goltsev yuriy - Ломать - не строить!

14
Ломать - не строить! Юрий Гольцев @ygoltsev

Upload: defcon-moscow

Post on 13-Aug-2015

892 views

Category:

Education


9 download

TRANSCRIPT

Page 1: Goltsev Yuriy - Ломать - не строить!

Ломать - не строить!Юрий Гольцев

@ygoltsev

Page 2: Goltsev Yuriy - Ломать - не строить!

Intro

Page 3: Goltsev Yuriy - Ломать - не строить!

Invest in your knowledge of practical information security

Page 4: Goltsev Yuriy - Ломать - не строить!

Please, don’t order a penetration test until…

Page 5: Goltsev Yuriy - Ломать - не строить!

My own TOP of security issues, related to internal networks:1. Weak password policy2. Default accounts3. Local accounts/unnecessary privileges4. Windows architecture5. WPAD configuration mismatch6. Antivirus software configuration mismatch7. No network segmentation8. No patch management

Page 6: Goltsev Yuriy - Ломать - не строить!

Weak password policy

DescriptionEasy to bruteforce

Common TargetsDirectory Service (Active Directory/Lotus Domino/LDAP/Novell/etc)

RecommendationsImplement strong password policy, just follow next rules:- 8 chars (at least)-Lower, upper case-Alpha-Numeric

Check for common passwords once a day (at least)

- Special chars- Change every 60 days

Page 7: Goltsev Yuriy - Ломать - не строить!

Default accounts

DescriptionEasy to bruteforce

Common TargetsDBs, network devices (routers/printers/etc)

Recommendations-Disable all unused accounts-Set strong password

Page 8: Goltsev Yuriy - Ломать - не строить!

Local accounts/unnecessary privileges

DescriptionLocal administrator accounts/privileges – is bad

Common TargetsWindows hosts

Recommendations-Disable accounts of local administrators on Windows hosts-Do not use GP to manage accounts of local administrators on Windows hosts

Page 9: Goltsev Yuriy - Ломать - не строить!

Windows architecture

DescriptionYou can’t prevent it, if you use it

Common TargetsWindows hosts

Recommendations-Follow principle of minimal privileges-Use privileged accounts for administration tasks only-Implement two factor authentication for privileged accounts-Implement patch management

Page 10: Goltsev Yuriy - Ломать - не строить!

WPAD configuration mismatch

DescriptionVery useful for corporate users if implemented, and for attacker – if not

Common TargetsWindows hosts

RecommendationsDisable WPAD (Web Proxy Auto Discovery) feature if it is not implemented

Page 11: Goltsev Yuriy - Ломать - не строить!

Antivirus software configuration mismatch

DescriptionAntivirus software can be disable with local admin privileges

Common TargetsWindows hosts

RecommendationsConfigure self defense feature of antivirus software

Page 12: Goltsev Yuriy - Ломать - не строить!

No network segmentation

DescriptionNo restrictions and no data filtration on network level

Common TargetsNetwork topology

RecommendationsImplement data filtration – it is better to use white lists for access

Page 13: Goltsev Yuriy - Ломать - не строить!

No patch management

DescriptionMS08-067 still can be found during penetration test

Common TargetsWindows/Unix hosts

RecommendationsImplement patch management

Page 14: Goltsev Yuriy - Ломать - не строить!

Outro