1
1

00:00:00,330  -->  00:00:02,220
<v Instructor>Profiling techniques.</v>
2

2

00:00:02,220  -->  00:00:04,140
When we talk about profiling techniques,
3

3

00:00:04,140  -->  00:00:06,600
our goal here is to identify who works
4

4

00:00:06,600  -->  00:00:08,190
at a particular company.
5

5

00:00:08,190  -->  00:00:10,080
We can do this a lot of different ways
6

6

00:00:10,080  -->  00:00:12,330
including gathering all those different emails
7

7

00:00:12,330  -->  00:00:13,860
that are out there on the internet,
8

8

00:00:13,860  -->  00:00:15,750
as well as looking at social media.
9

9

00:00:15,750  -->  00:00:17,880
Let's first talk about emails.
10

10

00:00:17,880  -->  00:00:20,370
Email harvesting is an open source intelligence
11

11

00:00:20,370  -->  00:00:21,960
or OSINT technique that's used
12

12

00:00:21,960  -->  00:00:24,870
to gather email addresses from a given domain.
13

13

00:00:24,870  -->  00:00:25,980
So for example if I wanted
14

14

00:00:25,980  -->  00:00:27,330
to find all the people who worked
15

15

00:00:27,330  -->  00:00:29,700
at Dion Training, I can start finding email
16

16

00:00:29,700  -->  00:00:33,150
addresses online by searching for @diontraining.com.
17

17

00:00:33,150  -->  00:00:34,500
And based on those addresses,
18

18

00:00:34,500  -->  00:00:36,480
I might be able to start gathering who else works
19

19

00:00:36,480  -->  00:00:38,190
at that company and get information there
20

20

00:00:38,190  -->  00:00:40,080
to build my list as I start trying
21

21

00:00:40,080  -->  00:00:42,420
to profile the people at this organization.
22

22

00:00:42,420  -->  00:00:45,810
For example, if I find jason@diontraining,
23

23

00:00:45,810  -->  00:00:47,310
I can start figuring out a couple of things.
24

24

00:00:47,310  -->  00:00:50,010
One, Jason works there, and two,
25

25

00:00:50,010  -->  00:00:52,020
the format of those email addresses,
26

26

00:00:52,020  -->  00:00:54,870
probably people's first name @diontraining.
27

27

00:00:54,870  -->  00:00:58,170
Or what if I found one that was jdion@diontraining?
28

28

00:00:58,170  -->  00:00:59,490
Well, that tells me they're probably using
29

29

00:00:59,490  -->  00:01:01,290
a first letter of the first name
30

30

00:01:01,290  -->  00:01:03,660
and then their last name as part of their email address.
31

31

00:01:03,660  -->  00:01:05,280
And based on that I can start guessing
32

32

00:01:05,280  -->  00:01:06,900
other people that work there.
33

33

00:01:06,900  -->  00:01:09,930
Maybe I have one that's Jason.dion@diontraining.
34

34

00:01:09,930  -->  00:01:12,090
That tells me it's first name dot last name
35

35

00:01:12,090  -->  00:01:13,920
and again, I can start guessing those addresses
36

36

00:01:13,920  -->  00:01:16,650
because if I know the CEO's name is John Smith,
37

37

00:01:16,650  -->  00:01:20,640
then probably his email is john.smith@diontraining.com
38

38

00:01:20,640  -->  00:01:22,200
and I can start attacking that person
39

39

00:01:22,200  -->  00:01:24,510
with some kind of a social engineering campaign.
40

40

00:01:24,510  -->  00:01:26,190
Now, some companies realize this
41

41

00:01:26,190  -->  00:01:28,560
and they start making very confusing email addresses,
42

42

00:01:28,560  -->  00:01:32,250
like jd1234@diontraining.com.
43

43

00:01:32,250  -->  00:01:33,690
Based on that, it'd be very hard
44

44

00:01:33,690  -->  00:01:35,730
for me to start guessing who works there.
45

45

00:01:35,730  -->  00:01:38,970
I wouldn't know if the guy's name was John or Jason or Joey,
46

46

00:01:38,970  -->  00:01:41,610
but I know it's JD, and that's probably some initials.
47

47

00:01:41,610  -->  00:01:43,590
And then this number is just randomized, and so
48

48

00:01:43,590  -->  00:01:45,900
that makes it very hard to figure out who it is.
49

