Auditorias de Seguridad Informática:
 Herramientas y alcances actuales


     www.enhacke.com                   0
Temas a tocar


    Estructura de la exposición:

    •   Seguridad Informática en Latinoamérica
    •   Mafias y hacking underground
    •   Hacking malicioso en Perú
    •   Auditorías - Metodología del Hacking
    •   Herramientas
    •   Aporte enHacke - Demo

2                    www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
              1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
              0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
              0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
              0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
              1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
              1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
              1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
              0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
              1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
              0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
              1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
              1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
              0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
              1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
              1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
              0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
              1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
              1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
              0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
              0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
              1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
              1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
              1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
              0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
              0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
              0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
              0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
              0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
              0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
              1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
              1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
              0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
              1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
              1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
              1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
              1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
              1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
              1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
              1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
              1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
              0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
              1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
              1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
              1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
              0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
              0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
              1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
              1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
              0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
              1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
              1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




    Seguridad Informática en Latinoamérica



3
Seguridad en la nube
   Servidores en la nube serán menos seguros que los equipos físicos
    en el 2012
       60% de los servidores virtualizados serán menos seguros
       Porque?
         No se incluye a un equipo de seguridad informática en la implementación




4                               www.enHacke.com
Que preocupa a los directivos?




5             www.enHacke.com
Presupuesto anual




6             www.enHacke.com
Pymes vs corporate




7             www.enHacke.com
Se quiere evitar…




8             www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
         1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
         0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
         0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
         0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
         1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
         1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
         1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
         0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
         1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
         0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
         1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
         1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
         0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
         1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
         1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
         0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
         1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
         1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
         0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
         0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
         1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
         1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
         1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
         0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
         0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
         0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
         0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
         0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
         0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
         1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
         1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
         0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
         1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
         1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
         1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
         1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
         1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
         1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
         1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
         1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
         0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
         1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
         1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
         1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
         0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
         0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
         1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
         1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
         0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
         1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
         1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




    Mafias y Hacking Underground



9
Botnets y Botmasters
                            Hackers maliciosos ofrecen
                             sus botnets con miles de
                             esclavos para alquiler
                            Atacan también a pedido
                            Ofrecen sus servicios
                             mediante canales de chat en
                             el internet
                            El pago es anonimo por
                             medio de egold, moneygram,
                             western union.




10             www.enHacke.com
Venta y distrib. de TARJETAS DE CREDITO




11            www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
      1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
      0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
      0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
      0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
      1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
      1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
      1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
      0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
      1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
      0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
      1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
      1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
      0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
      1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
      1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
      0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
      1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
      1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
      0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
      0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
      1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
      1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
      1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
      0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
      0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
      0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
      0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
      0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
      0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
      1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
      1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
      0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
      1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
      1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
      1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
      1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
      1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
      1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
      1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
      1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
      0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
      1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
      1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
      1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
      0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
      0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
      1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
      1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
      0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
      1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
      1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




     Perú y Latinoamerica



12
Perú? Hackers? Aquí?
    Crecimiento económico en el Perú
    Perú en la mira del mundo
      Pero no solo de inversionistas
      Sino también de ciberdelincuentes
      Las grandes inversiones vienen de la mano de grandes implementaciones IT
    Cibercrimen en Perú
      Alquiler de botnets para sabotear empresas
      Phishing y carding
      Paginas defaceadas (modificadas)
      Secuestro de información
      Skimming
      Extorsion
            Por videos
            Por información sensible


    13                              www.enHacke.com
Botnets latinas
                             En latinoamerica
                                 Hasta 12 dólares por mails
                                  corporativos con contraseña
                                 400 dolares por botnets de más
                                  de 200 máquinas
                                 Incriminación a pedido
                                 Secuestro de información
                                 Venta de BD de tarjetas de
                                  crédito




14                www.enHacke.com
Y en el Perú pasa algo??




15            www.enHacke.com
16   www.enHacke.com
17   www.enHacke.com
18   www.enHacke.com
19   www.enHacke.com
TQM ;) Te conectas mañana :-*
                            Personas sin moral y con
                             fines delictivos
                            Extorsion
                            Secuestros
                            Medios por donde actuan?
                                Hi5
                                Facebook
                                Redes sociales




20           www.enHacke.com
Uy! Una chica me esta agregando!!!




