Friday, October 24, 2014
11:18 AM
| Posted by
Unknown
|
(6) As the role of the CISO continues to evolve... - Hackers Squadron
As the role of the CISO continues to evolve within organizations towards that of an executive level position, we see a growing emphasis on traditional business administration skills over the more technical skills that previously defined the top security leadership job. Nonetheless, CISOs need to keep abreast of the latest down-in-the- weeds tools and technologies that can benefit their organization’s security posture, as well as those tools that are widely available which could be misused by malicious actors to identify and exploit network security weaknesses. In light of that fact, we recently spoke to Nabil Ouchn (@toolswatch ), the organizer of the Arsenal Tools exhibit and activities at the BlackHat Conferences in both the US and Europe since 2011, as well as being the founder of the portal ToolsWatch.org . ToolsWatch is a free interactive service designed to help auditors, penetration testers, and other security professionals keep their ethical hacking toolbox up to date with the latest and greatest resources. Ouchn is an influential security expert with over 15 years experience in vulnerability management, compliance assessment and penetration testing, and Co-Founder of an innovative SaaS Multi- Engines Threats Scanning Solution. As part of his research, Ouchn maintains several projects, including Default Password Enumeration (DPE), the open source correlated & cross-linked vulnerability database vFeed, and the Firefox Catalog of Auditing exTensions called FireCAT. We asked Ouchn to assemble what he believed to be the top hacker tools every CISO should at least understand, if not actively encourage for integration into their own security programs. (Part Two Here: Five More Hacker Tools Every CISO Should Understand) “Remember the paper Improving the Security of Your Site by Breaking Into It written 20 years ago by Dan Farmer and Wietse Venema?” Ouchn asked. “It is still valid today. The best approach to mitigating the vulnerabilities and threats to an information system remains having the ability to prove that they exist.” “The following is my list of tools every CISO should be on top of, and it was very hard to narrow it down to these few items with so many valuable tools out there,” Ouchn said. “My choices were driven by a combination of the tool’s value and their ease of use.” ARMITAGE “Metasploit has become over the years the best framework to conduct penetration testing on network systems and IT infrastructure. Nevertheless, I will focus on Armitage an open source effort to bring user-friendly interface to Metasploit,” Ouchn said. “Armitage demonstrations are very convincing and allow you to analyze weak and vulnerable machines in a network in just a few clicks. The compromised devices are depicted with a lightning round,” Ouchn continued. “This tool has brilliantly hidden the complexity of Metasploit (for a non- technical audience) in favor of usability, and is a great way to demonstrate the security in depth of an IT architecture,” Ouchn said. “In fact, the framework has several capabilities to exploit vulnerabilities in almost any type of layer to therefore infiltrate (by pivoting) systems to reach the network’s nerve center. Armitage should definitely be part of the CISO’s Arsenal and his internal Red Tiger team.” HASHCAT “There is constantly a battle between security folks and users when it comes to passwords. Although it is simple to deploy a Password Policy in a company, it’s also very difficult to justify it,” Ouchn noted. “Because in a perfect world from users perspective, the best password would be the name of the family cat with no expiration date, and this fact applies to any system that requires authentication.” “HashCat has shown that the selection of a strong password must be done carefully, and this tool allows us to demonstrate the ease with which a password can be recovered,” Ouchn said. “A CISO should certainly incorporate this password cracking tool in his arsenal because it allows to check the complexity of the company password policy. Of course, the complexity of a password is not the only criterion for a well- constructed policy, as there are a plethora of criteria: Duration, length, entropy, etc… So HashCat is a must have for any CISO.” (See also John the Ripper). WIFITE “You know what you have connected to when using your hardwired network, but have you ever wondered if the air is playing tricks on you? To test your WiFi security, Wifite has the simplest way,” Ouchn says. “The grip is instantaneous. It is written in Python and runs on all platforms. CISOs should need only to supply the WiFi interface they use and it does the job, verifying that the corporate wireless networks are configured according to the applicable Security Policy, and better yet, it can be used to identify any open and accessible network that can potentially be harmful in terms of Phishing” Ouchn continued. “Wifite allows the discovery of all devices that have an active wireless capability enabled by default (like some printers for example). Wifite is a very simple and convincing way for a CISO to validate the security of wireless networks. (See also AirCrack). WIRESHARK “Known for many years as Ethereal, WireShark is probably the best tool when it comes to sniffing for and collecting data over a network,” Ouchn says. “On the one hand, WireShark has boosted its capabilities with the support of several types of networks (Ethernet, 802.11, etc.) and also in the simplicity of its use through a very friendly user interface.” “WireShark allows a CISO to demonstrate that outdated protocols such as Telnet / FTP should be banned from a corporate network, and that sensitive information should be encrypted to avoid being captured by a malicious user,” Ouchn explained. “Beyond the sniffing features, WireShark is also a great way to validate the network filtering policy. When placed near filtering devices, it can detect the protocols and communication flow in use. WireShark should be considered by any conscious CISO to validate the filtering policy and the need for encryption. (See also Cain & Abel). SOCIAL ENGINEERING TOOLKIT (SET) “Those who attended the latest demo by David Kennedy (SET lead developer and author) at the BlackHat Arsenal in Las Vegas understand the importance of such a tool” Ouchn said. SET is a framework that helps the in creation of sophisticated technical attacks which operated using the credulity of the human. It can be used in the process of preparing a phishing attack mimicking a known website or trapping PDF files with the appropriate payload,” he continued. “The simplicity of use via an intuitive menu makes it an even more attractive tool.” “It is the dream of every CISO to drive security awareness campaigns without ruining the security budget. With SET, the team in charge of security audits can design attacks scenarios and distribute them internally to the targeted users,” Ouchn says. “This will confirm the users security perception within the company and validate the best Awareness Policy to deploy. The SET tool is very well maintained and is also based on a framework already mentioned above: Metasploit.”
Subscribe to:
Post Comments
(Atom)
Welcome to my Blog!
Bine ati venit pe blogul nostru.
Cand nu sunt pe blog calatorim!!!
When I'm not blogging, I'm traveling :-)
Email me atGuran
Search
Blogroll
© 2014 by Guran Cosmin.
You're welcome to link to this site or use a single image and brief description to link back to any post. Republishing posts in their entirety is prohibited without permission.
Pictures
Become a Fan
Find Us On Facebook
Contact Form
Video
720x90 AdSpace
Recent Videos
Movie
http://youtu.be/Yj0G5UdBJZw
guran. Powered by Blogger.
Wikipedia
Search results
Popular Posts
-
Tare !!!(guta mititel ) continuare
-
#unuro The Google Black Holes Code: inurl:"view.asp?page=" intext:"plymouth" >>Ok what this code does? So thi...
-
You can press these buttons on your keyboard to use Facebook faster. j , k — Scroll between News Feed stories p — Post a new status l — Li...
-
//// What is DNS ///// Did you know you could be connected to facebook.com – and see facebook.com in your web browser’s address bar – whil...
-
What is Role Of Cookie,types, uses, setting and Privacy Concerns About Cookies What is Role Of Cookie,types, uses, setting and Privacy Conce...
-
10 Free Keyloggers to monitor your Local PC or Laptop! Here is an exclusive list of top 10 free local keyloggers. However If you are plannin...
-
Your blog is your personal online diary which combines the text, images and other media, and links to other blogs, web p...
-
What is a VPN and how does it work? A VPN or Virtual Private Network is a method used to add security and privacy to private and public ne...
-
(5) KING OF HACKERS How to Lock Drive of Remote Windows 10/8/7 Victim PC https://www.youtube.com/watch?v=4CgNDXKXxVo Facebook fan page : htt...
-
(5) For Indians! Happy Diwali in Batch Style! :P ;)... - Legendary Hacking Learners For Indians! Happy Diwali in Batch Style! @echo off colo...
Followers
Contributors
Archive
-
▼
2014
(1156)
-
▼
October
(494)
- https://www.youtube.com/watch?v=hKROVKDIuDo فەرموو...
- (84) Facebook11 Useful Cloud Computing Tutorials h...
- (29) Pure Hacking - @@@ FIND USERNAMES + PASSWORDS...
- Encryption Server Ngerat Klein # compiler skips Pr...
- (99) FacebookCold Cream + Cornstarch + Food Colori...
- (225) FacebookDIY Fake Blood DIY Face Paint DIY Va...
- (167) FacebookWhat is a penetration test? What is ...
- (61) Facebook7 Places That Beginner Hackers Will F...
- (137) Facebook10 HTML5, CSS3 Tricks That Web Geeks...
- (131) Facebookhey guys! I'm back with a brand new ...
- (122) Facebook50 Open Source Software For Your Win...
- (2) wikiHow - wikiHow added a new photo.Happy Hall...
- (12) Google as A Hacking Tool Global search engine...
- (46) FacebookKali Tools List with Short Descriptio...
- (39) FacebookGoogle as A Hacking Tool Global searc...
- (17) new magic code @*[223317557774374:] remove * ...
- (12) Guys recently we explained what is Penetratio...
- (142) Facebook200+ Videos That Will Make You A Mas...
- (100) Facebookساب paypal.. حساب بنكى 206 دولار Ema...
- (176) FacebookTop free PC programs everyone should...
- (179) FacebookDay 31. Last minute DIY Halloween Co...
- (15) Nokia Mobiles Secret Codes :... - Cybercells ...
- (127) Facebook10 Powerful SQL Injection Tools That...
- Interesting facts about browsers - YouTubePublishe...
- (135) Facebook50 Free System And Network Admin Too...
- Cracking WPA & WPA2 key with Aircrack-ng on Kali L...
- (50) FacebookCracking WPA & WPA2 key with Aircrack...
- (237) FacebookGo Here And Copy All the Codes >>>ht...
- (144) FacebookHOW TO IDENTIFY FAKE FACEBOOK ACCOUN...
- (108) Facebook8 Of The Best Free Proxy Websites Fo...
- (111) FacebookHere Are Top 20 Hacking Forums! http...
- (106) FacebookFirst on GAE Club Exclusive Android ...
- (128) FacebookYes, Google Can Be Used For Hacking ...
- (115) Facebook"Would you like some cheese with tha...
- Say Hello To The World
- Blog To Build Relations
- What is a Blog?
- Facebook Tricks
- Incredible Google
- programming
- (116) Facebook@@@ AVOID FRIEND REQUEST BLOCK ...!!...
- Halloween inspiration
- (3) wikiHow - wikiHow added a new photo.wikiHow In...
- (56) FacebookHow To Write Your #Name In Stylish...
- (321) FacebookAnonymous DDOS Tool! https://filetea...
- (145) FacebookHacking BSNL Broadband Internet spee...
- (116) FacebookProxy Clé Orange ^^ Telecom ^^ Tunis...
- (207) Facebook((((Bl@cK $H@rK H@cK3r))))))))))) Fi...
- (195) FacebookLo g India Ki Security Camers ki Sit...
- (127) FacebookLo g India Ki Security Camers ki Sit...
- Cr4x3r b1k4$h What is aobbfile and how do I open...
- (227) FacebookHow to Create Blog Templates Without...
- (208) FacebookLo g India Ki Security Camers ki Sit...
- (113) FacebookCVE-2014-4877: Wget FTP Symlink Atta...
- (101) FacebookHow To bypass sms verification on we...
- What is Role Of Cookie,types, uses, setting and Pr...
- (197) Facebookhttp://www.helpever.net/adminLogin.p...
- (3) #11 [Share một số con SHELL thông dụng ]... - ...
- (99) Make Some Useful & Dangerous Viruses In... - ...
- (120) FacebookTop 10 Android Apps That Turn Your P...
- (5) Five steps to make stay hidden on the internet...
- (33) >>>> TOP WORLD Hackers <<<< You can actually....
- (31) >>>> TOP WORLD Hackers <<<< You can actually....
- (5) TOP WORLD hackers#Admin >>Cookie Stealing At...
- Disadvantages of JavaScript - YouTubePublished on ...
- ███████▓█████▓▓╬╬╬╬╬╬╬╬▓███▓╬╬╬╬╬╬╬▓╬╬▓█ ████▓▓▓▓╬...
- (100) fb trìçkß grœup bÿ Âbhîñàv#Admin_post How ...
- (3) Heyy guyzz.. Now Im telling u tht How to Bypas...
