• Tidak ada hasil yang ditemukan

Penetration testing & mitigation techniques

N/A
N/A
Protected

Academic year: 2024

Membagikan "Penetration testing & mitigation techniques"

Copied!
28
0
0

Teks penuh

(1)

Penetration Testing &

Mitigation Techniques

Sean Latimer Yalikun Yasheng Andrew David Masoud Shakiba

(2)

Contents

Penetration Testing – Introduction

Research Hardware/Software

John the Ripper – Abstract

Physical Credential Attacks Results

Remote Credential Attacks Results

Metasploit – Abstract

Metasploit Attack Results

Mitigation Techniques

(3)

Penetration Testing

What is Penetration Testing?

Our Project Focus

Importance of our Project

(4)

Target Audience

94% of NZ population are active internet users.

97% of students have access to a device.

(5)

Research Focus – Windows/Linux

(6)

Hardware and Software

(7)

John the Ripper - Abstract

What is John the Ripper?

John the Ripper Modes – Single Crack/Wordlist/Brute-Force

Main Goal of Attack

(8)

Physical Credential Attack – Process

Exploit System – Live Kali Linux

1

Extract Credential Files –

SAM/Shadow

2

Crack Passwords – John the Ripper

3

(9)

Physical System Exploitation - Windows

(10)

Physical System Exploitation - Linux

(11)

Physical

Credential Extraction – Windows (Mimikatz)

(12)

Physical Credential Extraction – Linux (Unshadow)

(13)

Remote Credential Attack - Process

Create Payload

1

Download

Payload –Victim Machine

2

Escalate Privileges – Bypass UAC (Windows)

3

Run Hashdump – Credential

Information

4

Crack Passwords John the

Ripper

5

(14)

Payload Creation – Windows/Linux

(15)

Remote Credential Attacks – UAC Bypass

(16)

Remote Credential Attacks - Hashdump

(17)

John the Ripper – Wordlist Method

(18)

John the Ripper – Brute Force Method

(19)

John the Ripper – Single-Crack Method

(20)

Results

Physical Credential Attacks

Windows (7/8/10) - Successful

Linux (Ubuntu/Fedora/Debian) – Successful Remote Credential Attacks

Windows(7/8) – Successful

Linux (Ubuntu/Fedora/Debian) – Successful

(21)

Metasploit - Abstract

What is Metasploit framework

framework that combines various security and exploiting tools

standardized interface and powerful vulnerabilities assessment

History of Metasploit

Establish by HD Moore in 2003 written in Perl

Migrate framework to Ruby in 2007

(22)

Metasploit

generate payload

(23)

Metasploit Exploitation

(24)

Metasploit Exploitation

(25)

Result

Operating system Fresh version Update version

Windows 7 success success

Windows 8 success success

Windows 10 success (detect by defender) success (detect by defender)

Fedora success success

Debian success success

Ubuntu success success

(26)

Mitigation Techniques

BIOS/Start-Up Password – Physical Attacks

Strengthening Passwords

Credential Guard – Windows 10

Windows Defender/Firewall

Antivirus

Educating Yourself/Others – Social Engineering/Securing System

(27)

Conclusion

Reflection

Lessons Learned

Project Review

(28)

Questions?

e-mail us:

Sean Latimer – [email protected] Yalikun Yasheng [email protected] Andrew David – [email protected]

Masoud Shakiba [email protected]

Referensi

Dokumen terkait