Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Intrusions and the Modern Web
Search
Benjamin Scott
November 23, 2015
Technology
140
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Intrusions and the Modern Web
how and why bad guys break into servers
Benjamin Scott
November 23, 2015
More Decks by Benjamin Scott
See All by Benjamin Scott
Practical Cross-Side Request Forgery
benjaminxscott
0
58
Starting your Infosec Career
benjaminxscott
0
410
Lie To Me: Mitigating Intrusions using Deception
benjaminxscott
0
79
Internet Security for Everyone
benjaminxscott
1
65
Beneath the Radar: covert traffic on the web
benjaminxscott
0
97
Securing your company's networks
benjaminxscott
0
80
Internet Forensics 101
benjaminxscott
0
75
Intro to Binary Analysis
benjaminxscott
0
60
Analyzing Evil PDF Files with peepdf
benjaminxscott
0
220
Other Decks in Technology
See All in Technology
アクセスキーが漏れた日にやるべきこと- 無効化の先にある本当の対応
kazzpapa3
0
310
AIに持続⼒を与える 判断の⻑期記憶設計
eiei114
1
690
電話に出る Python のログの話
shinnosuke_kishida
0
220
AIペネトレーションテスト・ セキュリティ検証「AgenticSec」紹介資料
laysakura
2
9.4k
安全性・開発速度・ユーザー体験の あいだで考える 事業会社のプロダクトセキュリティ
mixi_engineers
PRO
0
110
【GCC2026】TrueHDRIを用いたルックデブ環境とライティングテクニック
bandainamcostudios
PRO
0
370
AI画像認識を活用したゲーム内決済処理検証の自動化
gree_tech
PRO
0
450
tamachi.go 誕生の裏側
rymiyamoto
1
200
NANDでも描画したい!
nichica906
3
670
Kiro WebとCloud Sessions
nagisa53
2
190
dbt in Microsoft Fabric
ryomaru0825
0
230
OpenID for Verifiable Credentials 実装から見えた相互運用性確保までの道のり(OAuth/OIDC Numa (Immersion) Workshop 2026)
oidfj
PRO
0
110
Featured
See All Featured
How to audit for AI Accessibility on your Front & Back End
davetheseo
0
500
WENDY [Excerpt]
tessaabrams
11
39k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
360
AI in Enterprises - Java and Open Source to the Rescue
ivargrimstad
0
1.4k
Deep Space Network (abreviated)
tonyrice
0
270
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
280
Git: the NoSQL Database
bkeepers
PRO
432
67k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
249
1.3M
It's Worth the Effort
3n
188
29k
Prompt Engineering for Job Search
mfonobong
0
420
Why Our Code Smells
bkeepers
PRO
340
58k
HTML-Aware ERB: The Path to Reactive Rendering @ RubyCon 2026, Rimini, Italy
marcoroth
3
480
Transcript
Intrusions and the Modern Web Benjamin Scott
[email protected]
The Modern Web Threat model high - organized e-crime /
espionage groups Risk profile high - web developers want features / uptime Defense budget low - until breach hits the news
Goal of Intrusions Liquid assets credit cards / incoming traffic
/ hosting Enterprise access non-segmented network / shared admin Great visibility build profile of visitors who trust the site
Intrusion Lifecycle Break In find and exploit websec / appsec
issue Dig In install persistent backdoor Spread Out rinse and repeat
Break In Choose target highly trafficked / VIPs of interest
Try bruteforce default admin / SQLi / file inclusion Use exploit vulnerable service / CMS
(really) Break In Steal creds phish admins / keylog home
machines Buy access hire mercenaries / logins from underground SIGINT Use active MITM to inject binaries
Dig In Install webshell e-crime - PHP shells CN: Shell
Crew - ASP shells RU: Crouching Yeti - JavaScript patchwork RU: APT28 - custom kit with analytics Keep access local privilege escalation / new accounts
Spread Out Identify victims profile visitors / validate VIPs Deliver
exploits serve up tailored exploit Relay traffic implant commands sent via covert channel
Mitigations Monitoring new referers / odd scripts / insecure configs
Agile response share tools between operations / security / IT Clean deploys test appsec for CI / hardened images / CSP Hygiene checks scan / honeyclient / red team your site
Thanks for listening Benjamin Scott
[email protected]
github.com/benjaminxscott about.me/benjaminxscott