Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Intrusions and the Modern Web
Search
Benjamin Scott
November 23, 2015
Technology
140
1
Share
Intrusions and the Modern Web
how and why bad guys break into servers
Benjamin Scott
November 23, 2015
More Decks by Benjamin Scott
See All by Benjamin Scott
Practical Cross-Side Request Forgery
benjaminxscott
0
54
Starting your Infosec Career
benjaminxscott
0
390
Lie To Me: Mitigating Intrusions using Deception
benjaminxscott
0
75
Internet Security for Everyone
benjaminxscott
1
63
Beneath the Radar: covert traffic on the web
benjaminxscott
0
84
Securing your company's networks
benjaminxscott
0
77
Internet Forensics 101
benjaminxscott
0
73
Intro to Binary Analysis
benjaminxscott
0
57
Analyzing Evil PDF Files with peepdf
benjaminxscott
0
210
Other Decks in Technology
See All in Technology
自立を加速させる神器 - EMOasis #11
stanby_inc
0
150
扱える不確実性を増やしていく - スタートアップEMが考える「任せ方」
kadoppe
0
320
自分のハンドルは自分で握れ! ― 自分のケイパビリティを増やし、メンバーのケイパビリティ獲得を支援する ― / Take the wheel yourself
takaking22
1
940
「誰一人取り残されない」 AIエージェント時代のプロダクト設計思想 Product Management Summit 2026
mizushimac
1
660
目的ファーストのハーネス設計 ~ハーネスの変更容易性を高めるための優先順位~
gotalab555
8
2.2k
Rapid Start: Faster Internet Connections, with Ruby's Help
kazuho
2
730
「責任あるAIエージェント」こそ自社で開発しよう!
minorun365
9
2.2k
Chasing Real-Time Observability for CRuby
whitegreen
0
190
Standards et agents IA : un tour d’horizon de MCP, A2A, ADK et plus encore
glaforge
0
190
Hacobu Tech Deck
hacobu
PRO
0
120
実践ハーネスエンジニアリング:TAKTで実現するAIエージェント制御 / Practical Harness Engineering: AI Agent Control Enabled by TAKT
nrslib
12
4.7k
AI駆動1on1〜AIに自分を育ててもらう〜
yoshiakiyasuda
0
130
Featured
See All Featured
Information Architects: The Missing Link in Design Systems
soysaucechin
0
890
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
420
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
110
Digital Ethics as a Driver of Design Innovation
axbom
PRO
1
270
Sam Torres - BigQuery for SEOs
techseoconnect
PRO
0
250
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
How to make the Groovebox
asonas
2
2.1k
Speed Design
sergeychernyshev
33
1.6k
What's in a price? How to price your products and services
michaelherold
247
13k
Getting science done with accelerated Python computing platforms
jacobtomlinson
2
180
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
2
190
Transcript
Intrusions and the Modern Web Benjamin Scott
[email protected]
The Modern Web Threat model high - organized e-crime /
espionage groups Risk profile high - web developers want features / uptime Defense budget low - until breach hits the news
Goal of Intrusions Liquid assets credit cards / incoming traffic
/ hosting Enterprise access non-segmented network / shared admin Great visibility build profile of visitors who trust the site
Intrusion Lifecycle Break In find and exploit websec / appsec
issue Dig In install persistent backdoor Spread Out rinse and repeat
Break In Choose target highly trafficked / VIPs of interest
Try bruteforce default admin / SQLi / file inclusion Use exploit vulnerable service / CMS
(really) Break In Steal creds phish admins / keylog home
machines Buy access hire mercenaries / logins from underground SIGINT Use active MITM to inject binaries
Dig In Install webshell e-crime - PHP shells CN: Shell
Crew - ASP shells RU: Crouching Yeti - JavaScript patchwork RU: APT28 - custom kit with analytics Keep access local privilege escalation / new accounts
Spread Out Identify victims profile visitors / validate VIPs Deliver
exploits serve up tailored exploit Relay traffic implant commands sent via covert channel
Mitigations Monitoring new referers / odd scripts / insecure configs
Agile response share tools between operations / security / IT Clean deploys test appsec for CI / hardened images / CSP Hygiene checks scan / honeyclient / red team your site
Thanks for listening Benjamin Scott
[email protected]
github.com/benjaminxscott about.me/benjaminxscott