Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Intrusions and the Modern Web
Search
Benjamin Scott
November 23, 2015
Technology
140
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Intrusions and the Modern Web
how and why bad guys break into servers
Benjamin Scott
November 23, 2015
More Decks by Benjamin Scott
See All by Benjamin Scott
Practical Cross-Side Request Forgery
benjaminxscott
0
55
Starting your Infosec Career
benjaminxscott
0
410
Lie To Me: Mitigating Intrusions using Deception
benjaminxscott
0
78
Internet Security for Everyone
benjaminxscott
1
65
Beneath the Radar: covert traffic on the web
benjaminxscott
0
91
Securing your company's networks
benjaminxscott
0
79
Internet Forensics 101
benjaminxscott
0
75
Intro to Binary Analysis
benjaminxscott
0
59
Analyzing Evil PDF Files with peepdf
benjaminxscott
0
220
Other Decks in Technology
See All in Technology
LLMやAIエージェントをソフトウェアに組み込むプラクティス
shibuiwilliam
2
400
ソニー銀行におけるビジネスアジリティ向上のためのクラウドシフト戦略
srenext
0
590
SRE本の知られざる名シーン / The Hidden Gems of Google SRE Book
nari_ex
1
420
SoccerMaster: A Vision Foundation Model for Soccer Understanding
kzykmyzw
0
120
Alphaモジュール使っていいのかい!?いけないのかい!?どっちなんだいっ!?
watany
1
250
AIと共生する開発者プラットフォーム:バクラクのモノレポ×マイクロサービス基盤
sakajunquality
2
3.7k
ゴールデンパスは敷いただけでは道にならない ─ 企画部門のエンジニアが技術標準を事業価値に変えるまで
mhrtech
1
180
Oracle Exadata Database Service on Cloud@Customer X11M (ExaDB-C@C) サービス概要
oracle4engineer
PRO
2
8.4k
そのドキュメント、自動化しませんか?
yuksew
1
250
脱金融のフューチャー・デザイン / Future Design Beyond Finance
ks91
PRO
0
150
ruby.wasmとPicoRuby.wasmに対応した仮想DOMライブラリを作ってる話 #kaigieffect_kaigi
sue445
PRO
0
150
AmplifyHostingConstructからSSRフレームワークのためのホスティング設計を考察する/amplify-hosting-construct
fossamagna
1
170
Featured
See All Featured
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
360
The State of eCommerce SEO: How to Win in Today's Products SERPs - #SEOweek
aleyda
2
11k
How to Ace a Technical Interview
jacobian
281
24k
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
180
エンジニアに許された特別な時間の終わり
watany
108
250k
DBのスキルで生き残る技術 - AI時代におけるテーブル設計の勘所
soudai
PRO
67
56k
RailsConf 2023
tenderlove
30
1.5k
コードの90%をAIが書く世界で何が待っているのか / What awaits us in a world where 90% of the code is written by AI
rkaga
62
45k
Leading Effective Engineering Teams in the AI Era
addyosmani
9
2.1k
職位にかかわらず全員がリーダーシップを発揮するチーム作り / Building a team where everyone can demonstrate leadership regardless of position
madoxten
63
55k
Into the Great Unknown - MozCon
thekraken
41
2.6k
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
1
2k
Transcript
Intrusions and the Modern Web Benjamin Scott
[email protected]
The Modern Web Threat model high - organized e-crime /
espionage groups Risk profile high - web developers want features / uptime Defense budget low - until breach hits the news
Goal of Intrusions Liquid assets credit cards / incoming traffic
/ hosting Enterprise access non-segmented network / shared admin Great visibility build profile of visitors who trust the site
Intrusion Lifecycle Break In find and exploit websec / appsec
issue Dig In install persistent backdoor Spread Out rinse and repeat
Break In Choose target highly trafficked / VIPs of interest
Try bruteforce default admin / SQLi / file inclusion Use exploit vulnerable service / CMS
(really) Break In Steal creds phish admins / keylog home
machines Buy access hire mercenaries / logins from underground SIGINT Use active MITM to inject binaries
Dig In Install webshell e-crime - PHP shells CN: Shell
Crew - ASP shells RU: Crouching Yeti - JavaScript patchwork RU: APT28 - custom kit with analytics Keep access local privilege escalation / new accounts
Spread Out Identify victims profile visitors / validate VIPs Deliver
exploits serve up tailored exploit Relay traffic implant commands sent via covert channel
Mitigations Monitoring new referers / odd scripts / insecure configs
Agile response share tools between operations / security / IT Clean deploys test appsec for CI / hardened images / CSP Hygiene checks scan / honeyclient / red team your site
Thanks for listening Benjamin Scott
[email protected]
github.com/benjaminxscott about.me/benjaminxscott