21            www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
        1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
        0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
        0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
        0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
        1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
        1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
        1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
        0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
        1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
        0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
        1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
        1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
        0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
        1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
        1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
        0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
        1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
        1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
        0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
        0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
        1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
        1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
        1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
        0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
        0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
        0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
        0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
        0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
        0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
        1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
        1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
        0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
        1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
        1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
        1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
        1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
        1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
        1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
        1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
        1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
        0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
        1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
        1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
        1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
        0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
        0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
        1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
        1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
        0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
        1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
        1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




     Metodología del Hacking



22
Metodologia del Hacking

 1. Reconocimiento
     • Activo                         5. Limpiar              1.
     • Pasivo                          huellas          Reconocimiento
 2. Escaneo
 3. Obtener acceso
     • A nivel de Sistema
        Operativo / a nivel de
        aplicación
     • A nivel de red                4.
                                                                   2.
     • Denegación de servicio    Mantener
                                                                Escaneo
 4. Mantener el acceso           el acceso
     • Subir / alterar / bajar
        programas o data
                                                     3.
 5. Limpiar huellas
                                                   Obtener
                                                   Acceso

                         www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
                1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
                0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
                0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
                0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
                1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
                1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
                1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
                0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
                1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
                0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
                1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
                1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
                0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
                1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
                1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
                0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
                1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
                1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
                0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
                0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
                1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
                1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
                1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
                0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
                0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
                0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
                0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
                0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
                0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
                1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
                1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
                0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
                1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
                1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
                1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
                1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
                1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
                1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
                1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
                1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
                0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
                1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
                1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
                1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
                0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
                0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
                1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
                1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
                0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
                1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
                1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




     Herramientas Open Source en la Metodología del
                        Hacking




24
Algunas herramientas usadas

 Reconocimiento

 • Dig                           Obteniendo acceso
 • Nslookup
 • Maltego
 • google hacking                • Hydra
                                 • Metasploit
 Escaneo

 • Red
   • angryIP
   • autoScan                    Manteniendo acceso
 • Puertos
   • Nmap
   • Hping
   • Amap                        • Cryptcat
 • Vulnerabilidades              • Rootkit (evaluar)
   • Nikto
   • Nessus
   • openVas



25                    www.enHacke.com
1001110010101010111110111100110100000110001111000011010100111100011100010111000000111
     1110011011000101001110010011101000011110101001000011001110110001110010100001110111111
     0101001110110000000110010101010001000110000011000111000011001111010100100001110101111
     0000100001010000001010111011100100011111011000111010100101110011011000001100011110000
     0111001010000100001000010111101110110011001011110111100010000101011000101111111111111
     1010101010001100100110110101110001111000001111100111101000101011100010011011111110001
     1011011111011100111000001001111110101110110001000101000110010010101100101100001000011
     1111111010111000001100000100101101110000001010111100111101101010100000001000110000101
     0001111001000100000010011010011111001110100101100010010001111110110011010001000101110
     1101111000100100000001100001001001101101110010100111010001000010001000010101001111011
     0000010011100001010000100111110000111010000111110110010111101011011010010001010100000
     1100000110110111110100011100001111110011110101000010011000110101101100011010101111010
     1111101010011101110011011111111101001100111110100000001011000111001011001010010001000
     0111110111010001101001011001010001011001001101000110100010000110110010001101011111110
     1100100101011100010001010111111100011001000100101001010010010111110000100011110001101
     1001100110010101001001011101110111011100001001000011001100011110101100011111100101101
     0000010110111000001110111100000101101101011011000000111011101111011111001010101001011
     1100010101100110101111011111101010101101000010100110111001001100010100010110110101110
     1101001000010010000011011011110011110011001110000011011011111001001010101011011111110
     0100101001010001111111010001101010001011101010010110101101010100110111010000001111110
     0111001010101110001000110100111011011101110110001001001001110011000001001110100100100
     1100111100000100011000110010101111001101011010000101111011011100100111000100011011000
     1110110101010001010011110001100001001100101011110001111000001000100111000110111111111
     1100000000100010110111011111010011010101010111000110110100000011001010000110000111110
     0110110010101010001100101111011010101001010001011110110001101100100010000101001110011
     0101000001000011010011010011111100010100011101111111000111101010001111110101011100001
     0111111100001111000111000110110010011101110010011000100110101000010011010011001101011
     0000101011001100011001010010110111011101101000100010011000010100111101100100111100100
     0011111000100111010000110010011001011010110110001010010011101011110000011101000011101
     0111011100001101010111001000000010110011010010100001001010011001010111101111011000000
     1100101010100001110010011110100111000001101001000010101011101011000101011101000101001
     1000010010110001110000011100001000010111101110111110011001111011000100001001101001010
     0001010101001011010000100000001100011100110010001011101110001101110011000000011111001
     1011010100110010111000001100101100001001000011010001000001001010111011110000010010001
     1001011110110110010111000001111100110001100110101100110010000100110001111000000110010
     1100110011101100110001101110101110111100011000001111001111111111110111100010000011000
     1010100111000100110101000000011101100011110000011100100110010110110100110010001010001
     1000001100010101101100111001111111001100101101101000000011111010010101110010000110011
     1001111000101001001111011001001101000111011101111110111010111101110010000100111001100
     1111011101111100110110111010110000000101000100101010001000010100000111001111010101110
     1010101100010101110010000000111011001000001101000011100001111001001110011100000011110
     0001001100100101001110110011100111100100111100111010110100000011101001011001101111010
     1110100011111111011011111001110010011110110010001010001011111011110100100011101001000
     1111111001001011011110000000111110000111010101011100001011001100100110111110001110101
     1010101011101000000000110110110111100011100111001011110101010111010010100101011100001
     0001100000101110010110010111001010111111010110011010111010101100111011001110100011110
     0111111110011110110011111010111001000001000111010111001000010111000111001100110011001
     1110010001011111110000010110101100100101111000011101111010010000101101001001101000100
     1101001011101011101000001110111011100000101110111011001111111010000011000110000101111
     0100011001001011000001010010011101101011111101000000111111110000110100100011011101100
     1111110010001000011100001011110101000001001111011110001010101011100010100110100011000
     1100111011000001111001111101101111101111000111110110010011110010011111100000111010000




       Aporte enHacke



26
Condiciones determinantes
   Escena de la seguridad informática en el Perú
       Gente muy capaz
       Falta de motivación y perseverancia
       Barreras de lenguaje
       Universidades no incorporan cursos de seguridad informática en su
        currícula
       Falsa percepción de seguridad
       Existe material en español pero la mayoría esta en ingles y otros idiomas
       Ganas de hacer crecer la comunidad de seguridad informática

       …….




27                              www.enHacke.com
28   www.enHacke.com
Que se puede hacer con NinjaSec


     Reconocimiento                   Escaneo




                                     Mantener el
          Acceso
                                       acceso

29                 www.enHacke.com
Que haremos?

     Reconocimiento                  Escaneo
     •   Dig                         • Red  angryIp
     •   Nslookup
                                     • Puertos  nmap
     •   Maltego
     •   googleHacking               • Vuln.  metasploit




     Acceso                          Mantener Acceso
     • Hydra                         • Cryptcat
     • Metasploit




30                       www.enHacke.com
ATAQUE!!!



31   www.enHacke.com
#>echo MUCH4S GR4C14S !!!



