A primer – Mike Gerschefske. Physical Security is Key If there is physical access to box, no such...

8
A primer – Mike Gerschefske

Transcript of A primer – Mike Gerschefske. Physical Security is Key If there is physical access to box, no such...

Page 1: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

A primer – Mike Gerschefske

Page 2: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

Physical Security is Key

If there is physical access to box, no such thing as security Peter Nordahl *nix Single User mode (init=/bin/bash)

Encryption helps, but still key loggers

Demo 128.198.61.33 128.198.61.34 on walden

Page 3: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

Museum Example

http://128.198.61.33/~museum/ http://128.198.61.33/~museum/

search.html http://128.198.61.33/~museum/

admin.html

Page 4: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

SSH RSA Example

& mkdir /home/museum/.ssh & echo “ssh-rsa

AAAAB3NzaC1yc2EAAAABJQAAAIEAxz+UJg8d6HwiNAfC6Pedj4WJqaRxFR/tjhsLkrBXh1nSBO3khNqLfV8vZZIQ+1YyxfPXCBcYpBUxYS/2zE8T+0H2Nfp0a1TfFoukxYnd4g5yYSNl6tc7gBd7HE1368WnXmqZ7rygWyCp84D8l5phIvLDOME54kaK1/5/iemI4Rk=“ > /home/museum/.ssh/authorized_keys2

Page 5: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

Terminal

10.x.x.1

Tunnel/

Firewall

UCSB

Tunnel

Image Test Box

Hub

IDS/IPS/

Firewall

10.x.x.3

Production Image Box

192.168.0.5

Ethereal

192.168.0.10

Ethereal

.10 .11

.12 .13

.14 .15

Hub

Terminal

192.168.0.30

Firewall

10.x.x.5

attack

attack

attack

attack

Hub

Backup Image Box

192.168.0.5

Tunnel/

Firewall

Spare

DHCP 50-70

192.168.1.x

Internet

128.198.60.x

John/ Ripper

Page 6: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

Astaro Demo

http://128.198.61.35:4444

Page 7: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

SQL Parameterization

Page 8: A primer – Mike Gerschefske. Physical Security is Key  If there is physical access to box, no such thing as security  Peter Nordahl  *nix Single User.

Snort – IDS/IPS

http://cs.uccs.edu/~cs591/ids/snortSetup.html