Hacking Intranet Websites.pdf

(5522 KB) Pobierz
1
Hacking Intranet Websites
from the Outside
"JavaScript malware just got a lot more dangerous"
Black Hat (USA) - Las Vegas
08.03.2006
Jeremiah Grossman (Founder and CTO)
T.C. Niedzialkowski (Sr. Security Engineer)
Copyright © 2006 WhiteHat Security, inc. All Rights Reserved.
WhiteHat Security
WhiteHat Sentinel - Continuous Vulnerability
Assessment and Management Service for Websites.
2
Jeremiah Grossman (Founder and CTO)
Technology R&D and industry evangelist
Co-founder of the Web Application Security
Consortium (WASC)
Former Yahoo Information Security Officer
T.C. Niedzialkowski (Sr. Security Engineer)
Manages WhiteHat Sentinel service for enterprise
customers
extensive experience in web application security
assessments
key contributor to the design of WhiteHat's
scanning technology.
Copyright © 2006 WhiteHat Security, inc. All Rights Reserved.
3
Assumptions of Intranet Security
Doing any of the following on the
internet would be crazy, but on
intranet...
Leaving hosts unpatched
Using default passwords
Not putting a firewall in front of
a host
Is OK because the perimeter
firewalls block external access
to internal devices.
Copyright © 2006 WhiteHat Security, inc. All Rights Reserved.
4
Assumptions of Intranet Security
WRONG!
Copyright © 2006 WhiteHat Security, inc. All Rights Reserved.
Everything is web-enabled
routers, firewalls, printers, payroll systems,
employee directories, bug tracking systems,
development machines, web mail, wikis, IP
phones, web cams, host management, etc etc.
5
Copyright © 2006 WhiteHat Security, inc. All Rights Reserved.
Zgłoś jeśli naruszono regulamin