SlideShare a Scribd company logo
For those of you who
don’t know me
For those of you who
don’t know me
This is me ------>
My first computer
My second computer
Third Computer
Number 4
Number 5 (with dial up internet)
Much More Computers :)
My most recent computer :)
My favourite computer
Looks like this…
Looks like this… yes, that’s a Mainframe
Christopher O'Malley
President and CEO at Compuware
“There’s an acknowledged surge of interest in Agile and DevOps
on the mainframe. With good reason. Your business can’t be truly
agile unless your systems-of-record are truly agile. And for most
large enterprises, those systems run on the mainframe………”
https://www.linkedin.com/pulse/big-agile-devops-decision-you-need-make-today-christopher-o-malley
*) TechNerd examination points…
Email: henri@zdevops.com
Twitter: @henrikuiper
LinkedIN: https://nl.linkedin.com/in/wizardofzos
So how did I end up here?
Software
• Encryption
• Smartcrypt TDE
• SecureZIP
• Compression
• PKZIP
• Threat Detection
• TrapX
for most major platforms
Services
• Pentesting
• Vulnerability Checks
• Risk Assessments
• Security Officers!
• Monitoring
• Policy Enforcers
• Managed Security Services
www.srcsecuresolutions.eu
161116 PBSA Good, Bad, Ugly
Legal Stuff
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Cras feugiat velit ac justo finibus, ut molestie lectus bibendum. Duis leo massa, bibendum vitae imperdiet in,
commodo nec velit. Vivamus tincidunt, eros eu rutrum posuere, ex dui porta sapien, in placerat quam diam sit amet tortor. Aenean nec diam tellus. Integer ornare
euismod enim. Aenean ipsum diam, feugiat hendrerit justo ut, maximus ornare nisi. Nullam augue diam, malesuada consequat porta non, ullamcorper sed tortor.
Phasellus in lacus eget erat vestibulum hendrerit sed nec quam. Praesent ante magna, consequat eget ultrices vitae, congue sed leo. Vivamus nec felis ac neque
accumsan rutrum in id massa. Ut mollis in mauris a auctor. Aliquam dictum lectus vel vehicula iaculis.

Quisque at quam ut libero rhoncus consectetur. Proin ac ultricies lacus. Sed in mauris ut velit malesuada consequat in eu lorem. Quisque sollicitudin dapibus orci sit
amet feugiat. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia Curae; Class aptent taciti sociosqu ad litora torquent per conubia nostra,
per inceptos himenaeos. Nulla facilisi. Sed ultricies tellus in sem elementum, vitae fringilla ante vestibulum.

Nullam pharetra arcu odio, sed pharetra purus pulvinar et. Suspendisse nec aliquet orci. Nulla consequat elit ante, eu malesuada elit laoreet ut. Sed malesuada
ornare tortor. Pellentesque fringilla fermentum quam eget bibendum. Etiam porttitor, quam sit amet laoreet ultricies, erat ipsum fermentum metus, sit amet
elementum elit leo aliquet purus. Maecenas varius metus purus, eu eleifend est pellentesque a. Duis mauris eros, ultricies sit amet posuere sed, pulvinar ut elit.
Aliquam mattis ligula felis, sit amet venenatis ligula porta quis. Nunc ut vulputate ante. Pellentesque congue eleifend pellentesque. Curabitur bibendum porttitor sem,
eu varius mauris ultricies vitae. Phasellus pulvinar vestibulum gravida. Proin non eleifend odio. Aenean pharetra pretium orci ac scelerisque.

Sed lobortis vel magna nec volutpat. Nam et dui metus. Quisque aliquam ligula dapibus, convallis purus ac, accumsan ex. Ut id tempus diam, vel porttitor justo.
Pellentesque venenatis justo sem, sit amet interdum mauris tristique vitae. Fusce metus magna, suscipit vitae convallis eget, ultricies sed est. Fusce sodales diam sit
amet imperdiet venenatis. Aenean sed eros quis arcu dapibus porttitor id ut magna. Ut suscipit ex eu nibh bibendum posuere.

