Social Zombies: Your Friends Want to Eat Your Brains

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Social Zombies: Your Friends Want to Eat Your Brains - Presentation Transcript

    1. SOCIAL ZOMBIES Your Friends Want to Eat Your Brains
    2. STARRING...
    3. TOM ESTON
    4. KEVIN JOHNSON
    5. Social Networks “The New Hotness”
    6. 225 Million Users
    7. 110 Million Users
    8. Grew 752% in 2008!
    9. 8 million visitors in march 2009
    10. “Social networks & Blogs are now the 4th most popular online activity, ahead of personal email.” -Nielsen Online Report, March 2009
    11. How do socnets make $$?
    12. It’s in your Profile! • More information you share...more $ $ it’s worth! • Targeted advertising • Sell your Demographic Info • Sketchy Privacy/ToS Policies....
    13. In Social networks we Trust...
    14. Trust is Everything! • It’s how social networks work • More trust, the better for the socnet! • Attackers LOVE trust relationships!
    15. Fake Profiles
    16. It’s built to Exploit Trust • Who is the person behind the account? • Bots are Everywhere • Accounts are easy to create • Socnet User Verification = FAIL • Connections based on other “friends”
    17. Privacy Concerns
    18. 25 Random Things About You... • I’m your friend, I want to know more about you! • Innocent? • These are PASSWORD RESET QUESTIONS people!!
    19. Corporate Espionage? • Very effective in a Penetration test • Socnet Information = GOLD • Information Leakage on a Mass Scale!
    20. Default Privacy Settings • Wide Open for a reason! • Facebook has very good controls...but... • Do you know where they are? • Do your Friends/Family? • Do They Care?
    21. Security Concerns • Socnets are #1 Target for Malware • Spam • Disinformation • XSS, CSRF and more!
    22. Twitter Clickjacking & XSS
    23. Return of Koobface • Recycled ExploitS • Exploits Trust • STILL EFFECTIVE!
    24. Social Network Bots
    25. Delivery VIA Socnet API • Twitter Bots (n0tab0t, Realboy) • Automated tools and scripts...
    26. Automated Tools
    27. Pay Services
    28. Social Network Botnets?
    29. Facebot POC • Malicious Facebook APplication (looks normal) • Turns your PC into a Bot used for DDOS!
    30. Introducing... Kreios C2
    31. Kreios C2 Demo
    32. Browser Based Bots
    33. Browsers and Features... Oh My! • Browsers are getting more feature-rcih • Read that as more vulnerable! • Forget exploiting vulns • Abuse the features we are provided
    34. Browser Zombies • JavaScript used to hook the browser • Other technologies will work • Many frameworks available • BeEF • BrowserRider • Anehta
    35. SocNet Delivery • Embedded applications can insert JavaScript • Multiple options • Hook scripts are pushed • Userssitesredirected to hook are • Why would we allow this!?!?
    36. Oh Yeah Mafia Wars
    37. Server Side Information Collection
    38. Information is Power • Information gets us access • Social networks are littered with info • By how do we connect it together
    39. Third party apps to the rescue • Third party apps have access to everything • Permissions are open by default • Once a user says accept
    40. API’s FTW • Myspaceto anfacebook both provide access and api • These APIs provide the access we want • Allows connecting different users • Based on friends, groups, jobs or interests
    41. Social Butterfly • Social Butterfly is a third party application • Runs on attacker controlled servers • Collects the data from application users • Crosses the line between different sites • Fine line before violating TOS!
    42. Social Butterfly DEMO
    43. Prevention • User Education • End “opt-In” Socnet Developer Models • Control API Usage • Better Account verification • SPAM Throttling
    44. Conclusions
    45. MoRe Information • Facebook Privacy & Security Guide SPYLOGIC.NET • Kreios C2 www.digininja.org • New website dedicated to Social media security (announced at Defcon)
    46. Questions for the Zombies?

    + agent0x0agent0x0, 3 months ago

    custom

    760 views, 0 favs, 0 embeds more stats

    In Social Zombies: Your Friends want to eat Your Br more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 760
      • 760 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 19
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories