prepare yourself to become infosec professional

26
PREPARE YOURSELF TO BECOME INFOSEC PROFESSIONAL Presented by M. Syarifudin, ST, OSCP, OSWP Bandung, Jul 28 2016 Stadium General Course Telkom University 1

Upload: msyarifudin-st-oscp-oswp

Post on 13-Jan-2017

4.172 views

Category:

Career


0 download

TRANSCRIPT

Page 1: Prepare Yourself to Become Infosec Professional

PREPARE YOURSELF TO BECOME INFOSEC PROFESSIONAL

Presented by M. Syarifudin, ST, OSCP, OSWP

Bandung, Jul 28 2016Stadium General Course

Telkom University

1

Page 2: Prepare Yourself to Become Infosec Professional

Who is M. SYARIFUDIN ?

• Former Lecturer and Assistant Manager

• OSCP & OSWP Certified

• Information Security Trainer and Researcher

• Official Indonesian Kali Linux Translator

• Homepage : http://fl3x.us

2

Page 3: Prepare Yourself to Become Infosec Professional

LET’S TALK ABOUT…

• Information Security

• What Should be Prepared to become Infosec Professional

3

Page 4: Prepare Yourself to Become Infosec Professional

INFORMATION SECURITY OVERVIEW

• The practice of defending information from (un)authorised access, (mis)use, disclosure, disruption, modification, or destruction

4

Confidentiality Integrity Availability

source:wikipedia

Page 5: Prepare Yourself to Become Infosec Professional

WHY INFORMATION SECURITY NEEDED ?

• Information is very important asset

• Impact to the Business

5

People Technology System

Page 6: Prepare Yourself to Become Infosec Professional

SOME CASES

6

Referral System Vulnerability

Page 7: Prepare Yourself to Become Infosec Professional

SOME BREACHES

7

Source : https://haveibeenpwned.com

Page 8: Prepare Yourself to Become Infosec Professional

SOME CYBER ATTACKS

8

Source : http://www.thejakartapost.com/

Page 9: Prepare Yourself to Become Infosec Professional

SOME CYBER ATTACKS

9

Source : http://www.bbc.com/news/uk-36239805

Page 10: Prepare Yourself to Become Infosec Professional

10

Infosec Pro are always needed

Page 11: Prepare Yourself to Become Infosec Professional

INFOSEC PRO JOBS

• Penetration Tester / Ethical Hacker

• Information Security Consultant

• Security Engineer

• Information Security Specialist

11

Page 12: Prepare Yourself to Become Infosec Professional

INFOSEC PRO JOBS

• Information Security Manager

• Chief Information Security Officer

• Information Security Trainer

• etc

12

Page 13: Prepare Yourself to Become Infosec Professional

SAMPLE SALARY ( PENTESTER )

13

Source:http://www.payscale.com/research/US/Job=Penetration_Tester/Salary

Page 14: Prepare Yourself to Become Infosec Professional

SAMPLE SALARY ( PENTESTER )

14

77K USD per year -> 6.4K USD per month = Rp 84.000.000 per month

Page 15: Prepare Yourself to Become Infosec Professional

WHAT SHOULD BE PREPARED ?

• Have the Passion & Good Mental

• More focus on these Subjects :

• Operating System

• Computer Network and Security

• Cryptography, and Programming

15

Page 16: Prepare Yourself to Become Infosec Professional

WHAT SHOULD BE PREPARED ?

• Join to the Laboratory

• Join to the Infosec Community

• Decide your Interest

• Taking the Infosec Courses and Certifications

16

Page 17: Prepare Yourself to Become Infosec Professional

SOME INFOSEC CERTIFICATIONS

17

More info: https://www.offensive-security.com/information-security-certifications/

Page 18: Prepare Yourself to Become Infosec Professional

SOME INFOSEC CERTIFICATIONS

18

More info: http://www.giac.org/certifications/categories

Page 19: Prepare Yourself to Become Infosec Professional

SOME INFOSEC CERTIFICATIONS

19

More info: http://www.isaca.org/ More info: https://www.isc2.org/

Page 20: Prepare Yourself to Become Infosec Professional

20

Which one of your interest ?

Page 21: Prepare Yourself to Become Infosec Professional

What is PenTest ?

21

Real Attacks The Target Gain Access

Application NetworkSystem

Page 22: Prepare Yourself to Become Infosec Professional

Why Do a PenTest ?

22

$$$$$ Security Program

Protecting Infrastructure

Prevent Data Breaches

Penetration Test

Page 23: Prepare Yourself to Become Infosec Professional

About PenTest

23

Compromise IT System Security

Find Security VulnerabilitiesMust Have a Permission

Be Creative Exploit the Security Vuln.

Bypass Security MechanismThink like an Attacker

Page 24: Prepare Yourself to Become Infosec Professional

Penetration Testing Execution Standard

24

Intelligence GatheringPre-engagement

Threat ModellingVulnerability Analysis

Exploitation Post Exploitation

Reporting

http://www.pentest-standard.org

Page 25: Prepare Yourself to Become Infosec Professional

PENTEST DEMO

25

Let’s Hack the Target ;)

Page 26: Prepare Yourself to Become Infosec Professional

Thank You Any Question ?

“Contact Me” on http://fl3x.us

26