Quisque semper feugiat ante, pharetra ultrices turpis feugiat ac. Fusce non neque purus. Curabitur eget sagittis nunc, nec aliquam diam. Integer augue ligula,
eleifend ut eleifend vitae, congue eu est. Vestibulum semper, nunc nec placerat condimentum, tortor lectus tempor risus, eu viverra sem tortor sed dolor. Nam
volutpat nulla a felis ultricies, ac pellentesque ligula vehicula. Phasellus imperdiet velit sit amet laoreet sollicitudin. Morbi elementum viverra enim, eget feugiat sem
interdum nec. Nulla facilisi. Praesent ex lectus, posuere non molestie et, laoreet at lorem. Phasellus mollis, justo quis venenatis ultricies, ante ante ultrices est, sed
dapibus turpis odio ac leo. In pharetra velit commodo massa eleifend, eget vehicula felis commodo.
Legal Stuff
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Cras feugiat velit ac justo finibus, ut molestie lectus bibendum. Duis leo massa, bibendum vitae imperdiet in,
commodo nec velit. Vivamus tincidunt, eros eu rutrum posuere, ex dui porta sapien, in placerat quam diam sit amet tortor. Aenean nec diam tellus. Integer ornare
euismod enim. Aenean ipsum diam, feugiat hendrerit justo ut, maximus ornare nisi. Nullam augue diam, malesuada consequat porta non, ullamcorper sed tortor.
Phasellus in lacus eget erat vestibulum hendrerit sed nec quam. Praesent ante magna, consequat eget ultrices vitae, congue sed leo. Vivamus nec felis ac neque
accumsan rutrum in id massa. Ut mollis in mauris a auctor. Aliquam dictum lectus vel vehicula iaculis.

Quisque at quam ut libero rhoncus consectetur. Proin ac ultricies lacus. Sed in mauris ut velit malesuada consequat in eu lorem. Quisque sollicitudin dapibus orci sit
amet feugiat. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia Curae; Class aptent taciti sociosqu ad litora torquent per conubia nostra,
per inceptos himenaeos. Nulla facilisi. Sed ultricies tellus in sem elementum, vitae fringilla ante vestibulum.

Nullam pharetra arcu odio, sed pharetra purus pulvinar et. Suspendisse nec aliquet orci. Nulla consequat elit ante, eu malesuada elit laoreet ut. Sed malesuada
ornare tortor. Pellentesque fringilla fermentum quam eget bibendum. Etiam porttitor, quam sit amet laoreet ultricies, erat ipsum fermentum metus, sit amet
elementum elit leo aliquet purus. Maecenas varius metus purus, eu eleifend est pellentesque a. Duis mauris eros, ultricies sit amet posuere sed, pulvinar ut elit.
Aliquam mattis ligula felis, sit amet venenatis ligula porta quis. Nunc ut vulputate ante. Pellentesque congue eleifend pellentesque. Curabitur bibendum porttitor sem,
eu varius mauris ultricies vitae. Phasellus pulvinar vestibulum gravida. Proin non eleifend odio. Aenean pharetra pretium orci ac scelerisque.

Sed lobortis vel magna nec volutpat. Nam et dui metus. Quisque aliquam ligula dapibus, convallis purus ac, accumsan ex. Ut id tempus diam, vel porttitor justo.
Pellentesque venenatis justo sem, sit amet interdum mauris tristique vitae. Fusce metus magna, suscipit vitae convallis eget, ultricies sed est. Fusce sodales diam sit
amet imperdiet venenatis. Aenean sed eros quis arcu dapibus porttitor id ut magna. Ut suscipit ex eu nibh bibendum posuere.

Quisque semper feugiat ante, pharetra ultrices turpis feugiat ac. Fusce non neque purus. Curabitur eget sagittis nunc, nec aliquam diam. Integer augue ligula,
eleifend ut eleifend vitae, congue eu est. Vestibulum semper, nunc nec placerat condimentum, tortor lectus tempor risus, eu viverra sem tortor sed dolor. Nam
volutpat nulla a felis ultricies, ac pellentesque ligula vehicula. Phasellus imperdiet velit sit amet laoreet sollicitudin. Morbi elementum viverra enim, eget feugiat sem
interdum nec. Nulla facilisi. Praesent ex lectus, posuere non molestie et, laoreet at lorem. Phasellus mollis, justo quis venenatis ultricies, ante ante ultrices est, sed
dapibus turpis odio ac leo. In pharetra velit commodo massa eleifend, eget vehicula felis commodo.
EXCLUSIVELY INCLUSIVE
PROJECT
DATE
16/11/2016
PLATFORM BASED SECURITY ASSESSMENTS
THE GOOD, THE BAD AND THE UGLY
YOU’VE BEEN WARNED
AGENDA
The Good

The Bad

The Ugly
THE GOOD
IN-DEPTH SECURITY ASSESSMENT
FOR THE ENTIRE OPERATING SYSTEM
Platform Security Assessments
Are they better than Network Security Scanners? (Wireshark, nmap,
metasploit, …)?

Or better than Web Security Scanners? (OWASP, Burp Suite, …)?

They identify intrinsic security flaws
How do you do them?

And what’s the goal?
EXECUTING A SECURITY ASSESSMENT…..
LIST BASED AND/OR SERIOUSLY CHECKING THE SYSTEM?
“I don’t hate technology, I don’t hate hackers, because that’s just
what comes with it without those hackers we wouldn’t solve the
problems we need to solve, especially security.”
–Fred Durst, Limp Bizkit
“I don’t hate technology, I don’t hate hackers, because that’s just
what comes with it without those hackers we wouldn’t solve the
problems we need to solve, especially security.”
–Fred Durst, Limp Bizkit
“I don’t hate technology, I don’t hate hackers, because that’s just
what comes with it without those hackers we wouldn’t solve the
problems we need to solve, especially security.”
–Fred Durst, Limp Bizkit
Somewhere on http://quotemaster.org/Hacking
THE BAD : SOME PLATFORMS…
HTTPS://XKCD.COM/908/
“Type a quote here.”
–Johnny Appleseed
AWESOME !!
The Mainframe (for me)
The Mainframe (for most people I know)
What on Earth is a Mainframe?
youtube.com/watch?v=H_oAXf1Og_o
5m27secs
RULE #1
ALWAYS HAVE A BACKUP
RULE #1
ALWAYS HAVE A BACKUP
Mainframe Myths
Mainframes are old/legacy

Mainframes don’t run modern applications

Mainframes are expensive

There is a skill shortage

It’s unbelievably secure
Did you know…..
nmap and metasploit have support for
the mainframe?
tso-brute, vtam-enum, etc.
Every heard of ELV.APF?
3 words: Started Task Impersonation
Did you know…..
nmap and metasploit have support for
the mainframe?
tso-brute, vtam-enum, etc.
Every heard of ELV.APF?
3 words: Started Task Impersonation
Did you know…..
nmap and metasploit have support for
the mainframe?
tso-brute, vtam-enum, etc.
Every heard of ELV.APF?
3 words: Started Task Impersonation
Did you know…..
nmap and metasploit have support for
the mainframe?
tso-brute, vtam-enum, etc.
Every heard of ELV.APF?
3 words: Started Task Impersonation
THE UGLY
THE HACKERS ARE COMING FOR YOU
The hackers don’t care…
Offering their services via the dark web

Have plenty of resources

Operate like a regular business

three-letter (foreign) agencies?

Cyberwarfare 

…..
Remember the video?
Pretty interesting for hackers
So why does this happen….
So why does this happen….
Anti Patterns
Anti Patterns
Accepting “you don’t need to test this” scenarios
Anti Patterns
Accepting “you don’t need to test this” scenarios
Scoping off an assessment on the platform level
Anti Patterns
Accepting “you don’t need to test this” scenarios
Scoping off an assessment on the platform level
Assuming protocols and procedures are enforced (or controlled)
Anti Patterns
Accepting “you don’t need to test this” scenarios
Scoping off an assessment on the platform level
Assuming protocols and procedures are enforced (or controlled)
Complacency vs. Compliancy
Anti Patterns
Accepting “you don’t need to test this” scenarios
Scoping off an assessment on the platform level
Assuming protocols and procedures are enforced (or controlled)
Complacency vs. Compliancy
You can’t test this on production
Summary and things to remember
Summary
Summary
Don’t stick at the platform scope
Summary
Don’t stick at the platform scope
Include The Mainframe in all tests & assessments
Summary
Don’t stick at the platform scope
Include The Mainframe in all tests & assessments
Assume you already have been hacked
Summary
Don’t stick at the platform scope
Include The Mainframe in all tests & assessments
Assume you already have been hacked
Don’t believe previous reports
Summary
Don’t stick at the platform scope
Include The Mainframe in all tests & assessments
Assume you already have been hacked
Don’t believe previous reports
Be careful out there…..
170424 isaca lux slides

More Related Content

Similar to 170424 isaca lux slides

4.3 red scheme
4.3 red scheme4.3 red scheme
4.3 red scheme
hamza bekkali
 
Newspaper
NewspaperNewspaper
Newspaper
ESA Fabrication
 
Talk to parish clerks of Herefordshire about marketing and PR ideas
Talk to parish clerks of Herefordshire about marketing and PR ideasTalk to parish clerks of Herefordshire about marketing and PR ideas
Talk to parish clerks of Herefordshire about marketing and PR ideas
Ben Proctor
 
week3_garst_107357_mockupv1
week3_garst_107357_mockupv1week3_garst_107357_mockupv1
week3_garst_107357_mockupv1
Ashley Garst
 
16.9 blue scheme
16.9 blue scheme16.9 blue scheme
16.9 blue scheme
hamza bekkali
 
16.9 red scheme
16.9 red scheme16.9 red scheme
16.9 red scheme
hamza bekkali
 
16.9 mixed scheme dark version
16.9 mixed scheme   dark version16.9 mixed scheme   dark version
16.9 mixed scheme dark version
hamza bekkali
 
16.9 blue scheme
16.9 blue scheme16.9 blue scheme
16.9 blue scheme
hamza bekkali
 
16.9 mixed scheme dark version
16.9 mixed scheme   dark version16.9 mixed scheme   dark version
16.9 mixed scheme dark version
hamza bekkali
 
16.9 mixed scheme
16.9 mixed scheme16.9 mixed scheme
16.9 mixed scheme
hamza bekkali
 
Drupal camp DUBAI 2013
Drupal camp DUBAI 2013Drupal camp DUBAI 2013
Drupal camp DUBAI 2013
thedeeper
 
Death by PowerPoint
Death by PowerPointDeath by PowerPoint
Death by PowerPoint
david roberts
 
Biting the Bullet: Changing the way we use PowerPoint
Biting the Bullet: Changing the way we use PowerPointBiting the Bullet: Changing the way we use PowerPoint
Biting the Bullet: Changing the way we use PowerPoint
docrob900
 
Harnessing the Power of the Visual
Harnessing the Power of the VisualHarnessing the Power of the Visual
Harnessing the Power of the Visual
Kathleen A. Paris
 
Power point basics content-1
Power point basics content-1Power point basics content-1
Power point basics content-1
Kerry (aka KerryJ) Johnson
 
Marketing By Design
Marketing By DesignMarketing By Design
Marketing By Design
Brandon Eley
 
16.9 mixed scheme
16.9 mixed scheme16.9 mixed scheme
16.9 mixed scheme
hamza bekkali
 
ITT 2014 - Max Seelemann - Hello TextKit!
ITT 2014 - Max Seelemann - Hello TextKit!ITT 2014 - Max Seelemann - Hello TextKit!
ITT 2014 - Max Seelemann - Hello TextKit!
Istanbul Tech Talks
 
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customersTCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
TCUK Conference
 
Talis Keynote - David Errington | Talis Insight Europe 2016
Talis Keynote - David Errington | Talis Insight Europe 2016Talis Keynote - David Errington | Talis Insight Europe 2016
Talis Keynote - David Errington | Talis Insight Europe 2016
Talis
 

Similar to 170424 isaca lux slides (20)

4.3 red scheme
4.3 red scheme4.3 red scheme
4.3 red scheme
 
Newspaper
NewspaperNewspaper
Newspaper
 
Talk to parish clerks of Herefordshire about marketing and PR ideas
Talk to parish clerks of Herefordshire about marketing and PR ideasTalk to parish clerks of Herefordshire about marketing and PR ideas
Talk to parish clerks of Herefordshire about marketing and PR ideas
 
week3_garst_107357_mockupv1
week3_garst_107357_mockupv1week3_garst_107357_mockupv1
week3_garst_107357_mockupv1
 
16.9 blue scheme
16.9 blue scheme16.9 blue scheme
16.9 blue scheme
 
16.9 red scheme
16.9 red scheme16.9 red scheme
16.9 red scheme
 
16.9 mixed scheme dark version
16.9 mixed scheme   dark version16.9 mixed scheme   dark version
16.9 mixed scheme dark version
 
16.9 blue scheme
16.9 blue scheme16.9 blue scheme
16.9 blue scheme
 
16.9 mixed scheme dark version
16.9 mixed scheme   dark version16.9 mixed scheme   dark version
16.9 mixed scheme dark version
 
16.9 mixed scheme
16.9 mixed scheme16.9 mixed scheme
16.9 mixed scheme
 
Drupal camp DUBAI 2013
Drupal camp DUBAI 2013Drupal camp DUBAI 2013
Drupal camp DUBAI 2013
 
Death by PowerPoint
Death by PowerPointDeath by PowerPoint
Death by PowerPoint
 
Biting the Bullet: Changing the way we use PowerPoint
Biting the Bullet: Changing the way we use PowerPointBiting the Bullet: Changing the way we use PowerPoint
Biting the Bullet: Changing the way we use PowerPoint
 
Harnessing the Power of the Visual
Harnessing the Power of the VisualHarnessing the Power of the Visual
Harnessing the Power of the Visual
 
Power point basics content-1
Power point basics content-1Power point basics content-1
Power point basics content-1
 
Marketing By Design
Marketing By DesignMarketing By Design
Marketing By Design
 
16.9 mixed scheme
16.9 mixed scheme16.9 mixed scheme
16.9 mixed scheme
 
ITT 2014 - Max Seelemann - Hello TextKit!
ITT 2014 - Max Seelemann - Hello TextKit!ITT 2014 - Max Seelemann - Hello TextKit!
ITT 2014 - Max Seelemann - Hello TextKit!
 
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customersTCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
TCUK 2012, Ian Ampleford and Peter Jones, Why would we want to talk to customers
 
Talis Keynote - David Errington | Talis Insight Europe 2016
Talis Keynote - David Errington | Talis Insight Europe 2016Talis Keynote - David Errington | Talis Insight Europe 2016
Talis Keynote - David Errington | Talis Insight Europe 2016
 

Recently uploaded

Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
DianaGray10
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
Mariano Tinti
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
Aftab Hussain
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
Zilliz
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
Edge AI and Vision Alliance
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
Neo4j
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 

Recently uploaded (20)

Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 

170424 isaca lux slides

  • 1.
  • 2. For those of you who don’t know me
  • 3. For those of you who don’t know me This is me ------>
  • 8. Number 5 (with dial up internet)
  • 10. My most recent computer :)
  • 13. Looks like this… yes, that’s a Mainframe
  • 14. Christopher O'Malley President and CEO at Compuware “There’s an acknowledged surge of interest in Agile and DevOps on the mainframe. With good reason. Your business can’t be truly agile unless your systems-of-record are truly agile. And for most large enterprises, those systems run on the mainframe………” https://www.linkedin.com/pulse/big-agile-devops-decision-you-need-make-today-christopher-o-malley
  • 16. Email: henri@zdevops.com Twitter: @henrikuiper LinkedIN: https://nl.linkedin.com/in/wizardofzos
  • 17. So how did I end up here?
  • 18.
  • 19.
  • 20. Software • Encryption • Smartcrypt TDE • SecureZIP • Compression • PKZIP • Threat Detection • TrapX for most major platforms
  • 21. Services • Pentesting • Vulnerability Checks • Risk Assessments • Security Officers! • Monitoring • Policy Enforcers • Managed Security Services
  • 22.
  • 24. 161116 PBSA Good, Bad, Ugly
  • 25. Legal Stuff Lorem ipsum dolor sit amet, consectetur adipiscing elit. Cras feugiat velit ac justo finibus, ut molestie lectus bibendum. Duis leo massa, bibendum vitae imperdiet in, commodo nec velit. Vivamus tincidunt, eros eu rutrum posuere, ex dui porta sapien, in placerat quam diam sit amet tortor. Aenean nec diam tellus. Integer ornare euismod enim. Aenean ipsum diam, feugiat hendrerit justo ut, maximus ornare nisi. Nullam augue diam, malesuada consequat porta non, ullamcorper sed tortor. Phasellus in lacus eget erat vestibulum hendrerit sed nec quam. Praesent ante magna, consequat eget ultrices vitae, congue sed leo. Vivamus nec felis ac neque accumsan rutrum in id massa. Ut mollis in mauris a auctor. Aliquam dictum lectus vel vehicula iaculis. Quisque at quam ut libero rhoncus consectetur. Proin ac ultricies lacus. Sed in mauris ut velit malesuada consequat in eu lorem. Quisque sollicitudin dapibus orci sit amet feugiat. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia Curae; Class aptent taciti sociosqu ad litora torquent per conubia nostra, per inceptos himenaeos. Nulla facilisi. Sed ultricies tellus in sem elementum, vitae fringilla ante vestibulum. Nullam pharetra arcu odio, sed pharetra purus pulvinar et. Suspendisse nec aliquet orci. Nulla consequat elit ante, eu malesuada elit laoreet ut. Sed malesuada ornare tortor. Pellentesque fringilla fermentum quam eget bibendum. Etiam porttitor, quam sit amet laoreet ultricies, erat ipsum fermentum metus, sit amet elementum elit leo aliquet purus. Maecenas varius metus purus, eu eleifend est pellentesque a. Duis mauris eros, ultricies sit amet posuere sed, pulvinar ut elit. Aliquam mattis ligula felis, sit amet venenatis ligula porta quis. Nunc ut vulputate ante. Pellentesque congue eleifend pellentesque. Curabitur bibendum porttitor sem, eu varius mauris ultricies vitae. Phasellus pulvinar vestibulum gravida. Proin non eleifend odio. Aenean pharetra pretium orci ac scelerisque. Sed lobortis vel magna nec volutpat. Nam et dui metus. Quisque aliquam ligula dapibus, convallis purus ac, accumsan ex. Ut id tempus diam, vel porttitor justo. Pellentesque venenatis justo sem, sit amet interdum mauris tristique vitae. Fusce metus magna, suscipit vitae convallis eget, ultricies sed est. Fusce sodales diam sit amet imperdiet venenatis. Aenean sed eros quis arcu dapibus porttitor id ut magna. Ut suscipit ex eu nibh bibendum posuere. Quisque semper feugiat ante, pharetra ultrices turpis feugiat ac. Fusce non neque purus. Curabitur eget sagittis nunc, nec aliquam diam. Integer augue ligula, eleifend ut eleifend vitae, congue eu est. Vestibulum semper, nunc nec placerat condimentum, tortor lectus tempor risus, eu viverra sem tortor sed dolor. Nam volutpat nulla a felis ultricies, ac pellentesque ligula vehicula. Phasellus imperdiet velit sit amet laoreet sollicitudin. Morbi elementum viverra enim, eget feugiat sem interdum nec. Nulla facilisi. Praesent ex lectus, posuere non molestie et, laoreet at lorem. Phasellus mollis, justo quis venenatis ultricies, ante ante ultrices est, sed dapibus turpis odio ac leo. In pharetra velit commodo massa eleifend, eget vehicula felis commodo.
  • 26. Legal Stuff Lorem ipsum dolor sit amet, consectetur adipiscing elit. Cras feugiat velit ac justo finibus, ut molestie lectus bibendum. Duis leo massa, bibendum vitae imperdiet in, commodo nec velit. Vivamus tincidunt, eros eu rutrum posuere, ex dui porta sapien, in placerat quam diam sit amet tortor. Aenean nec diam tellus. Integer ornare euismod enim. Aenean ipsum diam, feugiat hendrerit justo ut, maximus ornare nisi. Nullam augue diam, malesuada consequat porta non, ullamcorper sed tortor. Phasellus in lacus eget erat vestibulum hendrerit sed nec quam. Praesent ante magna, consequat eget ultrices vitae, congue sed leo. Vivamus nec felis ac neque accumsan rutrum in id massa. Ut mollis in mauris a auctor. Aliquam dictum lectus vel vehicula iaculis. Quisque at quam ut libero rhoncus consectetur. Proin ac ultricies lacus. Sed in mauris ut velit malesuada consequat in eu lorem. Quisque sollicitudin dapibus orci sit amet feugiat. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia Curae; Class aptent taciti sociosqu ad litora torquent per conubia nostra, per inceptos himenaeos. Nulla facilisi. Sed ultricies tellus in sem elementum, vitae fringilla ante vestibulum. Nullam pharetra arcu odio, sed pharetra purus pulvinar et. Suspendisse nec aliquet orci. Nulla consequat elit ante, eu malesuada elit laoreet ut. Sed malesuada ornare tortor. Pellentesque fringilla fermentum quam eget bibendum. Etiam porttitor, quam sit amet laoreet ultricies, erat ipsum fermentum metus, sit amet elementum elit leo aliquet purus. Maecenas varius metus purus, eu eleifend est pellentesque a. Duis mauris eros, ultricies sit amet posuere sed, pulvinar ut elit. Aliquam mattis ligula felis, sit amet venenatis ligula porta quis. Nunc ut vulputate ante. Pellentesque congue eleifend pellentesque. Curabitur bibendum porttitor sem, eu varius mauris ultricies vitae. Phasellus pulvinar vestibulum gravida. Proin non eleifend odio. Aenean pharetra pretium orci ac scelerisque. Sed lobortis vel magna nec volutpat. Nam et dui metus. Quisque aliquam ligula dapibus, convallis purus ac, accumsan ex. Ut id tempus diam, vel porttitor justo. Pellentesque venenatis justo sem, sit amet interdum mauris tristique vitae. Fusce metus magna, suscipit vitae convallis eget, ultricies sed est. Fusce sodales diam sit amet imperdiet venenatis. Aenean sed eros quis arcu dapibus porttitor id ut magna. Ut suscipit ex eu nibh bibendum posuere. Quisque semper feugiat ante, pharetra ultrices turpis feugiat ac. Fusce non neque purus. Curabitur eget sagittis nunc, nec aliquam diam. Integer augue ligula, eleifend ut eleifend vitae, congue eu est. Vestibulum semper, nunc nec placerat condimentum, tortor lectus tempor risus, eu viverra sem tortor sed dolor. Nam volutpat nulla a felis ultricies, ac pellentesque ligula vehicula. Phasellus imperdiet velit sit amet laoreet sollicitudin. Morbi elementum viverra enim, eget feugiat sem interdum nec. Nulla facilisi. Praesent ex lectus, posuere non molestie et, laoreet at lorem. Phasellus mollis, justo quis venenatis ultricies, ante ante ultrices est, sed dapibus turpis odio ac leo. In pharetra velit commodo massa eleifend, eget vehicula felis commodo.
  • 27. EXCLUSIVELY INCLUSIVE PROJECT DATE 16/11/2016 PLATFORM BASED SECURITY ASSESSMENTS THE GOOD, THE BAD AND THE UGLY
  • 30. THE GOOD IN-DEPTH SECURITY ASSESSMENT FOR THE ENTIRE OPERATING SYSTEM
  • 31. Platform Security Assessments Are they better than Network Security Scanners? (Wireshark, nmap, metasploit, …)? Or better than Web Security Scanners? (OWASP, Burp Suite, …)? They identify intrinsic security flaws How do you do them? And what’s the goal?
  • 32. EXECUTING A SECURITY ASSESSMENT….. LIST BASED AND/OR SERIOUSLY CHECKING THE SYSTEM?
  • 33.
  • 34.
  • 35.
  • 36.
  • 37.
  • 38. “I don’t hate technology, I don’t hate hackers, because that’s just what comes with it without those hackers we wouldn’t solve the problems we need to solve, especially security.” –Fred Durst, Limp Bizkit
  • 39. “I don’t hate technology, I don’t hate hackers, because that’s just what comes with it without those hackers we wouldn’t solve the problems we need to solve, especially security.” –Fred Durst, Limp Bizkit
  • 40. “I don’t hate technology, I don’t hate hackers, because that’s just what comes with it without those hackers we wouldn’t solve the problems we need to solve, especially security.” –Fred Durst, Limp Bizkit Somewhere on http://quotemaster.org/Hacking
  • 41. THE BAD : SOME PLATFORMS… HTTPS://XKCD.COM/908/
  • 42. “Type a quote here.” –Johnny Appleseed AWESOME !! The Mainframe (for me)
  • 43. The Mainframe (for most people I know)
  • 44. What on Earth is a Mainframe? youtube.com/watch?v=H_oAXf1Og_o 5m27secs
  • 47. Mainframe Myths Mainframes are old/legacy Mainframes don’t run modern applications Mainframes are expensive There is a skill shortage It’s unbelievably secure
  • 48. Did you know….. nmap and metasploit have support for the mainframe? tso-brute, vtam-enum, etc. Every heard of ELV.APF? 3 words: Started Task Impersonation
  • 49. Did you know….. nmap and metasploit have support for the mainframe? tso-brute, vtam-enum, etc. Every heard of ELV.APF? 3 words: Started Task Impersonation
  • 50. Did you know….. nmap and metasploit have support for the mainframe? tso-brute, vtam-enum, etc. Every heard of ELV.APF? 3 words: Started Task Impersonation
  • 51. Did you know….. nmap and metasploit have support for the mainframe? tso-brute, vtam-enum, etc. Every heard of ELV.APF? 3 words: Started Task Impersonation
  • 52. THE UGLY THE HACKERS ARE COMING FOR YOU
  • 53. The hackers don’t care… Offering their services via the dark web Have plenty of resources Operate like a regular business three-letter (foreign) agencies? Cyberwarfare …..
  • 54. Remember the video? Pretty interesting for hackers
  • 55. So why does this happen….
  • 56. So why does this happen….
  • 58. Anti Patterns Accepting “you don’t need to test this” scenarios
  • 59. Anti Patterns Accepting “you don’t need to test this” scenarios Scoping off an assessment on the platform level
  • 60. Anti Patterns Accepting “you don’t need to test this” scenarios Scoping off an assessment on the platform level Assuming protocols and procedures are enforced (or controlled)
  • 61. Anti Patterns Accepting “you don’t need to test this” scenarios Scoping off an assessment on the platform level Assuming protocols and procedures are enforced (or controlled) Complacency vs. Compliancy
  • 62. Anti Patterns Accepting “you don’t need to test this” scenarios Scoping off an assessment on the platform level Assuming protocols and procedures are enforced (or controlled) Complacency vs. Compliancy You can’t test this on production
  • 63. Summary and things to remember
  • 65. Summary Don’t stick at the platform scope
  • 66. Summary Don’t stick at the platform scope Include The Mainframe in all tests & assessments
  • 67. Summary Don’t stick at the platform scope Include The Mainframe in all tests & assessments Assume you already have been hacked
  • 68. Summary Don’t stick at the platform scope Include The Mainframe in all tests & assessments Assume you already have been hacked Don’t believe previous reports
  • 69. Summary Don’t stick at the platform scope Include The Mainframe in all tests & assessments Assume you already have been hacked Don’t believe previous reports Be careful out there…..