WWHF 2020 (Virtual): Hack Dumberly Not Harder - Tim Medin

Опубликовано: 19 Октябрь 2024
на канале: Wild West Hackin' Fest
650
8

https://www.wildwesthackinfest.com

00:00 - Tim Medin's Screen
03:38 - Hack Shots Part Deux
04:44 - Lazy Is As Lazy Does
08:55 - Equifax
11:26 - Endpoint Protection Bypass
13:11 - Bad Passwords
18:20 - Test Accounts
19:46 - Help Me
21:35 - MFA
23:04 - Web Cam
28:04 - Amazon Signing
30:52 - MacOS
31:28 - MYSQL (MYFAV)
32:42 - Simple Hacker Inc™
33:01 - I know What You Did Last Hacking
39:49 - Don't Make Noob Squash
41:56 - Keep It Simple Stupid (K.I.S.S.)
43:15 - Teach Others
45:48 - The Accidental Panel Talk

----

Tim Medin discusses the dumbest red team tricks and hacks encountered over the years. We are going to take the A out of APT (again), because so few attackers really need to use advanced techniques. We'll also discuss the simple defenses that make an attacker's life much more difficult.

Tim Medin is the founder and Principal Consultant at Red Siege. Tim is also a Principal SANS Instructor, the SANS MSISE Program Director and a SANS course author. Through the course of his career, Tim has performed penetration tests on a wide range of organizations and technologies. He gained information security experience in a variety of industries including previous positions in control systems, higher education, financial services, and manufacturing. Tim is an experienced international speaker, having presented to a organizations around the world. Tim the creator of the Kerberoasting, a technique to extract kerberos tickets in order to offline attack the password of enterprise service accounts. Tim earned his MBA through the University of Texas. Tie holds the GWAPT, GPEN, GMOB, GCED, and GCIH certifications and he previously held the CCNA certification.