[01:41.060 --> 01:46.460] I guess we're still checking to see if we're having technical difficulties with the PowerPoint slides. [01:49.380 --> 01:52.640] Chris, why don't we go ahead and introduce ourselves around the table. [01:54.560 --> 02:00.540] Hi, I'm Dave, and I am a former hacker working in the security industry. [02:02.140 --> 02:11.200] I'm Steve Lutz, I'm a security consultant, and I'm working for a large consulting firm, a well-respected consulting firm. [02:11.540 --> 02:16.300] I'm Chris, I'm also a security consultant working for a large consulting firm. [02:16.500 --> 02:18.220] The same firm. [02:18.460 --> 02:19.240] The same firm. [02:19.780 --> 02:20.280] As you? [02:20.420 --> 02:21.740] We went to different high schools together. [02:23.380 --> 02:26.640] I'm Laura, security consultant, same firm. [02:28.040 --> 02:32.080] I'm Ira Winkler, security consultant, independent totally. [02:34.140 --> 02:36.320] So we outnumber the hackers four to one. [02:36.400 --> 02:38.080] Oh yeah, also author of Corporate Espionage. [02:38.120 --> 02:39.020] Everybody buy the book. [02:39.180 --> 02:40.000] Last plug of the day. [02:41.280 --> 02:45.160] And I have some really groovy t-shirts for sale in the front room. [02:45.940 --> 02:47.300] That would be our second plug. [02:49.100 --> 02:52.100] Hey, if we can't get the slides going, just go ahead and bring the box up here. [02:57.420 --> 02:59.560] Yeah, this one doesn't work very well. [02:59.720 --> 03:00.300] Try this one. [03:00.680 --> 03:09.580] Basically, what we want to do is talk today a little bit about the work that's being done between the corporate environment and the hacker community. [03:09.900 --> 03:19.640] A lot of clients are out looking at getting security consulting, but quite often they're scared to go out and seek out a quote-unquote hacker-cracker type source. [03:20.560 --> 03:27.340] So what we're doing is we're reaching out to the community, getting people who want to get involved and work with this. [03:28.160 --> 03:29.220] We have clients. [03:29.360 --> 03:30.660] We have people that want these services. [03:30.900 --> 03:41.420] We want to provide them service, the best service that we can, as well as giving them the quality that they want, that they deserve, getting the hacker community involved. [03:41.880 --> 03:48.340] It gives also the hacker community an opportunity to apply their trades while getting paid, as such. [03:49.420 --> 03:50.980] Oh, man, we've got slides now. [03:52.340 --> 03:53.720] Go ahead and hit the next one. [03:59.560 --> 04:00.160] Hit it again. [04:01.540 --> 04:04.120] It means, and who will guard the guards, as such. [04:05.120 --> 04:11.700] So what we look at is that the hacker community, some of the corporate environment, is a little bit nervous about them. [04:12.040 --> 04:20.280] So we go in there and kind of step in as an intermediary to bring some of you folks to get involved in the consulting end of it while we take care of our clients. [04:25.380 --> 04:25.740] Slide. [04:25.740 --> 04:26.560] Does this thing work? [04:27.420 --> 04:29.220] Well, I'm going to have to turn around and take a look at these. [04:30.020 --> 04:33.660] Tiger taming is the term that we use, obviously, the corporate term. [04:33.800 --> 04:36.280] It's used in all the publications, all the books. [04:36.460 --> 04:45.260] If we're going out and testing a computer system, a physical site, et cetera, it's also the term used by folks for a group of folks going in and attacking a system. [04:45.460 --> 04:45.800] Slide. [04:47.300 --> 04:48.120] What's the goal? [04:48.220 --> 04:55.540] We want to assess the security of a system by performing risk analysis, risk assessment, probing, penetration testing. [04:56.180 --> 04:58.760] The customer wants to know if their information assets are safe. [04:58.760 --> 05:01.980] They want to know if they can't be hit by nasty hackers as such. [05:02.660 --> 05:06.280] We want to go ahead and test them the best that we can. [05:06.840 --> 05:06.980] Slide. [05:08.600 --> 05:09.380] Is it legal? [05:09.560 --> 05:10.820] That's the big question that comes up. [05:10.880 --> 05:15.900] We have a lot of our corporate clients come to us and say, can we really have a hacker come in and do this? [05:16.120 --> 05:22.260] And then hackers at the same time that want to do consulting are worried about the liability issues involved. [05:22.260 --> 05:35.320] Well, it is legal if you've got a written contract with your customer, if you've got the liability issues covered, if you have the goals outlined, your in scope, out of scope type boundaries. [05:35.640 --> 05:40.500] So it is a legal thing to do if you have, obviously, a contract with your customer. [05:41.120 --> 05:41.560] Slide. [05:43.520 --> 05:43.920] All right. [05:44.080 --> 05:51.120] One of the things we should point out is that in some of these engagements, we look at, we asked our client, what is your equipment? [05:51.300 --> 05:53.660] What do we have, you know, rights to go after? [05:53.960 --> 06:00.000] And a lot of times there's gray areas because they're outsourcing, like internet service and so forth, web farms. [06:00.000 --> 06:02.900] And those are shared by other customers. [06:02.900 --> 06:09.100] So we have to really talk through with whoever they're outsourcing to to see if we get permission from them to attack those machines. [06:09.240 --> 06:10.940] Many times we don't get permission. [06:11.220 --> 06:15.460] So we kind of have to limit what we do and attack just specific machines. [06:15.980 --> 06:22.140] I know a lot of folks that are here are sysadmins, web admins, that sort of thing, coders. [06:22.460 --> 06:26.080] And a lot of folks want to get into consulting, setting up firewalls, that type of work. [06:26.440 --> 06:28.540] So, I mean, these are the keys that we look at. [06:28.540 --> 06:30.300] And these are hints for you as well. [06:30.500 --> 06:33.240] You know, define the scope, define the dollars before you get involved. [06:33.440 --> 06:34.120] Limit your liability. [06:34.780 --> 06:35.320] And next slide. [06:37.360 --> 06:40.580] The traditional cracking, I mean, I'm comparing it to what we're doing. [06:40.960 --> 06:42.700] I mean, you've got a totally different goal set. [06:42.800 --> 06:44.240] You're out there trying to get into a system. [06:44.500 --> 06:46.460] Break in, you've got an undefined schedule. [06:46.620 --> 06:49.380] Work as much as you want to do this. [06:50.440 --> 06:52.680] You know, you've got your liability up there as well. [06:53.940 --> 07:00.300] You know, the standard stuff that some of the other folks have indicated earlier with the addition of the angry moms, I suppose. [07:01.180 --> 07:07.660] On the corporate side, obviously, we've got angry bosses mostly and angry clients. [07:07.840 --> 07:10.140] But we define things. [07:10.240 --> 07:11.400] We have to stick within a schedule. [07:11.560 --> 07:12.620] We have to stick within a budget. [07:12.800 --> 07:15.140] And so do you if you're going out and doing these types of issues. [07:15.600 --> 07:15.840] Slide. [07:17.720 --> 07:22.520] What we call when I limit the liability is avoid the OSS. [07:26.440 --> 07:32.780] And to me, it's the last thing you want to do is get a client to call up and say, hey, you know, our DNS server went down. [07:32.920 --> 07:34.100] Are you guys doing anything? [07:34.540 --> 07:35.420] Oh, shit. [07:35.680 --> 07:37.160] But sometimes it gets a little more aggressive. [07:38.040 --> 07:39.720] It's like the McCarthy syndrome. [07:40.000 --> 07:41.540] It's like there's a commie behind every tree. [07:41.540 --> 07:50.020] So as soon as they hear we're on this test, anybody who's kind of suspicious, anything that goes wrong is immediately blamed on us until we can prove otherwise. [07:50.240 --> 07:51.760] So we have to be prepared for that. [07:51.980 --> 07:59.260] And how we protect ourselves is we keep logs of everything that we do in real time, every keystroke, everything that we get into. [07:59.700 --> 08:05.340] And we can play that back for them and review that at some time in the future and kind of prove what we did and didn't do. [08:05.580 --> 08:08.600] But we always end up having some kind of thing like that in engagement. [08:09.840 --> 08:11.380] Yeah, and let me also add something. [08:11.520 --> 08:14.840] When I've been doing penetration tests, in one case we were penetrating a bank. [08:15.100 --> 08:22.260] And what happened was we get a call from an