Monday, 17 February 2014

Microsoft sets Oct. 31 as stop date for Windows 7 consumer PC sales

But extends end-of-sales date for business PCs running Windows 7 Professional

Microsoft has set Oct. 31 as the end of sales of new consumer-grade Windows 7 PCs, but for now has left open the do-not-sell-after-this-date for business machines.

On the site where it posts such policies, Microsoft now notes that Oct. 31, 2014, is the end-of-sales date for new PCs equipped with Windows 7 Home Basic, Home Premium or Ultimate. All three are consumer-oriented versions of Windows 7; Home Premium has been the overwhelming choice of OEMs (original equipment manufacturers) for consumer systems.

Microsoft's practice, first defined in 2010, is to stop selling an older operating system in retail one year after the launch of its successor, and halt delivery of the previous Windows edition to OEMs two years after a new version launches. The company shipped Windows 8, Windows 7's replacement, in October 2012.

The setting of a deadline for consumer Windows 7 PCs followed a glitch last year when Microsoft named the same Oct. 31 date for all Windows 7 PCs, but then quickly retracted the posting, claiming that the notification had been posted "in error."

Some OEMs, notably Hewlett-Packard, have made headlines for marketing consumer-grade Windows 7 PCs, a sign of the fragmentation of the once-dominant Windows oligarchy, which always pushed the newest at the expense of older editions.

But while it has established an end-of-sales date for consumer PCs with Windows 7 pre-installed, Microsoft has yet to do the same for business PCs.

Microsoft will give a one-year warning before it demands that OEMs stop selling PCs with Windows 7 Professional, the commercial-quality version. Under that rule, Microsoft will allow computer makers such as Lenovo, HP and Dell to continue selling PCs with Windows 7 Professional until at least February 2015.

It's likely that the extension will be much longer.

Windows 7 has become the standard version for businesses, which have spurned Windows 8, largely because of its two-user interface (UI) model, which they consider disruptive to productivity and a needless cost that would require employee retraining.

Most analysts believe that Windows 7 will remain the most popular Microsoft operating system deployed by companies for years to come.

"There's a good chance that enterprises will stay on Windows 7 as long as possible," said Gartner analyst Michael Silver in an October 2013 interview. If his prediction turns out to be accurate, Windows 7 may reprise the stubborn persistence of Windows XP, the nearly-13-year-old OS that Microsoft will retire in April.

Even after Windows 8's launch, Windows 7's user share, a rough measurement of the prevalence of the OS on operational machines, has continued to grow. From October 2012 to January 2014, Windows 7's user share increased nearly 3 percentage points, representing a 6% gain during that period, according to data from analytics company Net Applications.

Some of Windows 7's gains certainly came at the expense of Windows XP, which has fallen more than 11 percentage points, a 28% decline, since October 2012 as users abandoned the old OS.

By making Windows 7 available, Microsoft and its OEMs not only continue to serve customers who want the OS, but make sure that new PC sales do not slump even more dramatically than they have already.

Consumer PC sales have plummeted -- last month Microsoft said sales of consumer-grade Windows licenses fell 20% in the December quarter compared to the same period the year before -- while the Redmond, Wash. company's business line of operating systems grew 12% year-over-year. In effect, enterprise spending kept PC shipments from tanking even more than the 10% contraction the industry experienced in 2013.

Extending Windows 7 Professional's availability on new hardware will also give Microsoft breathing room to continue its retreat from Windows 8's radical shift to a touch-first, tile-based UI, and to roll out a successor that caters even more to customers who rely on keyboard and mouse.

Microsoft is expected to unveil an update to Windows 8.1 this spring, perhaps in April, that will restore several desktop-oriented features and tools. Some reports based on leaked builds of this Windows 8.1 Update 1 have noted that on non-touch devices, the boot-to-desktop option will be enabled by default; if accurate, most users of traditional PCs will skip the colorful, tile-style Start screen. Windows 9 may appear as early as April 2015.

Retail sales of Windows 7 by Microsoft to distributors and customers were officially halted as of Oct. 31, 2013, but that deadline has been meaningless, as online retailers have continued to sell packaged copies, sometimes for years, by restocking through distributors who squirreled away older editions.

As of Saturday, for example, Amazon.com had a plentiful supply of various versions of Windows 7 available, as did technology specialist Newegg.com. The former also listed copies of Windows Vista and even Windows XP for sale through partners.

Even after Microsoft pulls the plug on Windows 7, there will be ways to circumvent the shut-down. Windows 8.1 Pro, the more expensive of the two public editions, includes "downgrade" rights that allow PC owners to legally install an older OS. OEMs and system builders can also use downgrade rights to sell a Windows 8.1 Pro-licensed system, but factory-downgrade it to

Windows 7 Professional before it ships.

