cyber security workshop @spit- 8th october 2016

40
Presented by:- Nilesh Sapariya Security Researcher | CEH v8 | Blogger

Upload: nilesh-sapariya

Post on 12-Apr-2017

119 views

Category:

Education


0 download

TRANSCRIPT

Page 1: Cyber Security Workshop @SPIT- 8th October 2016

Presented by:-Nilesh SapariyaSecurity Researcher | CEH v8 | Blogger

Page 2: Cyber Security Workshop @SPIT- 8th October 2016

Before We Start :- Disclaimer

My posts have nothing to do with my company of organization I’m working. Its strictly educational purpose only.

All the knowledge provided on this slides area unit for academic functions solely. The positioning is not any approach to blame for any misuse of the knowledge.

This slides is completely meant for providing data on “Computer Security”, “Computer Programming” and different connected topics and is not any approach connected towards the terms “CRACKING” or “HACKING” (Unethical).

The word “Hack” or “Hacking” that's used on this slides shall be considered “Ethical Hack” or “Ethical Hacking” severally.

We tend to believe solely in White Hat Hacking. On the opposite hand we tend to condemn Black Hat Hacking.

Page 3: Cyber Security Workshop @SPIT- 8th October 2016

Who Am I ? A researcher in Web Application Security

A Bug Hunter Enthusiast

4+ years of Experience in Information Security

Listed in top sites hall of fame

Speaker @Null Mumbai Chapter

Blogging at http://shield4you.blogspot.in/

A Twitter lover @nilesh_loganx

Page 4: Cyber Security Workshop @SPIT- 8th October 2016
Page 5: Cyber Security Workshop @SPIT- 8th October 2016

And Many more……

Page 6: Cyber Security Workshop @SPIT- 8th October 2016

This talk is about Cyber security Trends

How to kick start your career in to Information Security

How to protect organizations from cyber criminals

Page 7: Cyber Security Workshop @SPIT- 8th October 2016

But Why Cyber Security ?

Page 8: Cyber Security Workshop @SPIT- 8th October 2016

#Reason1 : Apple

https://twitter.com/Zerodium/status/781516292901789696

Page 9: Cyber Security Workshop @SPIT- 8th October 2016

#Reason2 : Google

https://twitter.com/soaj1664ashar/status/780481355192868864

Page 10: Cyber Security Workshop @SPIT- 8th October 2016

#Reason3 : Google

https://twitter.com/Dinosn/status/775912785549094912

Page 11: Cyber Security Workshop @SPIT- 8th October 2016

Why they pay this much for security ?

Page 12: Cyber Security Workshop @SPIT- 8th October 2016

#Reason1 : Yahoo - 500M Users’ Account Hacked

https://twitter.com/TripwireInc/status/779289562770268161

Page 13: Cyber Security Workshop @SPIT- 8th October 2016

#Reason2 : Dropbox Hacked

https://twitter.com/newsycombinator/status/770924645893668865

Page 14: Cyber Security Workshop @SPIT- 8th October 2016

Types of Hacker..

White Hat Grey Hat Black Hat

Page 15: Cyber Security Workshop @SPIT- 8th October 2016

White Hat Hackers

Page 16: Cyber Security Workshop @SPIT- 8th October 2016

Grey Hat Hackers

Page 17: Cyber Security Workshop @SPIT- 8th October 2016

Black Hat Hackers

Page 18: Cyber Security Workshop @SPIT- 8th October 2016

Cyber security Trends

Page 19: Cyber Security Workshop @SPIT- 8th October 2016

• Cloud services

https://en.wikipedia.org/wiki/Cloud_computing_security

Page 20: Cyber Security Workshop @SPIT- 8th October 2016

• Ransomware

Ransomware

https://en.wikipedia.org/wiki/Ransomware

Page 21: Cyber Security Workshop @SPIT- 8th October 2016

• IOT - Internet of Things

https://en.wikipedia.org/wiki/Internet_of_things

Page 22: Cyber Security Workshop @SPIT- 8th October 2016

IOT + XXE

https://medium.com/@iraklis/an-unlikely-xxe-in-hikvisions-remote-access-camera-cloud-d57faf99620f#.tcdpedaqd

Page 23: Cyber Security Workshop @SPIT- 8th October 2016

• Spear phishing

Ransomware

https://en.wikipedia.org/wiki/Phishing

Page 24: Cyber Security Workshop @SPIT- 8th October 2016

• Known vulnerabilities

https://www.owasp.org/index.php/Top_10_2013-Top_10

Page 25: Cyber Security Workshop @SPIT- 8th October 2016

CAREER PATH

Page 26: Cyber Security Workshop @SPIT- 8th October 2016
Page 27: Cyber Security Workshop @SPIT- 8th October 2016

Primary Domains in Information Security

1. Web Application Security / Mobile Application security

2. Network Security

3. Digital forensics

4. Secure Code review

5. Compliance :- ISO/COBIT implementation

6. Fuzzing / Exploitation

7. Security Architecture and Design

8. Software Development Security

Page 28: Cyber Security Workshop @SPIT- 8th October 2016

When will I get a job?

Page 29: Cyber Security Workshop @SPIT- 8th October 2016

Build yourself

Page 30: Cyber Security Workshop @SPIT- 8th October 2016

Listening is the key

Page 31: Cyber Security Workshop @SPIT- 8th October 2016

Must for Info Sec people:-

https://twitter.com/nilesh_loganx

Follow me + my followers ;)

http://null.co.in/

Subscribe to null mailing list + Attend free trainings

Page 32: Cyber Security Workshop @SPIT- 8th October 2016

Take Away :- #NeverGiveUp

Page 33: Cyber Security Workshop @SPIT- 8th October 2016

Deep dive into some real time attacks

How I could have hacked all Facebook accounts – 15K $

Page 34: Cyber Security Workshop @SPIT- 8th October 2016

A Story Of How I Landed On Dating Site and Secured it

http://shield4you.blogspot.in/2015/08/a-story-of-how-i-landed-on-dating-site.html

Page 35: Cyber Security Workshop @SPIT- 8th October 2016

Demo Time :-

Page 36: Cyber Security Workshop @SPIT- 8th October 2016
Page 37: Cyber Security Workshop @SPIT- 8th October 2016

Final Takeaway

https://twitter.com/brutelogic/status/649247337190137857

Page 38: Cyber Security Workshop @SPIT- 8th October 2016

PS:

This presentation is purely to give you idea about different domains and latest trends (2016) in information security.

Its up to you to decide right carrier path according to your choice / likes / dislikes

Page 39: Cyber Security Workshop @SPIT- 8th October 2016

Questions ?

Page 40: Cyber Security Workshop @SPIT- 8th October 2016

Thank you

Comments | Feedback | Suggestions Twitter : https://twitter.com/nilesh_loganx

Email: [email protected]

Blog: http://shield4you.blogspot.in/

LinkedIn: https://www.linkedin.com/pub/nilesh-sapariya/39/33/735

Slide share: http://www.slideshare.net/Nilesh_logan