The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and...

47
www.cloudsec.com | #CLOUDSEC The State of Web Defacements and Hacktivism Ryan Flores

Transcript of The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and...

Page 1: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

www.cloudsec.com | #CLOUDSEC

The State of Web Defacements and Hacktivism

Ryan Flores

Page 2: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

whoami

Page 3: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 4: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 5: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 6: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 7: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 8: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 9: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Cybercrime

• Actors: cybercriminals – traditional criminals

• Motivation: $$$

• Timeframe: immediate – several months

• Impact: financial loss, brand damage

• Targeting: opportunistic to targeted

Page 10: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 11: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 12: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 13: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 14: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Targeted Attack

• Actors: state sponsored

• Motivation:

• Timeframe: several months - years

• Impact: leverage, opportunity

• Targeting: highly targeted

Page 15: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Hacktivism

Page 16: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 17: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 18: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 19: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 20: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 21: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 22: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 23: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 24: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Arab Spring

0

200

400

600

800

1000

1200

1400

1600

1800

2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016

Page 25: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 26: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Anonymous and Lulzsec

0

50

100

150

200

250

300

350

400

450

1998 2000 2002 2004 2006 2008 2010 2012 2014 2016

Page 27: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

Defacement pages are

getting… boring

Page 28: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 29: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 30: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 31: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

Defacers can instantly turn

into Hacktivists

Page 32: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 33: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 34: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 35: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 36: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 37: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 38: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

Local Defacements and Issues

Page 39: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 40: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 41: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 42: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 43: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 44: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Page 45: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Summary

• Hackers operate in groups, by campaigns

• Grouped by country

• Real life events influence hacker motivation, driven by

• Patriotism

• Socio-political

• Opportunistic

• Uses known vulnerabilities

• Scans for vulnerable websites

Page 46: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

#CLOUDSEC

Summary

• Soft Targeting

• Targets by TLD and IP space

• Risk of Data Leakage

Page 47: The State of Web Defacements and Hacktivism · 2018-03-19 · The State of Web Defacements and Hacktivism Ryan Flores . #CLOUDSEC whoami . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC . #CLOUDSEC

Ryan Flores Forward Looking Threat

Research Team

Trend Micro [email protected]