« ROUND Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next

Re: Be careful what ya post on flopbook LOL. Teenage girl posts picture of cash on Facebook, family robbed within hours

By: Decomposed in ROUND | Recommend this post (0)
Mon, 18 Jun 12 5:24 PM | 180 view(s)
Boardmark this board | De's Test Board
Msg. 42066 of 45651
(This msg. is a reply to 42065 by capt_nemo)

Jump:
Jump to board:
Jump to msg. #

I took a Cyber Security course this Spring which included an assignment to design a Spear Phishing attack against key officials for a Nasdaq company. I chose a North Carolina manufacturer with about $125 million in annual sales. Facebook wound up being my top resource.

Although the CEO had considerable Security on his page, by the time I was done I had his photo, his wife's, his sister's, his kids', their home location and several photos of it (see below), its value, his income, his net worth, tax records, the office location, his home and work phone numbers, his e-mail address, the names and addresses of his High School buddies, his interests (baseball, fishing and Christianity), vacation photos (Atlanta Braves baseball camp!), and a lot more.

I wound up designing an attack based on an "In Memorium" guest book that the CEO's wife had signed. She'd written ""Ron, Brenda, Tina and Chris, Sidney and I are so sorry for your loss. We have a lot of fond memories of Shane chatting with him at the ball fields. We love you and will keep you in our prayers. Sidney and Amy Xxxxxx" - amy Xxxxxx (raleigh, NC)

BTW, in an ironic display of particularly bad taste, the guest book NOW says "The entry for Shane Yyyyy has expired." LOL! I think they could have phrased that a little more diplomatically, don't you?

Waaaaay too much information there for the wife of a very wealthy CEO to be doling out.

In my hypothetical attack, a spear phisher creates a yahoo account with the name of Shane's wife. "She" sends Amy an e-mail announcing a memorial softball game being held for Shane in Atlanta now that he's been gone for just over one year. She steers him to a website and signs off with a guilt trip. “Shane would have wanted you to come.” And “We love you guys.”

Of course, the attack was really about bilking money out of the family. It wouldn't have been too difficult, given that the CEO was close friends with the dead guy.

My instructor, by the way, said that he had no doubt that my attack would have worked. And... that there are special places in Hell reserved for anyone who would design an attack based on someone's dead friend! *grin*

The main lesson I learned? It doesn't really matter if you have your Facebook information protected if your friends don't have THEIR security set just as tight. I wasn't able to get much from the CEO or hs wife. But his sister's and, ultimately, his kids' pages gave me a TON of personal material about the family.

One of my instructor's other comments about my presentation was that if the CEO and his wife knew how much information I had obtained about their family, they would feel "incredibly violated."

Yup. No doubt about that.

The younger daughter and her friend: Uploaded Image

His sister, her husband, and an older woman: Uploaded Image

These pics are available in higher quality on Facebook. I'm not going to post them, though.

Here's the CEO's 6,986 sqft house in a suburb outside of Raleigh:
Uploaded Image




Avatar

Gold is $1,581/oz today. When it hits $2,000, it will be up 26.5%. Let's see how long that takes. - De 3/11/2013 - ANSWER: 7 Years, 5 Months


- - - - -
View Replies (2) »



» You can also:
- - - - -
The above is a reply to the following message:
Be careful what ya post on flopbook LOL. Teenage girl posts picture of cash on Facebook, family robbed within hours
By: capt_nemo
in ROUND
Mon, 18 Jun 12 10:25 AM
Msg. 42065 of 45651

These facebook zombies who can't live without it, and spend every waking minute on it. Truly sad,,,,,,,

Quickly attracting unwanted attention from criminals, a teenager in Australia failed to use her common sense when posting a photo on Facebook.

As mentioned by the BBC News recently, a 17-year-old girl was visiting her grandmother in Sydney, Australia when she took a picture of a ”large sum of cash” while helping her grandmother count her cash savings at the home. The teenager posted the picture on her Facebook feed around 4 p.m. on Thursday May 24. Approximately seven hours later, two masked men armed with a wooden club and a knife entered the girl’s family home 75 miles away in the town of Bundanoon. Upon entering the family home, the men found the 47-year-old mother of the girl as well as a 58-year-old man and 14-year-old boy, likely her father and brother.

Thief Browsing PCWhen speaking to the family, the two men wanted to talk to the girl about the sum of money in the picture that was posted on Facebook. After the girl’s mother convinced the two armed men that her daughter no longer lived at the address, they “took a small amount of cash and other personal property before leaving the house” according to the official police statement regarding the incident.

While no one was injured during the robbery, it’s clear that the two men were able to determine the location of the home from information posted on the teenage girl’s Facebook account. It’s also possible that at least one of the two men were friends with the girl on Facebook and were aware of the location of her family’s home.

Also within the official statement, the police reminded the public to be careful of the type of information that’s posted on social networks like Facebook. With the rise in popularity of geotagging photos with location data prior to posting on a social network, Facebook users may want to use groups to limit the amount of sharing among their entire friend’s list and avoid using public posts when publishing personal information or location data.

http://www.digitaltrends.com/social-media/teenage-girl-posts-picture-of-cash-on-facebook-family-robbed-within-hours/?src=Outbrain


« ROUND Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next