And enterprises with volume license agreements will never be at risk of losing access to Windows 7, as they are granted downgrade rights as part of those agreements, and so will be able to purchase, say, Windows 8.1 or Windows 9 PCs in 2015 or 2016, then re-image the machines with Windows 7.

The end-of-sales dates for Windows 7 are not linked in any way to the support schedule for the 2009 operating system. Microsoft will provide free non-security bug fixes and vulnerability patches for Windows 7 until Jan. 13, 2015 -- called "mainstream support" -- and follow that with a five-year stretch of "extended support" during which it will ship free security updates until Jan. 14, 2020.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Microsoft sets Oct. 31 as stop date for Windows 7 consumer PC sales

But extends end-of-sales date for business PCs running Windows 7 Professional

Microsoft has set Oct. 31 as the end of sales of new consumer-grade Windows 7 PCs, but for now has left open the do-not-sell-after-this-date for business machines.

On the site where it posts such policies, Microsoft now notes that Oct. 31, 2014, is the end-of-sales date for new PCs equipped with Windows 7 Home Basic, Home Premium or Ultimate. All three are consumer-oriented versions of Windows 7; Home Premium has been the overwhelming choice of OEMs (original equipment manufacturers) for consumer systems.

Microsoft's practice, first defined in 2010, is to stop selling an older operating system in retail one year after the launch of its successor, and halt delivery of the previous Windows edition to OEMs two years after a new version launches. The company shipped Windows 8, Windows 7's replacement, in October 2012.

The setting of a deadline for consumer Windows 7 PCs followed a glitch last year when Microsoft named the same Oct. 31 date for all Windows 7 PCs, but then quickly retracted the posting, claiming that the notification had been posted "in error."

Some OEMs, notably Hewlett-Packard, have made headlines for marketing consumer-grade Windows 7 PCs, a sign of the fragmentation of the once-dominant Windows oligarchy, which always pushed the newest at the expense of older editions.

But while it has established an end-of-sales date for consumer PCs with Windows 7 pre-installed, Microsoft has yet to do the same for business PCs.

Microsoft will give a one-year warning before it demands that OEMs stop selling PCs with Windows 7 Professional, the commercial-quality version. Under that rule, Microsoft will allow computer makers such as Lenovo, HP and Dell to continue selling PCs with Windows 7 Professional until at least February 2015.

It's likely that the extension will be much longer.

Windows 7 has become the standard version for businesses, which have spurned Windows 8, largely because of its two-user interface (UI) model, which they consider disruptive to productivity and a needless cost that would require employee retraining.

Most analysts believe that Windows 7 will remain the most popular Microsoft operating system deployed by companies for years to come.

"There's a good chance that enterprises will stay on Windows 7 as long as possible," said Gartner analyst Michael Silver in an October 2013 interview. If his prediction turns out to be accurate, Windows 7 may reprise the stubborn persistence of Windows XP, the nearly-13-year-old OS that Microsoft will retire in April.

Even after Windows 8's launch, Windows 7's user share, a rough measurement of the prevalence of the OS on operational machines, has continued to grow. From October 2012 to January 2014, Windows 7's user share increased nearly 3 percentage points, representing a 6% gain during that period, according to data from analytics company Net Applications.

Some of Windows 7's gains certainly came at the expense of Windows XP, which has fallen more than 11 percentage points, a 28% decline, since October 2012 as users abandoned the old OS.

By making Windows 7 available, Microsoft and its OEMs not only continue to serve customers who want the OS, but make sure that new PC sales do not slump even more dramatically than they have already.

Consumer PC sales have plummeted -- last month Microsoft said sales of consumer-grade Windows licenses fell 20% in the December quarter compared to the same period the year before -- while the Redmond, Wash. company's business line of operating systems grew 12% year-over-year. In effect, enterprise spending kept PC shipments from tanking even more than the 10% contraction the industry experienced in 2013.

Extending Windows 7 Professional's availability on new hardware will also give Microsoft breathing room to continue its retreat from Windows 8's radical shift to a touch-first, tile-based UI, and to roll out a successor that caters even more to customers who rely on keyboard and mouse.

Microsoft is expected to unveil an update to Windows 8.1 this spring, perhaps in April, that will restore several desktop-oriented features and tools. Some reports based on leaked builds of this Windows 8.1 Update 1 have noted that on non-touch devices, the boot-to-desktop option will be enabled by default; if accurate, most users of traditional PCs will skip the colorful, tile-style Start screen. Windows 9 may appear as early as April 2015.

