Ethical › Module 9 › Lesson 3
Countermeasures: Verify Out of Band
Callback rules, badges, MFA, reporting.
Visual · verify_out_of_band
Out-of-band means a channel you already trust: a number on the card, an official app, a badge check, MFA you never read to a caller. Report; do not send a test phish.
Opening
Verification is a second channel you already own — not a reply inside the lure, not a campaign you launch.
Lessons 1–2 named the mechanics and the shapes. This lesson names the controls: callback rules (you hang up and call a number you already have), badges and visitor process (politeness is not authentication), MFA (a second factor the message cannot complete — never read the code to the caller), and reporting (Topic 5’s official buttons, not forwarding malware to a group chat). Out-of-band (OOB) means the check does not travel inside the suspicious channel. This is original Cyberlium teaching mapped to the CEH v13 social-engineering domain — not official EC-Council training, not a certification, not exam dumps. Countermeasures are habits you write for YOUR household and YOUR accounts. They are not a reason to phish coworkers “to train them.” Next is Lab — Family Callback Rule: you write the habit; you never send a test phish. Here you lock se-countermeasures-notes.txt, chmod 600.
1. Callback rule: you initiate, on a number you already have
A callback rule is a pre-decided habit: if an unexpected call, chat, or mail asks for money, a password, an MFA code, a badge buzz, or a “quick install,” you stop. You do not continue in that channel. You use a number printed on YOUR card, a contact you saved last year, the official app you installed from the real store, or a walk to the desk. You do not call back the number the SMS provided. You do not click “Call support” in the lure. The attacker wants the verification to stay inside their theater. OOB is you leaving the theater.
Write the rule in boring language so panic can still follow it. Example shape (you will personalize in the lab): unexpected ask for secret or money → hang up / close the thread → open the app I already have or dial the number on the card / in my address book → if it was a workplace claim, use the IT path my employer published, not the lure’s phone. Family members who do not want a written file can still hear the one-sentence version. This course does not require you to drill them with fake calls. Telling them the rule is optional; sending them a lure “so they learn” is forbidden.
Command guide
Callback rule — WHAT/WHY (you initiate, number you already have)
═══ COMMANDS ═══
Command — copy this
cat >> "$NOTES" << 'EOF' callback_rule: I hang up, I look up a number I already have, I initiate not_callback: calling back the number on the caller-ID of a surprise call EOF
2. Badges and doors: the physical twin of MFA
A badge, turnstile, or receptionist log is a second factor for a building. Holding a door because someone has a box is skipping that factor — Lesson 2’s tailgating, now as a control you keep. If you work or study somewhere with badges, the literate habit is: I badge myself; I do not badge-in a stranger; I send visitors to the published check-in. You do not test this by trying to sneak into a building you do not control. You write the habit. Campus and employer physical security are their RoE, not your homework.
If you have no badge environment, write that honestly: my countermeasure is not holding unknown people into shared housing against a roommate’s lock, and I do not treat a café back room as a tailgating gym. Physical literacy without a workplace is still refusal plus reporting a real incident to building staff you already know — not a sting.
3. MFA and reporting: Topic 4–5 controls, still not a people-test
MFA is the silicon callback: something you have (a device prompt, a hardware key) that a mail thread cannot complete. Attackers who phish passwords then call to harvest the code are collapsing OOB back into-band. The counter is: never read a one-time code to a caller; never approve a prompt you did not start; if a prompt fires unexpectedly, deny it and check the official app. Unique passwords (Topic 4) shrink blast radius if a phish still gets one secret. MFA does not undo a wire you already sent. Name the theft, then pick the control — Topic 5 again.
Reporting is how the next inbox gets a filter. Use Report phishing in YOUR mail client, junk/block on SMS, store/app report if a listing was involved, and YOUR bank’s number on the card if money moved. Do not forward the attachment to family “so they see.” Do not hack back. Do not invent a government URL. Topic 5 Module 3 already covered official paths. This module only insists reporting is a countermeasure, and sending a test phish to coworkers is not “awareness training” unless a separate employer program with written RoE exists — which Cyberlium does not assign.
4. What the notes file holds: habits, not a red-team calendar
se-countermeasures-notes.txt: disclaimer, callback rule in your words, badge/door habit, MFA habit (never read the code), reporting path you actually use, NEVER list (no kits, no test phish, no SET/Gophish, no vishing), ethics. chmod 600 at $HOME/cyberlium-lab. Empty placeholders fail. A calendar of “phish the team every Friday” fails. Live OTPs and real card PANs in the file fail. The lab next lesson expands the callback rule into family-callback-rule.txt; this file is the control list that lab will assume you understand.
If you live alone, the “family” in the next lab title still means a rule you would give a household — you can write it for yourself as the only operator. You still do not send a lure to a friend to complete the feeling of a pentest.
5. Wrong vs right: in-band compliance vs OOB callback, badges, MFA, report
Worked failure — same word “verify,” opposite channel. Right leaves the lure’s theater.
Wrong
Call the number in the SMS. Read the MFA code to “IT.” Hold the badge door. Forward the .html to the family chat as training. Stand up Gophish against coworkers and call it awareness. Skip chmod. Store live OTPs in notes. Claim this is official CEH countermeasure labs.
Right
Hang up; dial a number you already have or open the official app. Do not hold a controlled door. Never read MFA to a caller. Report via official buttons. Write se-countermeasures-notes.txt chmod 600. Next: Lab — Family Callback Rule — still no sending test phish.
6. Hands-on: se-countermeasures-notes.txt — habits you will not test by attacking
Fill the headings. Run the checker (reads YOUR file only). chmod 600. Do not add SMTP tools. Windows: WSL/Git Bash or profile ACLs.
Command guide
MFA and reporting — WHAT/WHY then lock
═══ COMMANDS ═══
Command — copy this
cat >> "$NOTES" << 'EOF' report_where: (family chat / work ticket — fill) MFA_on_my_accounts: (Y/N/partial) still_not: a people-test of classmates EOF
Mission: se-countermeasures-notes.txt in cyberlium-lab (mode 600)
1) Write a callback rule, a badge/door habit, an MFA habit (never read the code), and a reporting path you actually use. 2) Fill $HOME/cyberlium-lab/se-countermeasures-notes.txt; run the checker; chmod 600. 3) Do not send a test phish. Do not vish. This is not official EC-Council training.
Stuck? Ask Cyberlium AI Mentor
If “the only real countermeasure is phishing my household so they click once” still feels true, ask for a hint — not a lure. Try: "Hint only: what is verify-out-of-band (number I already have / official app), why I never read MFA to a caller, why reporting is an official button not a group-chat forward, and where se-countermeasures-notes.txt lives at $HOME/cyberlium-lab chmod 600?" You still fill the file. No Gophish. No family sting.
You now treat verification as a channel you already trust — callback, badges, MFA, reporting — and you treat in-band compliance and “awareness phish” as failures. Notes are locked. This is original Cyberlium teaching mapped to the CEH v13 social-engineering domain, not official training, not a dump. Next — Lab — Family Callback Rule — you write the habit. You never send a test phish.
Knowledge Check
APPLY: An SMS says your bank will lock the account; it lists a phone number. What is OOB verify, and what is not?
Multiple choice
Knowledge Check
APPLY: True or False: Reading an MFA code to a caller who claims to be IT is “using the second factor,” and holding a badge door is polite MFA.
True or False
Knowledge Check
APPLY: Which notes pairing matches Lesson 3?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice