+ All Categories
Home > Documents > Barcamp 2009-Ninjitsu Attack Hack For Fun and Profit

Barcamp 2009-Ninjitsu Attack Hack For Fun and Profit

Date post: 02-Nov-2014
Category:
Upload: prathan-phongthiproek
View: 819 times
Download: 6 times
Share this document with a friend
Description:
 
Popular Tags:
35
Ninjitsu Attack: Hack f or Fun and Profit Prathan Phongthiproek ACIS Professional Center Information Security Consultant May 24 th , 2009
Transcript
Page 1: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Ninjitsu Attack: Hack for Fun and Profit

Prathan PhongthiproekACIS Professional CenterInformation Security ConsultantMay 24th, 2009

Page 2: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

What I’ve done ?

Penetration Testing (BlackBox and WhiteBox)

Security Consultant

Active Security Researcher for Fun (and Profit)

Devoted Hacker

Exploits and Vulnerabilities Disclosure (CWH Underground)

Hacking and Security Papers (WebApp, Wireless, OS)

Comments, Feedback ? >> [email protected] (Don’t spam mail !! lol)

# w03:19:18 up 1 min, 1 user, load average: 1.73, 0.71, 0.26USER TTY FROM LOGIN@ IDLE JCPU PCPUprathan phongthiproek tty1 - 03:18 0.00s 0.08s 0.01s

Page 3: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Overview

Exploit CMS Vulnerabilities

Web Browser’s Passive Attack

Wifi-Ninjitsu Attack For Profit

Lock Picking: Owned The Key

Other Techniques (Something Evil)

Page 4: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

A content management system (CMS) is computer application used to create, edit, manage, and publish content in a consistently organized

fashion.

Page 5: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 6: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 7: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 8: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 9: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

target.com/index.php?option=com_user&view=reset&layout=confirm

Page 10: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 11: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Exploit CMS Vulnerabilities

Page 12: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

How to protect CMS Hacking

Obey the Installer, and Remove /installation directory after install.

Security Issues are primarily caused by faulty third-party extensions.

Monitor HTTPD logs, bandwidth logs, and search terms for your site, in addition to traditional Linux intrusion detection & defense techniques to catch emerging threats before they hit your site.

Always patch New Version !!

Page 13: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Web Browser’s Passive AttackVulnerability in Windows Animated Cursor Handling

Page 14: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Web Browser’s Passive Attack

Page 15: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Web Browser’s Passive Attack'Internet Explorer 7 Uninitialized Memory Corruption Vulnerability'

Page 16: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Web Browser’s Passive Attack“Can we use Active Attack ?? >> ARP Poisoning”

Page 17: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Wifi-Ninjitsu Attack For Profit

Rouge AP (Evil Twin): Steal usernames, passwords and information from public wireless hotspots.

Why we don’t steal something evil like credit card (Pay to Play) ??

Can we Exploit victim machine through Web Browser Vuln or MS08-067 (Conficker Worms) ??

Page 18: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Wifi-Ninjitsu Attack For Profit

Rouge AP (Evil Twin): Steal usernames, passwords and information from public wireless hotspots.

Page 19: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Wifi-Ninjitsu Attack For Profit

Can we Exploit victim machine through Web Browser Vuln or MS08-067 (Conficker Worms) ??

Page 20: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Locks are not complicated mechanisms

Most locks are wildly easy to pick

Unpickable doesn’t mean invulnerable

Page 21: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 22: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 23: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 24: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 25: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 26: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 27: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 28: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 29: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 30: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 31: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The KeyIt’s typically as simple as that

Page 32: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 33: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Lock Picking: Owned The Key

Page 34: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

Other Techniques (Something Evil)

Page 35: Barcamp  2009-Ninjitsu Attack Hack For Fun and Profit

If someone is still in the room.. Q&A

THANK YOU


Recommended