Retail sales of Windows 7 by Microsoft to distributors and customers were officially halted as of Oct. 31, 2013, but that deadline has been meaningless, as online retailers have continued to sell packaged copies, sometimes for years, by restocking through distributors who squirreled away older editions.

As of Saturday, for example, Amazon.com had a plentiful supply of various versions of Windows 7 available, as did technology specialist Newegg.com. The former also listed copies of Windows Vista and even Windows XP for sale through partners.

Even after Microsoft pulls the plug on Windows 7, there will be ways to circumvent the shut-down. Windows 8.1 Pro, the more expensive of the two public editions, includes "downgrade" rights that allow PC owners to legally install an older OS. OEMs and system builders can also use downgrade rights to sell a Windows 8.1 Pro-licensed system, but factory-downgrade it to

Windows 7 Professional before it ships.

And enterprises with volume license agreements will never be at risk of losing access to Windows 7, as they are granted downgrade rights as part of those agreements, and so will be able to purchase, say, Windows 8.1 or Windows 9 PCs in 2015 or 2016, then re-image the machines with Windows 7.

The end-of-sales dates for Windows 7 are not linked in any way to the support schedule for the 2009 operating system. Microsoft will provide free non-security bug fixes and vulnerability patches for Windows 7 until Jan. 13, 2015 -- called "mainstream support" -- and follow that with a five-year stretch of "extended support" during which it will ship free security updates until Jan. 14, 2020.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Monday, 20 January 2014

Microsoft will furnish malware assassin to XP users until mid-2015

Malicious Software Removal Tool (MSRT) to scrub infected XP PCs for more than a year after Microsoft ends patches

Microsoft confirmed on Friday that it will continue to offer its malware scrubbing program to Windows XP users for more than a year after it stops patching the operating system.

"Microsoft's Malicious Software Removal Tool is aligned with the company's anti-malware engines and signatures, and as such the removal tool will continue to be provided for Windows XP through July 14, 2015," a company spokesperson wrote in an email reply to questions.

The Malicious Software Removal Tool (MSRT) is updated monthly as Microsoft targets specific major malware families it believes are the biggest threats at the time. It's distributed through Microsoft's Windows Update service and the business-grade Windows Server Update Service (WSUS) on "Patch Tuesday," the date each month when the company ships security patches and other fixes to customers. The MSRT automatically installs and then runs in a seek-and-destroy mission.

Users can also manually download the MSRT from Microsoft's website.

MSRT is not an antivirus program, but rather a cleanup utility designed to eradicate malware that has already wormed onto a Windows PC. The tool was first released in 2005.

The extension of MSRT's availability for Windows XP was part of Microsoft's decision last Wednesday to offer new anti-malware signatures to XP customers who run the company's free Security Essentials antivirus (AV) software.

Originally, Microsoft had said it would stop shipping Security Essentials' signature updates to XP PCs after April 8. But in a tacit nod to XP's widespread use, Microsoft postponed the cut-off until July 14, 2015.

Microsoft will ship its final public security patches for Windows XP in less than three months, ending nearly 13 years of support for the ultra-successful OS.

Microsoft did not reply Saturday to follow-up questions asking what channels it will use to distribute the malware eraser between April 8, 2014, and July 14, 2015.

If Microsoft continued to deliver the MSRT via Windows Update, the tool would be a valuable weapon in containing infections on Windows XP PCs.

Say a new malware family popped up, or an older one began infecting large numbers of Windows PCs, including those still running XP. Microsoft would be able to revise MSRT so it targets the new or suddenly aggressive malware for detection and deletion, and automatically put it on XP systems. Not only would that keep the remaining XP owners safer, but it would also reduce the number of compromised computers that could in turn be used by hackers to infect machines running the still-supported Vista, Windows 7 and Windows 8 operating systems.

The impact of the MSRT extension would be more muted if Microsoft required users to download the tool themselves. Even so, MSRT is a very popular download -- currently No. 2 on the company's Download Center -- indicating that large numbers of customers seek it out.

Although Microsoft has been urging customers to drop XP before the April 8 deadline for a new OS or PC, millions of machines worldwide will continue to run the aged OS for months and maybe even years to come.

According to metrics company Net Applications, Windows XP's user share -- the percentage of all personal computer owners who went online with that OS -- stood at 29% at the end of December 2014. Computerworld has forecast that at least 25% of all personal computers will be running the operating system at the end of April, and about 20% at the end of this year.

