how to catch your “hacker” or makeshift security

34
Sergey Soldatov Igor Gots HOW TO CATCH YOUR “HACKER” OR MAKESHIFT SECURITY

Upload: sergey-soldatov

Post on 27-May-2015

1.325 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: How to catch your “hacker” or makeshift security

Sergey Soldatov

Igor Gots

HOW TO CATCH YOUR “HACKER”

OR

MAKESHIFT SECURITY

Page 2: How to catch your “hacker” or makeshift security

AGENDA

• Water

• Fishing

• Fishbite

• Hookset

ZERONIGHTS 2012 GOTS/SOLDATOV 2

Page 3: How to catch your “hacker” or makeshift security

AGENDA

• Water

• Fishing

• Fishbite

• Hookset

ZERONIGHTS 2012 GOTS/SOLDATOV 3

Page 4: How to catch your “hacker” or makeshift security

W?

ZERONIGHTS 2012 GOTS/SOLDATOV 4

Page 5: How to catch your “hacker” or makeshift security

W?

ZERONIGHTS 2012 GOTS/SOLDATOV 5

Page 6: How to catch your “hacker” or makeshift security

INFOSECURITY DEPT. HAS TO

• Write corporate regulations

• Make assessments (compliance &/| pentest)

• Monitor logs!

ZERONIGHTS 2012 GOTS/SOLDATOV 6

Page 7: How to catch your “hacker” or makeshift security

INFOSECURITY DEPT. HAS TO

• Write corporate regulations

• Make assessments (compliance &/| pentest)

• Monitor logs!

ZERONIGHTS 2012 GOTS/SOLDATOV 7

Page 8: How to catch your “hacker” or makeshift security

ATTACK STAGES

• Information gathering

• Passive learning

• Active learning

• Obtaining access

• Maintaining access

• Erasing evidence

ZERONIGHTS 2012 GOTS/SOLDATOV 8

Page 9: How to catch your “hacker” or makeshift security

FISHING

• Firewall/UTM/… :-)

• IDS/IPS

• Commercial

• Opensource/free

• Log analysis

• Commercial

• Opensource/free

ZERONIGHTS 2012 GOTS/SOLDATOV 9

Page 10: How to catch your “hacker” or makeshift security

WHAT’S HAPPENING WHEN ONE’S BREAKING

• Use or modification of privileged accounts

• Configuration modification

• Unusual activity

• New services or applications

ZERONIGHTS 2012 GOTS/SOLDATOV 10

Page 11: How to catch your “hacker” or makeshift security

TOOL DEPLOYMENT

ZERONIGHTS 2012 GOTS/SOLDATOV 11

Page 12: How to catch your “hacker” or makeshift security

RECOMMENDED LIST OF EVENTS

ZERONIGHTS 2012 GOTS/SOLDATOV 12

• Pros:

• Microsoft recommends

• Cons:

• Huge amount of data

• Fun:

Page 13: How to catch your “hacker” or makeshift security

RECOMMENDED LIST OF EVENTS

ZERONIGHTS 2012 GOTS/SOLDATOV 13

• Pros:

• Microsoft recommends

• Cons:

• Huge amount of data

• Fun:

Page 14: How to catch your “hacker” or makeshift security

“IMPROVEMENTS” FOR MICROSOFT GUIDE

• Admin logon from unusual place

• Admin logon at unusual time

• From one IP by different accounts

• Lock >1 accounts from one IP

• Password/Hash dump

• Run system commands

ZERONIGHTS 2012 GOTS/SOLDATOV 14

• Pros:

• More AI

• Cons:

• Need time

Page 15: How to catch your “hacker” or makeshift security

UNIVERSAL METHODS

• Start a service

(windows)

• Events (almost) never

seen before

ZERONIGHTS 2012 GOTS/SOLDATOV 15

• Pros:

• Much more AI

• Cons:

• 100% we’ve

forgotten smth.

Page 16: How to catch your “hacker” or makeshift security

CONDITIONS

• OS default

configuration

• Up2date AV is up

and running

• OS (almost) up2date

ZERONIGHTS 2012 GOTS/SOLDATOV 16

• Tested tools:

• fgdump

• pwdump

• pwdumpx

• metasploit

• wce

• mimikatz

Page 17: How to catch your “hacker” or makeshift security

NEVER SEEN BEFORE EVENTS

• Approaches

• Timeout for statistic collection (up to 24 hours)

• Complex filtering (by criteria)

• Risks

• Server restart in case of intrusion

• Intrusion during statistic gathering

• Complex configuration

• Details of event happening

ZERONIGHTS 2012 GOTS/SOLDATOV 17

Page 18: How to catch your “hacker” or makeshift security

NEVER SEEN BEFORE EVENTS (RULE FOR SEC.PL)

ZERONIGHTS 2012 GOTS/SOLDATOV 18

Page 19: How to catch your “hacker” or makeshift security

ZERONIGHTS 2012 GOTS/SOLDATOV 19

FGDUMP (REMOTE)

Page 20: How to catch your “hacker” or makeshift security

PWDUMP6 (REMOTE)

ZERONIGHTS 2012 GOTS/SOLDATOV 20

Page 21: How to catch your “hacker” or makeshift security

PWDUMPX (REMOTE)

ZERONIGHTS 2012 GOTS/SOLDATOV 21

Page 22: How to catch your “hacker” or makeshift security

METASPLOIT

ZERONIGHTS 2012 GOTS/SOLDATOV 22

Page 23: How to catch your “hacker” or makeshift security

ZERONIGHTS 2012 GOTS/SOLDATOV 23

WCE (LOCAL)

Page 24: How to catch your “hacker” or makeshift security

BUT

ZERONIGHTS 2012 GOTS/SOLDATOV 24

Page 25: How to catch your “hacker” or makeshift security

BUT

ZERONIGHTS 2012 GOTS/SOLDATOV 25

Page 26: How to catch your “hacker” or makeshift security

BUT

ZERONIGHTS 2012 GOTS/SOLDATOV 26

Page 27: How to catch your “hacker” or makeshift security

BUT

ZERONIGHTS 2012 GOTS/SOLDATOV 27

Page 28: How to catch your “hacker” or makeshift security

MIMIKATZ (LOCAL)

ZERONIGHTS 2012 GOTS/SOLDATOV 28

… and NO LOGS!

Page 29: How to catch your “hacker” or makeshift security

MIMIKATZ (LOCAL)

ZERONIGHTS 2012 GOTS/SOLDATOV 29

… and NO LOGS!

Page 30: How to catch your “hacker” or makeshift security

MIMIKATZ (LOCAL)

ZERONIGHTS 2012 GOTS/SOLDATOV 30

… and NO LOGS!

Page 31: How to catch your “hacker” or makeshift security

MIMIKATZ (LOCAL)

ZERONIGHTS 2012 GOTS/SOLDATOV 31

… and NO LOGS!

Page 32: How to catch your “hacker” or makeshift security

MIMIKATZ (LOCAL)

ZERONIGHTS 2012 GOTS/SOLDATOV 32

… and NO LOGS!

Page 33: How to catch your “hacker” or makeshift security

DETECTION

ZERONIGHTS 2012 GOTS/SOLDATOV 33

Page 34: How to catch your “hacker” or makeshift security

HOPE, READY TO ANSWER YOUR QUESTIONS….

Thanks for Your attention!

Igor Gots

Sergey Soldatov

reply-to-all.blogspot.com

ZERONIGHTS 2012 GOTS/SOLDATOV 34