40
Traps of Gold Michael Brooks & Andrew Wilson

Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Traps  of  Gold  Michael  Brooks  &  Andrew  Wilson  

Page 2: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Cau.on.    Please  vet  anything  discussed  with  legal  and  

management.  

Page 3: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

FRUSTRATION  

http://www.flickr.com/photos/14511253@N04/4411497087/sizes/o/in/photostream/  

Page 4: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Our  en.re  defense  strategy  is  REACTIVE…    

AKA,  losing  

Page 5: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Fixes  known  issues  Someone  already  pwnd  it  Already  in  Produc@on!  

Patch  Management  

Page 6: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Reduces  Vulnerabili@es  Expensive  Limited  Effec@veness  

Secure  Development  

Page 7: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Free  groping  at  airport  You  aren’t  safer  Introduces  vulnerabili@es  

Security  Theater  

Page 8: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

What  is  missing?  But  if  they  aren’t  working…  

Page 9: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Fight  Back  

http://www.flickr.com/photos/superwebdeveloper/5604789818/sizes/l/in/photostream/  

Page 10: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“We  conclude  that  there  exists  no  clear  division  between  the  offense  and  defense.  -­‐  USMC,  Warfigh.ng  

Page 11: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

http://www.flickr.com/photos/travis_simon/3865383863/sizes/z/in/photostream/  

Page 12: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

They  have:  AUackers  are  human  too.  

• Finite  @me  •  Imperfect  tools  • Emo@on  /  Ego  /  Bias  • Risk  

Page 13: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

AUack  them  there.  So...  

Page 14: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“If  I  have  seen  further,  it  is  only  by  standing  on  the  shoulder  of  giants.  -­‐  Sir  Isaac  Newton  

Page 15: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Traps  of  Gold  

IDS  Systems  

Honeypots  

Exploits  

Page 16: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Attrition   Maneuver  

Two  Models  of  Warfare  

Page 17: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Maneuverability  

http://www.flickr.com/photos/travis_simon/3865383863/sizes/z/in/photostream/  

Page 18: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Stack  the  Deck  http://www.flickr.com/photos/jonathanrh/5817317551/sizes/o/in/photostream/  

Page 19: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“To  act  in  such  a  way  that  the  enemy  does  not  know  what  to  expect.  

Ambiguity:    Ambiguity    

Page 20: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Server  Banners  

File  Extensions  

Default  Files  

Who  needs  this?  

The  browser  doesn’t  care.  

Why  leave  these  up?  

Page 21: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Shut  up.  If  knowing  is  half  the  baUle  

Page 22: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“Convince  the  enemy  we  are  going  to  do  something  other  than  what  we  are  really  going  to  do  

Decep.on    

Page 23: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Lie  about  the  rest.  Reduce  what  they  can  know  

Page 24: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Blatantly  lying.  Increase  the  noise  by…  

Page 25: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Issues  Iden

@fied

 Before   AUer  

19   5462  Nikto  

6   300  Skipfish  

6   300  Wapiti  

6   300  w3af  

6   300  Prod  scan  

6   300  Prod  scan  

6   300  Prod  scan  

See  updates  after  talk  

That’s  real  though!  

Page 26: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Will  it?  But  that  wont  fool  people…  

Page 27: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Some  lies  are  beUer.  

http://www.flickr.com/photos/randomurl/459180872/sizes/l/in/photostream/  

Page 28: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“The  secrets  of  victory  thus  lie  in  the  taking  of  ini.a.ve.  

Ambiguity:    Tempo  

Page 29: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

It’s  about  awareness  and  ac.ng  sooner.  

It’s  not  about  reac.on  

Page 30: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Perceived  

Actual  

AXack  Surface  I  made  this  

up!  

And  I  can  watch  for  

this.  

Page 31: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

http://www.flickr.com/photos/derek_b/5837741974/sizes/o/in/photostream/  

Page 32: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

“I  love  it  when  a  plan  comes  together.  -­‐Hannibal  

Page 33: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Misdirec@on  ShuYng  down  tools  Increasing  awareness  

So  far  we’ve  shown:  

Page 34: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Can  we  break  it?  But…  

Page 35: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

http://www.flickr.com/photos/20106852@N00/2238271809/sizes/o/in/photostream/  

Page 36: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

To  recap.  Stop  ac.ng  like  this…  

Page 37: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:
Page 38: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Start  ac.ng  like  this.  

http://www.flickr.com/photos/kriztofor/3253758933/sizes/o/in/photostream/  

Page 39: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Fight  Back  

http://www.flickr.com/photos/superwebdeveloper/5604789818/sizes/l/in/photostream/  

Page 40: Traps of Gold - DEF CON® Hacking Conference€¦ · Title: Traps of Gold Author: Andrew Wilson Security Consultant, Trustwave SpiderLabs, Michael Brooks Security Researcher Subject:

Capture  The  Flag  

The  winner  takes  all  

hUp://cY.doublethunk.org