-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


PHDays

, 30 2017 . 09:06 +
Positive Hack Days 7, ( , ?) (The Standoff).

SOC, . , .

image




(Positive Technologies):


, , . , , . .


, ( ). , , . .

, , , , . .

5 :
  • -


SOC
SOC . , SOC , ( ).



12 , , . SOC . S.P.A.N (Servionica Palo Alto Networks).

image

, .

.

image

VMware.

( ) MaxPatrol 8 . 1719 pdf-.

. :
  • IDS .
  • IDS .
  • Moloch .
  • Network Analyzer .
  • Network Analyzer .
  • HIDS (host IDS) .
  • TIAS , .

. .

, 30 .

, PHDays .

image

, .

!



image

.

, ! 8 , 11-30.

, - , 19 IDS:
  • DMZ, .
  • vlan .

, ( ). Moloch . .

, , , . , - , , .

HIDS , - , .

, VPN, . !

  1. , , , , .
  2. - !
  3. , .

. SOC . . , , , .

image

, .



  1. , 198.18.78.12 - web- (198.18.12.177) . , . . . , - .
  2. .1. , . NAT . fair-play .
  3. (198.18.12.169) DMZ mysql (10.25.153.24). , . . , . .
  4. , DMZ. web-c (198.18.12.179) XSS. . xss, url. !
  5. web- (198.18.12.179) pureFTP. FTP. .
  6. web- (198.18.12.180) (/.git) . . !
  7. 00:30 10.64.94.0/24. DMZ. , . *- , !
  8. web- (198.18.12.141), /install. . .
  9. ! SMB. , Secret Net . , false positive .
  10. 198.18.12.169 /wp_include . .
  11. 05:00 07:00 . .
  12. 8:00 , : nmap, sqlmap, nessus, ( nmap). , user-agent: go-http-client , .
  13. , , , . , , .
  14. , 198.18.12.143. wordpress ( ) API- admin:admin123. . , .
  15. FTP. .

S.P.A.N.
, , , .

, !


image


  1. 20:26 smb 172.20.3.147 10.25.21.23. . -.
  2. , smb, snmp, sql. , . .
  3. , 203.0.113.169 ( ) wordpress white hat, .
  4. smb 172.20.3.147 10.25.21.24 ( , ).



! , , . , 100% .

, . ? :
  1. . - , , , . .
  2. ( ) , , .
  3. , . , , .

, , . - !

, . PHDays 8.

image


Positive Technologies ( , , ) .

S.P.A.N. , .

, .

Baymaxx .





.

image


UAC Bypass

I 2017

SDL. 2017
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/329730/


: [1] []
 

:
: 

: ( )

:

  URL