IRA bank employee who says, I thought you weren't supposed to do any of this social engineering garbage. [08:22.640 --> 08:23.240] It's like, why? [08:23.320 --> 08:23.800] What do you mean? [08:24.000 --> 08:28.780] It's like, well, somebody called us up and wanted to know what the password was for the financial transaction system. [08:29.460 --> 08:31.460] And it's like, well, why do you think that was us? [08:31.880 --> 08:34.660] And then it was like, oh, yeah. [08:34.820 --> 08:35.820] It's like, well, it had to be you. [08:35.900 --> 08:37.300] You're doing that penetration test. [08:37.300 --> 08:38.760] And it's like, well, guess what? [08:38.820 --> 08:39.600] It wasn't us. [08:40.020 --> 08:46.520] And the problem is you don't know if somebody is going to be breaking in at the same time you are for, well, illegally. [08:46.820 --> 08:49.220] And that's a major problem you have to also be able to deal with. [08:49.700 --> 08:52.400] And that's where the liability issues come in. [08:52.500 --> 08:52.640] Right. [08:52.640 --> 08:53.200] Hit the next slide. [08:54.640 --> 09:00.200] Or as we say, cover your ass, big time, before you go in there. [09:00.360 --> 09:09.100] If you're doing work for a client, setting up a firewall, a security bastion route, or whatever it is, because something's going to happen, and then they're going to come after you legally. [09:09.780 --> 09:10.500] Hit the next one. [09:12.280 --> 09:13.800] Why do companies want these? [09:13.920 --> 09:14.680] Well, it's pretty obvious. [09:14.860 --> 09:15.680] They're real nervous. [09:16.440 --> 09:18.160] They want to make sure their assets are safe. [09:18.280 --> 09:23.620] They want to test their skills or their systems against what's truly out there. [09:23.960 --> 09:33.060] And you can go and run some of the standard tools, but, you know, as we all know, those aren't going to find much more than a third or a half of the vulnerabilities out there, if that. [09:33.060 --> 09:35.560] So, you need specialists to come in. [09:35.680 --> 09:44.100] You know, a lot of the specialists in this room, to come in and test as many vulnerabilities as you can, and some of the latest and greatest ones, some of the new stuff that's hit the market. [09:45.080 --> 09:45.900] Hit the next one. [09:49.940 --> 09:52.340] Well, the benefits of this, I think, are pretty obvious. [09:53.120 --> 09:54.440] You get corporate. [09:56.240 --> 10:07.740] We're taking care of the liability side of it, and we've got, you know, all the clients out there, as well as we get the project management skills to go in and keep the project under wraps, cover the liability, et cetera. [10:08.020 --> 10:20.320] At the same time, you get the opportunity to have the best in the world, as such, go out and apply their trade to test the security of that firewall or that system and hit it again. [10:20.540 --> 10:23.560] As such, the hacker gets paid while applying his trade. [10:23.940 --> 10:26.740] So, I mean, it's kind of the best of both worlds for everyone there. [10:29.260 --> 10:30.900] I mean, hacking, again, what... [10:30.900 --> 10:37.340] Well, the hacking versus the auditing, and we talk about risk assessment and auditing, and you think about all the accountants and stuff out there. [10:38.600 --> 10:40.120] The goals are a lot different. [10:40.440 --> 10:46.880] I mean, we want to go and find as many vulnerabilities as we can, not necessarily break in, and we're going to use the standard tools. [10:47.100 --> 10:49.860] Well, we know that that's not going to find everything. [10:50.040 --> 10:51.220] It's not going to give the client value. [10:51.440 --> 11:00.120] So, by adding the hacking side to it and bringing it in, we can add all these additional skill sets and give the client the best that they can. [11:03.800 --> 11:11.860] Well, some of the fear that we've encountered out there, some of our clients, and we tell them up front, you know, we're going to use a hacker. [11:12.920 --> 11:15.200] And they always get a little, well, who is this guy? [11:15.280 --> 11:15.540] What's he do? [11:15.580 --> 11:16.380] Is he going to break another system? [11:16.440 --> 11:16.980] Is he going to kill us? [11:17.000 --> 11:17.280] Oh, my God. [11:17.340 --> 11:17.880] What is he going to do? [11:18.040 --> 11:20.140] As soon as he's off the job, is he going to break in and take our passwords? [11:20.220 --> 11:21.140] And all that kind of crap. [11:21.700 --> 11:27.640] And so we have to calm them down a little bit and get them over that fear and uncertainty, some of the trepidation, and build a trust factor. [11:27.640 --> 11:30.780] And we've used some of the folks here in the room for some of our jobs. [11:31.000 --> 11:31.140] Right. [11:31.620 --> 11:35.180] It depends on what our client's mindset is going into the engagement. [11:36.240 --> 11:37.940] Many times, they contact us. [11:38.060 --> 11:41.060] They hear that we have access to people in the underground. [11:41.620 --> 11:44.480] And it's their idea in the first place that they're just all for it. [11:44.480 --> 11:46.000] We don't have to, you know, convince anyone. [11:46.120 --> 11:47.240] We just get everyone to meet. [11:47.400 --> 11:48.680] They shake hands and we're in business. [11:49.080 --> 11:54.180] Like Chris said, other times, you know, it takes a little bit of talking and getting people comfortable with each other. [11:55.360 --> 12:13.180] In our experience, if we come into a client where there's some senior management, someone in senior management that's against it, it's probably a bad idea to continue with the engagement because at the end of the day, that's who's going to get us out of hot water when there's a problem. [12:14.080 --> 12:27.560] Some of the things we also see, and some of these guys, I know we're going to talk about that later, is that you bring in some real high-profile hacker guy and he's hacking in and all of a sudden, their tech guys find out about it. [12:27.780 --> 12:32.620] And all of a sudden, you start seeing stuff going on in their network when they're not even supposed to know that this is even happening. [12:32.620 --> 12:33.640] Telephones are being shut off. [12:34.120 --> 12:35.100] Computers are being attacked. [12:35.820 --> 12:39.120] Modems shut down right after you connect. [12:39.380 --> 12:40.640] And strange things happen. [12:40.720 --> 12:44.220] All of a sudden, their password file that you just cracked 20 minutes ago is encrypted. [12:46.380 --> 12:48.980] So, we've got a lot of little challenges out there with doing this. [12:49.160 --> 12:53.440] But that's part of the game that we're playing as well and trying to deliver the value to the client. [12:56.800 --> 13:00.120] We're going to talk a little bit about, I guess, some of the experiences that we've had. [13:01.380 --> 13:02.740] Ira's name's not up there, sorry. [13:03.980 --> 13:10.420] But some of the experiences that we've had doing this type of work, going out and selling it, working with the clients, and some of the fear they have. [13:10.720 --> 13:21.440] Because, I mean, really, if we're an open group, you know, we want to share the hacking and the security stuff and make systems more secure, we're going to go out and try to work with these clients to make them more aware. [13:22.000 --> 13:23.480] And I think that helps all of us. [13:23.600 --> 13:24.200] It gives us work. [13:24.360 --> 13:27.440] It gives some of the experts out here in firewalls work. [13:28.480 --> 13:36.220] It gives us an opportunity to, you know, to really share these experiences and enhance the tools and skill sets that are out there. [13:36.900 --> 13:38.280] But you can hit the next one. [13:39.860 --> 13:41.020] That's kind of the next part. [13:41.120 --> 13:41.960] The Q and F and A. [13:42.220 --> 13:46.660] So, really, I guess now we can... [13:46.660 --> 13:56.140] If you guys want to share some of the experiences that we've had and some of the recent clients that we've all worked on, and then I guess we can entertain some questions or what have you from the audience. [13:58.060 --> 14:05.320] Well, first thing I want to say for people out there who think this is the line of work for them and they're going to jump up and do it. [14:06.520 --> 14:13.460] One of the big differences between computer hacking and corporate work is the corporate wheels turn very slowly. [14:14.120 --> 14:16.170] Chris was talking about liability and contracts. [14:17.100 --> 14:21.860] And this isn't kind of jump out of bed and hack into