Social Engineering vs. Bank
After signing some legal boilerplate and “get out of jail free” paperwork, here’s what we agreed to: Pose as a vendor, enter the facility, plug into the network, sniff traffic, look for login and passwords, then try to become domain administrator of the network….
Within seconds I had a variety of logins and passwords, access to numerous shared folders, data, and administrative accounts.
Read this awesome story about how one network security provider gave their client an extra level of analysis from Dark Reading.