pen testing with confidence - lenny zeltser...pen testing with confidence: planning and executing to...

42
Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007

Upload: others

Post on 08-Aug-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Pen Testing with Confidence:Planning and Executing to Achieve the

Desired Results

Lenny ZeltserNYMISSA - 03.14.2007

Page 2: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Pen tests have become more popular.

Page 3: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Playing the role of an attacker is sometimes tricky for defenders.

Page 4: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Mishandled pen tests can be hazardous to your career.

Page 5: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Asking the right questions about the pen test is essential to success.

Page 6: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Of all assessment types, is pen test the one needed?

Q #1

Page 7: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

vulnerability assessment

Page 8: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

security policy assessment

Page 9: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

penetration test

Page 10: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

What is the scope of the test?

Q #2

Page 11: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

targets

Page 12: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

depth

Page 13: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

exclusions

Page 14: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

What tests should be performed?

Q #3

Page 15: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

denial of service

Page 16: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

physical security

Page 17: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

social engineering

Page 18: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

war dialing

Page 19: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

client-side attacks

Page 20: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become
Page 21: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Are non-commercial tools OK to use?

Q #4

Page 22: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

core impact

immunity canvas

metasploit

standalone exploits

backtrack distribution

Page 23: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

What is the attacker's profile?

Q #5

Page 24: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

professional vs. amateur

Page 25: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

attack of opportunity

Page 26: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Is the test black-box…Is the test back-box…… or white-box?

Q #6

Page 27: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

path of least resistance

Page 28: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

attack trees

Page 29: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become
Page 30: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become
Page 31: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

What are the time constraints?

Q #7

Page 32: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

duration of the test

Page 33: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

timing restrictions

Page 34: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

How to handle issues that may arise during the test?

Q #8

Page 35: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

targeted system crashed

Page 36: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

sensitive data found

Page 37: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

pen test contact form

Page 38: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

What to do with the pen test’s results?

Q #9

Page 39: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

The Internet is becoming less forgiving of security mistakes.

Page 40: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Well-planned, carefully-orchestrated pen testing helps.

Page 41: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Of all assessment types, is pen test the one needed?What is the scope of the test?What tests should be performed?

Are non-commercial tools OK to use?What is the attacker's profile?Is the test back-box or white-box?What are the time constraints?How to handle issues that may arise?What to do with the pen test’s results?

Page 42: Pen Testing with Confidence - Lenny Zeltser...Pen Testing with Confidence: Planning and Executing to Achieve the Desired Results Lenny Zeltser NYMISSA - 03.14.2007 Pen tests have become

Lenny Zeltser

InfoSec Practice LeaderGemini Systems, LLC