whatever system you want. [14:23.480 --> 14:27.240] But for me, it's really kind of a dream come true. [14:27.460 --> 14:30.080] I was a hacker back when I was a teenager. [14:30.720 --> 14:32.640] And I'm 14 years old. [14:32.720 --> 14:35.100] And all my friends are like, you've got to do this professionally. [14:35.140 --> 14:36.520] You're going to get yourself in trouble. [14:36.720 --> 14:40.320] And, you know, you know more than these guys and da-da-da-da-da-da-da. [14:41.640 --> 14:44.660] And, unfortunately, this didn't exist back then. [14:44.740 --> 14:47.940] And this wasn't kind of an opportunity. [14:47.940 --> 14:57.880] I don't know if it was the corporate mindset or was, you know, the widespread boom of the internet that kind of opened this up. [14:58.160 --> 15:13.560] But this type of work gives companies a way to take advantage of the skills that are out there, that people have, and see what it's like to undergo a real attack, you know, from all ends. [15:13.560 --> 15:18.420] Because it's not just going to be computer hackers sitting in their garage. [15:18.840 --> 15:23.360] But it might be an ex-hacker which is hired by a rival company. [15:23.520 --> 15:25.180] It could be industrial espionage. [15:25.180 --> 15:27.800] It could be, you know, what have you. [15:28.360 --> 15:39.860] And a penetration attack is a good way to, you know, realistically see what's going on with your system. [15:42.200 --> 15:42.680] Yeah. [15:44.060 --> 15:45.540] Oh, here's an interesting thing. [15:46.300 --> 15:59.480] Whenever, if you're in the business of doing this, and you're contacted by a client, and you get some security manager that says, hey, we really want this penetration test, you know, you've got to really assess where they sit in the totem pole of the corporation. [15:59.480 --> 16:17.300] For example, if they're just in charge of one particular network or division, and they say, we're contracting you to try and break into the entire company anywhere you want, any branch you want, you're probably going to find yourself in hot water, because you haven't spoken to the CEO or the board of directors or the CIO or the CFO. [16:17.840 --> 16:26.140] So right away in your mind, you've got to make sure that that's the level that you're dealing with, or you're going to run afoul of at least the corporation in a lawsuit or maybe the law. [16:27.840 --> 16:33.180] Speaking of the law, we have something that we do, which we call the get-out-of-jail-free card. [16:34.320 --> 16:54.040] We have the client sign a letter from the highest level of management that we can get our hands on, typically the CEO or the CFO, stating that we are doing this on their behalf, that we have permission and so forth and so on, and we keep that signed letter with us when we're working. [16:54.040 --> 17:03.880] We actually tape it up to the wall in the event that law enforcement might be tipped off by someone who's not privy to the exercise and come in and haul us away. [17:03.920 --> 17:07.700] So we're hoping we can hold this thing up and say, take this letter and just leave us alone. [17:07.960 --> 17:13.840] It also helps when you're trying to hop a fence or sneak in to the back door of the place. [17:13.860 --> 17:18.960] If you have to resort to trashing or something like that, you can also take out that get-out-of-jail-free card. [17:20.140 --> 17:29.240] We've never had to actually use it, but we had a close call, one engagement where we were all hacking with wireless modems, ricochet modems from Metricom. [17:30.760 --> 17:42.600] And somebody down in the totem pole in the company, I think it was one of the security administrators, noticed we were doing this and we were sort of playing cat and mouse with him for a couple of days and he'd see us and try to lock us out and we'd get back in and so forth. [17:42.820 --> 17:44.580] But he finally got fed up and called the FBI. [17:46.520 --> 17:51.380] And then we, one of the guys on our team, who's here actually, there he is. [17:52.780 --> 17:54.160] All of a sudden his modem went dead. [17:54.280 --> 17:55.100] He's like, what happened? [17:55.720 --> 17:56.380] What happened? [17:56.420 --> 17:57.820] And we're like, I don't know. [17:58.020 --> 18:03.920] We found out that somebody called the FBI and they were starting with him and working their way around the team. [18:04.160 --> 18:05.600] So everybody's like, what are we doing? [18:05.600 --> 18:06.860] And I said, just sit down, don't panic. [18:06.980 --> 18:09.340] We have the letter on the wall and we'll all go to jail together. [18:12.220 --> 18:15.880] So it's things like... and then finally we called the, you know, we called the senior manager. [18:16.060 --> 18:16.900] I think it was the CFO. [18:17.260 --> 18:18.680] Was it the CFO we were dealing with? [18:19.020 --> 18:19.920] Or somebody eye up. [18:20.280 --> 18:21.440] And then they got the word back to him. [18:21.500 --> 18:23.300] He called the FBI back and said, only kidding. [18:23.540 --> 18:24.560] It's one of us. [18:24.980 --> 18:27.880] So those are some of the things that we've found. [18:28.320 --> 18:29.100] You got to watch out for. [18:29.380 --> 18:46.520] You know, not to mention what Chris was talking about, where you might have a letter, you know, you have a contract with the top security guy, the president of a company, but you have techs and you have system, you know, system administrators who are still none too happy. [18:46.680 --> 18:58.720] And they'll get in a cat and mouse game, you know, screwing with you, whether it's, you know, trying to cut off your access or your personal access, because they don't like the fact that you have a signed contract to break into their system. [18:58.960 --> 19:02.700] They're humiliated, possibly, that you were able to get past their security. [19:02.700 --> 19:04.160] Worried about job security. [19:04.540 --> 19:05.060] Exactly. [19:05.360 --> 19:06.180] That's a big... [19:06.560 --> 19:17.320] And I think that is a big issue that, you know, we're expecting a lot of people skills out of the people we bring into projects, because we do hold many conferences with the angry sysadmins. [19:17.560 --> 19:29.780] And you really have to have very good people skills to have them buy into what you're doing and have them buy into it and feel good about maybe be doing better on their security. [19:30.420 --> 19:32.100] And also so you can get paid. [19:32.320 --> 19:32.760] Yeah. [19:32.760 --> 19:33.840] That's an important part. [19:34.140 --> 19:34.300] Yeah. [19:34.360 --> 19:39.600] And secondly, we have to make sure that you have to understand the industry. [19:39.820 --> 19:46.620] Just breaking into a box may be impressive to a CIO, but it's not going to be as impressive to a CFO. [19:46.620 --> 19:50.520] So if it's a bank, you have to know what information you're going after. [19:50.540 --> 19:54.860] Or if it's, you know, some computer company, you're going after trade secrets. [19:55.060 --> 19:57.840] So it's not a matter of just breaking into a box. [19:57.980 --> 20:02.260] That only maybe makes sense to a CIO and his people. [20:02.440 --> 20:04.680] So it really... you have to understand the industry. [20:04.860 --> 20:07.500] And we fully expect an understanding of that. [20:08.240 --> 20:10.020] Just to add a little bit to that. [20:10.460 --> 20:12.540] Currently, this week, I'm breaking into a company. [20:12.700 --> 20:14.880] I have control of their network right now, if you can't tell. [20:14.880 --> 20:21.900] But anyway, this company had four previous penetration tests performed on their network. [20:22.020 --> 20:30.100] And it was from the likes of... I can't really say, but let's just say, if you think of like the large consulting firms that do security consulting, all of them. [20:30.340 --> 20:33.820] And their tests, they said, we have control of your entire network. [20:34.120 --> 20:37.800] And to them, the companies, it was presented to the CIO and CEO. [20:38.100 --> 20:39.660] And they said, who cares? [20:39.680 --> 20:43.440] You're telling me that my company's been vulnerable for the last five years. [20:43.440 --> 20:44.900] It's vulnerable today. [20:45.040 --> 20:46.280] It will be vulnerable tomorrow. [20:46.520 --> 20:48.960] And we're still some of the... you know... [20:48.960 --> 20:53.600] Well, let's just say, we're still one of the best companies in the world at what we're doing. [20:53.800 --> 20:55.560] And nobody's doing anything about it. [20:55.780 --> 20:57.240] So, who really cares? [20:57.760 --> 21:03.400] So again, when we go in there, or at least when I go in there and do a penetration test, I don't care about computer access. [21:03.700 --> 21:07.180] I care about hurting them from a business perspective. [21:07.180 --> 21:07.520] Right. [21:07.720 --> 21:11.860] And then I go back and hand them their heads in a business perspective. [21:12.260 --> 21:14.020] They don't care if I access a computer. [21:14.300 --> 21:16.340] They care what I do after I get in. [21:16.740 --> 21:19.220] And the problem is, I guess I should say I do a little bit more. [21:19.480 --> 21:19.820] My... [21:19.820 --> 21:24.800] I guess my penetration tests are more counter-espionage, counter-terrorism types of studies. [21:25.060 --> 21:37.980] But when I go in there, again, I have targets, whether it's being able to make a financial transaction, whether it's being able to, again, steal their top product, or whether it's being able to, like, steal their strategic plans and stuff like that. [21:38.240 --> 21:38.460] Right. [21:38.460 --> 21:42.480] Again, it's more target-based than it is technical-based, because nobody cares about tech. [21:42.700 --> 21:42.740] It is system-based. [21:42.740 --> 21:46.840] We do exactly the same thing, which is part of scoping the project with your client. [21:47.100 --> 21:47.240] Yeah. [21:47.360 --> 21:49.220] You're going to say, all right, what's valuable to you? [21:49.460 --> 21:52.320] You know, paint us some scenarios that would really scare the shit out of you. [21:52.800 --> 21:57.620] And they'll say, all right, well, if they're a bank, they'll say, well, if anybody could get into the funds transfer system, my god. [21:57.620 --> 22:02.860] You know, if anybody could get into the credit card system and make a new account or pay their bills, that would be really bad. [22:02.960 --> 22:09.380] Or if it's a production manufacturing company, if they can get their drawings for next year, what they're planning. [22:09.540 --> 22:12.900] Or if it's a telephone company, you get to control the switches. [22:12.920 --> 22:17.180] If it's a hospital, then you're getting the list of all the patients with AIDS or something like that. [22:17.320 --> 22:21.120] So we get that list ahead of time of what they want to see, and we target that. [22:21.300 --> 22:23.820] And that's when we know we're done, when we get to those goals. [22:23.820 --> 22:28.140] And we can present them with these types of information and access. [22:29.100 --> 22:29.380] Question? [22:55.320 --> 22:55.800] Yeah. [23:08.750 --> 23:09.150] Yeah. [23:09.510 --> 23:09.790] Yeah. [23:11.410 --> 23:12.570] Yeah, let's say... [23:12.570 --> 23:14.450] Go ahead and repeat the question, Alex. [23:14.650 --> 23:15.430] I know a lot of these folks didn't... [23:15.430 --> 23:18.190] Okay, the question is, what about the insider threat? [23:18.190 --> 23:21.910] The insider threat is around 75% of the problem. [23:22.450 --> 23:23.950] And then, let me answer that. [23:24.250 --> 23:25.470] I don't know about... [23:25.470 --> 23:27.310] Again, I haven't worked with these people before. [23:27.530 --> 23:28.710] But I've got jobs... [23:28.710 --> 23:31.570] In order to get my foot in the door of companies, I really don't like... [23:31.570 --> 23:33.650] I mean, you can go through their firewall, but big deal. [23:33.870 --> 23:36.250] I get jobs through temporary service agencies. [23:36.430 --> 23:38.870] I got jobs through being a janitor. [23:39.110 --> 23:40.110] Again, things like that. [23:40.310 --> 23:41.870] And got in the company and within... [23:41.870 --> 23:44.370] You know, I basically have about a day and a half to do whatever. [23:44.370 --> 23:45.990] And I compromise them. [23:46.330 --> 23:47.550] And now, what was your second question? [23:47.850 --> 23:50.090] Well, I'd like to expound on that a little bit more. [23:50.250 --> 23:51.410] What we do is... [23:51.830 --> 23:54.510] We stay away from any kind of physical security testing. [23:54.830 --> 23:57.730] The closest thing that we'll ever get to it is trashing. [23:57.770 --> 23:59.510] We've only had to do it once on one engagement. [23:59.790 --> 24:00.810] We did it just to be thorough. [24:00.910 --> 24:02.110] We usually do a technical attack. [24:02.370 --> 24:05.770] But what happens is, we get remote access, which is what a hacker would do. [24:05.830 --> 24:07.730] Through the firewall, through some modems or whatever. [24:08.210 --> 24:12.710] But once we're on the network and peering on the network, we're like any other employee. [24:13.610 --> 24:21.530] So that's when we start what we call phase two of the engagement, which is a knowledgeable insider who's got access to the network. [24:21.750 --> 24:35.810] If we fail to get in remotely, which we never have, but if that ever happened, we would come in at some point in the engagement and say, we failed to get in remotely, now we want to come on site and play the role of the disgruntled internal employee who has access to the network. [24:36.190 --> 24:37.030] And so forth. [24:37.910 --> 24:38.230] Yeah. [24:38.330 --> 24:42.970] Part of some of the engagements that I've worked on, we spend a lot of time, you know, testing the inside machines. [24:43.110 --> 24:45.430] Because if you do a break-in, you might hit a specific target. [24:45.930 --> 24:50.710] But, you know, let's say you nail some RS6000 box that they have, but they got 20 of them. [24:51.330 --> 24:52.710] We need to test all 20 of them. [24:52.790 --> 24:57.690] Because they probably got the same admin set it up and did the same NFS mounts on every single one of them. [24:57.690 --> 25:00.430] So, an internal assessment is real good. [25:00.570 --> 25:01.430] You go through each box. [25:01.650 --> 25:03.410] And also, it's profitable, too. [25:03.490 --> 25:04.230] So that's a good part. [25:04.610 --> 25:05.970] You know, the more boxes, the better. [25:06.530 --> 25:08.310] And I think that's important, too. [25:08.490 --> 25:14.510] You know, when we do have clients that come to us and just say, oh, I've heard about hackers and I want to do a penetration study. [25:14.590 --> 25:15.630] We really sit down with them. [25:15.630 --> 25:15.950] We've heard about hackers. [25:16.310 --> 25:18.530] And we say, is this really what you want to do? [25:18.590 --> 25:22.650] I mean, what are your business issues that brought you to this point? [25:22.650 --> 25:28.690] Because maybe the money would be better spent doing some sort of internal work without performing the penetration study. [25:28.870 --> 25:31.690] So, it's not like, you know, we just do the penetration study. [25:31.810 --> 25:36.650] We really actually scope out outside, inside, and then further follow-up work with all their people. [25:36.830 --> 25:40.810] Yeah, because 95% of a penetration test, I know what I'm going to find. [25:41.190 --> 25:48.790] I mean, because penetration tests, the goal, I see it, is to find countermeasures and prioritize, you know, prioritize countermeasures. [25:48.970 --> 25:52.130] But I could tell you what you should have now, but companies want a point made. [25:52.390 --> 25:58.650] Because, again, any system, if you're a sysadmin now, I can tell you, you're the system isn't updated for known vulnerabilities. [25:58.870 --> 26:02.530] Bad passwords, users that have already left the company, things like that. [26:02.610 --> 26:03.370] Trusted hosts. [26:03.630 --> 26:04.350] Trusted hosts. [26:04.450 --> 26:05.430] Everybody's still using that internally. [26:05.750 --> 26:08.150] Like, you know, NFS mounting everything to everything. [26:08.810 --> 26:15.730] To answer the second part of your question, what we usually do at the end of these engagements is we give them a report that says, hey, this is what we found. [26:16.430 --> 26:22.650] We organize it by severity of what we think they should, you know, what was the worst problems. [26:22.650 --> 26:26.330] And we kind of give them, you know, a roadmap of what we think they should do about it. [26:26.890 --> 26:28.710] Which gets into the, you know, the education. [26:28.990 --> 26:38.530] And it's always in there right at the top, say, four, to sit down with the system administrators and give them some security training, you know, security awareness training. [26:39.050 --> 26:42.610] And kind of teach them some techniques on how to secure their boxes. [26:42.610 --> 26:44.870] And also kind of change their mindset that... [26:44.870 --> 26:50.650] There's a mindset that the firewall's there and we're here and everything's okay, so we don't have to really pay attention to security. [26:50.810 --> 26:59.450] Well, you're only like one dial-up modem away from, you know, access as if you're on the net or one bad firewall rule. [27:00.250 --> 27:02.330] So, we kind of try and change their mindset. [27:02.930 --> 27:08.250] Well, and as most you know, some of the biggest threats out there are just the facts that people use screwed up passwords and user IDs. [27:08.870 --> 27:12.710] And, I mean, that's the biggest threat that we find out there after we get inside the door. [27:12.830 --> 27:15.590] And so, that's the education and awareness part where you go in. [27:15.790 --> 27:19.630] And it's also, you know, more services that you can sell to the client and stuff. [27:19.790 --> 27:33.350] So, if you guys are out there doing this type of work, once you're done setting up the firewall, you see other vulnerabilities, you know, you can go and move forward and say, hey, we can help out in other areas by educating your employees about what to do and what not to do and educating the sysadmins. [27:33.350 --> 27:40.970] And part of the other thing is, if you're only educating the system administrators and the security administrators, you're going to have a problem. [27:40.990 --> 27:44.990] Because the big problem, what you want to do is you want to help detection as well. [27:45.150 --> 27:50.030] And the people that should be detecting this are the users whose systems you log into during a penetration test. [27:50.650 --> 28:00.230] The low-level managers, again, you have to work with the high-level people, but the low-level managers have to make sure that people don't have easy-to-guess passwords. [28:00.230 --> 28:05.590] They have to make sure that people look at that banner that says, the last time you logged in was at 3 a.m. [28:05.750 --> 28:06.430] Saturday morning. [28:06.690 --> 28:09.650] That should be a clue to people that somebody might have used their account. [28:09.930 --> 28:19.430] And they should... the low-level people should know, and I'm not talking about computer people, but anybody in the company should know that these are indications that your system's being screwed up. [28:19.590 --> 28:33.030] And at the same time, with a properly configured system, getting the access of a low-level person should not allow you to compromise their entire system, which is a problem which is going on in a lot of these corporate systems. [28:33.090 --> 28:38.110] There are no internal controls, which answered the invisible man's question over there. [28:38.330 --> 28:44.790] Well, actually, I should say it depends what that low-level person is doing, because the secretaries have the most valuable information in the world, usually. [28:45.910 --> 28:46.910] Well, yes and no. [28:47.090 --> 28:50.970] I mean, it depends if you want to talk about information or access to a system that's sensitive. [28:53.750 --> 29:02.250] Another thing that we've also found is after an engagement like this, Tiger team engagement, let's say we're charging X amount for that engagement. [29:02.490 --> 29:07.130] Well, we've also got the attention of senior management for that moment in time during the briefing. [29:07.270 --> 29:08.530] We have their undivided attention. [29:08.750 --> 29:18.090] And that's the time that we talk to them about a comprehensive security program for their organization that includes policy and procedures and training and all that kind of thing. [29:18.090 --> 29:22.210] And we always win work after the fact. [29:22.310 --> 29:23.770] We always win something. [29:23.990 --> 29:29.530] And it's anywhere in the order of three to five times the price of the Tiger team engagement. [29:30.350 --> 29:35.490] One thing, I guess, that's kind of cool about some of the stuff we get to do is, I mean, we're not just targeting modems to bust in. [29:35.570 --> 29:37.370] And I think this is the fun part of what we get to do. [29:37.630 --> 29:40.830] You know, the client will say, take us apart, take us down, see what you can get. [29:41.010 --> 29:45.750] You know, and they always, like, challenge you and get a little, I don't know, arrogant about it. [29:45.750 --> 29:46.730] Yeah, you can't break in. [29:46.990 --> 29:48.310] So... Let the games begin. [29:48.570 --> 29:49.670] That's a quote from a client. [29:49.970 --> 29:50.010] Yeah. [29:50.010 --> 29:52.170] They heard that just recently on a thing. [29:52.350 --> 29:54.750] So what's kind of fun is we get to go after the modems. [29:54.810 --> 29:55.710] We go after the firewall. [29:55.950 --> 29:58.270] You get to go after, you know, the routers. [29:58.390 --> 30:01.670] If they've got four different types of flavors of UNIX, you go after those. [30:01.830 --> 30:03.150] If they want you to go after MVS. [30:03.650 --> 30:08.690] So the kind of cool stuff is you get to go after a tandem box, an MVS box, a this, a that. [30:08.970 --> 30:09.990] Play with their network. [30:11.090 --> 30:12.170] You know, you get to have a ball. [30:12.250 --> 30:17.130] And I think that's the fun part that every engagement, you know, you get to see something a little bit new. [30:17.270 --> 30:20.850] And you're doing research from scratch every time you bust in. [30:21.870 --> 30:26.250] And since typically you have no idea what's on the other side, as you guys know, it's a lot of fun. [30:26.250 --> 30:28.830] And we get to penetrate all the way in with the blessing of the client. [30:29.390 --> 30:29.790] So... [30:33.070 --> 30:36.650] Let me put in a disclaimer here, because this is one of my pet peeves. [30:36.850 --> 30:44.770] I mean, I just hope you're not sitting out there thinking, well, gee, now if I hacked Sendmail 150 times, that means I'm qualified to do what you people up here are doing. [30:45.110 --> 30:59.270] And just to clarify this, the people we're looking for, at least I would look for, I'm sure they're probably looking for similar people, are probably higher quality sysadmins that primarily, that hack their own systems that aren't out there committing crimes on a regular basis. [30:59.950 --> 31:03.290] Because again, just accessing a computer is pointless. [31:03.530 --> 31:06.390] And again, I could train a monkey to hack a computer in two hours. [31:06.630 --> 31:10.750] It doesn't take a lot of talent, and I believe that's what the first speaker was talking about. [31:11.150 --> 31:19.170] You know, what people are looking for when they're looking for hiring penetration testers, are people that know the details of the internals of a box. [31:19.370 --> 31:29.750] They know the details and how to exploit and how to, more importantly, protect things like the applications, the operating systems, the networking components, and all that sort of stuff. [31:29.790 --> 31:35.590] We're not looking for a bunch of where's puppies or tools kitties to go ahead and work with us. [31:35.910 --> 31:43.490] You're looking for people that know what they're doing that can configure the systems, and penetrating is just kind of what they would normally do to learn how to protect it. [31:43.490 --> 31:45.550] Right, it's a byproduct of what they already know. [31:46.150 --> 31:47.130] I would agree with you. [31:47.230 --> 31:49.410] We're looking for the most knowledgeable people that we can find. [31:49.930 --> 32:02.650] We're also looking for people who, in their spare time, have given up the kind of questionable activities of going out and attacking systems without people's permission. [32:03.090 --> 32:12.050] We do employ people that have done that in the past and have ceased that activity, but it's on a very selective and case-by-case basis. [32:14.410 --> 32:14.930] Question? [32:16.110 --> 32:16.810] On the right. [32:20.740 --> 32:21.260] Hi. [32:25.920 --> 32:31.720] I'm a high school dropout, and I was able to do that by... I stopped going to school. [32:36.870 --> 32:47.390] I have a double-E degree and also a computer science degree, and I worked in defense for 12 years, different government agencies, and then flipped over to the commercial side when the wall came down. [32:47.390 --> 32:55.070] I saw that there was a limited career growth there, so I went over and worked for a large financial institution, and now I'm working with this consulting firm. [32:56.330 --> 32:57.430] I've got a math degree. [33:03.720 --> 33:05.640] Luke, you will see the dark side. [33:05.860 --> 33:06.840] Use your fork, Luke. [33:08.260 --> 33:11.100] I got a math degree, and then I got a master's in business. [33:11.300 --> 33:16.840] And I started off as doing just applications coding for one of the RBOCs. [33:17.800 --> 33:18.080] Uh-oh. [33:18.540 --> 33:25.000] And then getting involved as assist admin, and then I just gradually moved into security-related positions. [33:26.020 --> 33:37.040] I did my graduate work at one of the universities that has a security program now, and then did my thesis on Tempest, and then went into security management right out of graduate school. [33:42.220 --> 33:44.440] My undergraduate degree is in psychology. [33:44.500 --> 33:51.620] Then I went to work for NSA as an intelligence analyst and found out computer people got paid more, so I got into their computer intern program. [33:52.020 --> 33:59.500] And then, after a while, went to work for government contractors, and one of them happened to be doing commercial infosec work, and it was history from there. [33:59.680 --> 34:06.060] Oh, yeah, also, I got a master's so I could get paid more, and now I'm a doctoral candidate in information systems. [34:08.880 --> 34:09.580] Yay, me. [34:18.780 --> 34:19.560] It's out of line. [34:19.780 --> 34:20.180] Sorry. [34:20.940 --> 34:21.680] It's offline. [34:22.860 --> 34:25.380] If this question is out of line, just let me know. [34:25.420 --> 34:25.920] You're out of line. [34:26.300 --> 34:26.540] Okay. [34:27.860 --> 34:28.340] Sorry. [34:30.080 --> 34:32.080] I work at a publishing company. [34:32.180 --> 34:32.860] I'm a web developer. [34:33.040 --> 34:34.320] My best friends, this is admin. [34:34.500 --> 34:40.320] Do you have any advice for us poor people who can't afford to have geniuses like you hack into our systems? [34:40.500 --> 34:42.580] What's, like, the basic level stuff we can do? [34:42.920 --> 34:44.340] Did you ever hear of the internet? [34:45.000 --> 34:45.460] No. [34:45.680 --> 34:51.220] Go to the CERT, SIAC, download the tools, because, again, Satan's available for free. [34:51.360 --> 34:52.560] Tiger's available for free. [34:52.700 --> 34:55.340] Cops, Merlin, Tiger, Tripwire. [34:56.440 --> 35:00.040] Just about, there's, like, millions of utilities that are out there for free. [35:00.160 --> 35:03.740] The SIAC is, like, a one-stop shopping for security tools. [35:03.740 --> 35:05.040] You should be doing it yourself. [35:05.200 --> 35:06.200] There's probably other ones. [35:06.460 --> 35:07.280] Again, it's always good. [35:07.280 --> 35:08.060] 2,600. [35:09.140 --> 35:14.040] Well, 8LGM for, you know, downloading some attack tools to make sure you're not vulnerable. [35:14.340 --> 35:17.560] But honestly, well, actually, you should download those. [35:17.820 --> 35:20.740] You can download a whole bunch of them by just looking for the latest hacks. [35:20.740 --> 35:24.500] Well, read the CERT advisories, then search the internet for the tools. [35:25.440 --> 35:25.800] SEAC. [35:25.800 --> 35:25.900] Yeah. [35:26.020 --> 35:26.200] SEAC. [35:26.280 --> 35:27.540] SEAC advisories. [35:27.720 --> 35:30.920] Search the internet for the tools, then hack yourselves to see if you're vulnerable. [35:31.200 --> 35:38.260] But also, make sure you go to your vendors and make sure you have all their security patches, and update your security patches on a regular basis. [35:38.460 --> 35:40.040] Then you won't have to worry about the rest of the stuff. [35:40.040 --> 35:42.440] You really need to get your sysadmin educated. [35:42.680 --> 35:47.160] You know, get after them that, you know, adding user IDs is not quite exactly administration. [35:47.520 --> 35:55.120] And there's a lot of common sense that gets ignored when it comes to some of the higher level things. [35:55.280 --> 36:09.660] If you don't change your passwords, if you don't, you know, teach people not to write things down, teach people not to throw things out, because you can have, you know, the most cert-proof, completely, you know, high-tech security system. [36:10.040 --> 36:15.420] And if you have some guy who answers the phone with his password, you know, everything's down the drain. [36:15.760 --> 36:22.600] And that's something that often gets overlooked when it comes to the, you know, the high, high-tech security operations. [36:23.000 --> 36:23.360] Oh, yeah. [36:23.520 --> 36:31.640] Just along those lines, just as a word of warning, I realize, of course, all of you are highly intelligent hackers out there and wouldn't ever do anything like this. [36:31.780 --> 36:39.640] But if you're out there in that network room, just remotely telnetting into systems, guess what, your password's already compromised today. [36:40.120 --> 36:48.320] By the, just as an example, Roberto, if you're, you know, logging into Northeastern University, I'm not going to tell your password, but you should go out and change it. [36:48.400 --> 36:52.540] And so should everybody else who's been logging into remote systems over that network. [36:56.920 --> 36:57.680] Secure Shell. [36:58.020 --> 36:59.900] There are also a number of books out there. [37:00.040 --> 37:05.180] I mean, I think when we first started as security managers out in the field, there were no books to buy. [37:05.420 --> 37:06.820] And you can go to any bookstore now. [37:06.920 --> 37:08.580] And there are a ton of books on security. [37:09.600 --> 37:11.660] Cheswick, Bellevin, et cetera, et cetera, et cetera. [37:11.680 --> 37:11.920] Oh, yeah. [37:11.960 --> 37:14.700] Also the book Corporate Espionage by Ira Winkler is excellent. [37:14.780 --> 37:14.880] Who? [37:20.560 --> 37:20.920] Sir. [37:21.140 --> 37:21.360] Oh, it's the book. [37:21.560 --> 37:22.320] Oh, the book. [37:22.520 --> 37:22.640] Huh. [37:23.180 --> 37:24.260] Was there a question there? [37:44.560 --> 37:44.920] Okay. [37:45.400 --> 37:45.780] Oh, I'm sorry. [37:45.900 --> 37:47.940] The question was, have we ever testified are a hacker? [37:48.140 --> 37:49.700] Do we see ourselves as doing that? [37:49.700 --> 37:51.980] I get called in to do incident response. [37:52.620 --> 37:53.700] And if I ever... [37:54.400 --> 37:56.920] I mean, most of the crimes I do is mostly get the guy out. [37:57.120 --> 37:57.900] See if you can... [37:57.900 --> 38:01.620] Well, the companies want to screw them in non-public ways is what it amounts to. [38:01.960 --> 38:06.060] But if I do get called in to testify, and they're doing criminal stuff, hell yeah. [38:06.560 --> 38:09.000] But, you know, I don't see that really happening. [38:09.460 --> 38:10.760] I've never had to testify. [38:10.760 --> 38:14.140] I think it's kind of one of those things where we're in a catch-22. [38:15.560 --> 38:19.680] You know, you've got to take care of your client who's paying you big bucks to do certain things. [38:19.960 --> 38:25.320] And if somebody comes in and deletes their entire, you know, financial database, you know, that company's out of business. [38:25.740 --> 38:27.060] You've got to help your client out. [38:27.380 --> 38:32.400] I mean, I would rather not have to go out there and nail somebody that was, you know, some high school kid that was screwing around. [38:32.440 --> 38:33.900] But that's part of the thing. [38:33.920 --> 38:38.660] If you're a good sysmin, if you're a good hacker and stuff like that, you shouldn't make these kinds of mistakes. [38:38.660 --> 38:42.280] But I should say that that situation that you pointed out is extremely rare. [38:42.620 --> 38:47.120] The gentleman over here pointed out that, you know, 83% of the problems are internal. [38:47.340 --> 38:52.560] What we get a lot of is clients calling us saying, we've got someone who committed a fraud. [38:52.680 --> 38:55.020] They stole, you know, several million dollars and ran away with it. [38:55.080 --> 39:01.300] And we want you to come in here and help us figure out what happened and document everything, you know, the computer forensics side of the business. [39:01.760 --> 39:05.540] That's really the situation that we just find ourselves in more often than not. [39:06.260 --> 39:10.760] Hackers, when they break in, they're not there to steal money, typically. [39:11.100 --> 39:14.840] They're just sort of looking around and they kind of lock them out and end of story. [39:15.300 --> 39:19.840] They've got bigger fish to fry in the internal side with fraudulent employees. [39:20.920 --> 39:25.660] We found a guy, speaking of what hackers do when they break in, we found a guy on a big network we were looking at. [39:25.700 --> 39:30.100] He set up a doom server out on one of the boxes out