The Hacker’s cookbook · krishna1 bostonlife cutedevil2901 Z80937010301zzz 123456789 barbara...

Preview:

Citation preview

Be Passionate

The Hacker’s cookbook

MARTIN HALLER, CEO

Credit Matters VIII Discovering DNA 2.5

Martin Haller

Ethical hacker / penetration tester

Cofounder of PATRON-IT s.r.o.

Why should I bother with security

Permanent data loss (family photos, cryptocurrency, business data)

Personal discreditation (chats, GPS, camera, microphone, private photos)

Data leakage (NDA, know-how, source codes)

Damage to other subjects (passing a virus)

Password security

What is the deal with passwords?

Who knows my passwords?

No, passwords are not equal!

https://haveibeenpwned.com

Do you see your password?

sanandreas

supermen

courage

milo211

hozilibe

google66

pukometo

691979danik

neco83

qwertyui

killkitty

adam0915

phillips21

Dom2208que

bookcase

Huh0g012

krishna1

bostonlife

cutedevil2901

Z80937010301zzz

123456789

barbara

davidek

gitta1

mmamma

Centrum.1

jjitka1755

846867708

kocynka

725053777

214316871

Application security

Applications have bugs

Bugs are used to infect devices

Usually no user interaction is needed

Social engineering security

Outsmarting users

It is you versus a hacker

Interactive question

What is this device?

A) Flash drive

B) Keyboard

C) Network card

D) Computer

Physical security

Stolen devices

Unattended devices

Lent devices

Physical security

What can be found on a PC:

Browser history

Chat history

Documents

Stored passwords

Cookies

Password managers

Certificates

Live demo

1. Bug

2. Exploit

3. Vulnerable devices

4. How to profit

Summary

IT security is a complex thing

There is no magic pill

It cannot be rated by a questionnaire

Protect yourself

Unique passwords + password manager (e.g. LastPass, 1Password)

2FA authentication for important services

Update applications and devices (esp. operating system and web browsers)

Antivirus + firewall

Use common sense

Install just needed applications

Don’t let anyone touch your devices

Encrypt your devices (e.g. Bitlocker, FileVault)

Protect yourself (cont.)

Backup your data (e.g. utilize cloud storages)

Have a recovery plan

Be Passionate

Any questions?APP Feedback please

Credit Matters VIII Discovering DNA 2.5

THANK YOUMartin HallerPATRON-IT s.r.o.https://martinhaller.commartin.haller@patron-it.cz

Recommended