Those numbers were at the root of Microsoft's recent moves to help out XP users: While the company has remained adamant that bug patches will be discontinued after April 8, some cracks in its "Death to XP" policy have appeared, including the continued availability of Security Essentials' signatures and the lifespan extension for the MSRT.

The explanation: Microsoft has decided it best for all concerned -- including itself and its reputation -- that it throw some security bones, if only small ones, to those who can't or won't upgrade from XP.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Friday, 27 December 2013

3 Ways Enterprise IT Will Change in 2014

The holiday season is a great time to look back at the year, with an eye toward what we in the ever-changing world of information technology can expect in 2014. These three trends warrant your close attention in the new year.

In Light of NSA Revelations, companies Will Be Wary of the Cloud
For most businesses, 2013 was the year of the cloud. Companies that still hosted their email in house would in large part move that expense and aggravation to someone else. Microsoft SharePoint and other knowledge management solutions could be run in someone else's datacenter, using someone else's resources and time to administer, thus freeing your own people to improve other services or, gasp, work directly on enhancing the business.

But then Edward Snowden came around in June and started to release a series of damning leaks about the United States National Security Agency's capability to eavesdrop on communications. At first, most folks weren't terribly alarmed. But as the year wore on, the depth of the NSA's alleged capabilities to tap into communications - both with and without service provider knowledge - started to shake the faith of many CIOs in the risk/benefit tradeoff for moving to cloud services.

For companies in heavily regulated industries, it's hard to ignore the continued discovery of the depths to which the NSA has the capability to read data both in transit and at rest. Patient privacy records, sensitive financial transactions and any other data that must by law be kept private - is it now considered private? Can you warrant that to your customers? Can you warrant that to your regulators? Can you afford the risk that NSA access to your data represents? Is it even something that you can control, or do you just ignore it and hope for the best? (That is said with no judgment; given the realities of your business, that could very well be a valid strategy.)

How-to: 5 Tips to Keep Your Data Secure on the CloudMore: Who Can Pry Into Your Cloud-based Data?
In 2014, we'll see a continued analysis of just what services make sense in the cloud, but some old cherished low-hanging fruit, like email and collaboration, will no longer be considered "easy wins" because of these continuing allegations. Perhaps the cloud will not be the default choice going forward but, rather, a choice made after careful study of the environment, using these PRISM leaks as one important bit of context.

Microsoft's CEO Search Will Define the Future of Their Products in Your Organization
The biggest story of the first part of 2014 will undoubtedly be Microsofts selection for only its third CEO in its history. This job is one of the most important positions in the technology industry; who is selected, and what he or she does in her first 100 days, will set the tone for the next five to 10 years.

Reports as of the Monday morning after Thanksgiving 2013 suggest that the Microsoft board of directors has narrowed its potential selections to two: Satya Nadella, the current chief of servers and tooling at the company, and outsider Alan Mulally, who currently is in charge of the Ford Motor Company and is widely credited for executing a fantastic turnaround of operations, profits, and shareholder return after joining the company from Boeing, a corporate neighbor of Microsoft. ( Mulally denies he's interested in the Microsoft job, only heightening speculation.)

There are two main questions surrounding both the choice of chief executive and the immediate moves he makes in the first part of his tenure.

Will the new CEO continue the remake of Microsoft into a devices and services organization?
Steve Ballmer, the company's current CEO, has tried to convert the software company into an organization that makes a variety of devices, such as tablets and phones, which connect to services that Microsoft runs. This has been done both to make those devices more rich and useful for the end user but also to monetize that usage through enhanced upgrade services, advertising revenue and subscription profits.

Of course, this represents a big switch from Microsoft's traditional "pay us for the right to use this software in perpetuity" practice that propelled the business to its current height. Many investors and customers wonder if this transformation is beneficial to them. Will the new CEO elect to continue this transformation and carry on the vision of Steve Ballmer even after his departure? Or will the new CEO put pause on the progress and take a few months to assess whether that transformation is good for both Microsoft and its customers? The answers will have a big impact on the role Microsoft software and technology plays within your own business.

Will the cloud still be a huge focus of the company?
Will the continued preference of developing for Microsoft' cloud-based services versus its traditional on-premises software erode the trust of corporate customers who still have significant investments in their existing on premises licenses?

Related: Why Microsoft SharePoint Faces a Challenging Future
Nowhere is this tension more evident than in the Exchange community, where Exchange Server 2013 customers feel as if they are a distant second cousin to the Office 365 subscription data center environment. Complaints abound, from poor patch quality to irregular updates to features arriving in Office 365 but not Exchange Server 2013 for some time. These on-premises customers, paying many thousands of dollars for their combined server and client access license fees, feel shafted on their investment. Will this tension bleed over into other areas? Is the Exchange model the new model, warts and all, for the company's cloud focus? This is a trend to watch in 2014.

