o que interessa não é o servidor web gts 13 – são paulo

38
O que interessa não é o servidor web GTS 13 – São Paulo, Brasil Luiz Eduardo DoS Santos CISSP GISP GCIH CEH CWNE Senior Security Engineer – Latin America

Upload: others

Post on 18-Dec-2021

3 views

Category:

Documents


0 download

TRANSCRIPT

O que interessa não é o servidor web GTS 13 – São Paulo, Brasil

Luiz Eduardo DoS Santos

CISSP GISP GCIH CEH CWNE

Senior Security Engineer – Latin America

O que interessa não é (apenas) o servidor web GTS 13 – São Paulo, Brasil

Luiz Eduardo DoS Santos

CISSP GISP GCIH CEH CWNE

Senior Security Engineer – Latin America

Who am I?

 That same guy...

- GTS 13 – São Paulo – June 2009 - 3

Agenda

  Introduction

 Why are we here discussing this, now? (aka: infoSec)

 Beyond the web-server (the technical brief)

 Setting the stage

 Scenarios

 Conclusion

 Q&A

- GTS 13 – São Paulo – June 2009 - 4

Introduction

- GTS 13 – São Paulo – June 2009 - 5

Introduction

 Evolution   Internet focused on web services

  Attacks

 Mainstreaming

- GTS 13 – São Paulo – June 2009 - 6

Web/ Internet

 ~20 years ago (give or take) people start using the www

 Mid 90s it start growing all over the place

 Late 90s all companies have a web presence

 y2k people actively using the internet for “everything”

 The bubble busted

 Who survived

 Web2.0, social networks, etc...

- GTS 13 – São Paulo – June 2009 - 7

“useful” web services

  Internet banking

 e-commerce

 Stock trading

  .gov stuff

 b2b

  “i-commerce”

- GTS 13 – São Paulo – June 2009 - 8

Attacks

 FUN   Defacement/ local attacks (server-side)

  Network based (DoS)

 Web services (via worms, affecting the network)

 Profit   “Infection” attacks (flash, players, etc)

  Botnets, malware, etc

  Stealing (confidential) data

- GTS 13 – São Paulo – June 2009 - 9

Mainstreaming

 Web

  (useful) Services

 Web 2.0   Social Networks

- GTS 13 – São Paulo – June 2009 - 10

Why are we here ?

- GTS 13 – São Paulo – June 2009 - 11

InfoSec

  Information Security “Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction.” from wikipedia

 What information is important though?

- GTS 13 – São Paulo – June 2009 - 12

- GTS 13 – São Paulo – June 2009 - 13

Web/Web services

Applications

Monitoring & Protecting Data

Browser

DBA Thick Client 2 Tier App

Thin Client 3 Tier App

Application Interface

SQL

Data

The Typical Web Scenario

- GTS 13 – São Paulo – June 2009 - 14

Web

Database

Internet

Web Attacks

 SQL Injection

 XSS

 Cookie Poisoining

 Session-Hijacking

 Command Injection

 Web Worms

  ...

 Reality, very very important, but that would be a whole new talk...

- GTS 13 – São Paulo – June 2009 - 15

Setting the stage

- GTS 13 – São Paulo – June 2009 - 16

FEAR - GTS 13 – São Paulo – June 2009 - 17

AWARENESS

The Different Scenarios

 Aka: “explicando com maçãs”

 Nothing new, but, maybe part of the day-to-day activities we just assume are safe or just learned not to care about

  ... Or not realize it’s about database security

- GTS 13 – São Paulo – June 2009 - 18

The Typical Web Scenario

- GTS 13 – São Paulo – June 2009 - 19

Web

Database

Internet

Scenario 2 = The .gov site

- GTS 13 – São Paulo – June 2009 - 20

Scenario 3 = Internet Banking

- GTS 13 – São Paulo – June 2009 - 21

Scenario 4 = The ISP and the Bank

- GTS 13 – São Paulo – June 2009 - 22

Scenario 5 = The Happy Call Center Rep

- GTS 13 – São Paulo – June 2009 - 23

For sure?

- GTS 13 – São Paulo – June 2009 - 24

Database Servers

- GTS 13 – São Paulo – June 2009 - 25

Shipping Dept

Marketing Dept

Sales Dept

Customer Services

DBA(s)

Technical Support

Always there

- GTS 13 – São Paulo – June 2009 - 26

New factor

- GTS 13 – São Paulo – June 2009 - 27

- GTS 13 – São Paulo – June 2009 - 28

- GTS 13 – São Paulo – June 2009 - 29

Company Credibility, really?

 Would you stop using a site that got pwn3d?

- GTS 13 – São Paulo – June 2009 - 30

Profit = Money? (always?)

- GTS 13 – São Paulo – June 2009 - 31

- GTS 13 – São Paulo – June 2009 - 32

Cloud Computing / Outsourcing

- GTS 13 – São Paulo – June 2009 - 33

Corporate Espionage

- GTS 13 – São Paulo – June 2009 - 34

Conclusion (leading to solutions?)

 Provider side:   Avoid/ eliminate bad business practices

  Enforce policies (like, no user/dba credential sharing)

  (try to) solve internal abuse

  Bring the security maturity from the perimeter to the internal net

  (smart) DiD, not only throwing boxes in the net

  Test your infrastructure, servers, etc, for security

 Customer side   Analyse risks involved before taking decisions on providers

  Analyse what you do as a mortal user on the internet

  Take brand-damaging seriously

- GTS 13 – São Paulo – June 2009 - 35

Until “Visite a Nossa Cozinha” for InfoSec

- GTS 13 – São Paulo – June 2009 - 36

Questions?

- GTS 13 – São Paulo – June 2009 - 37

- CONFIDENTIAL - 38

Muito Obrigado Luiz Eduardo DoS Santos

le<at>imperva.com