Enterprise Ethical Hacking Cloud Applications

Tuesday, 3:15 PM EST - SAND DOLLAR

Securing of the web application is an enormous task. In this talk, we will explore how to protect enterprise applications. We will explore different kinds of vulnerabilities and hot to secure your applications properly. Security patterns need to be understood by first wearing the hat of a hacker and then putting the hat as a defender. In this workshop, we will explore different security patterns and determine how to prevent attacks.

We will be using Kali Linux to understand Ethical hacking techniques using Metasploitable applications. In the end, we will see how OpenVas can help in scanning the vulnerabilities in the application.

In this workshop we will explore following:

  • Threat Modeling techniques using Threat modeling tool
  • Reconnaissance to gather information, Google hacking database, Exploit Database
  • Scanning for vulnerabilities using Burp Proxy, FoxyProxy, SSL Scan, OWASP ZAP
  • Exploitation with DOS attacks
  • Risk Analysis

Workshop Requirements

This session is a workshop. Please come prepared.

Install Microsoft
Microsoft threat modeling tool
https://www.microsoft.com/en-us/sdl/adopt/threatmodeling.aspx
https://www.microsoft.com/en-us/download/details.aspx?id=49168

Install Kali Linux
http://docs.kali.org/general-use/kali-linux-virtual-box-guest
To reset install from terminal:
apt-get update
apt-get upgrade -y
apt-get dis-upgrade -y
reboot

Install Metasploitable
https://sourceforge.net/projects/metasploitable/
Installing on virtual box:
http://www.hacking-tutorial.com/tips-and-trick/install-metasploitable-on-virtual-box/#sthash.Tdh0WG8j.dpbs

Install openvas vulnerability scanning tool
https://www.kali.org/penetration-testing/openvas-vulnerability-scanning/

Useful apts to download from terminal:apt-get install preload
apt-get install bleachbit
apt-get install bum
apt-get install gnome-do
apt-get install apt-file
apt-get install scrub
apt-get install shutter
apt-get install figlet
apt-get install metagoofil
apt-get install whois
apt-get install dmitry
apt-get install recon-ng
apt-get install theharvester
apt-get install httrack

Get the exercises from here:
http://tinyurl.com/huusd4d

About Rohit Bhardwaj

Rohit Bhardwaj

Rohit Bhardwaj is a Director of Architecture working at Salesforce. Rohit has extensive experience architecting multi-tenant cloud-native solutions in Resilient Microservices Service-Oriented architectures using AWS Stack. In addition, Rohit has a proven ability in designing solutions and executing and delivering transformational programs that reduce costs and increase efficiencies.

As a trusted advisor, leader, and collaborator, Rohit applies problem resolution, analytical, and operational skills to all initiatives and develops strategic requirements and solution analysis through all stages of the project life cycle and product readiness to execution.
Rohit excels in designing scalable cloud microservice architectures using Spring Boot and Netflix OSS technologies using AWS and Google clouds. As a Security Ninja, Rohit looks for ways to resolve application security vulnerabilities using ethical hacking and threat modeling. Rohit is excited about architecting cloud technologies using Dockers, REDIS, NGINX, RightScale, RabbitMQ, Apigee, Azul Zing, Actuate BIRT reporting, Chef, Splunk, Rest-Assured, SoapUI, Dynatrace, and EnterpriseDB. In addition, Rohit has developed lambda architecture solutions using Apache Spark, Cassandra, and Camel for real-time analytics and integration projects.

Rohit has done MBA from Babson College in Corporate Entrepreneurship, Masters in Computer Science from Boston University and Harvard University. Rohit is a regular speaker at No Fluff Just Stuff, UberConf, RichWeb, GIDS, and other international conferences.

Rohit loves to connect on http://www.productivecloudinnovation.com.
http://linkedin.com/in/rohit-bhardwaj-cloud or using Twitter at rbhardwaj1.

More About Rohit »