The Role of the Cloud Broker Will Emerge in 2014
Whatever Microsoft does and whatever the revelations about the NSA's PRISM program mean for your business, the continued push around consumerization will mean more cloud services for your organization, not fewer. PRISM might eliminate email and other line of business data from being considered in a move to the cloud - but other, less sensitive data can still be stored in the cloud. The corporate IT department can take advantage of a number of cloud businesses that are designed to save money and lower the cost of access to data while revealing new insights and workflows that may not have been feasible for your organization before.

Blog: Dirty Secrets of Dropbox, Google Drive and Other Cloud Storage ServicesAlso: How to Find the Cloud Storage Service That's Right for You
In 2014 that the cloud broker or cloud solution provider position will really come into its own and begin bearing fruit. Vendor neutral, pay-for-service cloud brokers will be able to consult on your situation and recommend both a provider and a strategy for making use of that provider's products and services for any given task or workload.

IT departments will be in the drivers' seats, able to really sit down with a knowledgeable set of professionals and figure out exactly what solution and what model works best. The cloud broker role will be best placed to help the furthering of the IT organization's transformation from a cost center to a place where new revenues and profits are generated - an additional trend to watch in 2014.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 17 December 2013

Microsoft joins group seeking to replace passwords

The FIDO Alliance envisions a system where users can interact with an online service without surrendering personal details

Microsoft has joined the FIDO Alliance, an industry group attempting to craft industry standards that reduce reliance on passwords, long regarded as a weak point in Web security.

Launched in July 2012, FIDO, which stands for Fast IDentity Online, is hoping its specifications for security devices and browser plugins will be widely adopted across the technology industry.

+ Also on Network World: Bitcoin -- 8 Funny Money videos +

Such efforts depend on voluntary adoption by many companies and organizations. So far, those participating in FIDO include heavyweights Google, MasterCard, Lenovo, Infineon, LG Electronics and a variety of smaller companies.

Authentication hardware and software widely varies, with many proprietary clients and protocols. FIDO hopes that standardizing authentication technologies will lead to better interoperability and innovations in biometrics, PINs (personal identification numbers) and secondary authentication technologies, according to its website.

Usernames and passwords underpin most online services but are easy to intercept. Computer security experts have long warned of password weaknesses, such as easy-to-guess ones and people who reuse them across multiple services.

Password replacement technology has a high bar: it needs to be both effective and simple for users.

FIDO envisions a software client that's installed on computers that employ public key cryptography to authenticate users. All major Web browsers will be supported. The initial focus will be on securing access through Web browsers to Web applications. The group also plans authentication options for Android phones soon and eventually for Windows tablets and Apple products.

When FIDO authentication is used, a user will not need to submit their biometric or personal information to an online service.

The FIDO Alliance will eventually submit its protocol to groups dedicated to Web standards, such as the Internet Engineering Task Force or the World Wide Web Consortium.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, 12 December 2013

Juniper EVP Muglia abruptly quits

Leaves networking company shortly after new CEO is named

Bob Muglia, executive vice president of Juniper Networks' software solutions division, has abruptly resigned from the company following the appointment of a new CEO.

Juniper confirmed Muglia’s departure via this e-mailed statement: “We can confirm that Bob Muglia is leaving Juniper Networks effective Tuesday, December 10. We thank Bob for his contributions to Juniper and wish him well in his future endeavors.

“(CEO) Kevin Johnson will step in as Acting GM of the software division through the end of the month. He will then transition the organization over to Shaygan Kheradpir when he starts as our new CEO in January. We will be relentlessly focused on our customers through this transition.”

The move was first reported on Tuesday by the San Francisco Business Times, which did not give a reason for Muglia’s departure, but did outline the compensation package he will receive.

+ MORE ON NETWORK WORLD Juniper finally talks SDNs +

Juniper named Kheradpir, a former Barclays and Verizon information technology executive, as its new CEO a month ago. Kheradpir replaces Johnson, who last summer announced plans to retire once a new CEO was found.

Muglia, who also worked with Johnson while the two were at Microsoft, was mentioned as a possible replacement for Johnson. But after Johnson’s unremarkable five-year tenure at Juniper, many thought it unlikely Juniper would turn to another former Microsoft software executive to assume leadership of the company.

"Muglia, in my opinion, was always a long shot to get the role," said financial analyst, consultant and blogger Nikos Theodosopoulos, a long time Juniper watcher.

