A perspective to incident response
- r another set of recommendations for malware authors
A perspective to incident response or another set of recommendations - - PowerPoint PPT Presentation
A perspective to incident response or another set of recommendations for malware authors Alexandre Dulaunoy - TLP:WHITE alexandre.dulaunoy@circl.lu June 7, 2013 CIRCL, national CERT of Luxembourg CIRCL 1 is composed of 6 full-time incident
1http://www.circl.lu/ 2http://www.smile.public.lu/ 2 of 21
3 of 21
3Don’t worry security software can also fall into this category. 4or a trend for a security researcher 4 of 21
5 of 21
6 of 21
5http://www.circl.lu/pub/tr-13/ 7 of 21
6Assuming X.509 revocation process is properly working at your target 8 of 21
9 of 21
7Not only DigiNotar if you look at the reason of revocation in the CRLs, CA compromise is not uncommon. 10 of 21
11 of 21
8http://www.circl.lu/pub/tr-12/ 12 of 21
13 of 21
90x35e1066ccd15873eeef8518966b70f8b first 16 bytes - with default admin password 14 of 21
15 of 21
16 of 21
10http://www.circl.lu/pub/tr-14/ 17 of 21
11http://www.circl.lu/pub/tr-13/ 18 of 21
19 of 21
12urlhttp://www.slideshare.net/grugq/opsec-for-hackers 20 of 21
21 of 21