Live data from Hacker News

The Beirut Bank Job (2017)

darknetdiaries.com

1–10 of 44 posts

Re: The Beirut Bank Job (2017)

#4

Where does it say he was in the wrong bank?

I found this story yesterday and was quite confused as well, because in the YouTube video of him telling the story that they link, he just leaves that part out. But in the audio at the top of the page (and the transcript), he explains it.

Re: The Beirut Bank Job (2017)

#6
post #5

Where does it say he was in the wrong bank?

It doesn't. He walked up to the door of the wrong bank and his driver alerted him.

That’s a different incident. There’s another, much more serious wrong-bank story near the end of the interview.

Re: The Beirut Bank Job (2017)

#9
post #5

Where does it say he was in the wrong bank?

It doesn't. He walked up to the door of the wrong bank and his driver alerted him.

My wife just shared this podcast with me. That’s in the first two-thirds - the last third is where he breaks in to the wrong bank.

Re: The Beirut Bank Job (2017)

#10
Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping default accounts had not been disabled and was quickly in. Having a look about it turned out very quickly to be a financial system that had nothing to do with the client. Actually seemed to be a case of the system was sharing data and a college of mine soon pointed out that this stunk at not only a security level but more importantly the financial services regulation. We did the report and that whole aspect got swept under the carpet and I was never asked back to that clients site ever again.

That's not the worst story of security within a financial service company/bank I've experienced but sure did start to open my eye's how interlocked some companies are with others who you would not expect for numerous reasons.

I will say that if you do find yourself in places you wasn't expecting, you do notice and notice pretty quickly and raise questions, also you start to become more mindful - "how easy would it be to social engineer penetration testers to break into a bank for you", it's a thought and more so as they would just need to engineer management to task you such a job. Not aware of that happening, but can easily see how that could be orchestrated.

Post reply on HN