Other observers suggested Muglia was comfortable working with Johnson and perhaps did not relish establishing a new relationship with Kheradpir.

Juniper did not say who would assume Muglia’s role heading up the company’s software business. Muglia developed Juniper’s software-defined networking strategy, which relies on a new software licensing model for more of the company’s revenue.

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com



Thursday, 7 November 2013

Social Engineering: The Basics

What is social engineering? What are the most common and current tactics? A guide on how to stop social engineering.

You've got all the bells and whistles when it comes to network firewalls and your building's security has a state-of-the-art access system. You've invested in the technology. But a social engineering attack could bypass all those defenses.

Say two fire inspectors show up at your office, show their badges and ask for a walkthrough—you're legally required to give them access to do their job. They ask a lot of questions, they take electrical readings at various wall outlets, they examine wiring under desks. Thorough, aren't they? Problem is, in this case they're really security consultants doing a social engineering 'penetration test' and grabbing access cards, installing keystroke loggers, and generally getting away with as much of your business's private information as they can get their hands on. (See How to rob a bank for details from this real-world example.)

Social engineers, or criminals who take advantage of human behavior to pull of a scam, aren't worried about a badge system. They will just walk right in and confidently ask someone to help them get inside. And that firewall? It won't mean much if your users are tricked into clicking on a malicious link they think came from a Facebook friend.

In this article, we outline the common tactics social engineers often use, and give you tips on how to ensure your staff is on guard.

What is social engineering?
Social engineering is essentially the art of gaining access to buildings, systems or data by exploiting human psychology, rather than by breaking in or using technical hacking techniques. For example, instead of trying to find a software vulnerability, a social engineer might call an employee and pose as an IT support person, trying to trick the employee into divulging his password.

Famous hacker Kevin Mitnick helped popularize the term 'social engineering' in the '90s, although the idea and many of the techniques have been around as long as there have been scam artists of any sort. (Watch the video to see social-engineering expert Chris Nickerson size up one building's perimeter security)
Through a Social Engineer's Eyes
Social Engineering expert Chris Nickerson reveals what criminals are looking for when it comes vulnerabilities in building security.

How is my company at risk?
Social engineering has proven to be a very successful way for a criminal to "get inside" your organization. In the example given above, once a social engineer has a trusted employee's password, he can simply log in and snoop around for sensitive data. Another try might be to scam someone out of an access card or code in order to physically get inside a facility, whether to access data, steal assets, or even to harm people.

Chris Nickerson, founder of Lares, a Colorado-based security consultancy, conducts 'red team testing' for clients using social engineering techniques to see where a company is vulnerable. Nickerson detailed for CSO how easy it is to get inside a building without question.

In one penetration test, Nickerson used current events, public information available on social network sites, and a $4 Cisco shirt he purchased at a thrift store to prepare for his illegal entry. The shirt helped him convince building reception and other employees that he was a Cisco employee on a technical support visit. Once inside, he was able to give his other team members illegal entry as well. He also managed to drop several malware-laden USBs and hack into the company's network, all within sight of other employees. Read Anatomy of a Hack to follow Nickerson through this exercise.

In What it's like to steal someone's identity professional pen tester Chris Roberts, founder of One World Labs, says he too often meets people who assume they have nothing worth stealing.

"So many people look at themselves or the companies they work for and think, 'Why would somebody want something from me? I don't have any money or anything anyone would want,'?" he said. "While you may not, if I can assume your identity, you can pay my bills. Or I can commit crimes in your name. I always try to get people to understand that no matter who the heck you are, or who you represent, you have a value to a criminal."


Sneaky stuff. Give me some specific examples of what social engineers say or do.
Criminals will often take weeks and months getting to know a place before even coming in the door or making a phone call. Their preparation might include finding a company phone list or org chart and researching employees on social networking sites like LinkedIn or Facebook.

In the case of Roberts, he was asked to conduct a pen test for a client who was a high-net-worth individual to see how easy it would be to steal from him. He used a basic internet search to find an email address for the individual. From there, it snowballed.

Useful Books on Social Engineering!

Social Engineering: The Art of Human Hacking
By Hadnagy and Wilson (Wiley, Dec 2010)
"This book covers, in detail, the world's first framework for social engineering."

No Tech Hacking: A Guide to Social Engineering, Dumpster Diving, and Shoulder Surfing
By Johnny Long et al (Syngress 2008)
"Whether breaking into buildings or slipping past industrial-grade firewalls, my goal has always been the same: extract the informational secrets using any means necessary."

"We searched for the e-mail address online were able to find a telephone number because he had posted in a public forum using both," said Roberts. "On this forum, he was looking for concert tickets and had posted his telephone number on there to be contacted about buying tickets from a potential seller."

