Top Banner
COMPLIACE CHRIS NICKERSON Guerillas in the Wires
159

Guerrillas in the Wire

Apr 14, 2018

Download

Documents

LARES
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 1/159

COMPLIACE

CHRIS NICKERSONGuerillas in

the Wires

Page 2: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 2/159

the Wires

hi. =)

Page 3: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 3/159

Thanks

Page 4: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 4/159

Page 5: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 5/159

Page 6: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 6/159

Page 7: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 7/159

Page 8: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 8/159

Page 9: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 9/159

Page 10: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 10/159

Page 11: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 11/159

Page 12: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 12/159

Page 13: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 13/159

Page 14: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 14/159

Anyway...

Page 15: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 15/159

I’m Chris 

Page 16: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 16/159

Page 17: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 17/159

Page 18: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 18/159

Page 19: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 19/159

Page 20: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 20/159

-me

• Pain in the arse

•Loudmouth

• Hacker Punk

• Tells lies (professionally)

• Is called all sorts of bad

words.. That I will likelysay throughout this talk

• Cant code well

• Talks $hit

Drinks a LOT• Is an overall J3rk

Page 21: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 21/159

Page 22: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 22/159

Page 23: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 23/159

Page 24: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 24/159

Page 25: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 25/159

Page 26: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 26/159

Page 27: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 27/159

LARES

Page 28: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 28/159

Page 29: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 29/159

Page 30: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 30/159

Page 31: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 31/159

Page 32: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 32/159

Page 33: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 33/159

Page 34: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 34/159

Electronic• Network Pentesting

• Surveillance/ plants

Social• In Person Social Engineering

• Phone Conversation

• Social Profiling

Physical• Lockpicking

• Direct Attack

EP Convergance

• Attacks on

physical

systems that

are network

enabled

ES Convergance

• Blackmail

Phishing• Profiling

• Creating moles

PS Convergance

• Tailgaiting

• Impersonation

Page 35: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 35/159

Figure Out Whatis Important tothe company

Steal It !

Page 36: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 36/159

Page 37: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 37/159

Page 38: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 38/159

To get you awake

Page 39: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 39/159

Get you to THINK about

what we are doing

Page 40: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 40/159

Page 41: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 41/159

So… 

Page 42: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 42/159

Page 43: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 43/159

Page 44: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 44/159

Page 45: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 45/159

Page 46: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 46/159

Page 47: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 47/159

Page 48: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 48/159

Page 49: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 49/159

Page 50: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 50/159

Page 51: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 51/159

Page 52: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 52/159

We areclearly

doingsomething

wrong

Page 53: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 53/159

Page 54: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 54/159

Page 55: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 55/159

2012 Infosec Year In review 

2,644 incidents were reported (Up117.3% from 2011)

267,000,000 records exposed

Over 150,000,000 in ONE incident

84.7% of the records exposed camefrom business

45% of incidents included publicreleases of passwords

Page 56: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 56/159

Page 57: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 57/159

Page 58: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 58/159

Persians vs Scythians

Page 59: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 59/159

ROME vs Britons

Page 60: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 60/159

Page 61: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 61/159

Mongolians vs Tanguts

Page 62: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 62/159

Vs.

Page 63: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 63/159

Page 64: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 64/159

El Empecinado

Aka

Juan Martín Díez

Page 65: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 65/159

Page 66: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 66/159

Page 67: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 67/159

Page 68: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 68/159

Page 69: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 69/159

Page 70: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 70/159

Page 71: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 71/159

Page 72: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 72/159

Page 73: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 73/159

Page 74: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 74/159

Page 75: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 75/159

Page 76: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 76/159

Structureexists even

in Guerilla

warfare

Page 77: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 77/159

Page 78: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 78/159

h l

Page 79: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 79/159

The only

patch for

Human

Stupidity isEXPERIENCE

Page 80: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 80/159

Page 81: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 81/159

Page 82: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 82/159

So how does

all of this

apply to us?

Page 83: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 83/159

Environment

AttackerDefender

Home Field

Advantage 

Page 84: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 84/159

Page 85: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 85/159

Page 86: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 86/159

 

Page 87: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 87/159

Page 88: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 88/159

Page 89: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 89/159

Page 90: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 90/159

Page 91: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 91/159

Page 92: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 92/159

ENCRYPTION

Own the box/steal the keys

Page 93: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 93/159

Keylog

GPU Cracking is fun TO the cloud!!

Attack 3rd party crypt

And if all else fails… 

Page 94: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 94/159

Page 95: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 95/159

Page 96: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 96/159

 Nmap… --data-

length=0

Or –f

Or just go faster –T5

Lame… that this STILL

works in many cases

Page 97: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 97/159

Roll your own crypto

Page 98: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 98/159

Use “other” data streams

(mDNS, Airdrop,BITS,DNS, HTTP,SIP)

Go to the phones..