 www.enhacke.com            0

ENHACKE - Ninjasec en LinuxWeek

  • 1.
    Auditorias de SeguridadInformática: Herramientas y alcances actuales www.enhacke.com 0
  • 2.
    Temas a tocar Estructura de la exposición: • Seguridad Informática en Latinoamérica • Mafias y hacking underground • Hacking malicioso en Perú • Auditorías - Metodología del Hacking • Herramientas • Aporte enHacke - Demo 2 www.enHacke.com
  • 3.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Seguridad Informática en Latinoamérica 3
  • 4.
    Seguridad en lanube  Servidores en la nube serán menos seguros que los equipos físicos en el 2012  60% de los servidores virtualizados serán menos seguros  Porque?  No se incluye a un equipo de seguridad informática en la implementación 4 www.enHacke.com
  • 5.
    Que preocupa alos directivos? 5 www.enHacke.com
  • 6.
    Presupuesto anual 6 www.enHacke.com
  • 7.
    Pymes vs corporate 7 www.enHacke.com
  • 8.
    Se quiere evitar… 8 www.enHacke.com
  • 9.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Mafias y Hacking Underground 9
  • 10.
    Botnets y Botmasters  Hackers maliciosos ofrecen sus botnets con miles de esclavos para alquiler  Atacan también a pedido  Ofrecen sus servicios mediante canales de chat en el internet  El pago es anonimo por medio de egold, moneygram, western union. 10 www.enHacke.com
  • 11.
    Venta y distrib.de TARJETAS DE CREDITO 11 www.enHacke.com
  • 12.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Perú y Latinoamerica 12
  • 13.
    Perú? Hackers? Aquí?  Crecimiento económico en el Perú  Perú en la mira del mundo  Pero no solo de inversionistas  Sino también de ciberdelincuentes  Las grandes inversiones vienen de la mano de grandes implementaciones IT  Cibercrimen en Perú  Alquiler de botnets para sabotear empresas  Phishing y carding  Paginas defaceadas (modificadas)  Secuestro de información  Skimming  Extorsion  Por videos  Por información sensible 13 www.enHacke.com
  • 14.
    Botnets latinas  En latinoamerica  Hasta 12 dólares por mails corporativos con contraseña  400 dolares por botnets de más de 200 máquinas  Incriminación a pedido  Secuestro de información  Venta de BD de tarjetas de crédito 14 www.enHacke.com
  • 15.
    Y en elPerú pasa algo?? 15 www.enHacke.com
  • 16.
    16 www.enHacke.com
  • 17.
    17 www.enHacke.com
  • 18.
    18 www.enHacke.com
  • 19.
    19 www.enHacke.com
  • 20.
    TQM ;) Teconectas mañana :-*  Personas sin moral y con fines delictivos  Extorsion  Secuestros  Medios por donde actuan?  Hi5  Facebook  Redes sociales 20 www.enHacke.com
  • 21.
    Uy! Una chicame esta agregando!!! 21 www.enHacke.com
  • 22.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Metodología del Hacking 22
  • 23.
    Metodologia del Hacking 1. Reconocimiento • Activo 5. Limpiar 1. • Pasivo huellas Reconocimiento 2. Escaneo 3. Obtener acceso • A nivel de Sistema Operativo / a nivel de aplicación • A nivel de red 4. 2. • Denegación de servicio Mantener Escaneo 4. Mantener el acceso el acceso • Subir / alterar / bajar programas o data 3. 5. Limpiar huellas Obtener Acceso www.enHacke.com
  • 24.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Herramientas Open Source en la Metodología del Hacking 24
  • 25.
    Algunas herramientas usadas Reconocimiento • Dig Obteniendo acceso • Nslookup • Maltego • google hacking • Hydra • Metasploit Escaneo • Red • angryIP • autoScan Manteniendo acceso • Puertos • Nmap • Hping • Amap • Cryptcat • Vulnerabilidades • Rootkit (evaluar) • Nikto • Nessus • openVas 25 www.enHacke.com
  • 26.
    1001110010101010111110111100110100000110001111000011010100111100011100010111000000111 1110011011000101001110010011101000011110101001000011001110110001110010100001110111111 0101001110110000000110010101010001000110000011000111000011001111010100100001110101111 0000100001010000001010111011100100011111011000111010100101110011011000001100011110000 0111001010000100001000010111101110110011001011110111100010000101011000101111111111111 1010101010001100100110110101110001111000001111100111101000101011100010011011111110001 1011011111011100111000001001111110101110110001000101000110010010101100101100001000011 1111111010111000001100000100101101110000001010111100111101101010100000001000110000101 0001111001000100000010011010011111001110100101100010010001111110110011010001000101110 1101111000100100000001100001001001101101110010100111010001000010001000010101001111011 0000010011100001010000100111110000111010000111110110010111101011011010010001010100000 1100000110110111110100011100001111110011110101000010011000110101101100011010101111010 1111101010011101110011011111111101001100111110100000001011000111001011001010010001000 0111110111010001101001011001010001011001001101000110100010000110110010001101011111110 1100100101011100010001010111111100011001000100101001010010010111110000100011110001101 1001100110010101001001011101110111011100001001000011001100011110101100011111100101101 0000010110111000001110111100000101101101011011000000111011101111011111001010101001011 1100010101100110101111011111101010101101000010100110111001001100010100010110110101110 1101001000010010000011011011110011110011001110000011011011111001001010101011011111110 0100101001010001111111010001101010001011101010010110101101010100110111010000001111110 0111001010101110001000110100111011011101110110001001001001110011000001001110100100100 1100111100000100011000110010101111001101011010000101111011011100100111000100011011000 1110110101010001010011110001100001001100101011110001111000001000100111000110111111111 1100000000100010110111011111010011010101010111000110110100000011001010000110000111110 0110110010101010001100101111011010101001010001011110110001101100100010000101001110011 0101000001000011010011010011111100010100011101111111000111101010001111110101011100001 0111111100001111000111000110110010011101110010011000100110101000010011010011001101011 0000101011001100011001010010110111011101101000100010011000010100111101100100111100100 0011111000100111010000110010011001011010110110001010010011101011110000011101000011101 0111011100001101010111001000000010110011010010100001001010011001010111101111011000000 1100101010100001110010011110100111000001101001000010101011101011000101011101000101001 1000010010110001110000011100001000010111101110111110011001111011000100001001101001010 0001010101001011010000100000001100011100110010001011101110001101110011000000011111001 1011010100110010111000001100101100001001000011010001000001001010111011110000010010001 1001011110110110010111000001111100110001100110101100110010000100110001111000000110010 1100110011101100110001101110101110111100011000001111001111111111110111100010000011000 1010100111000100110101000000011101100011110000011100100110010110110100110010001010001 1000001100010101101100111001111111001100101101101000000011111010010101110010000110011 1001111000101001001111011001001101000111011101111110111010111101110010000100111001100 1111011101111100110110111010110000000101000100101010001000010100000111001111010101110 1010101100010101110010000000111011001000001101000011100001111001001110011100000011110 0001001100100101001110110011100111100100111100111010110100000011101001011001101111010 1110100011111111011011111001110010011110110010001010001011111011110100100011101001000 1111111001001011011110000000111110000111010101011100001011001100100110111110001110101 1010101011101000000000110110110111100011100111001011110101010111010010100101011100001 0001100000101110010110010111001010111111010110011010111010101100111011001110100011110 0111111110011110110011111010111001000001000111010111001000010111000111001100110011001 1110010001011111110000010110101100100101111000011101111010010000101101001001101000100 1101001011101011101000001110111011100000101110111011001111111010000011000110000101111 0100011001001011000001010010011101101011111101000000111111110000110100100011011101100 1111110010001000011100001011110101000001001111011110001010101011100010100110100011000 1100111011000001111001111101101111101111000111110110010011110010011111100000111010000 Aporte enHacke 26
  • 27.
    Condiciones determinantes  Escena de la seguridad informática en el Perú  Gente muy capaz  Falta de motivación y perseverancia  Barreras de lenguaje  Universidades no incorporan cursos de seguridad informática en su currícula  Falsa percepción de seguridad  Existe material en español pero la mayoría esta en ingles y otros idiomas  Ganas de hacer crecer la comunidad de seguridad informática  ……. 27 www.enHacke.com
  • 28.
    28 www.enHacke.com
  • 29.
    Que se puedehacer con NinjaSec Reconocimiento Escaneo Mantener el Acceso acceso 29 www.enHacke.com
  • 30.
    Que haremos? Reconocimiento Escaneo • Dig • Red  angryIp • Nslookup • Puertos  nmap • Maltego • googleHacking • Vuln.  metasploit Acceso Mantener Acceso • Hydra • Cryptcat • Metasploit 30 www.enHacke.com
  • 31.
    ATAQUE!!! 31 www.enHacke.com
  • 32.
    #>echo MUCH4S GR4C14S!!! www.enhacke.com 0