3. Hacking og pentesting + DDoS-angreb mod finanssektoren
I denne episode snakker vi om penetrationtesting, og om hvordan man kan arbejde med pentesting.
Vi snakker også om DDoS-angrebet mod finanssektoren i januar 2023.
Links:
Cyber Killchain (https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html)
MITRE ATT&CK® (https://attack.mitre.org/)
PicoCTF (https://picoctf.org/)
OverTheWire (https://overthewire.org/wargames/)
HackThisSite (https://www.hackthissite.org/)
Vulnhub (https://www.vulnhub.com/)
Hack The Box (https://www.hackthebox.com/)
Damn Vulnerable Web Application (https://github.com/digininja/DVWA)
Kali Linux (https://www.kali.org/)
Application layer attacks (https://www.cloudflare.com/learning/ddos/application-layer-ddos-attack/)
DDoS Attack Trendes 2022 Q4 (https://blog.cloudflare.com/ddos-threat-report-2022-q4/)
LUCID: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection (https://github.com/doriguzzi/lucid-ddos)
23 Dec 2022
2. Threat modelling, security champions og lignende munterheder i softwaresikkerhed + NIS2 interview med Karsten Dahl Vandrup
Trusselsbilledet
CFCS - Cybertruslen mod Danmark (https://www.cfcs.dk/globalassets/cfcs/dokumenter/trusselsvurderinger/cybertruslen-mod-danmark-2022.pdf)
OWASP Web Top 10 (https://owasp.org/www-project-top-ten/)
OWASP Cloud Top 10 (https://owasp.org/www-project-cloud-native-application-security-top-10/)
ISC Stormcast (https://isc.sans.edu/podcast.html)
Threat modelling
STRIDE (https://en.wikipedia.org/wiki/STRIDE_(security))
LINDUNN (https://www.linddun.org/about) Privacy by design
Threat modelling manifesto (https://www.threatmodelingmanifesto.org/)
Security Champions (https://resources.infosecinstitute.com/topic/an-overview-of-the-owasp-security-champions-playbook/) playbook
NIS2 med Karsten Dahl Vandrup
NIS2 webinar - Lektion 1: Kom i gang med NIS2 med en risikoanalyse
https://www.youtube.com/watch?v=7RbvPag4kvA (https://www.youtube.com/watch?v=7RbvPag4kvA)
NIS2 webinar - Lektion 2: Få struktureret din IT-sikkerhed (ISMS)
https://www.youtube.com/watch?v=xso-TyrjfA8 (https://www.youtube.com/watch?v=xso-TyrjfA8)
NIS2 webinar - Lektion 3: Sikkerhedsbrud - hvad gør vi nu?
https://www.youtube.com/watch?v=qA-HndBmb6M (https://www.youtube.com/watch?v=qA-HndBmb6M)
8 Nov 2022
1. Om bogen "Hvad er kryptografi for noget?" og om hackerangreb mod DSB
Den første episode for podcasten "It-sikkerhed med A33nt" 🥳
*** Indhold ***
-- Anmeldelse af Lars Ramkilde Knudsens bog, "Hvad er kryptografi for noget?"
-- Totalnedbrud hos DSB pga. hackerangreb
*** Kontakt ***
https://twitter.com/a33nt (https://twitter.com/a33nt)
*** Links ***
-- Kryptobog https://www.polyteknisk.dk/home/Detaljer/9788750211341
-- Lars Ramkilde Knudsen (https://www.linkedin.com/in/lars-ramkilde-knudsen-085b725/) https://www.linkedin.com/in/lars-ramkilde-knudsen-085b725
-- https://www.dencrypt.dk
-- https://piiguard.com
-- Nedbrud hos DSB (https://www.dr.dk/nyheder/indland/leverandoer-lukkede-it-system-efter-sikkerhedsbrist-og-pludselig-stod-alle-tog-i) https://www.dr.dk/nyheder/indland/leverandoer-lukkede-it-system-efter-sikkerhedsbrist-og-pludselig-stod-alle-tog-i
-- Fem konkrete råd (https://www.computerworld.dk/art/262545/fem-konkrete-raad-saadan-undgaar-du-at-havne-i-den-situation-som-dsb-endte-i-da-togdriften-blev-hacket ) https://www.computerworld.dk/art/262545/fem-konkrete-raad-saadan-undgaar-du-at-havne-i-den-situation-som-dsb-endte-i-da-togdriften-blev-hacket
Contact IT-sikkerhed med A33nt
Guest appearances
Books guests
Based on episode analysis; this does not confirm that the show is currently accepting guests.
Host of IT-sikkerhed med A33nt?
Claim your podcast to manage its listing and keep your show details accurate.
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.
Explore this show Podcast research with Pod Engine