmarting its customer support agents

When IT professionals talk about the security of could computing, they usually refer to the vulnerability of a given system to hacking or malware infection. But cloud services are run by human beings, and as such they are as susceptible to the powers of persuasion as any business.

Ian Mann, a security consultant for ECSC and author of Hacking the Human, was recently hired by a software-as-a-service provider to see if he could penetrate its system. He chose to do this by exploiting the customer support helpline to gain administrator access to the SaaS system.

Pretending to be a senior employee at one of the SaaS provider’s customers, Mann timed numerous calls to the helpline to ensure that he would get a different customer support agent every time. His strategy was to persuade each successive agent to give him more and more information about how to access the system, on the basis that each one would assume he must be legitimate given that he had got that far.

The technique worked, Mann says. “At no point did I authenticate at all. Once I got to a certain point, the customer service people just assumed that I must have authenticated to get that far.”

What this proves, he says, is that strict security procedures are in fact less secure than flexible controls. “From a social engineering perspective, strict security protocols are not as good as flexible ones – once you’ve broken them they are defenceless.”

So if human agents are a weak point, does that mean that cloud services that offer less human IT support are more secure? Not necessarily, says Mann, because if the volume of customer support calls is low, then the security procedures that call centre operatives must follow are likely to be simplistic and therefore easily exploited. 


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">