The Art of Deception_ Controlling the Human Element of Security - Kevin D. Mitnick [104]
“Right.... Okay, Mr. Underwood is 6973. Anna Myrtle is 2127.”
“Hey, you’ve been a big help. Thanks.”
Anna’s Call
“Finance, Anna speaking.”
“I’m glad I found somebody working late. Listen, this is Ron Vittaro, I’m publisher of the business division. I don’t think we’ve been introduced. Welcome to the company.”
“Oh, thank you.”
“Anna, I’m in Los Angeles and I’ve got a crisis. I need to take about ten minutes of your time.”
“Of course. What do you need?”
“Go up to my office. Do you know where my office is?
“No.”
“Okay, it’s the corner office on the fifteenth floor—room 1502. I’ll call you there in a few minutes. When you get to the office, you’ll need to press the forward button on the phone so my call won’t go directly to my voice mail.”
“Okay, I’m on my way now.”
Ten minutes later she was in his office, had cancelled his call forwarding and was waiting when the phone rang. He told her to sit down at the computer and launch Internet Explorer. When it was running he told her to type in an address: www.geocities.com/ron_insen/manuscript.doc.exe.
A dialog box appeared, and he told her to click Open. The computer appeared to start downloading the manuscript, and then the screen went blank. When she reported that something seemed to be wrong, he replied, “Oh, no. Not again. I’ve been having a problem with downloading from that Web site every so often but I thought it was fixed. Well, okay, don’t worry, I’ll get the file another way later.” Then he asked her to restart his computer so he could be sure it would start up properly after the problem she had just had. He talked her through the steps for rebooting.
When the computer was running again properly, he thanked her warmly and hung up, and Anna went back to the Finance department to finish the job she had been working on.
Kurt Dillon’s Story
Millard-Fenton Publishers was enthusiastic about the new author they were just about to sign up, the retired CEO of a Fortune 500 company who had a fascinating story to tell. Someone had steered the man to a business manager for handling his negotiations. The business manager didn’t want to admit he knew zip about publishing contracts, so he hired an old friend to help him figure out what he needed to know. The old friend, unfortunately, was not a very good choice. Kurt Dillon used what we might call unusual methods in his research, methods not entirely ethical.
Kurt signed up for a free site on Geocities, in the name of Ron Vittaro, and loaded a spyware program onto the new site. He changed the name of the program to manuscript.doc.exe, so the name would appear to be a Word document and not raise suspicion. In fact, this worked even better than Kurt had anticipated; because the real Vittaro had never changed a default setting in his Windows operating system called “Hide file extensions for known file types.” Because of that setting the file was actually displayed with the name manuscript.doc.
Then he had a lady friend call Vittaro’s secretary. Following Dillon’s coaching, she said, “I’m the executive assistant to Paul Spadone, president of Ultimate Bookstores, in Toronto. Mr. Vittaro met my boss at a book fair a while back, and asked him to call to discuss a project they might do together. Mr. Spadone is on the road a lot, so he said I should find out when Mr. Vittaro will be in the office.”
By the time the two had finished comparing schedules, the lady friend had enough information to provide the attacker with a list of dates when Mr. Vittaro would be in the office. Which meant he also knew when Vittaro would be out of the office. It hadn’t required much extra conversation to find out that Vittaro’s secretary would be taking advantage of his absence to get in a little skiing. For a short span of time, both would be out of the office. Perfect.
lingo
SPYWARE Specialized software used to covertly monitor a target’s computer activities. One form is used to track the sites visited by Internet shoppers so that on-line advertisements can be tailored to their