• No results found

TEFO STUDERUS HACKING 4 FUN & PROFIT

N/A
N/A
Protected

Academic year: 2021

Share "TEFO STUDERUS HACKING 4 FUN & PROFIT"

Copied!
43
0
0

Loading.... (view fulltext now)

Full text

(1)

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

Ivan Bütler

Compass Security AG, Switzerland

[email protected]

TEFO STUDERUS

TEFO STUDERUS

TEFO STUDERUS

TEFO STUDERUS

HACKING 4 FUN & PROFIT

HACKING 4 FUN & PROFIT

HACKING 4 FUN & PROFIT

HACKING 4 FUN & PROFIT

(2)

Ist die Dame reich? Scheinheirat???

(3)

Ivan Bütler, CEO Compass Security

E1

[email protected]

blog.csnc.ch

Twitter.com/ibuetler

© Compass Security AG www.csnc.ch Slide 3

Twitter.com/ibuetler

Xing

~ibuetler

LinkedIn

~ibuetler

(4)

Ethical Hacker / Penetration Tester

Gründer & CEO Compass Security AG

Lecturer @ University of Applied Science Rapperswil

Lecturer @ University of Applied Science Lucerne

Lecturer @ University of St.Gallen

Speaker @

BlackHat Las Vegas 2008

SmartCard (In) Security

Speaker @

IT Underground Warsaw 2009

© Compass Security AG www.csnc.ch Slide 4

Speaker @

IT Underground Warsaw 2009

Advanced Web Hacking

Speaker @

Swiss IT Leadership Forum Nice

2009

Cyber Underground

Gründer der

Swiss Cyber Storm

Konferenz

Vorstandsmitglied von Information Security

Society Switzerland (

ISSS

)

Vorstandsmitglied von

Cyber Tycoons

(5)

Agenda

Credit Card Fraud / Handel von illegalen Gütern

Gezielte Attacken

Mobile Security

Nationale Cyber Defense Strategie

© Compass Security AG www.csnc.ch Slide 5

Nationale Cyber Defense Strategie

Security Community

(6)

Angriffe auf Server im Internet (Webseiten etc.)

Direkte Attacken

BLOCKED

© Compass Security AG www.csnc.ch Slide 6

PASSED

(7)

SQL Einleitung

Protokoll

© Compass Security AG www.csnc.ch Slide 7

HTTPS

RMI

(8)

SQL Injection Angriff

Protokoll

© Compass Security AG www.csnc.ch Slide 8

RMI

HTTPS + SQL Hacker Code

(9)

Demo 1: SQL Injection

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(10)

Wie bereichert man sich? (1)

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(11)

Show

: Video 1: Cyber Market

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(12)

Handel von illegalen Gütern

Dumps

Stolen Credit Cards

Carders

Provider of “Dumps”

Carding

Using Dumps

WU

Western Union

WMZ

Web Money

© Compass Security AG www.csnc.ch Slide 12

WMZ

Web Money

WU

Western Union

LR

Liberty Reserve

CVVs

Card Verification Value

Drops

Remailing Location

(13)

Zahlen über Liberty Reserve?

Payment with Liberty

Reserve

(14)

Liberty Reserve?

-> Internet Währung (anonym)

(15)

Liberty Reserve als Internet Währung

Verkäufer/Käufer brauchen ein LR Konto

Das LR Konto bekommt man durch ein E-Mail (anonym)

© Compass Security AG www.csnc.ch Slide 15

(16)

LR Wechselstuben

Richtiges Geld wird in LR gewechselt

Dazu braucht es sogenannte Exchanger Banken (Russland)

Es gibt mehr als 100 Exchanger Banken

© Compass Security AG www.csnc.ch Slide 16

(17)

Wie bereichert man sich? (2)

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(18)

Trennung „Hacking“ von Bereicherung

Hacking

Financial

Benefit

(19)

Agenda

Credit Card Fraud / Handel von illegalen Gütern

Gezielte Attacken

Mobile Security

Nationale Cyber Defense Strategie

© Compass Security AG www.csnc.ch Slide 19

Nationale Cyber Defense Strategie

Security Community

(20)

Umgehung der Perimeter Sicherheit

Gezielte Angriffe

© Compass Security AG www.csnc.ch Slide 20

(21)

Covert Channel Attacke

USB Stick Attack

Auslieferung über USB-Stick

© Compass Security AG www.csnc.ch Slide 21

Internet

Company Network

Start via

Auto-Start

Angreifer kontrolliert

das *Opfer* aus der

Ferne

(22)

Demo 2: Gezielte Attacken

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(23)

