0:00 Music 0:06 Let's discuss protection from all that stuff. 0:10 Because like I said, there are a big amount of stuff which is possible to discuss. 0:16 They are all very different vectors. 0:20 I don't want to overload you with the stuff. 0:23 I think I already overloaded you with some. 0:26 But the idea here is that 0:29 You should verify. 0:32 If you can verify, verify. 0:35 If you can update software, update it. 0:37 Do not expose information in the internet. 0:41 Do not put all your projects in GitHub. 0:44 Because your keys can be leaked. 0:49 Your data can be leaked. 0:51 Do not put, you know, something that is sensitive in the Internet and make it public. 1:00 Thinking that nobody will find it. 1:02 I will tell you the story about Google Documents. 1:06 Google Documents have very long URL. 1:09 And when you share it with everyone, you expect that nobody will be able to find it. 1:15 But there is crazy stuff about that thing. 1:19 So Google made a very serious mistake. 1:24 They created ability for guys to shorten 1:31 Google documents link. 1:33 So they created the Google, something like this domain. 1:42 And after it was like something like this. 1:46 So you could short your document with such a link. 1:53 And some crazy guys, they spent half of their life to brute force all that stuff and to extract all the information from those documents. 2:05 And they even created a community who were brute forcing short links. 2:10 And they would force all the short links. 2:14 Short. 2:16 Short links, brute force. 2:19 So you should understand that sometimes you don't even expect that such type of attack would exist. 2:26 You just shorten the link, you send it, and it was brute force. 2:31 Brute forcing or real short links. 2:37 Let me show you. 2:40 Wikipedia, there is URL. 2:46 URL link. 2:48 This is the official website of those guys who start to do that stuff. 2:56 So continue to the website. 3:00 Continue. 3:02 So think about amount of time those guys spend. 3:07 They connected big amount of people to brute force, shortened URLs to exfiltrate data. 3:14 And this is amount which they brute force for, for example, Microsoft AKMS. 3:21 So, or whatever, just bit.lo, bit.lo, right? 3:29 I think, where is it? 3:32 Bit.lo, bit.do. 3:35 So every time you show the URL, you see bit.do. 3:41 Short code, alphabet set. 3:44 And basically you can just download this stuff and try to find your company name. 3:51 So some guys already did it and I will show you. 3:57 Gray Cloud Brood. 4:05 Gray. 4:08 Gray Cloud Brood. 4:12 I have a separate, you know, slides about that stuff, but I just wanted to cover it real quick. 4:18 Crown, boot, links, stream, buckets. 4:24 This one. 4:26 So those guys, they are not only brute force. 4:30 the shortened links. 4:31 They also brute force the cloud providers. 4:34 So let's input the company name. 4:39 Let's put maybe judges, for example. 4:45 So, Jaja is not found. 4:47 Yeah, obviously. 4:49 Let's put maybe Uber. 4:52 So this is amount of exposed information in the cloud for Uber. 4:59 So when you just go here, 5:04 You can see, I don't know, if we want, maybe like PDF only. 5:16 I'm not sure why it's not like sorting by PDF. 5:18 Okay, you need to register. 5:20 But the idea here is that it is analyzing the S3 buckets and based on those S3 buckets, it is trying to extract. 5:29 Look, this is open S3 bucket. 5:31 This is example of open. 5:35 Digital Ocean. 5:36 This is Open Digital Ocean hosting. 5:39 And look, what is open? 5:41 If I will copy it, I will just put it here. 5:47 I misspelled it. 5:51 It can be password. 5:53 It can be anything. 5:55 So you got the point that 5:58 Guys are bootforcing the S3 buckets, bootforcing the DigitalOcean, bootforcing the Google, bootforcing blobs for Microsoft. 6:08 They are bootforcing their shortened URLs. 6:11 You see shorteners. 6:13 And let's put like Uber, for example. 6:18 And see. 6:19 This short URL is partnersuber.com. 6:26 So let's see, for example, what can we find? 6:31 So this one is some links for the internal partners for Uber. 6:37 Like an example. 6:40 I can see some pages. 6:42 Maybe I will be able to find, you know, some documents. 6:49 So maybe I will put docs.google.com. 6:56 Maybe I want to read somebody's docs. 7:02 Yeah, let's just read docs of some people. 7:06 Maybe if I put the company name, I will be able to do it. 7:12 Let's see. 7:13 Some are open or everything is closed. 7:15 Yeah. 7:17 Yeah, this guy has no idea, right? 7:20 That his stuff was exposed. 7:22 He's like selling some stuff and he shortened URL. 7:26 So you got the point that if attacker will want, he will collect a lot of information from cloud, from shorteners, from whatever he wants. 7:41 So, yeah. 7:44 Something like this. 7:44 So, protection again. 7:47 Do not expose. 7:48 Update software. 7:50 If something is going on, you don't know how to handle it, ask for help. 7:54 Always be careful. 7:55 Stay informed. 7:56 And try to know about types of attacks.
0:00 Music 0:06 Let's discuss protection from all that stuff. 0:10 Because like I said, there are a big amount of stuff which is possible to discuss. 0:16 They are all very different vectors. 0:20 I don't want to overload you with the stuff. 0:23 I think I already overloaded you with some. 0:26 But the idea here is that 0:29 You should verify. 0:32 If you can verify, verify. 0:35 If you can update software, update it. 0:37 Do not expose information in the internet. 0:41 Do not put all your projects in GitHub. 0:44 Because your keys can be leaked. 0:49 Your data can be leaked. 0:51 Do not put, you know, something that is sensitive in the Internet and make it public. 1:00 Thinking that nobody will find it. 1:02 I will tell you the story about Google Documents. 1:06 Google Documents have very long URL. 1:09 And when you share it with everyone, you expect that nobody will be able to find it. 1:15 But there is crazy stuff about that thing. 1:19 So Google made a very serious mistake. 1:24 They created ability for guys to shorten 1:31 Google documents link. 1:33 So they created the Google, something like this domain. 1:42 And after it was like something like this. 1:46 So you could short your document with such a link. 1:53 And some crazy guys, they spent half of their life to brute force all that stuff and to extract all the information from those documents. 2:05 And they even created a community who were brute forcing short links. 2:10 And they would force all the short links. 2:14 Short. 2:16 Short links, brute force. 2:19 So you should understand that sometimes you don't even expect that such type of attack would exist. 2:26 You just shorten the link, you send it, and it was brute force. 2:31 Brute forcing or real short links. 2:37 Let me show you. 2:40 Wikipedia, there is URL. 2:46 URL link. 2:48 This is the official website of those guys who start to do that stuff. 2:56 So continue to the website. 3:00 Continue. 3:02 So think about amount of time those guys spend. 3:07 They connected big amount of people to brute force, shortened URLs to exfiltrate data. 3:14 And this is amount which they brute force for, for example, Microsoft AKMS. 3:21 So, or whatever, just bit.lo, bit.lo, right? 3:29 I think, where is it? 3:32 Bit.lo, bit.do. 3:35 So every time you show the URL, you see bit.do. 3:41 Short code, alphabet set. 3:44 And basically you can just download this stuff and try to find your company name. 3:51 So some guys already did it and I will show you. 3:57 Gray Cloud Brood. 4:05 Gray. 4:08 Gray Cloud Brood. 4:12 I have a separate, you know, slides about that stuff, but I just wanted to cover it real quick. 4:18 Crown, boot, links, stream, buckets. 4:24 This one. 4:26 So those guys, they are not only brute force. 4:30 the shortened links. 4:31 They also brute force the cloud providers. 4:34 So let's input the company name. 4:39 Let's put maybe judges, for example. 4:45 So, Jaja is not found. 4:47 Yeah, obviously. 4:49 Let's put maybe Uber. 4:52 So this is amount of exposed information in the cloud for Uber. 4:59 So when you just go here, 5:04 You can see, I don't know, if we want, maybe like PDF only. 5:16 I'm not sure why it's not like sorting by PDF. 5:18 Okay, you need to register. 5:20 But the idea here is that it is analyzing the S3 buckets and based on those S3 buckets, it is trying to extract. 5:29 Look, this is open S3 bucket. 5:31 This is example of open. 5:35 Digital Ocean. 5:36 This is Open Digital Ocean hosting. 5:39 And look, what is open? 5:41 If I will copy it, I will just put it here. 5:47 I misspelled it. 5:51 It can be password. 5:53 It can be anything. 5:55 So you got the point that 5:58 Guys are bootforcing the S3 buckets, bootforcing the DigitalOcean, bootforcing the Google, bootforcing blobs for Microsoft. 6:08 They are bootforcing their shortened URLs. 6:11 You see shorteners. 6:13 And let's put like Uber, for example. 6:18 And see. 6:19 This short URL is partnersuber.com. 6:26 So let's see, for example, what can we find? 6:31 So this one is some links for the internal partners for Uber. 6:37 Like an example. 6:40 I can see some pages. 6:42 Maybe I will be able to find, you know, some documents. 6:49 So maybe I will put docs.google.com. 6:56 Maybe I want to read somebody's docs. 7:02 Yeah, let's just read docs of some people. 7:06 Maybe if I put the company name, I will be able to do it. 7:12 Let's see. 7:13 Some are open or everything is closed. 7:15 Yeah. 7:17 Yeah, this guy has no idea, right? 7:20 That his stuff was exposed. 7:22 He's like selling some stuff and he shortened URL. 7:26 So you got the point that if attacker will want, he will collect a lot of information from cloud, from shorteners, from whatever he wants. 7:41 So, yeah. 7:44 Something like this. 7:44 So, protection again. 7:47 Do not expose. 7:48 Update software. 7:50 If something is going on, you don't know how to handle it, ask for help. 7:54 Always be careful. 7:55 Stay informed. 7:56 And try to know about types of attacks.