Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec....

47
Stu Hirst Photobox

Transcript of Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec....

Page 1: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

Stu HirstPhotobox

Page 2: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...
Page 3: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

War Stories - From The

Front Lines Of InfoSec!

@stuhirstinfosec

Page 4: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

Disclaimers;

• I like memes.

• I don’t take myself too seriously.

• Some of these stories may or

may not have happened….

@stuhirstinfosec

Page 5: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

Who Am I?

@stuhirstinfosec

•Public Speaker

•Run Security Scotland

Meet Up

•Run the AWS Security

Slack Forum

•Regular LinkedIn ‘Brain

Farter’

Page 6: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

The most difficult part of

security incidents is that we

don’t know what we don’t know!

(and we often rely on people telling us!)

Page 7: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER ONE

Page 8: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

For legal

reasons, I can’t tell you….

Page 9: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Page 10: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Boogle BadWords -Compromised Passwords

Impact: £30,000 of account spendAttack vector: hack

What Happened/What Did We Do….

Page 11: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•2FA all the things!•Use a password manager!

•Don’t trust 3rd parties, even boogle!

Page 12: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER TWO

Page 13: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Open AWS ElasticSearch ClusterImpact: outage

Attack vector: ransomware

What Happened/What Did We Do….

Page 14: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Page 15: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Open AWS S3 Buckets are

one of the easiest hacks to do….

… you just need to find them!

Page 16: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Don’t make anything in AWS publicly

accessible by default!

•Alert on S3 open to the world!

•Automate, automate, automate!

Page 17: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER THREE

Page 18: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Phishing email with macro in Word docImpact: minimal

Attack vector: Phishing

What Happened/What Did We Do….

Page 19: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Don’t jump to conclusions!

•Allow yourself time to make decisions!

•Educate, train and test!

Page 20: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER FOUR

Page 21: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Two mySQL databases with default creds

Impact: thousands in bug bounty paymentAttack vector: hack

What Happened/What Did We Do….

Page 22: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Be careful who you get to carry

out work for you!

•Lock down your data, all of it!

Page 23: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER FIVE

Page 24: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

The Mystery Chinese ‘Bots’

Impact: hours of investigation!

Attack vector: none?!

What Happened/What Did We Do….

Page 25: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Understand when an incident has

reached a conclusion!

•Focus on what you CAN protect, not on what you CAN’T

Page 26: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER SIX

Page 27: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

The Public Wi-fi Password!

Impact: unknown

Attack vector: hack

What Happened/What Did We Do….

Page 28: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Check your office space before

events!

•Employ a healthy dose of paranoia!

Page 29: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER SEVEN

Page 30: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

The Trump Balloon

Impact: Twitter craziness!

Attack vector: unknown

What

Happened/What Did We Do….

Page 31: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Don’t trust what you read on Twitter!

•Be careful with what you say on social media!

•Protect your personal accounts - you’re easy to find!

Page 32: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER EIGHT

Page 33: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Wannacry

Impact: A month of pain!

Attack vector: malware

What

Happened/What Did We Do….

Page 34: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Where were we when Wannacry first kicked off?

Page 35: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Where was I for the week after it kicked off?

Page 36: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Don’t take holidays!

•Be prepared to change your view on something, quickly!

Page 37: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

INCIDENT NUMBER NINE

Page 38: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

The p*ssed-off leaver!Impact: £20k a week!

Attack vector:

insider/rogue employee

What

Happened/What Did We Do….

Page 39: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

1.84 days to spot2.£20k a week cost3.Nearly 50 failures in process

Page 40: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Not everyone leaves ‘happy’

•If you’re a manager, ensure accesses have been removed!

Page 41: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

SOME OF THE MORE

LIGHT HEARTED INCIDENTS!!!

Page 42: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Page 43: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

And to leave you with….

Toilet humour….

Page 44: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Page 45: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Lessons Learned!•Don’t take your laptop into the

toilet!

•Stickers help!

Page 46: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

@stuhirstinfosec

Thank you!

We’re recruiting!

Twitter; stuhirstinfosec

Page 47: Stu Hirst Photobox · Photobox. War Stories - From The Front Lines Of InfoSec! @stuhirstinfosec. Disclaimers; ...

Q&A