Hva avanserte hackere gjør for å få tilgang - Publisert.pptx

O
Hva avanserte
hackere gjør for å få
tilgang
Oddvar Moe
TrustedSec | @oddvarmoe
Oddvar Moe
TrustedSec
Red Teamer @TrustedSec
Hacker/Blogger/Speaker/Researc
her
Hobby: Fisking (ikke Phishing),
3dprinting, gaming, røyke kjøtt,
Hva er en avansert hacker?
Ofte referert som APT
Forskjellige mål avhengig
av gruppe
Hva er en avansert hacker?
https://docs.google.com/spreadsheets/d/1H9_xaxQH
pWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit
#gid=1636225066
Google etter: excel apt groups
RED TEAMER – HVA ER DET?
Være en “ekte” trussel
Minimum 4 uker
Ikke bli oppdaget (blue team)
Kan også være fysisk
Ikke en pentest
Målbasert!
Faser I et angrep
Faser I et angrep – Fokus I denne
sesjonen
Kartlegging
Mål er å forstå bedriften
Se etter (med hacker øyne)
• DNS / IP / Porter
• Dorking / Filer / Metadata / Epost / Github
• Teknologi I bruk / skjermbilde fra webtjenester
• Passord lekkasjer
• Nylig aktivitet SoMe
Hva avanserte hackere gjør for å få tilgang - Publisert.pptx
Kartlegging - DNS
Kartlegging - DNS
Kartlegging - IP
DEMO
DNS / SHODAN
OSINT
Kartlegging - Dorking
Kartlegging - Dorking
Kartlegging - Dorking
Kartlegging - Metadata
Kartlegging - Skjermbilde
Mange verktøy
• Aquatone (Min favoritt)
• EyeWitness
• GoWitness
Hva avanserte hackere gjør for å få tilgang - Publisert.pptx
Kartlegging – Passord lekkasjer
Finne e-post addresser
Mønster I passord
Finner dumps I forskjellige “forum” på nettet
Mange online tjenester også
DEMO
Dehashed / Emails
Kartlegging - Brukere
Benytte funnet e-post addresser
Verifiser mot O365 / Timing OWA / Teams
Finne flere? Bruke LinkedIn
Kartlegging - Brukere
Kartlegging - Brukere
Kartlegging - Brukere
Kartlegging - Skanning
Skanne porter (noen utvalgte)
Dirbusting (Se etter filer på webservere)
Oppnå tilgang
Passord spraying
Ekstern sårbarhet
Phishing
3.part (ServiceNow…)
Plante fysisk enhet
Ny kartlegging ved oppnådd tilgang
Passord Spraying
Forskjellige verktøy avhengig av tjenester
• Office 365
• On-Prem
• ADFS
• Andre? Okta?
Passord Spraying – Verktøy
On-Prem Exchange:
• Mailsniper
• Ruler
• Metasploit owa_login
On-Prem Lync/S4B:
• LyncSmash
Passord Spraying – Verktøy
Office 365
• o365Spray (også ADFS)
• TeamFiltration
Passord Spraying
Passord lister er viktig
Bedriftsnavn + år + !
Passord Spraying - MFA
Logge inn et par ganger ila dagen
Noen ganger godtar bruker push
Ekstern sårbarhet
Ikke vanlig, men skjer
• Mest vanlig er SQL Injection, Webshell upload
• Dårlig eller default passord på ekstern tjeneste
(test/test)
• Manglende patch
DEMO
USB STICK
Hva avanserte hackere gjør for å få tilgang - Publisert.pptx
Phishing
Tilpasses til hvert oppdrag
Bygger pretext basert på sosiale medier og ansatte
Personlig liker jeg å gå mot nyansatte (LinkedIn)
Phishing - Eksempel
Phishing - Eksempel
Hva avanserte hackere gjør for å få tilgang - Publisert.pptx
Phishing - Eksempel
Phishing - Eksempel
Phishing - Eksempel
Tiltak
Sjekk din egen bedrift for åpne ting på nettet
Tren brukere på phishing
Utfør herding av systemene
Gjennomfør pentest / red team
Bygg deteksjoner
?
TAKK FOR MEG!
@oddvarmoe
Oddvar.moe@trustedsec.com
LINKER
https://github.com/OJ/gobuster/releases
https://github.com/Flangvik/TeamFiltration
https://github.com/darkoperator/dnsrecon
https://github.com/FortyNorthSecurity/EyeWitness
https://github.com/michenriksen/aquatone
https://dnsdumpster.com
https://shodan.io
https://osintframework.com
https://www.exploit-db.com/google-hacking-database
https://github.com/0xZDH/o365spray
https://github.com/nyxgeek/lyncsmash
https://github.com/proxycannon/proxycannon-ng
Takk til våre sponsorer
Tusen takk!
1 of 49

Recommended

Red teaming and war stories by
Red teaming and war storiesRed teaming and war stories
Red teaming and war storiesOddvar Moe
64 views69 slides
Enkel og effektiv herding av windows by
Enkel og effektiv herding av windowsEnkel og effektiv herding av windows
Enkel og effektiv herding av windowsOddvar Moe
143 views23 slides
Phishing past mail protection controls using azure information by
Phishing past mail protection controls using azure informationPhishing past mail protection controls using azure information
Phishing past mail protection controls using azure informationOddvar Moe
233 views27 slides
App-o-Lockalypse now! by
App-o-Lockalypse now!App-o-Lockalypse now!
App-o-Lockalypse now!Oddvar Moe
811 views58 slides
#Lolbins - Nothing to LOL about! by
#Lolbins - Nothing to LOL about!#Lolbins - Nothing to LOL about!
#Lolbins - Nothing to LOL about!Oddvar Moe
986 views58 slides
Windows binærfiler by
Windows binærfilerWindows binærfiler
Windows binærfilerOddvar Moe
557 views66 slides

More Related Content

Featured

ChatGPT and the Future of Work - Clark Boyd by
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
28K views69 slides
Getting into the tech field. what next by
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
6.6K views22 slides
Google's Just Not That Into You: Understanding Core Updates & Search Intent by
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
6.9K views99 slides
How to have difficult conversations by
How to have difficult conversations How to have difficult conversations
How to have difficult conversations Rajiv Jayarajah, MAppComm, ACC
5.6K views19 slides
Introduction to Data Science by
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data ScienceChristy Abraham Joy
82.6K views51 slides
Time Management & Productivity - Best Practices by
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
169.8K views42 slides

Featured(20)

ChatGPT and the Future of Work - Clark Boyd by Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd28K views
Getting into the tech field. what next by Tessa Mero
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
Tessa Mero6.6K views
Google's Just Not That Into You: Understanding Core Updates & Search Intent by Lily Ray
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray6.9K views
Time Management & Productivity - Best Practices by Vit Horky
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
Vit Horky169.8K views
The six step guide to practical project management by MindGenius
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
MindGenius36.7K views
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright... by RachelPearson36
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
RachelPearson3612.7K views
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present... by Applitools
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Applitools55.5K views
12 Ways to Increase Your Influence at Work by GetSmarter
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
GetSmarter401.7K views
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G... by DevGAMM Conference
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
DevGAMM Conference3.6K views
Barbie - Brand Strategy Presentation by Erica Santiago
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
Erica Santiago25.1K views
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well by Saba Software
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Saba Software25.3K views
Introduction to C Programming Language by Simplilearn
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming Language
Simplilearn8.5K views
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr... by Palo Alto Software
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...
The Pixar Way: 37 Quotes on Developing and Maintaining a Creative Company (fr...
Palo Alto Software88.4K views
9 Tips for a Work-free Vacation by Weekdone.com
9 Tips for a Work-free Vacation9 Tips for a Work-free Vacation
9 Tips for a Work-free Vacation
Weekdone.com7.2K views
How to Map Your Future by SlideShop.com
How to Map Your FutureHow to Map Your Future
How to Map Your Future
SlideShop.com275.1K views

Hva avanserte hackere gjør for å få tilgang - Publisert.pptx

Editor's Notes

  1. https://osintframework.com https://dnsdumpster.com https://www.shodan.io/dashboard country:no product:"Remote Desktop Protocol“