there. [39:30.100 --> 39:32.500] And he was flying, so... [39:32.990 --> 39:35.000] The sysadmins were surprised. [39:35.300 --> 39:36.420] Oh, just the one thing. [39:36.600 --> 39:42.220] I was called in and I was an expert witness against America Online, if anybody... [39:44.640 --> 39:49.720] Got a question? [39:51.720 --> 39:54.440] So, what happens when you do find something out? [39:56.460 --> 39:57.520] Oh, it turned off. [39:57.720 --> 39:58.280] I'm sorry. [39:58.440 --> 39:58.980] I'm sorry. [39:59.180 --> 40:05.740] I heard this great story during the war, World War II, at Los Alamos. [40:07.600 --> 40:13.280] Feynman got in the habit of, the fellow there, got in the habit of reading when a safe was open. [40:13.380 --> 40:16.280] He could read the last two numbers, the first two numbers of the combination. [40:16.280 --> 40:17.280] Three numbers. [40:17.820 --> 40:25.420] So, any safe, with any information about the atom bomb, he could crack because he just happened to have this absent-minded habit of picking off the first two numbers. [40:26.120 --> 40:29.980] One day he cracks the colonel's safe, and the colonel really wants to know how this happened. [40:30.520 --> 40:33.020] And he tells them, well, you know, this is really interesting. [40:33.220 --> 40:37.640] Any time one of these safes here is open, you can fiddle around with it and get the first two numbers real easy. [40:38.040 --> 40:39.440] You should tell everybody about this. [40:39.520 --> 40:41.460] So the colonel says, yeah, yeah, I see, that's real important. [40:43.020 --> 40:44.980] A month later, he goes back to something like that. [40:44.980 --> 40:48.980] He goes back to the facility, and all the secretaries are very, very nervous. [40:49.100 --> 40:51.340] Tell them, please, please, you, Mr. Feynman, get out of my office. [40:51.500 --> 40:52.240] Get out of my office. [40:52.580 --> 40:59.300] And it turns out the colonel sent a memo around that says not close your safe when you're not using it so that people can't read it. [40:59.480 --> 41:01.620] It says, did Mr. Feynman show up at your office? [41:01.960 --> 41:02.540] Oh, yes. [41:02.540 --> 41:08.020] Well, if he did, they got a message that said change your safe combination and don't let him around. [41:08.280 --> 41:10.360] So what happens when you do find something out? [41:10.560 --> 41:11.400] Do you ever get denial? [41:12.600 --> 41:12.960] Absolutely. [41:14.020 --> 41:22.060] We run into that kind of situation quite often at clients, especially with the security administrators or the sysadmins. [41:22.920 --> 41:25.440] You try and tell them what, you know, this is what we found. [41:25.480 --> 41:37.360] And they're like, okay, then the threat is that anybody like you, so, you know, it's only going to be the ultra-sophisticated attacker that's going to be able to exploit it. [41:37.360 --> 41:39.900] And I always sit down and say, no, that's not true. [41:40.660 --> 41:45.180] Someone of medium sophistication will take, instead of three days, maybe a week. [41:46.080 --> 41:48.820] Somebody with a lower level will take three weeks. [41:48.900 --> 41:51.180] And someone with almost no skills will take six months. [41:51.300 --> 41:53.880] But eventually everybody's going to end up in the same place. [41:53.960 --> 41:55.320] It's just a function of time. [41:56.180 --> 41:57.660] And we try and drill that into their heads. [41:57.660 --> 41:58.800] But, yeah, they deny it, of course. [41:58.920 --> 42:00.600] They say, oh, well, only you could have done that. [42:00.700 --> 42:01.840] And that's not the case. [42:02.020 --> 42:12.200] Well, last one that I worked on, the way in was the, one of my guys just dialed up one of their bay routers and it just offered up a root access prompt. [42:12.200 --> 42:16.380] So, it's like, yeah, you know, we're, we're Uber hackers. [42:16.900 --> 42:18.120] We really got you. [42:18.600 --> 42:22.700] You know, so, yeah, you have to explain it to them sometimes, like... [42:22.700 --> 42:24.020] But that's the people skills again. [42:24.180 --> 42:27.300] I mean, our goal is not to go in there and make anybody feel stupid. [42:27.420 --> 42:35.560] So, it's very important that you have the ability to bring them back around to understand how they configured their system was inappropriate. [42:35.880 --> 42:37.200] So, it's very important people skills. [42:37.480 --> 42:48.240] Yeah, and along those lines, in one case, and I don't know, kind of an example, just like that, I met with the CEO of a company and handed him the manufacturing instructions to a multi-billion dollar product. [42:48.740 --> 42:51.900] And basically said, well, here it is. [42:51.980 --> 42:55.800] And the CEO goes, well, now I have to look at this as a risk situation. [42:55.960 --> 42:59.560] What's the odds that somebody as good as you is going to come in and do this? [43:00.540 --> 43:02.620] And, you know, it's like, well, it took me a day. [43:02.800 --> 43:06.320] And it's like, but the problem is, it's like, I go, now look at it this way. [43:06.400 --> 43:10.640] You've had seven cases of industrial espionage that you've called in the FBI already. [43:10.640 --> 43:13.480] And essentially, you've caught some really stupid people. [43:13.700 --> 43:19.000] Do you think if you have stupid people coming after you, that smart people also want this multi-billion dollar stuff? [43:19.420 --> 43:21.680] He's like, well, maybe I can see your point. [43:21.900 --> 43:23.860] And then we had the FBI give them a briefing. [43:24.300 --> 43:32.200] But, you know, sometimes it takes that level of, you know, most of the time you can point to past incidents where they've caught people because they don't know about the successes. [43:32.960 --> 43:37.760] And I want to say another thing on a recent job. [43:37.840 --> 43:48.660] It was discovered that a software product purchased by a vendor had a code used for the password, which is something that was actually a substitution. [43:48.660 --> 43:50.520] It could be figured out on paper. [43:51.140 --> 44:02.560] This is the type of thing that, without a penetration test, you know, no system administrator is going to say, why don't I try to figure out the password scheme, which is used by this product which we purchased from a vendor. [44:02.560 --> 44:15.480] And it's the type of thing where a system administrator is not going to be, you know, he can tighten his security and he can, you know, insure against outside attacks. [44:15.600 --> 44:23.220] An inside attack, somebody can, you know, examine that and, you know, see... [44:23.960 --> 44:37.400] Yeah, we may come across things where, for example, we're at kind of a standstill in an attack where we're going to look really closely at some particular application or security system, much more closely than anyone would normally do. [44:37.640 --> 44:43.660] And in the course of that, find something interesting out that is of interest both to the client and particularly to the vendors. [44:43.680 --> 44:47.260] So we'll feed that information back in that order, you know, whoever pays us. [44:47.660 --> 44:49.580] Yeah, we can take a couple more questions, I guess. [44:49.580 --> 44:50.520] Yeah, we'll take a few more questions and we've got to wrap it up. [44:50.520 --> 44:51.620] Yeah, we can cut it down. [44:59.600 --> 45:05.060] The question is, were you surprised to read that fiber optic downloaded password files from all over the internet? [45:06.440 --> 45:06.840] Oops. [45:07.560 --> 45:09.620] He didn't download the passwords intentionally. [45:09.860 --> 45:11.880] I happened to be with him at the time when that happened. [45:12.380 --> 45:12.760] You were. [45:13.420 --> 45:13.660] Yeah. [45:13.840 --> 45:19.140] And it was an inadvertent action. [45:19.740 --> 45:25.620] He was basically messing with an NNTP server using a standard exploit that should have been patched a long time ago on the net. [45:25.620 --> 45:35.040] And what happened was the machine that he was doing it on was misconfigured to broadcast everything to all the other NNTP servers in the world. [45:35.200 --> 45:37.460] And some of them started mailing back password files. [45:39.780 --> 45:41.840] So he didn't intentionally do that. [45:42.280 --> 45:47.380] And the thing that the media kind of missed was that he didn't get mailed passwords. [45:47.400 --> 45:49.180] He got mailed encrypted passwords. [45:49.840 --> 45:51.980] And then you have to take it to the next level to crack it. [45:51.980 --> 45:55.120] And