Security Basics mailing list archives

RE: The Greatest Military Social Engineering Attack Since The Trojan's Horse?


From: "Rivest, Philippe" <PRivest () transforce ca>
Date: Thu, 3 Jul 2008 12:56:48 -0400

Same for me. Here is what I got from my very quick lookup
http://www.liberation.fr/actualite/monde/336475.FR.php?rss=true&xtor=RSS-450

French:
Comme les otages séquestrés étaient divisés en trois groupes, l'armée,
invoquant grâce à ses agents infiltrés parmi les gardiens guérilleros un faux
ordre d'Alfonso Cano, le nouveau chef des Farc, a obtenu que les otages
soient réunis "soit-disant toujours sur ordre de Cano" par leurs geôliers et
que leur transfert se déroule dans un lieu du sud du pays.


English: (should be more or less accurate forgive me!)
Since the hostage were divided in 3 groups, the army, stating that since that
there infiltrated agent issued a false order to Alfonso Cano, the new leader
of FARC, got to unite the hostage "with the false order of Cano" by there
"**agents**" and that there transfer be made to a location in the south of
the country.


Well we all know that after the the helicopter took the hostage to a safe
place.


CNN states that:
http://www.cnn.com/2008/WORLD/americas/07/03/hostage.drama/index.html
+The agents gained the rebels' trust and rose to the top of FARC's
+leadership council as well as a team assigned to guard the hostages.

+When the time was ripe, the moles used the authority they'd gained within
+the group to order the 15 hostages moved from three separate locations to
+one central area, and the game was on

+Once the hostages -- including former presidential candidate Ingrid
+Betancourt and three American contractors -- were gathered, the agents
+ordered a 90-mile march through the steamy jungle, Montoya said


+The agents told their FARC comrades that an "international mission" -- such
+as the Red Cross or a U.N. delegation -- was coming to visit the hostages,
+Montoya said.


+The helicopter crew told the 60 or so real rebels that the chopper was
+going to ferry the hostages to the meeting with the "international
+mission," Montoya said.

+All 15 hostages were handcuffed and placed aboard the helicopter, along
+with two of their guards, leaving the rest of the FARC detachment on the
+ground.

+Once the chopper was up and safely away from the landing zone, the fake
+rebels persuaded the real ones aboard to hand them their weapons. Moments
+later, both rebels were on the floor of the aircraft, cuffed and
+blindfolded by their erstwhile comrades, Betancourt said


Merci / Thanks
Philippe Rivest, CEH
Vérificateur interne en sécurité de l'information
Courriel: Privest () transforce ca
Téléphone: (514) 331-4417
www.transforce.ca


-----Message d'origine-----
De : listbounce () securityfocus com [mailto:listbounce () securityfocus com] De la
part de Daniel I. Didier
Envoyé : 3 juillet 2008 11:04
À : Jon.Kibler () aset com; security-basics () securityfocus com
Objet : RE: The Greatest Military Social Engineering Attack Since The
Trojan's Horse?

Jon,
I'm interested in this topic but I don't know much about it.  Can you
share with us what you know about the social engineering aspects of this
attack?  I too am very interested.

Thanks,
Dan

www.NetSecureIA.com


-----Original Message-----
From: listbounce () securityfocus com
[mailto:listbounce () securityfocus com]
On Behalf Of Jon Kibler
Sent: Thursday, July 03, 2008 8:57 AM
To: security-basics () securityfocus com
Subject: The Greatest Military Social Engineering Attack Since The
Trojan's Horse?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

By now I am sure you are all aware of the Columbian military's freeing
of the FARC hostages. What I find most interesting is that this
appears
to be a purely social engineering attack.

The English language media have not provided that much detail thus far
about the social engineering aspects of the operation. If anyone has
more information regarding how the rescue was social engineered,
please
post it to this thread.

Just based on what I have seen thus far, this may turn out to be one
of
the greatest social engineering attacks in military history.

Jon Kibler
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-224-2494
s: 843-564-4224

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkhszJIACgkQUVxQRc85QlOU8gCfY0mZpxg+Bv2VG3+Vu3Ip7eec
zEAAn3/QlrgzrhkSMlXC8e1fIccOE8C4
=QZ9T
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


Current thread: