hanssens telecom roadshow 2015 - hacking 101

36
h@Cking l0l

Upload: malik-mesellem

Post on 21-Jan-2018

527 views

Category:

Presentations & Public Speaking


0 download

TRANSCRIPT

Page 1: Hanssens Telecom Roadshow 2015 - Hacking 101

h@Cking l0l

Page 2: Hanssens Telecom Roadshow 2015 - Hacking 101

Malik Mesellem

Ethical Hacker

MME BVBA

° 2010

Security audits

and training

Objective

approach

Focus is

to advise

No-nonsense

mentality

Page 3: Hanssens Telecom Roadshow 2015 - Hacking 101

What are we afraid of?

Buffer

overflows

DoS

Port

scans

Trojans

IP spoofing

Page 4: Hanssens Telecom Roadshow 2015 - Hacking 101

We all have

firewalls ;)

(since 1990)

I don’t think so…

Old skool

attacks✝

Page 5: Hanssens Telecom Roadshow 2015 - Hacking 101

So WTH(ack) is the problem?

And who is

the enemy?

Page 6: Hanssens Telecom Roadshow 2015 - Hacking 101

A new wave of client-side threats…

Page 7: Hanssens Telecom Roadshow 2015 - Hacking 101

Complex application-level attacks

Page 8: Hanssens Telecom Roadshow 2015 - Hacking 101

Complex application-level attacks

Page 9: Hanssens Telecom Roadshow 2015 - Hacking 101

Your secure (?) infrastructure

IP PBX / Web apps

DC

Member computers

Firewall

Page 10: Hanssens Telecom Roadshow 2015 - Hacking 101

Hacker’s attack plan?

ATTACK

the border

= web apps

Page 11: Hanssens Telecom Roadshow 2015 - Hacking 101

Application-level attack

SQL injection

SELECT * FROM

… WHERE …

‘ OR 1=1--

Page 12: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 13: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 14: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 15: Hanssens Telecom Roadshow 2015 - Hacking 101

Web server DOWN ;(

Page 16: Hanssens Telecom Roadshow 2015 - Hacking 101

Hacker’s attack plan?

ATTACK

the weakest

= humans

Page 17: Hanssens Telecom Roadshow 2015 - Hacking 101

Client-side attacks

Social engineering

Phishing,

malware,

exploits

Page 18: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 19: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 20: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 21: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 22: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 23: Hanssens Telecom Roadshow 2015 - Hacking 101

Member computers DOWN ;(

Page 24: Hanssens Telecom Roadshow 2015 - Hacking 101

You’ve just lost several assets!

They are inside

the network…

Page 25: Hanssens Telecom Roadshow 2015 - Hacking 101

Now they go for the GOLD!

Credentials, hashes,

and tokens…

Page 26: Hanssens Telecom Roadshow 2015 - Hacking 101
Page 27: Hanssens Telecom Roadshow 2015 - Hacking 101

GAME OVER

You’ve lost

everything $$$

Page 28: Hanssens Telecom Roadshow 2015 - Hacking 101

GAME OVER

You’ve lost

everything $$$

Page 29: Hanssens Telecom Roadshow 2015 - Hacking 101

OMG… we definitely need heroes!

Page 30: Hanssens Telecom Roadshow 2015 - Hacking 101

What if…

Page 31: Hanssens Telecom Roadshow 2015 - Hacking 101

Secure Telecom &

VoIP Solutions

Page 32: Hanssens Telecom Roadshow 2015 - Hacking 101

Security Audits

& Training

Page 34: Hanssens Telecom Roadshow 2015 - Hacking 101

Our Heartbeat Scan is a complete audit

Critical and vital parts are scanned and analyzed

Potential threats and vulnerabilities are identified

Spread over several days for a fixed price

Comprehensive checkpoints

Report contains at least 100 pages!

Executive summary

Technical findings

Remediations

Security Audits

Page 35: Hanssens Telecom Roadshow 2015 - Hacking 101

Security Audits Checkpoints in this Heartbeat Scan

Vulnerability Assessment (LAN/WAN)

Penetration Testing (LAN/WAN)

Web Application Scans (OWASP Top 10)

Active Directory Review and Password Audit

Business Continuity - Disaster Recovery Check

Software Updates Compliance Check

Malware and Endpoint Inspection

Firewall Configuration Review

Wireless Security Survey

Email spear phishing campaign

SPECIAL OFFER

Page 36: Hanssens Telecom Roadshow 2015 - Hacking 101

Check our calendar here