49

00:01:45,900  -->  00:01:48,030
Now, most companies aren't doing this though.
50

50

00:01:48,030  -->  00:01:48,863
Why?
51

51

00:01:48,863  -->  00:01:50,550
Because this makes it harder for their employees
52

52

00:01:50,550  -->  00:01:52,483
to email each other too,
53

53

00:01:52,483  -->  00:01:53,970
because they don't know each other's names then, right?
54

54

00:01:53,970  -->  00:01:55,980
And so there is usually a standard convention
55

55

00:01:55,980  -->  00:01:57,630
like a first name, a last name,
56

56

00:01:57,630  -->  00:01:59,160
a first letter and a last name,
57

57

00:01:59,160  -->  00:02:01,020
or a first name dot a last name,
58

58

00:02:01,020  -->  00:02:02,610
or something of that nature.
59

59

00:02:02,610  -->  00:02:04,020
Now, some other things you can look at when
60

60

00:02:04,020  -->  00:02:06,558
you start looking at these different emails is
61

61

00:02:06,558  -->  00:02:07,391
some other ways that they're done.
62

62

00:02:07,391  -->  00:02:11,130
For instance, our company uses support@diontraining.com
63

63

00:02:11,130  -->  00:02:12,480
and you know that's a valid address
64

64

00:02:12,480  -->  00:02:14,340
that goes to lots of different people.
65

65

00:02:14,340  -->  00:02:16,050
But if you emailed something like
66

66

00:02:16,050  -->  00:02:18,840
operations@diontraining.com, that might work too
67

67

00:02:18,840  -->  00:02:20,910
and it might get to my operations team.
68

68

00:02:20,910  -->  00:02:22,980
Or you might have instructor@diontraining
69

69

00:02:22,980  -->  00:02:25,320
and you guess things based on the person's position,
70

70

00:02:25,320  -->  00:02:27,180
that might be something that's there.
71

71

00:02:27,180  -->  00:02:29,580
Or if you have things like that, you might guess
72

72

00:02:29,580  -->  00:02:32,460
that the COO or the CEO has their email address
73

73

00:02:32,460  -->  00:02:36,690
of coo@diontraining.com for your chief operating officer.
74

74

00:02:36,690  -->  00:02:38,880
And by guessing these things, you can start then
75

75

00:02:38,880  -->  00:02:41,476
building up your campaigns and figuring things out.
76

76

00:02:41,476  -->  00:02:44,220
Now, there are many different ways to gather email
77

77

00:02:44,220  -->  00:02:46,290
addresses when you're doing this email harvesting,
78

78

00:02:46,290  -->  00:02:48,060
besides just sitting there and guessing them
79

79

00:02:48,060  -->  00:02:49,440
like I was just doing.
80

80

00:02:49,440  -->  00:02:51,270
We can go and buy them from spammers
81

81

00:02:51,270  -->  00:02:53,790
or legitimate sites as sales leads
82

82

00:02:53,790  -->  00:02:56,513
and we would get a list of 10,000 emails for $20,
83

83

00:02:56,513  -->  00:02:58,890
and then we could start going through those.
84

84

00:02:58,890  -->  00:03:00,990
Or we might go to Google and we start searching
85

85

00:03:00,990  -->  00:03:02,520
for things like I said before.
86

86

00:03:02,520  -->  00:03:05,520
For example, you might search for a star@diontraining.com
87

87

00:03:05,520  -->  00:03:07,830
on Google to see what comes back anywhere
88

88

00:03:07,830  -->  00:03:10,710
that we have an @diontraining.com email address
89

89

00:03:10,710  -->  00:03:12,570
listed on some website, some piece
90

90

00:03:12,570  -->  00:03:14,910
of social media or something like that.
91

91

00:03:14,910  -->  00:03:17,100
Or you can actually test these emails
92

92

00:03:17,100  -->  00:03:18,750
by checking if they're going to bounce back
93

93

00:03:18,750  -->  00:03:21,480
by going through and using an email dossier.
94

94

00:03:21,480  -->  00:03:24,570
As I do pen tests, I love to use centralops.net.
95

95

00:03:24,570  -->  00:03:26,370
I can put in an email address here
96

96

00:03:26,370  -->  00:03:28,350
and it will actually test that email and tell me
97

97

00:03:28,350  -->  00:03:31,620
if it's valid before I ever send an email to that server.
98

98

00:03:31,620  -->  00:03:33,630
This way, I can prepare my attacks
99

99

00:03:33,630  -->  00:03:35,130
as part of my reconnaissance phase
100

100

00:03:35,130  -->  00:03:37,770
and weaponization before I move into delivery.
101

