The Beirut Bank Job (2017)
darknetdiaries.com
darknetdiaries.com
That's not the worst story of security within a financial service company/bank I've experienced but sure did start to open my eye's how interlocked some companies are with others who you would not expect for numerous reasons.
I will say that if you do find yourself in places you wasn't expecting, you do notice and notice pretty quickly and raise questions, also you start to become more mindful - "how easy would it be to social engineer penetration testers to break into a bank for you", it's a thought and more so as they would just need to engineer management to task you such a job. Not aware of that happening, but can easily see how that could be orchestrated.
I like the idea of social engineering management into hiring pen testers... How large a shadow organization could conceivably remain undetected on the payrolls of a large corporation, I wonder.
There's a short story in there somewhere, at the very least.
Award for excellence in pentesting.
Well, the report is never empty but in general it's not as if you always hit jackpot, sometimes there's a very small attack surface in a black box test (or if it's a black box because your account credentials are still not arranged...), sometimes there's a mostly default install of something and that's secure by default because a lot of people already looked at the project, or sometimes they just did a good job.
Not being invited back can be more than one thing. Embarrassing the company is one of the most effective way of losing clients, though. It also doesn't help get issues fixed because the manager will prioritize saving face over anything else, including protecting assets.
If you enable them to protect assets without looking bad using good communication... that manager will want you for every test.
You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.
If you had a back bone as a consultant your period 2 report would start with “unresolved issues from last time”, so you would very quickly have to resign due to your ethical baseline not being met. Therefore same outcome.
Huh? Your job is to point to issues, not to ensure they're resolved.
Not as extreme as this case but, I've had cases where customers gave me the wrong IP address range for external work in the past, or where the customer had been told they had a dedicated server, when their web hosting company had actually put them on a shared host.
To avoid that, in the larger orga I worked for we had a checklist for the morning-of: check signature on indemnification agreement, run a WHOIS on the provided IPs and domains. Fewer and fewer people have their own v4 ranges, but the companies that pay our rates are typically large enough to still have it. If not, they had to tell us in advance whom we should expect it to be hosted with.
The team that has initial contact also checks, but we were supposed to double check anyway and it was a good thing, too. Getting caught hacking another company is not a situation you want or be in as a security company.
In the transcript, search for "A few years pass. Jason gets another call for another security awareness engagement" and read from there.
You may have seen it in the news just over a year ago. Basically, what happens when a physical pentest goes wrong....
> [The bank manager] raised his hand during this whole all-hands meeting and he says what about the free computers? Do we still get the new computers? I'm like no, I was lying to you. I'm a horrible person.
And this one after getting caught at the wrong bank:
> He calls the guy who hired us to rob the bank. They start talking and halfway through the conversation he literally says do we have to split the cost for this? At that point I realized it was probably going to be okay.
Tons of great episodes on this podcast. It's really a treasure.
The Sehnaoui family is very powerful and well known in Lebanon. The guy works for the cousin of the owner of the bank. People aren't as gullible as we imagine them to be, but it's a good story for PR, resold over and over.
That seems an unremarkable assertion to me.
Do these corporations want all their employees to act as their private security force and secret police? I think most employees (rightly) dont give a shit if the company suffers. When it does well they dont get rewarded. They just gotta work somewhere so they can pay the rent and get food.
Your employer has the power to make you do all sorts of things. But they cant make you care.
Right there in the article/podcast.
Generally Lebanon is quite free of "run-of-the-mill" crimes (thefts, rapes, murders). Most crimes happen in the political sphere: assassinations and mainly massive graft and corruption from the politicians who have pillaged the country for decades.