Tunnel Vision: Exploring VPN Post-Exploitation Techniques - Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
Estás en »Webinars
Estás en »Webinars
Jueves 26 de Set, 2024
We have all heard this story before - a critical vulnerability is discovered in a VPN server. It's exploited in the wild. Administrators rush to patch. Panic spreads across Twitter. Attackers have long sought to exploit VPN servers - they are accessible from the internet, expose a rich attack surface, and often lack in security and monitoring. Historically, VPNs were primarily abused to achieve a single objective: gaining entry into internal victim networks. While this is evidently very valuable, control over a VPN server shouldn't solely be seen as a gateway to the network, and can certainly be abused in various other ways. In this talk, we will explore VPN post-exploitation - a new approach that consists of different techniques attackers can employ on the compromised VPN server to further progress their intrusion. To demonstrate this concept, we will inspect two of the most common VPN servers on the market - Ivanti Connect Secure and Fortigate, and show how an attacker with control over them can collect user credentials, move laterally, and maintain persistent access to the network. We will conclude by detailing best practices and principles that should be followed by security teams when using VPN servers to reduce the risk from post-exploitation techniques. During the session, you will: - Explore critical vulnerabilities and real-world exploits on popular VPN platforms. - Discover post-exploitation tactics for credential collection, lateral movement, and persistent access. - Learn best practices to enhance VPN security and reduce advanced threat risks.
04:30 - 05:00 hs GMT+1
05:00 - 06:00 hs GMT+1
12:30 - 13:00 hs GMT+1
05:00 - 06:00 hs GMT+1
17:00 - 18:00 hs GMT+1
00:00 - 01:00 hs GMT+1
14:00 - 15:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
07:00 - 08:00 hs GMT+1
01:00 - 02:00 hs GMT+1
03:00 - 04:00 hs GMT+1
09:00 - 10:00 hs GMT+1
10:00 - 11:00 hs GMT+1
00:00 - 01:00 hs GMT+1
05:00 - 06:00 hs GMT+1
01:00 - 02:00 hs GMT+1
10:00 - 11:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
05:30 - 06:00 hs GMT+1
05:00 - 06:00 hs GMT+1
09:00 - 10:00 hs GMT+1
00:00 - 01:00 hs GMT+1
10:00 - 11:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
00:00 - 01:00 hs GMT+1
01:00 - 02:00 hs GMT+1
11:00 - 12:00 hs GMT+1
16:00 - 17:00 hs GMT+1
00:00 - 01:00 hs GMT+1
05:00 - 06:00 hs GMT+1
01:00 - 02:00 hs GMT+1
07:00 - 08:00 hs GMT+1
01:00 - 02:00 hs GMT+1
01:00 - 02:00 hs GMT+1
04:30 - 05:00 hs GMT+1
05:00 - 06:00 hs GMT+1
12:30 - 13:00 hs GMT+1
05:00 - 06:00 hs GMT+1
17:00 - 18:00 hs GMT+1
La Autoridad Portuaria de la Bahía de Algeciras (APBA) ha instalado cámaras térmicas en las zonas de mayor tránsito de pasajeros del puerto para controlar la temperatura corporal de los pasajeros sin necesidad de pararles. ... Leer más ►
Publicado el 2-Jul-2020 • 14.23hs
Publicado el 25-Ene-2017 • 19.27hs
Publicado el 20-Ene-2017 • 13.11hs
Publicamos grabación de webinar que tuvo lugar el pasado 28/03/2019 por el CIO del Grupo de Medios de Comunicación español Vocento Jorge Oteo en el que explica su visión de la Ciberseguridad hoy. ... Leer más ►
Publicado el 29-Mar-2019 • 10.12hs
Publicado el 20-Jun-2018 • 11.21hs
Publicado el 31-May-2018 • 10.21hs
... Leer más ►
Publicado el 23-Jun-2020 • 16.05hs
Publicado el 26-Set-2019 • 10.36hs
Publicado el 26-Mar-2019 • 12.09hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs