byod presentation init 6 + issa pr chapter joint meeting

20
Obsidis Consortia, Inc. BYOD:Bring Your Own Darkside José L. Quiñones-Borrero, BS MCP, MCSA, MCT, CEH, CEI, GCIH, GPEN, RHCSA

Upload: jose-quinones

Post on 14-Jan-2015

1.070 views

Category:

Technology


2 download

DESCRIPTION

A technical overview of the dangers of BYOD in an enterprise

TRANSCRIPT

Page 1: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Obsidis Consortia, Inc.

BYOD:Bring Your Own Darkside

José L. Quiñones-Borrero, BSMCP, MCSA, MCT, CEH, CEI, GCIH, GPEN, RHCSA

Page 2: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

What is OC, Inc?

• Obsidis Consortia, Inc. [OC, Inc.] is a non-profit organization that promotes security awareness in the community and supports professional development of security professionals, students and enthusiasts in Puerto Rico.

• OC, Inc. has develop and is supporting initiatives like the Init6 Security User Group, Professional Training & Workshops, Network and Security Systems Simulation Scenarios (Capture the Flag), Security BSides Puerto Rico Conference and a Community Outreach Program.

Page 3: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Why BYOD?

• What's Mine Is Mine, What's Yours Is Mine, Too

• Employees Happier, More Productive?

• Gartner Predicts by 2017, Half of Employers will Require Employees to Supply Their Own Device for Work Purposes

Page 4: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Why NOT?

• Little or no control over devices

• Privacy issues about device’s content

• No jurisdiction over devices

Page 5: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

What are these devices?

Page 6: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Laptops

• Live CD/USB– Live USB Creator– Unetbootin

• Virtual Machines– VMware Player– VirtualBox

• Full OS on Hardware– Kali/Backtrack– Pentoo– BackBox

Page 7: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Smartphones and Tablets

• Jailbreak iOS

• Rooted Android

• Ubuntu Touch (Phone)

Page 8: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Others

• Home Routers– Linksys WRT-54G– Alfa Network AP-121U– TP-Link WR703N

• Custom Firmware– DD-RWT– OpenWrt w/Jasager– Totmato Router

Page 9: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Let focus on iOS …

Page 10: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Apple iOS AppStore Goodness

• iNet• TIOD• IPScanner• zScan Pro• Whois• TCPinger• Net Utility

• VNC viewer• RDP client• aSubnet

• Python 2.7

Page 11: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Cydia

Page 12: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Jailbroken iOS

• Tools– nmap, tcpdump, ettercap, aircrack-ng*, dns2tcp,

netcat• Development– Python, Ruby, Perl, SQLite

• OS– wget, curl, grep, sed, awk, inetutils, whois, locate

• Deamons– dns, http, dhcp, ftp, vnc

Page 13: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Installing Metasploit on iOS

1. Jailbrake your iOS devices2. Install BigBoss Recomended Tools3. ruby_1.9.2-p180-1-1_iphoneos-arm.deb4. iconv_1.14-1_iphoneos-arm.deb5. zlib_1.2.3-1_iphoneos-arm.deb6. metasploitframework4.5.tgz

Page 14: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

What about Android?

Page 15: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

PwnPad ($895.00)

•Wireless ToolsAircrack-ng•Kismet •Wifite•Reaver•MDK3•EAPeak•Asleap•FreeRADIUS-WPE

•HostapdBluetooth Tools:•bluez-utils•btscanner•bluelog•Ubertooth tools•Web ToolsNikto•Wa3f

•Network ToolsNET-SNMP•Nmap•Netcat•Hping3•Macchanger•Tcpdump•Tshark•Ngrep•Dsniff•Ettercap-ng•SSLstrip

•Hamster & Ferret•Metasploit 4•SET•Easy-Creds

•John (JTR)•Hydra•Pyrit•Scapy

Page 16: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Can we be more creative?

Page 17: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Red Teaming BYOD

• Raspberry Pi ($35)– 700 Mhz A7, 512MB, HD, 2 USB 2.0, Ethernet– Huge development community– Debian and Red Hat based distros

• CubieBoard ($80)– 1 Ghz A10, 1 GB, HD, 2 USB 2.0, Ethernet– Some community support– Ubuntu and Android

• Odroid ($90)– 1.7 Quad A9, 2GB, HD, 2USB 2.0, Ethernet– No community yet(new platform)– Ubuntu and Android

Page 18: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Demo

Page 19: BYOD presentation Init 6 + ISSA PR Chapter joint meeting

Open Discussion …

Q & A