The phone number turned out to be an office number and Roberts called pretending to be a publicist. From there he was able to obtain a personal cell phone number, a home address, and, eventually, mortage information. The point being from one small bit of information, a social engineering can compile an enitre profile on a target and seem convincing. By the time Roberts was done with his pen test, he knew where the person's kids went to school and even was able to pull a Bluetooth signal from his residence.

Once a social engineer is ready to strike, knowing the right thing to say, knowing whom to ask for, and having confidence are often all it takes for an unauthorized person to gain access to a facility or sensitive data, according to Nickerson.

The goal is always to gain the trust of one or more of your employees. In Mind Games: How Social Engineers Win Your Confidence Brian Bushwood, host of the Internet video series Scam School, describes some of the tricks scam artists use to gain that trust, which can vary depending on the communication medium:

-- On the phone:
A social engineer might call and pretend to be a fellow employee or a trusted outside authority (such as law enforcement or an auditor).

According to Sal Lifrieri, a 20-year veteran of the New York City Police Department who now educates companies on social engineering tactics through an organization called Protective Operations, the criminal tries to make the person feel comfortable with familiarity. They might learn the corporate lingo so the person on the other end thinks they are an insider. Another successful technique involves recording the "hold" music a company uses when callers are left waiting on the phone. See more such tricks in Social Engineering: Eight Common Tactics.

-- In the office:
"Can you hold the door for me? I don't have my key/access card on me." How often have you heard that in your building? While the person asking may not seem suspicious, this is a very common tactic used by social engineers.

In the same exercise where Nickerson used his thrift-shop shirt to get into a building, he had a team member wait outside near the smoking area where employees often went for breaks. Assuming this person was simply a fellow-office-smoking mate, real employees let him in the back door with out question. "A cigarette is a social engineer's best friend," said Nickerson. He also points out other places where social engineers can get in easily in 5 Security Holes at the Office.

This kind of thing goes on all the time, according to Nickerson. The tactic is als o known as tailgating. Many people just don't ask others to prove they have permission to be there. But even in places where badges or other proof is required to roam the halls, fakery is easy, he said.

"I usually use some high-end photography to print up badges to really look like I am supposed to be in that environment. But they often don't even get checked. I've even worn a badge that said right on it 'Kick me out' and I still was not questioned."

-- Online:
Social networking sites have opened a whole new door for social engineering scams, according to Graham Cluley, senior technology consultant with U.K.-based security firm Sophos. One of the latest involves the criminal posing as a Facebook "friend." But one can never be certain the person they are talking to on Facebook is actually the real person, he noted. Criminals are stealing passwords, hacking accounts and posing as friends for financial gain.

One popular tactic used recently involved scammers hacking into Facebook accounts and sending a message on Facebook claiming to be stuck in a foreign city and they say they need money.

"The claim is often that they were robbed while traveling and the person asks the Facebook friend to wire money so everything can be fixed," said Cluley.

"If a person has chosen a bad password, or had it stolen through malware, it is easy for a con to wear that cloak of trustability," he said. "Once you have access to a person's account, you can see who their spouse is, where they went on holiday the last time. It is easy to pretend to be someone you are not."

See 9 Dirty Tricks: Social Engineers Favorite Pick-up Lines for more examples.
Social engineers also take advantage of current events and holidays to lure victims. In Cyber Monday: 3 online shopping scams and 7 Scroogeworthy scams for the holidays security experts warn that social engineers often take advantage of holiday shopping trends by posioning search results and planting bad links in sites. They might also go as far as to set up a fake charity in the hope of gaining some cash from a Christmas donation.

Why do people fall for social engineering techniques?
People are fooled every day by these cons because they haven't been adequately warned about social engineers. As CSO blogger Tom Olzak points out, human behavior is always the weakest link in any security program. And who can blame them? Without the proper education, most people won't recognize a social engineer's tricks because they are often very sophisticated.

Social engineers use a number of psychological tactics on unsuspecting victims. As Bushwood outlines in Mind Games, successful social engineers are confident and in control of the conversation. They simply act like they belong in a facility, even if they should not be, and their confidence and body posture puts others at ease.
This is your brain on social engineering

Brian Brushwood is really good at tricking people. So good he founded a website called "Scam School".
Brushwood understands how social engineers mislead people. Four basic principles:
They project confidence. Instead of sneaking around, they proactively approach people and draw attention to themselves.
They give you something. Even a small favor creates trust and a perception of indebtedness.
They use humor. It's endearing and disarming.
They make a request and offer a reason. Psych 101 research shows people are likely to respond to any reasoned request.