- IT INFO: Cookie Stealing Attack:Hack Any Account l...
- AndroRAT Full Setup + Clean Download + Port Forwar...
- (12) TRICK2. BREAKING DOWN PARTS BY PARTS Open... ...
- (41) FACT - Timeline PhotosFACT CREATE FACEBOOK PA...
- How To Create Facebook Page Without Name : BY ANUJ...
- (¯`·._.·ha3ker-site·._.·´¯)Hello Friends! Welcome ...
- (5) HACKING AND SECURITYAdd your friends to this g...
- (103) FacebookTop 10 Best C/C++ Compilers And IDEs...
- (101) Facebook________ Open Your Backtrack termina...
- (99) Facebook5 Ways to use linux in windows Linux ...
- (10) Hacking Trick - You cannot convert a facebook...
- (3) Facebookpecial Request to all my dear brother ...
- #Admin >>What are some of the main reasons why ...
- (85) Bypass UAC Protection of Remote Windows PC in...
- (3) All Tech Free - Defraggler PRO With Keys Free ...
- (2) #Admin >>Create Barcodes using Excel<< Steps-....
- (10) How To Hack Windows Admin. Password With the....
- (6) #Admin >>Chat with your friends in MS DOS<< 1)...
- (2) #Admin >>How to remove password from WinRAR......
- (6) FacebookHacking Windows 7 Logon Password Witho...
- (3) Hidden Android Secret Codes :... - Cybercells ...
- #Admin >>What is the difference between... - TOP W...
- Best Youtube Tricks Every Internet User Should... ...
- (65) #Admin >>What does a server do?<< ->>:A... - ...
- (62) Hello Friends. There is a new trick that... -...
- vb.net textbox... - تبادل الخبرات في مجال الحاسبvb...
- (112) FacebookHappy National Chocolate Day! Make H...
- (2) Adobe Photoshop Lightroom v5.6 Multilingual......
- (60) Danger Hackers (Public Hacking Group)Hurrah! ...
- (12) Muslim HackersHACKING without any hardwork bo...
- CREATING SERVER
- (1) CS Server(ADSL) CREATING SERVER 1.Go to... - C...
- (6) PC Tricks ClubDo you want to create your own l...
- http://rahulitc.com admin rahul دور على لوحه التحك...
- (179) FacebookSOME DANGEROUS AND DEADLY HACKING TR...
- (102) HACKING A CREDIT CARD What is credit card ?....
- (108) FacebookU Also can download serial number fr...
- (100) Hacking Trick - New Computer Virus List GEOR...
- Blogger: Blogger DashboardreadingjjjjjjBlogger: Bl...
- (99) IndiHack - Hello, GET UNLIMITED FREE HOSTING ...
- (74) ﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞﱞ ﱞﱞﱞhack a website usi...
- HOW TO DO PHISHING? hey guys, today i will describ...
- (4) Recently we said about creating virtual machin...
- (24) Microsoft has achieved a lot of successful......
- (17) Cyber Elite - Hack Remote PC using Payload in...
- (27) Earn Free Unlimited Recharge from Ladooo Andr...
- (104) Facebook►PHP(Navigations)◄ <!--?php if($_SER...
- (170) FacebookNSTALLATION INSTRUCTION 1. Copy code...
- (165) FacebookRemotely Control Your Window 7 and 8...
- Facebook New Tips And Tricks 2013 Facebook tips an...
- Kashif ShadMicrosoft Windows xp or 7 (32-bit/64-bi...
- (131) NOWUse Hard Disk As Ram Step 1: Go to Start-...
- (1) Muslim Hackers。 ☆ 。★ 。 ☆ 。★。 ★。 ...
- (5) The Expert - The Expert a adăugat 2 fotografii...
- (2) *********Gather Cookies and History of Mozilla...
- (3) Hackers Den - How to install whatsaap on iPad ...
- (33) How To Accept or Reject All Friend Request At...
- (133) FacebookHow tO HaCK #FACEBOOK ACCOUNT the...
- (128) FacebookHow to Hide the Drives ( c: d: e: et...
- (124) FacebookHack any pc with ip address... Requi...
-
▼
October
(494)
0 comments:
Post a Comment