Mike - Use Their Machines Against Them: Loading Code with a Copier episode artwork

EPISODE · Sep 26, 2016

Mike - Use Their Machines Against Them: Loading Code with a Copier

from DEF CON 24 [Audio] Speeches from the Hacker Convention · host DEF CON Announcements

Materials: https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Extras https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Use-Their-Machines-Against-Them-WP.pdf https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Use-Their-Machines-Against-Them.pdf Use Their Machines Against Them: Loading Code with a Copier Mike Principal Cyber Security Engineer, The MITRE Corporation We've all worked on ‘closed systems’ with little to no direct Internet access. And we've all struggled with the limitations those systems put on us in the form of available tools or software we want to use. I didn't like struggling, so I came up with a method to load whatever I wanted on to a closed system without triggering any common security alerts. To do this I had to avoid accessing the Internet or using mag media. In the end all I needed was an office multi-function machine and Excel. It's all any insider needs. 

For my presentation and demo, I'll show you how I delivered a select group of PowerSploit tools to a clean, isolated machine. Of course, Excel has been known as vector for macro viruses for quite some time and some of the techniques--such as hex-encoding binary data and re-encoding it on a target machine--are known binary insertion vectors but I have not found any prior work on an insider using these techniques to deliver payloads to closed systems. You'll leave my presentation knowing why Excel, umm, excels as an insider attack tool, how to leverage Excel features to load and extract arbitrary binary data from a closed network, and what to do if this really frightens you. Mike has over 20 years experience in the military. He has been part of everything from systems acquisition, to tactical intelligence collection, to staff work, to leading a unit dedicated to data loss prevention. He recently retired from active military service and is now working as a systems security engineer. This is Mike's first security conference presentation and will also be the first public release of a tool he has written. Mike has previously published twice in 2600 magazine. Mike is super proud of his OSCP certification. He's also a CISSP.

Twitter: @miketofet

Episode metadata supplied by the publisher feed · Published Sep 26, 2016

Materials: https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Extras https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Use-Their-Machines-Against-Them-WP.pdf https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Use-Their-Machines-Against-Them.pdf Use Their Machines Against Them: Loading Code with a Copier Mike Principal Cyber Security Engineer, The MITRE Corporation We’ve all worked on ‘closed systems’ with little to no direct Internet access. And we’ve all struggled with the limitations those systems put on us in the form of available tools or software we want to use. I didn’t like struggling, so I came up with a method to load whatever I wanted on to a closed system without triggering any common security alerts. To do this I had to avoid accessing the Internet or using mag media. In the end all I needed was an office multi-function machine and Excel. It’s all any insider needs. For my presentation and demo, I’ll show you how I delivered a select group of PowerSploit tools to a clean, isolated machine. Of course, Excel has been known as vector for macro viruses for quite some time and some of the techniques—such as hex-encoding binary data and re-encoding it on a target machine—are known binary insertion vectors but I have not found any prior work on an insider using these techniques to deliver payloads to closed systems. You’ll leave my presentation knowing why Excel, umm, excels as an insider attack tool, how to leverage Excel features to load and extract arbitrary binary data from a closed network, and what to do if this really frightens you. Mike has over 20 years experience in the military. He has been part of everything from systems acquisition, to tactical intelligence collection, to staff work, to leading a unit dedicated to data loss prevention. He recently retired from active military service and is now working as a systems security engineer. This is Mike’s first security conference presentation and will also be the first public release of a tool he has written. Mike has previously published twice in 2600 magazine. Mike is super proud of his OSCP certification. He’s also a CISSP. Twitter: @miketofet

PodParley-generated summary based on available episode metadata and transcript content.

NOW PLAYING

Mike - Use Their Machines Against Them: Loading Code with a Copier

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of DEF CON 24 [Audio] Speeches from the Hacker Convention?

Episode duration information is not available.

When was this DEF CON 24 [Audio] Speeches from the Hacker Convention episode published?

This episode was published on September 26, 2016.

What is this episode about?

Materials: https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Extras https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Mike-Rich-Use-Their-Machines-Against-Them-WP.pdf https://media.defcon.org/DEF...

Can I download this DEF CON 24 [Audio] Speeches from the Hacker Convention episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!