Waraxe IT Security Portal
Login or Register
September 5, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 1407
Members: 0
Total: 1407
Full disclosure
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 /CVE-2026-12556
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
O-CMS 1.0.0 Authenticated OS Command Injection viaai_cli_script
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read
Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass
Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure
Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API
Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read
Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server
Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server
WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf
thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirectCGI Program
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Phishing and Social Engineering -> First post ?
Post new topicReply to topic View previous topic :: View next topic
First post ?
PostPosted: Tue May 09, 2006 11:08 pm Reply with quote
ToXiC
Moderator
Moderator
Joined: Dec 01, 2004
Posts: 181
Location: Cyprus




That seems to be the latest thread in the world of the internet ... Social engineering will never be out dated because we are humans and we are allowed to make mistakes. The thing is that we have to be aware not to make the same mistake all the time ..

I bought a t-shirt thats says Social Engineering specialist. Because there is not patch for human stupidity ... I am with that quote and i beleive thats the main idea behind Social Engineering and phishing.

well phishing is not just a hotmail scum or yahoo or anything else. Phishing can be used for ANY login screen .. may be a cpanel screen may be a paypal login screen and so on .. Anything that has the following form :

Quote:
username :
password :


Smile emm seems silly but .. its the truth..

ok .. now .. i know waraxe is doing a great job on that .. and thats a nice new section on the forum .. but we need some permitions to open an online scum service Razz

good work waraxe

_________________
who|grep -i blonde|talk; cd~;wine;talk;touch;unzip;touch; strip;gasp;finger;gasp;mount; fsck; more; yes; gasp; umount; make clean; sleep;wakeup;goto http://www.md5this.com
View user's profile Send private message Visit poster's website MSN Messenger
PostPosted: Fri May 26, 2006 2:36 am Reply with quote
Torian
Regular user
Regular user
Joined: May 26, 2006
Posts: 8




social engineering is EASY

some tips to get beginners started...

to get his/her birthdate
"when is your birthday? i want to get you a present!"

to get his/her postal code
"can you give me your full address so i can send you a postcard?"

just make it very subtle and dont bombard the victim with questions.
View user's profile Send private message
PostPosted: Fri May 26, 2006 4:05 pm Reply with quote
fizzi
Advanced user
Advanced user
Joined: Sep 14, 2005
Posts: 55




Anybody found already the login screen to the matrix?
<lol>
Rolling Eyes
View user's profile Send private message
PostPosted: Mon Nov 26, 2007 3:23 pm Reply with quote
quinda
Beginner
Beginner
Joined: Nov 25, 2007
Posts: 1




Torian wrote:
social engineering is EASY

some tips to get beginners started...

to get his/her birthdate
"when is your birthday? i want to get you a present!"

to get his/her postal code
"can you give me your full address so i can send you a postcard?"

just make it very subtle and dont bombard the victim with questions.


The great thing about social engineering is that if someone is 'free and easy' with information like that, they usually are careless enough to use the same password for several sites / purposes. So once you get their 'just another forum' login, the chances are you've got their work / bank / pc details too Smile
View user's profile Send private message
PostPosted: Sun Dec 06, 2009 1:02 am Reply with quote
amlord1
Beginner
Beginner
Joined: Dec 06, 2009
Posts: 1




Torian wrote:
social engineering is EASY

some tips to get beginners started...

to get his/her birthdate
"when is your birthday? i want to get you a present!"

to get his/her postal code
"can you give me your full address so i can send you a postcard?"

just make it very subtle and dont bombard the victim with questions.


Lol, this is an old post, but I thought this was funny; for many online games, people are not supposed to give out birthdays because it truely is a safety hazard; all you need to steel someone's account and reset their info is their birthday, first name, and their log in name. All of which are easy to get; start a conversation; ask how old they are; then say your the same age; "WOW ME TOO! When were you born?" automatically have their birthday. And you know the year, because of how old they are. Their name is what you get in the beginning, because you say "hi, my name is_____" and they are likely to give you theirs. Login name is somewhat harder; but what's funny, is once you get into a conversation, just look for a few things; ask for an MSN or email address. Guess what; if their in game name (IGN) matches their email address, then chances are that's also their login name. If not, ask if they have a main account. This works for many things other than just online games.

Be creative, and always be smarter than the target.
View user's profile Send private message
First post ?
www.waraxe.us Forum Index -> Phishing and Social Engineering
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.037 Seconds