Network Security & Hardware - eWeek

Network Security & Hardware: LABS GALLERY: SocialPET Lets Businesses Phish Their Own Employees to Test Security Smarts


One of the biggest security risks that companies face is employees who fall victim to phishing e-mails, which can lead to stolen log-in credentials and virus infections. SocialPET is a simple Web-based testing tool that lets businesses run their own phishing tests to find out which employees understand security procedures and which are at risk to falling prey to real phishing scams.
 
  • LABS GALLERY: SocialPET Lets Businesses Phish Their Own Employees to Test Security Smarts
    by Jim Rapoza
  • Setup
    To get started with SocialPET, you add the names and e-mails of the users who will receive the test phishing e-mail and create a false e-mail to send the message from.
  • Templates
    SocialPET includes a number of templates for different security tests, including sending info on a new Web mail interface and information on a required system patch. The templates create basic e-mail text that can be edited.
  • The Phish
    Once a SocialPET test has been activated, users receive a phishing e-mail directing them to a fraudulent Website.
  • The Response
    In this test, users are sent to a fake Outlook Web Access page. No matter what log-in is used, the page will fail to load and will return to the log-in page.
  • Fake Patch Page
    Other phishing tests include fake patches and fake anti-virus pages. On this page, clicking on the Download and Apply Patch button will do nothing (except notify the admin that the employee has failed the test).
  • Basic Reports
    Once a phishing test is completed, SocialPET provides basic reports that show how employees fared on the test. The report also displays a graph comparing your company's score against other companies'.
  • Report Details
    Additional reports include details about what individual employees did during the phishing test. SocialPET can also generate a PDF report.
xڽZ[s6~~;vƑQ|5/{ HBj`P}H jy|8oi&4oAuB>K9lHbc.!KvfzC7o``ƛVYQ|v$UK*7-;RLDL1OwҨxL^>.B࿏F:|=F#mX021q #yF.#An{R7Yh[((6j{A،LQLDruzH&$fvȿ+|>o~QLg\M<4#9 "L7'f*Ή{'_tt6g4Wln(3сױ1,?ۈnS3aܰ)M)vtZ4ܪwP臑WhNdm\)N;-<><:1)+Vʢ M&x9tKS:f:bLόGA7|TR_`O ! =bA.|vأY.sJ՘'>l?v#=bmLƝ>2VFΖhR=*dE` rR~/) *xjzָdBaL7ܔGRChC2/A ˕$ QsjIiP":L8%=v$"Zu0o|k^$8;HFY_ѰJ:*w"d'rf+F k@1zvHQ9ZI9mab(bZWZO;­S҂WM@YblI[7MNO$GkĿd4w$K[/N=pbGCmr5xj3EFT '-4M|?${i)lp_f*BlK'45JtϓXZɟ8yIJL,Hv_I:`L?@:v^R>  GJj92 ֹt. X ST$T񝊽` w>^U4K ױO@` y|ȄR\@~HKVc- + A׽2&X: fdwwCRdvau,sDk} X4I8]P:F׋' q Y|3!S`_/GvujC7swFʑUBCRW USҀ|9OΞf[rfLt ^i'PuqS;QMYK 9,$lcG̓W\!JfI+knsqeQapS#Z7>g67c 3O#$vjڧDw% vӂֽWˆלWestOuO~)\9c.4ga-q a cp+)=jѤ:6*7p}SUA^8/VK@V ncFјjTT>g_Y#xO3+(XP.u1sgֽ]0? V|țjUxמo4g{l qEig`oiXI%k#׉x`+,B!S]OLmSgNVӪ2讞]BU:m-.U3g`GG*ar;LmTkqء9j[Xo2cQ JvV_ܔ&˼C]`I`z#p7PD'RMApuPy#y&յy8$Pc.kEb oDz j*cnW~#Z3H䈘 M؞(.D-bt7")th8ɗn &5 ;όF)xp98R.'2]([yw~ޑZuU )RX^c݆̪f;OY*@Λ5`(3<>v&NXyB)@ SPpxdMADfTaz8ak`9 &*nZS4,PB qٓu"fˆI^KerDdTF-V% yD&'.mϹZ4%|f5!jC΅knVuoP7`Tcy^d `. )3_Qg dw %+7L>x G?HA W{1q;b!+l{rČaUjDOaXnI hNjqE,~BA{S(Ж 3:E !hw==]},w<5DaهyukО&w0.]#H1 &Կã~F:d#[JFcDxʵ;horV4Z[i~gF9.J%*2b24(55mtI*ז׸י]^s/1שro-2^7^4 es>,