Direkte Verbindungen nach Aussen

Einfache Inside-Out Attacke

Corporate LAN Internet

© Compass Security AG www.csnc.ch Slide 23

Direkte Channels

ACK tunnel

TCP tunnel (pop, telnet, ssh)

UDP tunnel (syslog, snmp)

ICMP tunnel

(24)

LAN Proxy

Proxifizierte Verbindungen nach Aussen

Erweiterte Inside-Out Attacken

© Compass Security AG www.csnc.ch Slide 24

Corporate LAN Internet

DMZ Proxy

Proxified Channels

Socks SSL tunnel

HTTP/S tunnel (payload of http = tunnel)

HTTP/S proxy CONNECT method tunnel

DNS tunnel

FTP tunnel

Mail tunnel

(25)

Spearphishing

Malicious

Mail

© Compass Security AG www.csnc.ch Slide 25

Microsoft Office Word Document

(26)

Hardware Bot Client

(27)

PlugBot Konzept

(28)

APT (Advanced Persistent Threat)

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(29)

Advanced Persistent Threat

Command & Control Communication (DNS Tunneling)

Client

DNS Server

POLL

POLL

© Compass Security AG www.csnc.ch Slide 29

Command File

Commands POLL

(30)

Statistik: Exploits vor Patch verfügbar

Advisory is

published

Patch

© Compass Security AG www.csnc.ch Slide 30

54 days

Exploit

6

days

Patch

(31)

Advanced Persistent Threat

2007

2009

2011

Today

© Compass Security AG www.csnc.ch Slide 31

Erst-Infektion

(keine local

admin rechte)

C&C

Ausbau der

Privilegen auf

Local Admin

(32)

Advanced Persistent Threat

Zombie Host

Zombie Host

Agent

Agent

C&C Server

© Compass Security AG www.csnc.ch Slide 32

Zombie Host

Agent

(33)

Agenda

Credit Card Fraud / Handel von illegalen Gütern

Targeted Attacks

Mobile Security

National Cyber Defense Strategy

© Compass Security AG www.csnc.ch Slide 33

National Cyber Defense Strategy

Security Community

(34)

Attacks & Interfaces

(35)
(36)

Demo 3: SMS Spoofing

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

(37)

SMS-ID-Spoofing

© Compass Security AG www.csnc.ch Slide 37

(38)

Agenda

Credit Card Fraud / Handel von illegalen Gütern

Targeted Attacks

Mobile Security

Nationale Cyber Defense Strategie

© Compass Security AG www.csnc.ch Slide 38

Nationale Cyber Defense Strategie

(39)

National Cyber Defense Strategy

Tel.+41 55-214 41 60 Fax+41 55-214 41 61 [email protected] www.csnc.ch Compass Security AG Glärnischstrasse 7 Postfach 1628 CH-8640 Rapperswil

Schweiz

(40)

Nationale Cyber Defense Strategie

ANTIZIPATION

Abschätzen von

Technologien und Trends

© Compass Security AG www.csnc.ch Slide 40

PRÄVENTION

REAKTION

Verfahren und

Prozesse,

Kompetenzen,

Kommunikation

Installation Firewalls,

Anti-Virus, IDS/IPS,

Penetration Testing

Anti-Hacking Tools

(41)

Wir brauchen Cyber Spezialisten!

Österreich sucht mit der Cyber Security Austria

die besten Talente

zwischen 14 und 22 Jahren.

(42)

Risiken kennen und Verantwortung

übernehmen!

(43)

Ivan Bütler, Compass Security AG

[email protected]

Fragen?!

© Compass Security AG www.csnc.ch Slide 43

References

Related documents

The 20-page “Guide to Leadership Education Programs in Georgia for Aspiring Leaders in Gwin- nett County Public Schools,” scheduled to be published in the 2012-13 school year,

Computer viruses/malware; online credit card fraud; online hacking; online harassment; online identity theft; online scams (eg fraudulent.. lotteries/employment opportunities);

When running BehavioWeb in authentication mode the system will compare the keystroke record collected during the transaction with the behavioral profile that is associated with

The second sudden southward turning of IMF Bz that caused intensi fication of the storm (in the recovery phase) resulted in prompt penetration of eastward IEF to low-latitude

If we become victims of credit card theft, it takes time and effort to close down accounts and have new credit cards issued and sent to you in addition to correcting billing

Mobile Card Fraud Alerts for Amegy Visa Credit and Debit Cards No Charge. VISA ® BUSINESS DEBIT CARD LIMITS 8 Visa Business Debit

We apply the second experimental test to investigate the general performance of the proposed algorithm on the integer programming problems by plotting the values of function

Preventing Credit Card Fraud Page 3 Credit card fraud occurs any time your credit card account is used without your knowledge or permission.. Credit card fraud costs