the 10 best ways to hack a registry · simon mccalla. when you consider securing a business against...

35
The 10 best ways to hack a registry... Simon McCalla

Upload: others

Post on 13-Mar-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

The 10 best ways to hack a registry...Simon McCalla

Page 2: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

When you consider securing a business

against losing data, what do you typically think

of...?

Page 3: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 4: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

Looks complicated to hack...

And to be honest...it is.

Page 5: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

What if there was another, much easier way of

breaking in...?

Page 6: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

Let’s become a ‘hacker’ for the next 10mins

You don’t need any technical skills...

Page 7: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

1. Walk through the front door

Page 8: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 9: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 10: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

2. Walk through the back door

Page 11: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 12: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

3. Pick up the telephone

Page 13: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 14: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 15: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

4. Send someone a present

Page 16: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 17: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

5. Leave some USB sticks lying around

Page 18: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 19: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

6. Pretend to be an employee

Page 20: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 21: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 22: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

7. Get a job as a cleaner

Page 23: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 24: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 25: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

8. Login to their WiFi

Page 26: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 27: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

9. Steal their equipment

Page 28: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 29: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

10. ....oh ok, now let’s try some traditional hacking

Page 30: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And
Page 31: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

What can we do to prevent this from happening?

Page 32: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

1. Review and make some common-sense changes to your security arrangements

2. Train your staff to recognise and deal with social-engineering attacks

3. Test yourselves

4. Pay someone to try and hack you using these methods

5. Learn from the experience, be prepared to change: don’t be proud

Page 33: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

What did Nominet learn from doing this?

Page 34: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

1. Need to undergo this exercise with sensitivity and care

2. Bring your staff along with you: explain everything

3. Make the exercises challenging and fun

4. Do it repeatedly – keep people on their guard

Page 35: The 10 best ways to hack a registry · Simon McCalla. When you consider securing a business against losing data, what do you typically think of...? Looks complicated to hack... And

Thank You.