itcamp 2012 - paula januszkiewicz - stronghold to strengthen

36
itcampro @ itcamp12 # Premium conference on Microsoft technologies Private & Public Cloud ITCamp 2012 sponsors

Upload: itcamp

Post on 13-May-2015

456 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud ITCamp 2012 sponsors

Page 2: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Page 3: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Agenda

1 2 4

Intruduction

Hardening Techiques Summary

3

Infrastructure Techniques

Page 4: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Hacker Role in IT Development

• Hackers make IT security world running

• Hackers encourage us to be up to date

• Hackers test the newest technology

What is the security

trend?

Page 5: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen
Page 6: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen
Page 7: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen
Page 8: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

8

19790509

Page 9: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Security Intelligence Report

http://www.microsoft.com/security/sir/

Page 10: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Agenda

1 2 4

Intruduction

Hardening Techiques Summary

3

Infrastructure Techniques

Page 11: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud

External Views

Page 12: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 13: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 14: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Page 15: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Test Your Users

• Play a social engineer role

• Monitor them…

• …and show you do it

• Break users’ passwords

• Train them well

Page 16: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 17: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Know At Least One Scripting Language

• Hackers love scripts

– Perl

– Python

• You should love PowerShell 2.0

– Server Role management modules

– Server management

– Remoting

– Microsoft Common Criteria

Page 18: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Incorrect Access Control Lists

Page 19: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 20: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

WYSI (NOT) WYG

Page 21: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 22: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Use Debugger

• Variable choices:

– SoftICE

–WinDbg

–DEBUG

– IDA Pro

• One idea:

– To look through the code and data structures

• Administrators: Crash dump analysis

• Process Explorer

Picture: commons.wikimedia.org

Page 23: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 24: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Page 25: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 26: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 27: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen
Page 28: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Network Monitoring

• Watch for protocol anomalies

– Data can leak through the data field

– Watch for protocols used not only for data transfers

• Monitor the traffic

– Unfortunately some traffic may happen only once a month

Page 29: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Page 30: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Page 31: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Agenda

1 2 3

Hacker role in IT development

Hacker Techniques and Demos

Things you should remember and summary

Page 32: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Demo

Lack of General Revisions

Page 33: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Lack of Training

Page 34: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Keep Your Knowledge Up To Date

• Know law regulations in your country

• IT resources – Mailing Lists

– Blogs / RSS

– Webcasts

• Security bulletins – Microsoft

– SANS

– ISS

Page 35: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

Private &

Public Cloud Have Your Own Toolkit

• Internet Browser is sometimes enough

• CMD and build-in system tools

• Specialist tools

• Your own scripts

• Social engineering skills

• PowerShell 2.0/3.0

Page 36: ITCamp 2012 - Paula Januszkiewicz - Stronghold to Strengthen

itcampro @ itcamp12 # Premium conference on Microsoft technologies

[email protected]

Thank you!