if you're not going to crack it, well, then it's quite secure. [45:55.380 --> 45:59.120] If you're going to start cracking the password files, you're going to get a lot of stuff out of it. [45:59.180 --> 45:59.760] But he never did. [45:59.940 --> 46:07.660] He just went, compiled the list, contacted CERT, and said, here's a list of vulnerable sites. [46:08.460 --> 46:17.500] And they thanked him for that information because then they could go out and kind of finish up the last 1,200 or so sites that hadn't patched that particular bug. [46:17.720 --> 46:19.240] It goes back to that CYA. [46:19.240 --> 46:30.280] And just remember, if you're what I would call a security professional without a criminal past, you're going to be given the benefit of the doubt. [46:30.880 --> 46:34.080] FIBRE will not be given the benefit of the doubt in most people's lives. [46:34.240 --> 46:40.300] And just remember that if you happen to show up with a criminal past, you're not going to be given the benefit of many people's doubts. [46:42.200 --> 46:43.640] Yeah, it doesn't matter. [46:44.060 --> 46:50.760] Just remember, there are repercussions for going out and doing illegal hacking or unauthorized hacking and be prepared to pay them. [46:50.920 --> 47:06.020] Right, on a counterpoint to that statement, the fact that you have fiber optic, for example, just take him as an example, carries a lot of weight with people that they say, okay, yeah, he's been, you know, he was a badass out on the net and so forth in various networks, [47:06.160 --> 47:08.200] but at the same time, he definitely knows what he's doing. [47:08.360 --> 47:09.220] There's no question about it. [47:09.220 --> 47:15.320] And, you know, if you bring in, you know, a hacker X or somebody they've never heard of, then you also have the credibility issue. [47:15.700 --> 47:22.640] So, it's a catch-22, but, you know, we always, you're right, we always have to overcome that when it's a celebrity that we bring in and, you know, everybody knows. [47:22.840 --> 47:26.220] Yeah, I just like to say a felony conviction is not a job qualification. [47:27.840 --> 47:28.780] But it doesn't always hurt. [47:28.960 --> 47:30.280] Yeah, sorry, there was a... [47:51.480 --> 47:51.840] Profitable. [47:52.560 --> 47:53.160] No, no. [47:53.700 --> 47:54.060] Sorry. [47:55.540 --> 48:01.940] There's a lot of people in this room who are hackers, who are hacking their own machines, hacking legally. [48:02.460 --> 48:04.820] They're not going out there and breaking into other people's machines. [48:05.000 --> 48:10.540] They're basically examining the technology that they can get their hands on and understanding how it works and then publishing that information. [48:10.760 --> 48:11.720] There's nothing wrong with that. [48:12.340 --> 48:16.480] The people that we're pulling on, that's all that they do these days. [48:16.480 --> 48:22.020] Maybe in the past, some of them may have done certain things, like breaking into other people's systems without their permission. [48:22.600 --> 48:25.060] But the fact of the matter is, is that they don't do that anymore. [48:25.520 --> 48:30.620] And they're doing what I call inner hacking, which is they're just taking the stuff that they own and messing around with it. [48:30.740 --> 48:34.780] I mean, we've got a group of folks here who are basically their own R&D department. [48:34.780 --> 48:37.420] And that helps us out quite a bit. [48:38.200 --> 48:44.520] I would have to say to all the people creating the bad press, if you want to call it that, you know, thank you. [48:44.660 --> 48:47.660] But honestly, I don't need you to create jobs for me. [48:47.880 --> 48:50.740] There are more than enough people that want it without the bad press. [48:50.740 --> 48:54.520] I mean, it makes it an annoyance, like if you're out there breaking into systems. [48:54.780 --> 49:00.100] When I'm out there trying to catch a real criminal, if you want to call it a real criminal, you're just a pain in the ass. [49:00.840 --> 49:02.400] And there's no way around it. [49:02.520 --> 49:07.380] I mean, you know, you're really just a pain in the ass if you're out there breaking into systems. [49:07.980 --> 49:12.720] I mean, because none of you ever decided to email back the administrator, oh, by the way, I broke in using this. [49:12.840 --> 49:19.800] The first place you go are to the bulletin boards to try to prove you're not a loser, which if you have to go to bulletin boards to prove you're not a loser, you are. [49:19.800 --> 49:30.540] But anyway, if you want to do that, you have to go ahead and realize you're giving the information to the criminals, making more criminals breaking back into the system. [49:30.900 --> 49:32.140] And really, you're a pain in the ass. [49:32.240 --> 49:34.840] We should have signed a liability thing before we came up here. [49:35.180 --> 49:38.020] I just want everyone to know that's Winkler with a W. [49:43.960 --> 49:47.200] Okay, we can take one more question and we've got to wrap this up. [49:48.140 --> 49:48.780] Alright. [49:49.380 --> 49:58.700] You're all looking to hire people who are expert level people, obviously, and who have prior experience coming into the game. [49:59.960 --> 50:10.560] And there are obvious reasons, we've already discussed this, why you wouldn't want to be learning in an illegal situation where you're doing illegal hacking. [50:10.560 --> 50:26.980] So, as far as where one goes to pick up all of these skills that are prerequisite for this type of a job, you know, the only thought that popped into my head was, okay, get a job as a sysadmin and do legitimate work and learn in that kind of environment. [50:27.580 --> 50:33.580] But then, you know, the story about, if you know Randall Schwartz, everybody know that story? [50:33.900 --> 50:40.560] Randall Schwartz was a sysadmin who had done... he ran crack on his password files. [50:40.800 --> 50:41.820] He was the sysadmin. [50:42.020 --> 50:44.340] That's a standard thing to do to protect your own systems. [50:45.360 --> 50:49.240] I think it was the talent he was working for, prosecuted him. [50:49.540 --> 50:54.540] Well, there's a little more to the Randall Schwartz story that I prefer not to go into, but it wasn't the... [50:54.540 --> 51:01.440] He didn't crack... he cracked the password files, supposedly, of a unit that he was not working for. [51:03.460 --> 51:06.220] That was... and there was more to it than that, but anyway. [51:06.220 --> 51:14.120] Do you find... so I guess my question is, is there an environment out there in the working world where... [51:14.860 --> 51:22.820] have companies become more accepting of this so that they will let their own people train on the job and better themselves in security measures? [51:23.500 --> 51:29.620] And will they... sysadmins who come on the scene to try these techniques and build their own... [51:29.620 --> 51:29.980] Definitely. [51:30.540 --> 51:32.620] That depends on the company, I should say. [51:32.780 --> 51:40.600] But just in case people think it has to be on the job, has anybody ever heard of, like, downloading Linux for free or FreeBSD or all those other sorts of things? [51:40.600 --> 51:42.360] You can do it at home, but we're seeing a lot of companies. [51:42.520 --> 51:48.320] I mean, every single company that I've seen, when we come in to do these engagements, they're asking us for knowledge transfer. [51:48.560 --> 51:55.180] And then they show up to their little, you know, internal tiger team, which is usually a couple of sysadmins with a clue, or maybe not. [51:55.540 --> 52:00.400] And, you know, they also have their, you know, ISS and Satan, and they're ready to try to... [52:00.400 --> 52:06.280] And they have permission to go out there and, you know, scan their own machines on the network. [52:06.440 --> 52:15.540] So I've yet to see a company that doesn't have some kind of team put together like that these days, this past year or so. [52:17.480 --> 52:18.720] Yeah, I guess we'll wrap it up. [52:18.860 --> 52:19.820] Well, thank you for coming. [52:20.300 --> 52:21.080] Thanks a lot. [53:22.690 --> 53:27.410] We're going to start the private eye panel in just a couple of minutes, so don't stray too far. [53:27.550 --> 53:29.090] This is going to be pretty fascinating stuff. [53:44.230 --> 53:49.950] Hello, whoever owns the handle Princess, I need you to go up to the DJ booth in the network room. [53:49.970 --> 53:51.970] You've got a friend who's puking his guts out. [53:52.290 --> 53:52.970] Thank you.