101

00:03:37,770  -->  00:03:40,380
Now, once the attacker has this list created,
102

102

00:03:40,380  -->  00:03:41,970
now they can start using that
103

103

00:03:41,970  -->  00:03:43,800
in social engineering attempts,
104

104

00:03:43,800  -->  00:03:46,200
and there's lots of different ways you can do this as well.
105

105

00:03:46,200  -->  00:03:49,050
For example, I might take some of those email addresses
106

106

00:03:49,050  -->  00:03:51,270
and use them to find you on social media.
107

107

00:03:51,270  -->  00:03:52,710
Now that I have you on social media,
108

108

00:03:52,710  -->  00:03:54,360
I can build up a friendship and trust
109

109

00:03:54,360  -->  00:03:55,620
and then conduct additional
110

110

00:03:55,620  -->  00:03:58,140
social engineering attempts against you there.
111

111

00:03:58,140  -->  00:03:59,880
By using this information that I've gathered
112

112

00:03:59,880  -->  00:04:02,190
from this email harvesting, it gives me a foothold
113

113

00:04:02,190  -->  00:04:04,350
and a way into your organization to be able
114

114

00:04:04,350  -->  00:04:06,510
to start finding out more details about you,
115

115

00:04:06,510  -->  00:04:07,770
about the people you employ,
116

116

00:04:07,770  -->  00:04:10,140
and what weaknesses you may have.
117

117

00:04:10,140  -->  00:04:12,180
Now, another way we can do this is we can actually
118

118

00:04:12,180  -->  00:04:15,060
start taking that information from the social media sites
119

119

00:04:15,060  -->  00:04:17,460
and use OSINT software to collect it all for us
120

120

00:04:17,460  -->  00:04:19,740
because this can be really time consuming otherwise,
121

121

00:04:19,740  -->  00:04:21,180
and we want to have a way to aggregate
122

122

00:04:21,180  -->  00:04:22,710
and process all that data
123

123

00:04:22,710  -->  00:04:24,180
from all these different sites
124

124

00:04:24,180  -->  00:04:25,650
to create this detailed picture
125

125

00:04:25,650  -->  00:04:27,600
of the user's interests, their habits,
126

126

00:04:27,600  -->  00:04:30,600
their geographic locations, and other things like that.
127

127

00:04:30,600  -->  00:04:31,680
And just three of those sites
128

128

00:04:31,680  -->  00:04:33,090
that are used by attackers are ones
129

129

00:04:33,090  -->  00:04:37,830
like these, pipl.com, peeku.com, and echosec.net.
130

130

00:04:37,830  -->  00:04:40,170
All of these are open source intelligent tools
131

131

00:04:40,170  -->  00:04:42,480
that do this aggregation for you to find out
132

132

00:04:42,480  -->  00:04:45,930
and build these profiles on those users for a given company.
133

133

00:04:45,930  -->  00:04:48,330
Now, the last one I want to talk about is the harvester
134

134

00:04:48,330  -->  00:04:50,190
and the harvester is one you'll actually talk
135

135

00:04:50,190  -->  00:04:52,980
about and learn about inside pen test plus.
136

136

00:04:52,980  -->  00:04:56,100
This is a command line tool used by penetration testers
137

137

00:04:56,100  -->  00:04:57,840
to gather subdomain information
138

138

00:04:57,840  -->  00:05:00,900
and email addresses across an organization
139

139

00:05:00,900  -->  00:05:02,340
as they're trying to do their pen test
140

140

00:05:02,340  -->  00:05:03,780
to gather information for a
141

141

00:05:03,780  -->  00:05:05,610
follow on social engineering attack.
142

142

00:05:05,610  -->  00:05:07,960
Now for the exam, everything I covered
143

143

00:05:08,917  -->  00:05:11,146
in this lesson is not really going to be tested.
144

144

00:05:11,146  -->  00:05:12,030
You're not going to get a lot of questions on them,
145

145

00:05:12,030  -->  00:05:13,410
but you should be thinking about these
146

146

00:05:13,410  -->  00:05:16,173
as you're building your profiles and your scenarios
147

147

00:05:16,173  -->  00:05:17,940
as part of threat hunting and threat modeling,
148

148

00:05:17,940  -->  00:05:21,706
because they are ways and attack vectors that could be used
149

149

00:05:21,706  -->  00:05:23,513
by an attacker to target your organization.
