36
Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Embed Size (px)

Citation preview

Page 1: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Escalating Privilege Through Better CommunicationWHY STOP AT DOMAIN ADMIN?

@BEAUWOODS

Page 2: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Agenda

0 The Situation: Why we need to be better

1 The Problem

2 What Works

3 Hands On Hacking

Page 3: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

0 The Situation: Why we need to be better

Page 4: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS
Page 5: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

1 The Problem

Page 6: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Why won’t [THEY] do the [RIGHT]™ thing?

I’m sure that [THEY] Don’t get it Hate me Are evil

For varying values of [THEY] including Manufacturers Vendors Software and hardware makers Bosses

Page 7: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Why won’t [THEY] do the [RIGHT]™ thing?

I’m sure that [THEY] Don’t get it Hate me Are evil

For varying values of [RIGHT]™ including things That are expensive I can’t present/explain well I don’t understand well Affect operations or strategy Require conceptual shifts

Page 8: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

1 What Works

Page 9: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Kill Chain

Hacking: The process we know well

1 Reconnaissance and Network Mapping

2 Vulnerability Discovery

3 Exploitation

4 Persistence

Stakeholder

Enabling Change

Of Influence

Empathy and Understanding

Page 10: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

1 What Works

Reconnaissance and Stakeholder Mapping

Page 11: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Official Structure

CEO

CFO COO CMO CIO CxO

Admin

Chain of Command Committees Budget Approvals

Page 12: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Unofficial Structure

Who is liked…or not? Trusted Advisors/Influencers Who drinks together?

Page 13: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Exercise:One does not simply WALK into the executive boardroom

Page 14: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

External Stakeholders

What external stakeholders may exist for a medical device manufacturer?

Page 15: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

1 What Works

Empathy and Understanding

Page 16: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Factual Background

Work history – industries, roles, etc. Education Passions and hobbies

Page 17: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Motivation

Role models Bonus structure Career ambitions Challenges and priorities

Page 18: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Hopes, Dreams, and Aspirations (and Fears)

What keeps them up at night? What would make them a hero? What triggers fear vs. hope? Why do they do what they do

on a human scale?

Page 19: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Executive Time Budget

Financials

New Ventures

Lunch

IT

HR

Infosec

Physical Security

Lolcats

Regulations Financials Competitors Breaches

…get their attention.

Page 20: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Operational Workflow

Business Intelligence Decisioning

Priorities

DirectionMission

Research

Data

Frame-work

Action

Data Collection

Page 21: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Disciplinary Literacy

1 year 5 years 10 years

Functional Conversant Literate

Page 22: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Functional Illeteracy

Page 23: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Medical Jargon

A 6 French by 26 cm right double-J ureteral stent

was passed over the glidewire, and the glidewire

was removed. A curl was seen in the upper pole

of the right kidney under fluoroscopic vision and a

curl was seen in the bladder under cystoscopic

vision.

Page 24: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Medical Jargon

A 6 French by 26 cm right double-J ureteral

stent was passed over the glidewire, and the

glidewire was removed. A curl was seen in the

upper pole of the right kidney under

fluoroscopic vision and a curl was seen in the

bladder under cystoscopic vision.

Page 25: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Medical Jargon

A blah blah by blah blah blah blah blah blah

was blah blah the blah, and the blah

was removed. A blah was seen in the blah blah

of the right kidney under blah blah and a

blah was seen in the blah under blah

blah.

Page 26: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Interactive Example

The cross domain issue comes in when there is a form that

accepts POST methods only. You can create a page that has

a form that submits to the remote website via POST through

a JavaScript click event. If it’s protected by a nonce that

vulnerability goes away, but most websites aren’t protected

by CSRF in this way.

Page 27: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

1 What Works

Enabling Change

Page 28: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Work the system

Up, down, and sideways Adaptation Persistence Riding waves and news

Page 29: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

In the terms, and at the level of the audience

Features versus benefits (values and objectives)

Speaking their language Incorporating their ideas

Page 30: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Making action easy

Be two steps ahead Do their work Pilots and proofs of concept

Page 31: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Recap

1 RECONNAISSANCE AND

STAKEHOLDER MAPPING

2 EMPATHY AND

UNDERSTANDING

3 ENABLING CHANGE

4 PERSISTENCE

Page 32: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Example Scenario

Page 33: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Practicing enabling change

What considerations should we think about?What questions might which stakeholders ask?Who might engage with which external

stakeholders?What relationships might make influence

easier or harder?Who are the critical decision-makers?

Page 34: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Practicing enabling change

What strategies and tactics will make this easy?What motivates each stakeholder?Who needs to feel “ownership”?What makes the stakeholder look like a hero?How to avoid making any villains?

Page 35: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Practicing enabling change

Convince the decision-maker of your idea.Clear, concise, impactfulAddress each stakeholder’s fears/goalsBottom Line Up Front (BLUF)

Page 36: Escalating Privilege Through Better Communication WHY STOP AT DOMAIN ADMIN? @BEAUWOODS

Escalating Privilege Through Better CommunicationWHY STOP AT DOMAIN ADMIN?

@BEAUWOODS