Главная
Study mode:
on
1
Introduction
2
Motivation
3
Major Breaches
4
Target Breach
5
Critical Flaw
6
Missed Alarms
7
The Biggest Issue
8
US Senate Report
9
Summary
10
Sands Casino
11
How it happened
12
No alerts missed
13
Industry response
14
Credential theft
15
IT industry focus
16
Windows password storage
17
Minicats
18
Boring Alternatives
19
Defending Against This
20
Hand Diagram
21
Credentials
22
Extracting hashes
23
Using double hashes
24
A funny Facebook video
25
Why did this fail
26
Force Guest
27
Authentication
28
Remote Desktop
29
Demo
30
Prevent Privilege Escalation
31
Authentication Policies
32
Offensive Options
33
Pay attention to credentials
Description:
Explore credential assessment mapping and privilege escalation at scale in this 56-minute conference talk from Derbycon 2015. Delve into major breaches like Target and Sands Casino, examining critical flaws and missed alarms. Investigate the IT industry's focus on credential theft and Windows password storage. Learn about defensive strategies, including authentication policies and preventing privilege escalation. Gain insights into offensive options and the importance of credential management. Witness a demonstration and understand why certain security measures fail. Discover how to extract hashes, use double hashes, and implement effective authentication policies to enhance your organization's security posture.

Break Me - Credential Assessment Mapping Privilege Escalation at Scale - Matt Weeks

Add to list
00:00
-00:45