Services
View this document in PDF format
Internet Security Testing
Any device with access to the Internet is a potential open door to would-be hackers.
Mitnick Security Consulting provides vulnerability assessments during which it
closely maps the network architecture, examines all open ports, hosts and services
with access to the Web, and ensures that these network devices are secure. Defensive
thinking gathers information such as domain names, IP network ranges, operating
system and applications, to identify systems on the network, how they are related,
the services that are exposed through open ports (such as http, SMTP, terminal
services, etc.). Once open ports and attached services are identified, Mitnick
Security Consulting determines whether each service has been updated with the
most recent patches and identifies other vulnerabilities located within the exposed
services.
In addition to conducting vulnerability assessments, Mitnick Security Consulting
performs more rigorous penetration tests in which the information gathered from
its assessment is used to attempt to penetrate the network. This more thorough
procedure can confirm whether potential vulnerabilities are, in fact, capable
of being exploited to expose the network.
Following all vulnerability assessments and penetration tests, Mitnick Security
Consulting uses the information it gathers to prepare a thorough vulnerability
analysis and offers recommendations for strengthening network security.
Intranet Security Testing
While outside threats must be guarded against, business must also protect against
potential threats from within their own networks. Using many of the same techniques
and procedures for Internet Security Testing, Mitnick Security Consulting provides
Intranet risk assessment and analysis to protect against the potential threat
posed by insiders.
Depending on the client’s needs, intranet testing can be performed by
Mitnick Security Consulting under varying degrees of disclosure of network information
from the client, for example with or without network accounts.
Dial-in RAS Security Testing
Dial-in links pose a potential threat to the integrity of the network security
system. Mitnick Security Consulting examines dial-up connections that allow
employees to access the network through public telephone lines or other dial-up
connections. Given a range of telephone exchanges that may include modems, Mitnick
Security Consulting can identify target numbers that allow for remote access.
Using these numbers, Mitnick Security Consulting attempts to exploit vulnerabilities
in the system and gain access to the network. Mitnick Security Consulting can
also assess risks posed by the exposure of dial-up connections to the public
telephone network which might undermine the client’s own internal security
architecture.
Web Application Assessment
This assessment examines what services are being offered on Web-based portals
and e-commerce applications to examine potential vulnerabilities with respect
to authentication, authorization, data integrity, data confidentiality, and
consumer privacy concerns. Mitnick Security Consulting can test these applications
using either zero-knowledge testing or full-access testing to examine the full
range of potential vulnerabilities. Mitnick Security Consulting also conducts
source code audits to identify any potential vulnerability among the applications
and scripts that are accessible through the Web.
Wireless Assessment
Wireless networks, while highly convenient, present additional security threats
since the wireless signals are not limited by the physical boundaries of a traditional
network. Mitnick Security Consulting evaluates how to prevent wireless communications
from being exposed to eavesdropping and access by unauthorized intruders. Additionally,
Mitnick Security Consulting examines the enterprise infrastructure for unencrypted
or standard WEP enabled access points that may be vulnerable in order to ensure
the security of the network.
Social Engineering Assessments
Social engineering involves manipulating and/or deceiving company employees
and other human resources to gain unauthorized access to a network or to confidential
information. Mitnick Security Consulting is the premier consulting firm in its
ability to identify weak links in the security chain through exploitation of
human vulnerabilities.
Mitnick Security Consulting’s principal, Kevin Mitnick, is widely recognized
in the industry as the foremost authority on the topic of social engineering.
His book The Art of Deception: Controlling the Human Element of Security offers
an authoritative examination of potential threats posed by social engineering
attacks. Mitnick Security Consulting leverages its unparalleled expertise in
this field to expose what is often the weakest link in the information security
apparatus: the human element.
Once individual or systemic weaknesses are identified, Mitnick Security Consulting
recommends procedures designed to ensure that employees do not divulge information
that could compromise company assets. The social engineering assessment not
only uses tactics intended to gain confidential information, but also to induce
unsuspecting employees to create vulnerabilities that can subsequently be exploited
to gain access to confidential information.
Telecommunications Assessment
Mitnick Security Consulting has unique experience testing vulnerabilities in
private bank exchanges that operate company voicemail and messaging systems.
Unauthorized access to these systems can allow an intruder to eavesdrop on and
manipulate employee voicemail messages, initiate outgoing calls from internal
company lines, and access corporate telephone networks and directories.
Database Assessment
Client lists, credit card records, and other confidential information held in
databases must be given particular protection from unauthorized disclosure.
Mitnick Security Consulting tests database integrity to determine whether any
vulnerability may compromise this sensitive information.
Physical Security Testing
Access to confidential information can often be obtained by simply gaining physical
access to company premises. Mitnick Security Consulting conducts on-site surveillance
to assess physical security and uses social engineering, pass key duplication,
and other techniques designed to gain physical entry into secure areas and the
network system.
Forensics
In addition to preventing future attacks, Mitnick Security Consulting can conduct
forensic analysis to evaluate past security breaches. This analysis examines
log reports, compares backups to identify modifications to the network, and
investigates the introduction of foreign software tools to help identify intruders,
determine the extent to which the network has been compromised, and mitigate
potential damages from the intrusion.
Training
Mitnick Security Consulting provides training seminars to IT professionals and
employees with access to sensitive information to better educate them about
the risks of social engineering and how to prevent themselves from falling prey
to ruses posed by competitors or malicious intruders. These seminars are dedicated
to preventing human error from undermining an otherwise robust information security
infrastructure.
|
 |
 |
Get Kevin's Business Card |
 |
 |
 |
Watch Barry pick a lock using Kevin's business card
Send your IP address and password (just kidding) to:
2245 N. Green Valley Parkway
Suite 411
Henderson, NV 89014
Please enclose $5 cash (no other form of payment is accepted) plus a self-addressed stamped envelope, otherwise you can attend one of my speaking engagements to obtain a free lock-pick business card.
Please note, if the correct payment and the SASE are not enclosed, we will cancel the order and absolutely nothing will be returned to you. Accordingly, please correctly order one or more of my business cards by properly following the above instructions.
If you are located outside the USA, please include a prepaid self-addressed envelope (you can use FedEx, DHL, or UPS) and enclose either 5 dollars, Euros, or GBP, cash only, for each card.
We don't accept any other currencies.
|
 |
 |
 |
Recent Press Coverage |
 |
 |
 |
The people involved in sale of lost iPhone revealed
Apr 29, 2010 - CNET News
Mitigating the social engineering threat
Apr 21, 2010 - TechRepublic
Ataques más comunes en Internet
Mar 18, 2010 - Euskadinnova.net
Kevin Mitnick to keynote World Game Protection Conference
Feb 16, 2010 - SecurityInfoWatch.com
Smoking the Competition: Creative business cards are the ones people remember
Feb 2010 - Entrepreneur Magazine
Hackers for Hire
Feb 2, 2010 - Fox News
IT pros pick their favorite books
Dec 21, 2009 - SearchWinIT.com
My Favorite Hackers
Dec 3, 2009 - Discovery News
Entrepreneurs Who Thrive on Risky Business
December 4, 2009 - BusinessWeek
Q&A: Kevin Mitnick, from ham operator to fugitive to consultant
June 22, 2009 - Cnet News
First Person: Kevin Mitnick
May 30, 2009 - Financial Times
5 Ways to Foil Hackers
May 28, 2009 - Alibaba.com
'Twitterjacking' -- Identity Theft in 140 Characters or Less
May 1, 2009 - Fox News
High-Tech Defectors
April 29, 2009 - Forbes
Facebook: Will the real Kevin Mitnick please stand up?
March 16, 2009 - Cnet News
World's Greatest Hacker Says Obama's BlackBerry Can Be Breached
February 13, 2009 - Fox News
Hacker Hunter
December 2008 - Psychology Today
The tried-and-true identity theft technique: Talking you into giving up your information
November 1, 2008 - The Privacy Council
Kevin Mitnick: The Magic Hacker Reformed
October 1, 2008 - GovTechBlogs.com
Kevin Mitnick Tells All in Upcoming Book -- Promises No Whining
August 28, 2008 - Wired.com
Reformed Hacker Looks Back
August 21, 2008 - Forbes.com
Hacking Caller ID: unblocking blocked phone numbers
July 23, 2008 - CNet.com
Uber-Hacker Kevin Mitnick Signs Tell-All Book Deal
July 20, 2008 - Silicon Alley Insider
Social Engineering 101: Mitnick and other hackers show how it's done
July 20, 2008 - CNet.com
5 lessons learned about computer security
July 14, 2008 - CIO.com
Mitnick is on the Die Hard 4 Special Edition set
DVD Times
Interview: Ex-hacker Mitnick On Avoiding Fraudsters
Mar. 31, 2008 - Practical eCommerce
Super Phreak: Ed Piskor Talks "WIZZYWIG"
Feb. 1, 2008 - comicbookresources.com
Fred
Thompson's Record: Cybersecurity Good, Free Culture Bad
Sept. 5, 2007 - Wired.com
The IRS gets socially engineered again!
August 3, 2007 - MSNBC
Kevin
Mitnick presents at Infragard General Meeting
July 18, 2007 - Matt Hester
The
59 Top Influencers in IT Security
July 9, 2007 - kutakutik.or.id
A
portable sense of security
July 6, 2007 - examiner.com
The Invisible Digital
Man
June 2007 - Playboy
Hacker
to Write Autobiography
February 2007 - Sydney Morning Herald
Security's
25 Most Influential
December 2006 - Security Magazine
Man
on the Run
September 2006 - American Way
Kevin
Mitnick on HP's Hack Attack
September 2006 - Red Herring
read more >>
|
 |
|