(Translate to 16 octave

audio and exfil over fax)

Hopefully you sawSteffen Wendzel’s talk

if not go find em

Page 99: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 99/159

Page 100: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 100/159

 AV/Anti-

Page 101: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 101/159

Page 102: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 102/159

Page 103: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 103/159

Custom checksums are

not hard… theres

apps for that =)

Page 104: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 104/159

Clearthelog.rb

Page 105: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 105/159

… rm

Run scripty logcleaners in your

tools*MSF,CORE,CANVAS all

have **so do mostexploit kits (yeay

china)

Page 106: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 106/159

Of the

Page 107: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 107/159

6Top Firewalls

How many can

effectivelyblock TCP ports?

Page 108: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 108/159

-Source NSS Labs Firewall Group test

:Section: TCP Split Handshake

Page 109: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 109/159

Page 110: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 110/159

Page 111: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 111/159

Page 112: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 112/159

Page 113: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 113/159

Page 114: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 114/159

Page 115: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 115/159

WHAT DO

 WE DO?

STEP 0

Page 116: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 116/159

STEP 0

EDUCATION

Page 117: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 117/159

Implement

Page 118: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 118/159

Implement

Awareness

and

KnowledgeFormula

Page 119: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 119/159

Defense = capability (awareness + knowledge) +experience

Capability =(Knowledge + Awareness) Can we defend

against an attack?

Experience – over all ability to

understand/plan/execute/and remain on task during

the event

**ps… this is not math… just conceptual. Most companies out there couldn’t put

actual ACURATE values on controls or any of the areas above if they even tried.

Crawl,walk,run… 

Page 120: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 120/159

Page 121: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 121/159

Page 122: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 122/159

Practice

BASIC

INFOSEC!

Patching

Page 123: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 123/159

Patching

Page 124: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 124/159

“The more

sophisticated

Page 125: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 125/159

sophisticated

thetechnology, the

more vulnerable

it is toprimitive

attack. People

often overlook

the obvious” –

Dr WHO

Page 126: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 126/159

Align With

the business

objectives

Page 127: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 127/159

Page 128: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 128/159

Page 129: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 129/159

Page 130: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 130/159

What does

your company

DO???

Page 131: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 131/159

How does it

do it?

Page 132: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 132/159

Page 133: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 133/159

Page 134: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 134/159

Page 135: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 135/159

Now what?

Grow Revenew Buy firewall

Page 136: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 136/159

Increase Productreliability

Increase brand

value

Launch xyz new

thing

Increase customerservice/satisfaction

Deploy DLP

Move to Cloud

Install moar AV

WAF

Page 137: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 137/159

Page 138: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 138/159

Page 139: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 139/159

Page 140: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 140/159

How much do

Page 141: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 141/159

you spend onDisaster

Recovery.

(Average is

1 8% t t l

Page 142: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 142/159

Average costof a

downtime

$287,600

Multiply that

Page 143: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 143/159

by the # ofbugs found in

code that can

stop aservice

Page 144: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 144/159

Page 145: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 145/159

TEST TO SEE IF ITWORKS….. DUMMY 

VulnerabilityAssessments?

Page 146: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 146/159

Page 147: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 147/159

Page 148: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 148/159

Process

Page 149: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 149/159

Figure Out Whatthe Company

Thinks is Important

Steal It !

Page 150: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 150/159

5

+ Customdesigned attack

kitsAt ANY time

Non Interactive,without update

+ CorporatePartner Attacks

4 + 0daydevelopment

At ANY time

Non Interactive,Without update

unlessurgent/issue

based

+ Physical Attacks

3Exploitation of ALL

KNOWNvulnerabilities w/non-interactive

sessions

Extendedengagement time

window

Non interactive w/update

+ Individualattacks

2

Exploitation of Known

vulnerabilities atALL layers w/

interactive sessions

Unlimited Timewindow during

engagement

Interactivew/scheduled update

+ Indirect attacks

1Exploitation of 

knownVulnerabilities atall layers underApplication with

interactivesessions

Constrained Timewindows

Interactive w/constant client

updateDirect Attacks

Page 151: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 151/159

 

FOLLOW A REPEATABLE

METHODOLOGY

Allow a FULL TEST

Page 152: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 152/159

Allow a FULL TEST

to get FULL VALUE• ACT as you would NORMALLY

 – Systems attack : tests IR plan

 – System Error: tracks mean time to

issue identification

 – Service Outage: tests/identifies

flaws in BCP – System down: tests/identifies

flaws in DR plan

Page 153: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 153/159

Page 154: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 154/159

SET REASONABLE

EXPECTAITONS

Page 155: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 155/159

Page 156: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 156/159

Page 157: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 157/159

What do you

have to lose?

Page 158: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 158/159

YOU HAVE

ALREADY BEENHACKED

Page 159: Guerrillas in the Wire

7/30/2019 Guerrillas in the Wire

http://slidepdf.com/reader/full/guerrillas-in-the-wire 159/159