___________    ____________    ____  __  ___    ______________
 |\    ____  \  |\    ____   \  |\   \|\ \|\  \  |\_____    ____\
 | \   \__|\  \ | \   \__|\   \ | \   \ \ \ \  \ | |   |\   \   |
 \  \    ___   | \ \    ____   \ \ \   \_| \_|  \ \|___| \   \__|
  \  \   \_|\  \_ \ \   \__|\   \ \ \      _     \      \ \   \
   \  \   \\ \   \ \ \   \ \ \   \ \ \     |\ http://www.haxworx.com
    \  \___\\ \___\ \ \___\ \ \___\ \ \____| \_____\      \ \___\
     \ |   | \ |   | \ |   | \ |   | \ |   |\ |    |       \ |   |
      \|___|  \|___|  \|___|  \|___|  \|___| \|____|        \|___|
                                                           

##############################################
#    Social Engineering 1 By BrainRawt       #
#    -------------------------------         #
#    Hacking My Way Into A Free ISP Account  #
#                                            #
#    Email: brainrawt@hotmail.com            #
#    Site: http://www.haxworx.com            #
##############################################

Updated on 5-11-02

You ever want something but not know how to get it?  Are you a hacker but you are having
trouble gaining access?  Change your way of thinking and move to the next level.

Study......Study People....

You dont have to know computers to be a hacker. People are hackable just the same.

Have you ever wanted something from your mom and she wouldnt give it to you?  Have you
ever gotten that something by being extra special to your mother?  You know what Im talking 
about...  "I love you mom", "You are the kewlest mom", "Just this once mom and i promise not
to tell dad".

These are classic samples of social engineering.  Now that we have the idea to what
exactly I am talking about, lets move on.  I am gonna walk you through a few hacks I have
pulled off in my time as an "engineer".


###############################################################
#  Hacking My Way Into A Free ISP Account  (lame but it works)#
###############################################################

I was targeting a certain ISP because they were local and I felt the need for dialup access on
an account that wasnt mine so that I could hack from it.

This has got to be the easiest and most dumbest hack ever.  

I called up this isp and talked to a man we will call Shawn.  I have changed all the real names,
addresses, numbers, and so forth to protect myself and those that I have engineered.

-------------------------------------------------------------
 thisandthat isp.  This is Shawn, how may I help you?

Hello Shawn.  How are you today? (As if I care? Im just sucking ass.)

Im good and how are you?

Im great. Thank you.

What can I do for you sir?

I want to get on the internet and I was told to call this number by a friend.

Is this the right number? (acting stupid makes them feel extra smart and extra secure)

Yes sir this is the right number.  Would you like to sign up for an account?

Can I do this over the phone or do I have to drive somewhere?

You can do this over the phone. (Im Thinking. YOU DONT KNOW WHAT I LOOK LIKE? YOU ALLOW THIS?)

Service will be $21.00 a month, I need a 1st and last name, a phone number, and a street address.

Are you interested sir?

yes I am.  Can I get on tonight and look at webpages on the internet? (acting dumb again)

It will take 24 hours to activate your account sir.  You can get on the internet tomorrow.

well......ok then.  I think I can do that then.

ok good.  Lets get you signed up.

ok

What is your 1st and last name sir?

Brian Huddle (Pulled that out of a phone book)

Street address?

372. N Green St. Indianapolis IN. 46**** (found that next to Brian Huddles name. :P)

OK Mr. Huddle.  What is your phone number?

892-567-35** (Bet you cant guess where I got that. hehe)

OK great. Do you want this bill to be sent to you monthly or do you just want it billed 
          to your home number?

home phone please.  (I was like WHAT? You really let me do that?  WHOA)

What do you want your username to be Mr Huddle?

My username? What do you mean? (acting stupid again)

The name in front of your email address.  bhuddle@thisandthat.isp. 
       (Now he thinks he is something special)

OHHHH hehe.  Im sorry.  this is new to me.  What you said will work fine.   bhuddle.

Ok Mr Huddle.  Your username is bhuddle and your pass is 5ng8skr.

How do you want me to send the setup instructions to you? Do you have a fax or do you wish that 
       I send them to your address?

Its ok Shawn.  My friend here says that he can set it up for me and that we dont need the 
           setup information. (I have already scoped them and gathered the dialup/dns numbers)

Ok then sir.  You should be ready to go in 24 hours.  Thank you for choosing thisandthat isp and 
       have a nice day.

Thank You Sir.  You have a nice day as well.

I now have an account at thisandthat isp as bhuddle to hack from for a month (safe time).  The real 
person wont get billed for a month and It is best that we not still be using the account when he/she 
calls the isp complaining of a bill that they shouldnt have.  There wasnt much social engineering in 
this story other than acting normal and alittle computer illiterate.  If this ISP performed on a more 
secure level, they would never allow anyone to sign up without PROOF of id.  I still to this day can 
call that ISP and get an account using this same method.

    Source: geocities.com/eljehad1/se

               ( geocities.com/eljehad1)