Penetration Testing 2.0 - Corporate Tiger Team

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    1 Favorite

    Penetration Testing 2.0 - Corporate Tiger Team - Presentation Transcript

    1. Penetration Testing 2.0: Corporate Tiger Team Tom Eston
    2. Why are you here? • Threats to your organization • Why a Tiger Team? • How can you do this? • Real world scenario • ...it’s one of the last talks of the day!
    3. Threats to your organization (Yes, Dan Kaminsky is a threat...)
    4. No Tech Attacks
    5. Social Engineering “The clever manipulation of the natural human tendency to trust” “Because there is no patch for human stupidity”
    6. “Thief woos bank staff with chocolates... then steals $28 million in diamonds”
    7. 64%
    8. Dumpster Diving
    9. Tailgating
    10. This might be a problem...
    11. Shoulder Surfing
    12. Buy his book!
    13. Electronic Attacks
    14. External Network Attacks • Web applications • External servers • Wireless • DNS and BGP Internet Routing
    15. Help! Their attacking our clients! (aka: Internal Network Attacks)
    16. Phishing
    17. 94%
    18. Malfunction • Software glitches • Process breakdown • Act of God/War/Terrorism • Disruption
    19. What is a Tiger Team?
    20. What does a Tiger Team test?
    21. Physical Security
    22. Technology (Electronic)
    23. Application
    24. Security Awareness
    25. Testing Methodology • ISSAF/NIST 800-42 • OSSTMM v2 • OWASP Testing Guide • Other Penetration Testing Methodologies
    26. Team Formation
    27. Internal Team
    28. The need for “experts” • Physical Security • Network/Application Pentest • Social Engineering and People Skills!
    29. Third-Party Assisted
    30. What to look for in a 3rd Party? • Physical Security • Social Engineering • Network Penetration • Inguardians • Lares Consulting
    31. Conducting the Assessment
    32. What’s the goal?
    33. Get permission!
    34. Reconnaissance
    35. Maltego
    36. Penetration and Exploitation
    37. Coordinate the Attack
    38. Facility Walk Through
    39. Reporting and Clean-up
    40. Real World Assessment Example
    41. Tiger Team TV Show
    42. Let’s Review... • Threats to your organization • What is a tiger team, what can it test • Methodologies, how to form your team • Real world example

    + agent0x0agent0x0, 12 months ago

    custom

    1272 views, 1 favs, 1 embeds more stats

    Presentation given at the 2008 Ohio Information Sec more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1272
      • 1269 on SlideShare
      • 3 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 0
    Most viewed embeds
    • 3 views on http://www.pentest.sg

    more

    All embeds
    • 3 views on http://www.pentest.sg

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories