欢迎来到天天文库
浏览记录
ID:39713970
大小:679.82 KB
页数:43页
时间:2019-07-09
《A peek under the Blue Coat》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、ApeekundertheBlueCoatProxySGinternalsRaphaëlRigo/AGI/TX5ITBlackHatEurope-2015-11-12ApeekundertheBlueCoatOutline1Introduction2Storage:filesystemsandregistry3Binaries4KernelandOSmechanisms5Understandinginternals6Securitymechanisms7ConclusionBlackHatEurope-2015-11-122ApeekundertheB
2、lueCoatOutline1Introduction2Storage:filesystemsandregistry3Binaries4KernelandOSmechanisms5Understandinginternals6Securitymechanisms7ConclusionBlackHatEurope-2015-11-123ApeekundertheBlueCoatWhat?Why?BlueCoatProxySG?enterprise(Web)proxyoneofthemostdeployedinbigcompanieslotsofcompl
3、exfeatures:URLcategorization(WebSenseandothers)videostreaming/instantmessagingspecifichandlingMAPIandSMBproxy/cache/prefetcheretc.runsproprietarySGOSWhyresearchProxySG?widelyusedinAirbusGroupinterestingtargetformaliciousactors:logbypass,Internetexposed,MITM,etc.noknownpreviousre
4、search:unknownsecuritylevelsecuritybulletins:mostlyOpenSSLandWebadministrationinterfacebugsBlackHatEurope-2015-11-124ApeekundertheBlueCoatResearchStudyobjectives:assesstheglobalsecuritylevelwriterecommendationsforsecuredeploymentbepreparedforforensicsincaseofacompromisedProxySG
5、Whypublish?firstpublicinfobutsurelynotfirstresearchfosterresearch=)bettersecurityToday’spresentation:rawtechnicalresults,asastartingpointforresearchgoesfromlowlevel(FS)tohighlevel,followingourapproachappliestoallProxySGmodelsand6.xversionsuptoQ12015BlackHatEurope-2015-11-125Apeek
6、undertheBlueCoatGettingstartedRunningProxySG:hardware:commodityx86CPUs,HDD,etc.VMwareappliancesCommonversions:5.5:olderversion,EOLAug20146.2:previouslongtermrelease,EOLOct20156.5:latestlongtermrelease,recommendedbyBCTogetafirstlook,weneedtoaccessthefilesystem:6.?(6.4):smallFAT32
7、partitioncontainingproprietaryBCFSimageolderversions:fullyproprietarydiskpartitionning/data(noFAT32)BlackHatEurope-2015-11-126ApeekundertheBlueCoatOutline1Introduction2Storage:filesystemsandregistry3Binaries4KernelandOSmechanisms5Understandinginternals6Securitymechanisms7Conclus
8、ionBlackHatEurope-2015-11-127ApeekundertheBlueCoatOndi
此文档下载收益归作者所有