penetration testing - university of texas at dallasinternet firewall web server 424242.21 dns server...

30

Upload: others

Post on 17-Oct-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259
Page 2: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Penetration Testing

Page 3: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

XYZ Bank

Page 4: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

What is Penetration Testing?

○○

○○

Page 5: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Why Should We Care?→

○○

Page 6: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Metasploit Framework

○○○

Page 7: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 8: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Scanning

○○

○○

Page 9: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Scanning

●○○

●○○○

Page 10: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Scanning

Page 11: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 12: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Initial Exploit

○○○

Page 13: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Initial Exploit

○○

■■■

Page 14: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 15: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Escalate Privileges

○○○

Page 16: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 17: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Establish Persistence

○○

Page 18: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 19: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Move Laterally

○○

○○

Page 20: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Move Laterally

Page 21: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Move Laterally

Page 22: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Steps of Penetration Testing

Page 23: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Obtain “Crown Jewels”

Page 24: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Ethics and Laws

Page 25: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Ethics and Laws○

○■

○■

○■

Page 26: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Ethics and Laws

Page 27: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Ethics and Laws●

Page 28: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259
Page 29: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259

Questions?

Page 30: Penetration Testing - University of Texas at DallasInternet Firewall Web Server 424242.21 DNS Server 42.42.42.59 *root pASSWORD Internet Firewall Web Server 4242.4221 DNS Server 42.424259