Home > Services > Profiling > Client Side Attack and Penetration

PROFILING

Client Side Attack & Penetration

Essentials

SecureState’s Client-Side Penetration Test simulates the main attack methods of the hacking community. “Spear Phishing” is an example of Client-Side attacks that are often used to target organizations. Hackers attempt to circumvent an organization’s security controls and to gain access to the internal network. An act as simple as an employee browsing a Website, an attacker can have full access to the organization’s network and systems. In most organizations, the Internet facing systems are a high security zone with layers of protection. Attackers have shifted their methods, and have been focusing their efforts on the employees of the organizations by taking advantage of the loose security in client-side systems. There are several methods of attack and SecureState uses a combination of social engineering attacks and email attacks to gain access to the network.

  • Attackers have shifted their methods and have been focusing on the employees of an organization
  • Client-side systems can be vulnerable to multiple forms of attack including web browsers, office software and more
  • Social Engineering techniques are used to exploit client side systems

Benefits

Social engineering is often an easy way for attackers to “hack the human element” and gain access to sensitive data; or fully compromise an organization. Often, the attacker will attempt to gain a level of comfort or form a trust relationship with the individual on the phone and leverage that trust for an attack. SecureState’s client side penetration test also checks the security controls such as anti-virus and HIDS (Host Based Intrusion Detection System) on client side systems. In addition, egress access is tested to determine if an attacker can communicate outbound to systems under their control.

Expertise

SecureState has a 100% success rate in Client-Side Penetration Testing. Our engineers can “spoof” originating phone numbers to appear to be calling from your organization’s phone block or pretend to be a 3rd party vendor. In doing so, we can persuade an individual to download backdoors or to reveal sensitive usernames, passwords, credit card information, salary information, trade secrets, and much more. By crafting special e-mail messages to members of your organization, SecureState can persuade individuals to click a malicious link that instantly compromises the system and gives us full access to your organization’s network. These messages can appear to come from legitimate employees of your organization.

Did You Know?

  • SecureState has a 100% success rate in Client-Side Penetration Testing
  • Client-Side attacks are a major cause of security breaches in companies
  • Penetration Tests are not Vulnerability Assessments
  • Penetration Tests should be performed at least once a year and after any significant application modification or network upgrade

Our Approach and Methodology

The SecureState Profiling Team are well known and highly regarded as experts in Penetration Testing. Our approach follows industry accepted testing methodologies such as PTES, NIST 800-115 and OSSTMM. By following these methodologies, our clients can accurately replicate the testing SecureState has performed in their own environment to accurately mitigate identified vulnerabilities. The SecureState Profiling Team also helps identify strategic “root cause” issues through our Penetration Tests. Our Risk Management Team is uniquely positioned to work closely with the Profiling Team in order to assist clients with mitigating these strategic “root cause” issues.

Phase I – Pre-engagement Interactions:

In this phase, SecureState works with the client to establish the rules of engagement as well as the scope and exchanges contact information with both parties. Next, we provide a detailed Project Charter which contains information on scope and all the required elements to conduct the testing. The Project Charter is discussed on the kickoff call prior to the beginning of the engagement

Phase II – Intelligence Gathering:

SecureState begins any Client Side Penetration Test by conducting an extensive search of open source intelligence on the target company and its employees. This research gathers pertinent information regarding the target company and its employees from public databases, tax records, job openings, social networks, Internet search engines, and much more.

Additionally, SecureState will develop scenarios tailored toward the specific company and employees. These scenarios are based off the intelligence that was previously gathered.

Phase III – Pretexting:

Pretexting is all about creating a scenario which will convince the victim to click on a link to visit a website or take some form of action. In some cases, this can involve an elaborate scenario which includes impersonating current or former employees. For example, SecureState can create a website to elicit user account credentials to a web mail system. SecureState calls an employee impersonating a help desk worker and solicits account credentials. Once we have the proper information, SecureState can login and gather more information regarding the victim and company. Another example is to craft a highly convincing, phishing email that is sent to multiple employees. The email appears to originate from the target company and gains the trust of the employees. These types of examples simulate real attacks that have lead to security breaches in the past. Furthermore, SecureState can create custom scenarios based on any threats identified in Phase I.

Phase IV – Exploitation:

Once the pretexting phase is complete, the exploitation phase begins. SecureState sends emails, or makes phone calls based on the pretexting scenarios previously developed. For any of the attacks SecureState initiates in the exploitation phase, the goal is to compromise the clients’ computer so that it can be used to “pivot” to other systems on the network. SecureState may initiate attacks against popular client side applications such as Microsoft Office and Adobe Acrobat Reader. Once this access is achieved, SecureState will look for additional systems to compromise in an attempt to gain privileged access.

Phase V – Post Exploitation:

The Post Exploitation Phase includes pillaging, penetrating further into the network, documentation and erasing any remains we might have left behind.

Phase VI – Reporting:

As part of the deliverable, SecureState provides a report which contains a short graphical summary aimed at senior management, a narrative body which details major findings and a detailed findings section aimed at the technical staff. Additionally, we provide a closing call and high level executive presentation to summarize the penetration test as well as provide an opportunity to ask questions about the engagement.

What Makes Us Different

  • Uses a team-based approach for all Penetration Tests
  • Utilizes proprietary Vulnerability Linkage Theory (VLT) to achieve a greater attack
  • Demonstrates proprietary tools to Clients during Penetration Testing
  • Publishes our own Exploits, Zero Days and Tools to the Information Security Community
  • Profiling Team members are known as experts in Penetration Testing worldwide
  • Profiling Team members are frequent speakers at National and world-wide security and hacking conferences; such as DEFCON, Black Hat, OWASP AppSec, SANS, ShmooCon, THOTCON, DerbyCon, ToorCon and more
  • Conducts all Client-Side Penetration Tests from our state-of-the-art hacking facility in SecureState’s world headquarters; a DOD cleared facility
  • SecureState has the capability of performing secure remote Internal Penetration Tests using the latest Penetration Testing technology
  • Provides a secure two-factor authentication web portal for access to Penetration Test results
  • Follows industry standard testing methodologies, vulnerability rating systems and uses real attack data collected by SecureState through years of assessments to compare your company to your industry peers from a security perspective

Downloads

We Can Help You