Read the details in Mind games: How social engineers win your confidence
"People running concert security often aren't even looking for badges," said Brushwood. "They are looking for posture. They can always tell who is a fan trying to sneak back and catch a glimpse of the star and who is working the event because they seem like they belong there."

Social engineers will also use humor and compliments in a conversation. They may even give a small gift to a gate-keeping employee, like a receptionist, to curry favor for the future. These are often successful ways to gain a person's trust, said Bushwood, because 'liking' and 'feeling the need to reciprocate' are both fixed-action patterns that humans naturally employ under the right circumstances.

Online, many social engineering scams are taking advantage of both human fear and curiosity. Links that ask "Have you seen this video of you?' are impossible to resist if you aren't aware it is simply a social engineer looking to trap you into clicking on a bad link.

Successful phishing attacks often warn that "Your bank account has been breached! Click here to log in and verify your account." Or "You have not paid for the item you recently won on eBay. Please click here to pay." This ploy plays to a person's concerns about negative impact on their eBay score.

"Since people spend years building eBay feedback score or 'reputation,' people react quickly to this type of email. But, of course, it leads to a phishing site," said Shira Rubinoff, founder of Green Armor Solutions, a security software firm in Hackensack, New Jersey. "Many people use eBay, and users often bid days before a purchase is complete. So, it's not unreasonable for a person to think that he or she has forgotten about a bid they made a week prior."

Recent phishing lures even take advantage of the economic downturn, said Rubinoff. It has not been uncommon for fake emails to turn up that claim to be from human resources which say: 'You have been let go due to a layoff. If you wish to register for severance please register here,' and includes a malicious link.

No one wants to be the person that causes problems in this economy, so any email that appears to be from an employer will likely elicit a response, noted Rubinoff. Lares' Nickerson has also seen cons that use fake employer emails.

"It might say, 'In an effort to cut costs, we are sending W-2 forms electronically this year,'" said Nickerson.

How can I educate my employees to prevent social engineering?
Awareness is the number one defensive measure. Employees should be aware that social engineering exists and also aware of the tactics most commonly used.

For elements of an effective security awareness program, see Seven Practical Ideas for Security Awareness and Now Hear This!.

Fortunately, social engineering awareness lends itself to storytelling. And stories are much easier to understand and much more interesting than explanations of technical flaws. Chris Nickerson's success posing as a technician is an example of a story that gets the message across in an interesting way. Quizzes and attention-grabbing or humorous posters are also effective reminders about not assuming everyone is always who they say they are.

"In my educational sessions, I tell people you always need to be slightly paranoid and anal because you never really know what a person wants out of you," said Lifrieri. The targeting of employees "starts with the receptionist, the guard at the gate who is watching a parking lot. That's why training has to get to the staff."

Social engineering tricks are always evolving, and awareness training has to be kept fresh and up to date. For example, as social networking sites grow and evolve, so do the scams social engineers try to use there; see 5 Facebook, Twitter Scams to Avoid and 5 More Facebook, Twitter Scams to Avoid.

The National Cyber Security Alliance recently launched a 'Stop.Think. Connect.' campaign to get users to give more thought to their online behavior so they recognize social engineering cons before they get in trouble.

But it isn't just the average employee who needs to be aware of social engineering. A study conducted in 2010 found executives are actually the easiest targets. In Social engineering: 4 reasons why executives are the easiest targets Jayson Street, a security consultant and CIO of Stratagem 1 Solutions, says executives are soft targets for many reasons, including a lax security attitude and their tendency to use the latest technology—even before it is properly vetted.

Although it's a tactic to use with great caution, fear of embarrassment is a strong motivator. Nobody likes to look foolish, and a successful social engineering test does make the victim feel foolish. This is partly why storytelling works—the reader or listener feels empathy for the person who "got suckered."

Consider this factor if you choose to design an in-house social engineering penetration test. A little embarrassment will put everyone on their toes; crossing the line to humiliation will only make employees angry.


Are there any tools to help make this process more effective?
A number of vendors offer tools or services to help conduct social engineering exercises, and/or to build employee awareness via means such as posters and newsletters.

Also worth checking out is social-engineer.org's Social Engineering Toolkit, which is a free download.

The toolkit helps automate penetration testing via social engineering, including "spear-phishing attacks", creation of legitimate-looking websites, USB drive-based attacks, and more.


MCTS Certification, MCITP Certification

Microsoft MCTS Certification, MCITP Certification and over 3000+
Exams with Life Time Access Membership at http://www.actualkey.com