SharePoint Security
Advanced SharePoint Security Tips and Tools
22 Feb 2012 – OWASP L.A. 2012 – Los Angeles, CA
Presen sented ed b by: Francis Brown Stach & Liu, LLC www.stachliu.com
SharePoint Security Advanced SharePoint Security Tips and Tools 22 - - PowerPoint PPT Presentation
SharePoint Security Advanced SharePoint Security Tips and Tools 22 Feb 2012 OWASP L.A. 2012 Los Angeles, CA Presen sented ed b by: Francis Brown Stach & Liu, LLC www.stachliu.com Agenda O V E R V I E W Br Brief ef Int
Advanced SharePoint Security Tips and Tools
22 Feb 2012 – OWASP L.A. 2012 – Los Angeles, CA
Presen sented ed b by: Francis Brown Stach & Liu, LLC www.stachliu.com
2
Brief ef Int Intro t to S Shar harePoint
int S t Security ity
O V E R V I E W
3
G E T T I N G U P T O S P E E D
4
MS SharePoint Products & Technologies
Wind ndows S s Shar harePoint Services ( es (WSS) )
e ShareP ePoint nt S Server er 2007/2010 ( 7/2010 (MOSS)
ePoint nt D Designer ner 2007/2010 ( 7/2010 (SPD)
5
MS SharePoint Products & Technologies
6
MS SharePoint Products & Technologies
7
MS SharePoint Products & Technologies
8
MS SharePoint Products & Technologies
9
Intro to SharePoint
10
Intro to SharePoint
Base Base Site UR URLs: s:
11
Intro to SharePoint
12
Intro to SharePoint
13
W H A T Y O U S H O U L D K N O W
R I S K O F E X P O S U R E
14
15
S H A R E P O I N T S E C U R I T Y
# Security Tip 1 Know your external exposure… 2 Beware of normal users with excessive access… 3 Spot check user permissions and inheritance… 4 Beware 3rd party plugins/code…BUT not too much… 5 Backup every which way from Sunday… …
16
K N O W Y O U R E X T E R N A L E X P O S U R E
F I N D I N G H O L E S
17
1. 1. “Googl gle H Hack ck y yourse self”
3.
EW: SharePoint Google Regexs for S&L SearchDiggity – 121 queries
2. 2. Sha SharePoint nt U URL B Brut ute-forcing
2.
EW: Tool to bruteforce SharePoint URLs – 101 known extensions
3. 3. Nmap ap for r other r Share rePoint a administrat rative a apps ps
S H A R E P O I N T A D M I N W E B A P P S
18
G O O G L E H A C K I N G S H A R E P O I N T
19
G O O G L E H A C K I N G S H A R E P O I N T
20
G O O G L E H A C K I N G S H A R E P O I N T
21
B I N G H A C K I N G S H A R E P O I N T
22
S H O D A N F O R S H A R E P O I N T
23
S H A R E P O I N T H A C K I N G A L E R T S
24
S H A R E P O I N T H A C K I N G T O O L S
25
S H A R E P O I N T U R L B R U T E F O R C I N G
26
27
B E W A R E U S E R S W I T H E X C E S S I V E A C C E S S
M O R E T H A N Y O U B A R G A I N E D F O R . . .
28
es exampl mples es
Admini nist strat ation n exampl mples es
C O N T I N U E D S H A R E P O I N T H A C K I N G
29
S H A R E P O I N T W E B S E R V I C E S
30
31
C H E C K P E R M I S S I O N S A N D I N H E R I T A N C E
32
S E C U R I T Y T I P S
33
S E C U R I T Y T I P S
34
S E C U R I T Y T I P S
35
U S E R P E R M I S S I O N S
36
U S E R P E R M I S S I O N S
37
U S E R P E R M I S S I O N S
38
U S E R P E R M I S S I O N S
39
U S E R P E R M I S S I O N S
40
B E W A R E 3RD P A R T Y C O D E… N O T T O O M U C H
N E C E S S A R Y E V I L
41
like an iPhone with no apps
e Sha hareP ePoint nt d dep eployment ents
R O G U E D E P L O Y M E N T S
42
Quest Software - Server Administrator for SharePoint
R O G U E D E P L O Y M E N T S
43
McAfee - Network Discovery for Microsoft SharePoint
S O L U T I O N S
44
S O L U T I O N S
45
F E A T U R E S
46
F E A T U R E S
47
F U T U R E S E C U R I T Y
48
S A N D B O X E D S O L U T I O N S
49
50
B A C K U P E V E R Y W H I C H W A Y F R O M S U N D A Y
M A N Y M E T H O D S … M O S T T E R R I B L E
51
1. Microsoft System Center: Data Protection Manager 2. Windows 2003/2008 Server backups 3. Stsadm.exe cmdline tool backups 4. Central Administration v3 backups 5. SharePoint Designer backups 6. Site and List template backups 7. Raw MS SQL database backups
S H A R E P O I N T D E S I G N E R
52
S T S A D M / C E N T R A L A D M I N I S T R A T I O N
53
S I T E A N D L I S T T E M P L A T E S
54
S I T E A N D L I S T T E M P L A T E S
55
R A W S Q L D A T A B A S E S
56
For
mor
e info:
Email: contact@stachliu.com Project: diggity@stachliu.com Stach & Liu, LLC www.stachliu.com
58
Stach ach & & Li Liu S Shar arePoint Hack acking g Diggi ggity Pr Proj
info:
http://www.stachliu.com/index.php/resources/tools/sharepoint-hacking-diggity-project/