Pular para o conteúdo principal

Compartilhe

Verdade Inconfortável

Qualquer pessoa pode rastrear você online em menos de 10 minutos — e é completamente legal. Visual: tela preta + cursor piscando. Subtítulo: "O que é OSINT e por que isso muda tudo para sua empresa." 02 Slide OSINT não é espionagem. É investigação com dados que você mesmo deixou para trás. Open Source Intelligence = inteligência gerada a partir de fontes públicas: redes sociais, registros, domínios, metadados. Tudo legal. Tudo disponível. E tudo sobre você. 03 Slide Empresas perdem processos por não saber o que está publicado sobre elas. Documentos vazados, e-mails esquecidos, fotos com metadados, contratos em cache. A prova que condena sua empresa pode estar indexada no Google agora. 04 Slide Provas digitais têm validade legal — mas só se coletadas corretamente. Print de tela não serve em juízo. Hash criptográfico, timestamp certificado e cadeia de custódia são o que diferenciam evidência de suposição. 05 Slide O erro mais comum: descobrir a prova e destruí-la sem querer ao ...

Attack and Defend: #Linux Privilege Escalation Techniques of 2016 LEIA E COMPARTILHE

Introduction Privilege escalation is an important step in an attacker’s methodology.



 Privilege escalation is the practice of leveraging system vulnerabilities to escalate privileges to achieve greater access than administrators or developers intended. Successful privilege escalation attacks enable attackers to increase their level of control over target systems, such that they are free to access any data or make any configuration changes required to ensure freedom of operation and persistent access to the target system (Williams, 2016).

 While organizations are statistically likely to have more Windows clients, Linux privilege escalation attacks are significant threats to account for when considering an organization's information security posture. Consider that an organization’s most critical infrastructure, such as web servers, databases, firewalls, etc. are very likely running a Linux operating system. 

Compromises to these critical devices have the potential to severely disrupt an organization’s operations, if not destroy them entirely. Furthermore, Internet of Things (IoT) and embedded systems are becoming ubiquitous in the workplace, thereby increasing the number of potential targets for malicious hackers. Given the prevalence of Linux devices in the workplace, it is of paramount importance that organizations harden and secure these devices. The challenge is that system administrators may be unaware of threats to their Linux system, and by extension, their organization. After all, it is easy to overlook Linux systems that are setup once and summarily forgotten about. Furthermore, administrators may lack the skill or knowledge to properly examine and secure Linux-based IoT devices and embedded devices. 

These shortcomings can be addressed through a detailed examination of the threats to enterprise Linux systems, remembering that offense informs defense. The purpose of this research is to examine Linux privilege escalation techniques in detail, particularly techniques that are in active use as of 2016. The techniques examined include current kernel exploits, exploiting weak system configurations, and also conducting physical access attacks where only a keyboard is present. 

Clique no texto para ler o arquivo original

Comentários

Manual de Fontes Abertas

CLICA

Pericia Digital

Como usar um Agente OSINT IA

Postagens mais visitadas