• Tidak ada hasil yang ditemukan

Security Awareness jateng

N/A
N/A
Protected

Academic year: 2017

Membagikan "Security Awareness jateng"

Copied!
31
0
0

Teks penuh

(1)

Security Awareness

(2)

Incident di LPSE

Sulit Melakukan Upload

Password berubah

FiPenyalahgunaan user LPSE

le Upload diganti

File corrupt

OS Corrupt

HDD rusak

Aplikasi Tidak Bisa Di Akses

(3)

Side Effect

• LPSE kehilangan kepercayaan termasuk oleh LKPP

• Audit oleh eksternal mulai inspektorat, BPKP, Kejaksaan, Kepolisian, BPK atau KPK

• Review pegawai oleh Atasan

(4)

Review Fungsi IT di LPSE

• Administratif

• Fisik

– Akses Ruang server (finger print,kunci & gembok)

– CCTV

• Orang

(5)

Review Fungsi IT di LPSE

• Teknik

– Fungsi redundancy environment

• Power Source (Listrik PLN dan Genset)

• Temporary Power Source (UPS)

• Cooling (Primary and Backup)

– Fungsi Redundancy data

• Backup Data file dan DB (COLD atau HOT)

• Mirroring System

– Fungsi Monitoring

• Monitoring ketersediaan

• Monitoring capacity

(6)

Common Security Threat LPSE

• Remote ssh steal password

• Ransomware Database

• HTTP Header Modification

• Defaced

• SQL Injection

• SSH Without Password

• Slowloris DDOS (Flooding)

• Brute Force

(7)

Remote steal password

• Add source code into openssh

(8)
(9)
(10)
(11)
(12)
(13)

Ransomware Database

Send 0.5 BTC to this address and go to this site http://ann2hzqgedo3plvu.onion/ to recover your database! SQL dump will be available after

payment! |

(14)
(15)
(16)
(17)

SQL Injection

• 112.215.44.239 - - [07/Jun/2015:14:26:00 +0800] "GET

/eproc/faqpage?q=%2D%34%38%35%32%27%29%29%29%20%4F%52%20%28%31%34%38%32%3D%34 %39%38%37%29%20%41%4E%44%20%28%28%28%27%76%62%4B%6A%27%3D%27%76%62%4B%6A HTTP/1.1" 403 234 "-" "sqlmap/1.0-dev (http://sqlmap.org) »

(18)
(19)
(20)

• bl0wsshd 6.71p (/usr/bin/ssh, /usr/sbin/sshd)

• Perl IRC bot

• rainroot, file ./u (privilege gainer, permission: suid)

• MiG log cleaner

• php-reverse-shell

(21)
(22)

What to do ???

Separate security for each entity in the Infrastructure

Manage User Access Control

Password Policy

Different User Access

Hardening Remote System

Hardening Kernel OS

Manage Log System

Secure Communication Channel

(23)

Password Policy :

Used cracklib PAM Library : libpam-cracklib

Edit file PAM configuration

– /etc/pam.d/system-auth on Centos

– /etc/pam.d/common-password on Debian

Set Complexity Configuration

“...

password requisite pam_cracklib.so try_first_pass retry=3 minlength=12 lcredit=3 ucredit=2 dcredit=3 ocredit=2 difok=4

…....”

(24)

Different User Access :

allow root / admin login from spesific console

Create Different User

Assign user to spesific group

(25)

• Limit User Remote

• Use non Standart Port

• Disable non-usable fitur

– TCP Forward

– Tunnel

– X11 Forward

(26)

• Using rsyslog

• Using Adiscon Log Analyzer for Web UI

(27)

Secure Communication Channel

• Type VPN :

– Site to Site VPN

– Remote Access Site VPN

• Jenis VPN :

– VPN Software (OpenVPN , Softether VPN)

(28)
(29)
(30)
(31)

Referensi

Dokumen terkait

yang cukup tinggi dan Semakin banyak koagulan (Al 2 (SO 4 ) 3 ) yang ditambahkan akan mengakibatkan sebagian endapan melarut kembali, sehingga pada penambahan (Al 2 (SO 4 ) 3 )

1) Before using LS-PBI using GSP, a pre-test was given to the students in group 1, group 2 and group 3 to determine their initial level of geometric thinking. 2) Next, the first

Penelitian ini bertujuan untuk menentukan laju korosi baja Hardox 450 dalam medium asam sulfat (H 2 SO 4 ) 3% dan natrium sulfat (Na 2 SO 4 ) 3% yang ditambahkan dan tanpa

3.1.2 DFD Level 1 3 Menu Admin + user 2 Layar Pilihan Menu USER Username + Password Pesan kesalahan Username Password Hakakses 5 Surat Keluar + 4 Surat Masuk + 6 Surat Dihapus +

A. IDENTITAS CALON PESERTA DIDIK 1. Nama Lengkap :……… 2. Nama Panggilan :………3. Tempat Tanggal Lahir :………4. Jenis Kelamin :………5. Agama :………6. Anak Ke-

Penelitian ini bertujuan untuk menentukan laju korosi baja Hardox 450 dalam medium asam sulfat (H 2 SO 4 ) 3% dan natrium sulfat (Na 2 SO 4 ) 3% yang ditambahkan dan tanpa

Conclusion Invariant optimal control problems on other matrix Lie groups of low dimension, like theunitary groups SU 2 and U 2 theorthogonal groups SO 3, SO 4 and SO 5 SE 3 and SE

Contents Section 1: The Indian social security system for cross border workers 4 Section 2: Benefits of social security agreements 7 Section 3: Compliance requirements 9 Section 4: