Social Engineering > :marseyhacker:

https://twitter.com/vxunderground/status/1701758864390050145
59
Jump in the discussion.

No email address required.

I'm surprised this doesn't happen more often.

Ask the average service desk wagie how they verify a user's identity before they reset their password and they'll just look at you like :marseyblankstare:

Jump in the discussion.

No email address required.

"Need a password reset Mr. Sneed? Sure, I've reset it to Bu$$y1488. Have a good day."

And that's all I need to do. 2-factor authentication tied to their direct phone number takes care of all that pesky "verification" shit.

Jump in the discussion.

No email address required.

>he can get people to actually set up their stupid company phones

Wow. What planet do you live on?

Jump in the discussion.

No email address required.

Have our users set THEMSELVES UP? :marseylaugh: oh lord no! We set their phones up with Microsoft Intune. Idk how that wizardry works, that's not what I'm paid for, but it takes care of everything behind the scenes.

Jump in the discussion.

No email address required.

Error: This device is not compliant! :marseysnappyenraged2:

I'm assuming that intune has some sort of auto flashing feature that our server monkeys haven't figured out :marseydepressed:

Jump in the discussion.

No email address required.

Some of that shit comes from the top down too because otherwise god forbid sysadmins or infrastructure teams might have to get off their butt and make something that looks like it was developed after 2005.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.