黑客入侵机场以获得乐趣和教育(以及更好的安全监控).pdf

编号:402817 PDF 35页 4.59MB 下载积分:VIP专享
下载报告请您先登录!

黑客入侵机场以获得乐趣和教育(以及更好的安全监控).pdf

1、Hacking Airports for Fun and Education(and better security monitoring,too!)Meredith Kasper&Tom KopchakHurricane LabsSetting the sceneWho are we?Meredith KasperDirector of Technical Services Hurricane Labs.CPTC competition director,former CPTC competitor.Tom KopchakDirector of Technical Operations,Te

2、chnical Account Manager Hurricane Labs.CPTC competition directorWhat is CPTC?CPTC:A premier international offensive security competition.Challenge:Conduct a penetration test of a fictitious company,and deliver the results to management.Started RIT in 2015.Still going strong 10 years later.Offensive

3、Security+Custom Environment+Business=CPTCCPTC ThemesWe create a new theme(target organization)every year.Themes of recent years:2024 Social Media Company2023 Airport2022 Hotel2021 Candy Manufacturing Co.2020 Public Utility2019 Financial Institution2018 Transportation App2017 Elections Provider Build

4、ing the environmentNew Year=New EnvironmentTypical Environment=20-40 HostsBusiness HostsWindows&Linux serversWorking AD environmentCustom ApplicationsTONS of VulnerabilitiesTypically 150+known issues by the time were finished We Log EVERYTHINGOur preferred tool of choice:SplunkSplunk agents(Universa

5、l Forwarders)deployed to all systems that support it in the environment.If theres data to be collected,we try to do it.Most Windows+Linux inputs enabled,higher collection thresholds than“normal”for increased visibility.Custom inputs to support the competition.Key SourcetypesSplunk Stream(HTTP,DNS,TC

6、P and UDP)WinEventLog:Security(Authentication and Change)Sysmon(Process Logging)WinNetMon(Traffic Logs by Process)Bash_history&powershell transcriptsOffice365 admin/message traceAWS VPC flowReally stupid()file integrity monitoring ps and netstatRobert A.Kalka Metropolitan Skyport(RAKMS)Deep Dive Sim

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(黑客入侵机场以获得乐趣和教育(以及更好的安全监控).pdf)为本站 (alkaid) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