Owning the Auditors: WPA-PSK and USB Sticks

94
vote

It is once again that time of the year where our company goes through it annual audit. This is mostly a painless process for the IT department, with the exception of having to collect a few files and some data from the transaction history. However, given that our IT staff has been around for several years, we know the routine. One other advantage to workplace longevity is that we also know the auditors, who we see several times during the year. As a result, there is some friendly banter between our department and the members of the audit team. While this is mostly harmless, this year the auditors raised the ante and gave us permission to try to "own" them. The follow details what we did to accomplish this and provides both an entertaining and educational illustration as to the dangers associated with plugging into an un-trusted network and assuming people won't mess with your data.

Continue reading here....