introducing weakness into security devices
play

Introducing Weakness Into Security Devices Tuning To A Different - PowerPoint PPT Presentation

Introducing Weakness Into Security Devices Tuning To A Different Key BSidesVienna 20/1/12 Arron finux Finnon Evasion T echniques Dancing Past Your Defences!!! BSidesVienna 20/1/12 Arron finux Finnon 3 Things I Want T o Share


  1. Introducing Weakness Into Security Devices Tuning To A Different Key BSidesVienna 20/1/12 Arron “finux” Finnon

  2. Evasion T echniques Dancing Past Your Defences!!! BSidesVienna 20/1/12 Arron “finux” Finnon

  3. 3 Things I Want T o Share Today's Outline! BSidesVienna 20/1/12 Arron “finux” Finnon

  4. ONE – Obtaining Samples Diversity Is Important BSidesVienna 20/1/12 Arron “finux” Finnon

  5. T wo – Knowledge Is Key Understanding What We Know BSidesVienna 20/1/12 Arron “finux” Finnon

  6. Three – Implementation Is Critical When Is It Not! BSidesVienna 20/1/12 Arron “finux” Finnon

  7. The Threat From Vulnerability to Exploit BSidesVienna 20/1/12 Arron “finux” Finnon

  8. MS08-067 Vulnerability The ChrisJohnRiley of Exploits BSidesVienna 20/1/12 Arron “finux” Finnon

  9. BSidesVienna 20/1/12 Arron “finux” Finnon

  10. Metasploit Framework The Tool of Champions BSidesVienna 20/1/12 Arron “finux” Finnon

  11. Security Devices Okay Its IDSes today BSidesVienna 20/1/12 Arron “finux” Finnon

  12. The Common Intrusion Detection Framework E-Boxes A-Boxes C-Boxes D-Boxes Events, Analysers, Countermeasures, Data/Storage BSidesVienna 20/1/12 Arron “finux” Finnon

  13. T o React or Not T o React Events need to be understood BSidesVienna 20/1/12 Arron “finux” Finnon

  14. T aking Something At Face Value Leaves A Lack of Understating BSidesVienna 20/1/12 Arron “finux” Finnon

  15. So My Story Finux has a tale or two BSidesVienna 20/1/12 Arron “finux” Finnon

  16. Show Evasions DCERPC::smbpipeio BSidesVienna 20/1/12 Arron “finux” Finnon

  17. Documentation Time DCERPC::smb_pipeio Use a different delivery method for accessing named pipes BSidesVienna 20/1/12 Arron “finux” Finnon

  18. “The "trans" option will use a NtTransact command on the named pipe to deliver a request and trigger a reply from the server. During the development process, I noticed that just sending a "read" request after stuffing the request down via plain named pipe writes would also trigger processing.” HD to Finux – 08/08/11 BSidesVienna 20/1/12 Arron “finux” Finnon

  19. Set DCERPC::smbpipeio rw BSidesVienna 20/1/12 Arron “finux” Finnon

  20. Set DCERPC::smbpipeio trans BSidesVienna 20/1/12 Arron “finux” Finnon

  21. Popularity Is Social Proof Because its cool its right? BSidesVienna 20/1/12 Arron “finux” Finnon

  22. Your Added Bonus ! “..and one more thing” Moment! BSidesVienna 20/1/12 Arron “finux” Finnon

  23. The Dangers of Character Matching The Butthead Evasion Technique BSidesVienna 20/1/12 Arron “finux” Finnon

  24. SID:1239 - RFParalyze WTF, CVE-2000-0347 BSidesVienna 20/1/12 Arron “finux” Finnon

  25. alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"NETBIOS RFParalyze Attempt"; flow:to_server,established; content:"BEAVIS"; content:"yep yep";) If there is a TCP connection on port 139 and you see the string “BEAVIS” and the String “yep, yep” please alert!!!!!!! BSidesVienna 20/1/12 Arron “finux” Finnon

  26. ++ BSidesVienna 20/1/12 Arron “finux” Finnon

  27. ++ BSidesVienna 20/1/12 Arron “finux” Finnon

  28. ++ BSidesVienna 20/1/12 Arron “finux” Finnon

  29. That's All Folks! This Will be That Q&A Time BSidesVienna 20/1/12 Arron “finux” Finnon

  30. Conclusions Time Brace Yourself BSidesVienna 20/1/12 Arron “finux” Finnon

  31. Contacting Finux finux@finux.co.uk www.finux.co.uk Twitter @f1nux www.alba13.com - Coming Soon BSidesVienna 20/1/12 Arron “finux” Finnon

Recommend


More recommend