+ All Categories
Home > Technology > DerbyCon 2012

DerbyCon 2012

Date post: 28-Nov-2014
Category:
Upload: frank-hackett
View: 463 times
Download: 0 times
Share this document with a friend
Description:
Frank J Hackett and Justin Brown. "Breaking into Security"
23
BREAKING INTO SECURITY 1
Transcript
Page 1: DerbyCon 2012

BREAKING INTO SECURITY

1

Page 2: DerbyCon 2012

2

JOHNNY LONG

Page 3: DerbyCon 2012

3

JOE MCCRAY

Page 4: DerbyCon 2012

4

BRIAN DOMSCHKE

Page 5: DerbyCon 2012

WHO ARE WE?

5

Page 6: DerbyCon 2012

JUSTIN “SPRIDEL”

BROWNOSINT Ninja

Web App Ninja in TrainingHFC Booth Guy

Newest Co-Host of ISDPodcastBaylor Grad

6

Page 7: DerbyCon 2012

FRANK J. HACKETT

7

Senior Systems EngineerNetwork Guru

Sys Admin From HellSecurity guy in training

WVU Dropout

Page 8: DerbyCon 2012

8

‣Why do you want to listen to us?

‣What’s worked for us and what hasn’t

‣What we’ve done to get involved

‣Tips for Mentors!!

WHAT ARE WE TALKING ABOUT?

Page 9: DerbyCon 2012

LEARN TO COMMUNICATE

9

‣IRC‣irc.freenode.net - use SSL!‣Tools that you use (#snort, #nmap, #ettercap-project, etc)‣OS’s (#backtrack-linux, #pentoo, #ubuntu, etc)‣Ask questions‣Don’t ask if you may ask‣CHECK GOOGLE, FAQ, FORUMS BEFORE!!!

Page 10: DerbyCon 2012

TWEETER!!

10

‣Get an account!‣Get over it and stop shunning all social media

‣Tweet and make friends‣See new ideas‣Links!‣Open and free knowledge

Page 11: DerbyCon 2012

TWEETER CONT’D!!

11

@DerbyCon@Dave_Rel1k@Irongeek_ADC@fjhackett@spridel11@oncee@Hack3rcon@j0emccray@JaysonStreet@nullthreat

@iampr1me@mubix@hdmoore@c0ncealed@gl11tch@hacktalkblog@carnal0wnage@n00bznet@ihackstuff@ISDpodcast

Page 12: DerbyCon 2012

MEETUPS

12

‣Local Spots (AustinHA, NoVAH, PhoenixSSH, OSOC, RVAsec, etc‣Professional Spots (ISSA, ISACA, Infraguard, etc‣Cons! (AIDE, DerbyCon, Shmoocon, Hack3rcon, BSides)‣Make friends! Talk to people. They won’t bite.‣Hangout have a beer‣Listen to the talks don’t just hangout in the CTF all day

Page 13: DerbyCon 2012

ONLINE

13

‣IRC‣Skype‣Google Hangouts‣Twitter‣Failbook‣LinkedIn‣Your Trusted Mentors/Friends/Random Hackers

Page 14: DerbyCon 2012

LEARN TO LISTEN

14

‣Podcasts‣ISDPodcast‣Pauldotcom‣Securabit‣Risky Business

Page 15: DerbyCon 2012

LEARN TO STOP BEING LAZY

15

‣Get involved with those friends you made at the con‣Hackers for Charity - Go sign up!!! (NOW!)‣Random Hacks of Kindness‣Security R00kies‣Make your own group!

Page 16: DerbyCon 2012

BUDGET LABS

16

‣VirtualBox‣VMware Player‣VMware Workstation ($$)‣VMware Fusion ($$)‣Parallels ($$)‣Think small - one victim vs entire network‣Start Vulnerable ‣MS08_067‣Metasploitable(s)‣Webgoat‣Mutillidae

Page 17: DerbyCon 2012

LEARN TO READ

17

‣Books! zOMG‣Professional Penetration Testing - Thomas Wilhelm‣Grey Hat Hacking - Harris, Harper, Eagle, & Ness‣Metasploit: The Penetration Tester’s Guide - O’Gorman, Kearns, Kennedy, Aharoni

‣./command -h‣nano/vi/vim - look at the code!‣Forums‣Googlefu

Page 18: DerbyCon 2012

LEARN WHAT DOESN’T WORK

18

‣Don’t troll‣Take a joke... seriously just take it and laugh‣Be respectful‣Don’t spam‣Be open to new ideas - different approaches‣Don’t expect step by step instructions

Page 19: DerbyCon 2012

LEARN WHAT DOESN’T WORK

18

‣Don’t troll‣Take a joke... seriously just take it and laugh‣Be respectful‣Don’t spam‣Be open to new ideas - different approaches‣Don’t expect step by step instructions

Page 20: DerbyCon 2012

KNOW WHO YOU’RE TALKING TO

19

‣Distinct difference between Anonymous and a security professional‣People lie on the internet‣Not everyone wants to help you‣Protect yourself

Page 21: DerbyCon 2012

KNOW WHO YOU’RE TALKING TO

19

‣Distinct difference between Anonymous and a security professional‣People lie on the internet‣Not everyone wants to help you‣Protect yourself

Page 22: DerbyCon 2012

SUGGESTIONS THAT HELPED US

20

‣Scripting! The power of the “for loop”‣Get comfortable in CLI‣Be an aggressive learner‣Help out where you can‣Give back - don’t only take‣Finding your niche

Page 23: DerbyCon 2012

QUESTIONS AND COMMENTS

21

@spridel11@fjhackett


Recommended