BSides Philly 2017 – MFA: It’s 2017 and You’re Still Doing It Wrong

by  and  | Dec 13, 2017

Security Risk Advisors is proud to have been a Platinum Sponsor at BSides Philly on Friday, December 8th. In addition to continued involvement in and support for the BSides organization, Security Risk Advisors’ Chris Salerno and Dan Astor also presented on Multi Factor Authentication best practices – and areas for improvement.  The presentation is available to watch on YouTube, and slides are available on Slideshare, below:

 

Presented at BSides Philadelphia, December 8, 2017

We can all agree that having single-factor remote access gateways (VPN, Citrix, Remote Apps, etc.) exposed on the internet is a poor decision and a large security risk. These portals, can allow for a direct connection into the internal corporate environment. Once there, an attacker can begin to identify internal vulnerabilities, move laterally, escalate privileges, persist, and hoover out all the data they want. Fortunately, these portals are increasingly behind a multi-factor solution (phone call, hard/soft token, certificate, etc.). While this does help to reduce the attack surface from a direct brute force (username and password), there are often overlooked options or misconfigurations that can allow an attacker to bypass this solution or directly disrupt business operations. In this talk we’ll be covering methods that we’ve used to bypass MFA solutions to obtain internal network access from the internet.

 

 

 

Dan Astor Chris Salerno

Chris Salerno
Archive

Chris leads SRA’s 24x7 CyberSOC services.  His background is in cybersecurity strategy based on NIST CSF, red and purple teams, improving network defenses, technical penetration testing and web applications.

Prior to shifting his focus to defense and secops, he led hundreds of penetration tests and security assessments and brings that deep expertise to the blue team.

Chris has been a distinguished speaker at BlackHat Arsenal, RSA, B-Sides and SecureWorld.

Prior to Security Risk Advisors, Chris was the lead penetration tester for a Big4 security practice.

Dan Astor
Director of Offensive Security, Research & Innovation at Security Risk Advisors |  Archive

Dan Astor is Director of Offensive Security, Research & Innovation at Security Risk Advisors, where he leads and oversees SRA’s penetration testing, application security, red team, and offensive security research practices.

Dan is responsible for the technical direction and execution of these services, including the development and maintenance of SRA’s testing methodologies, standards, tooling, quality practices, and operator tradecraft. He works closely with SRA’s technical teams to continually evolve how engagements are delivered as technologies, attacker techniques, regulatory requirements, and client environments change.

His work includes leading and supporting complex adversary simulation and threat-led penetration testing programs, including engagements aligned with TIBER-EU and DORA Threat-Led Penetration Testing (TLPT) requirements. He also helps guide the development of offensive security capabilities for highly regulated organizations and critical industries.

As part of SRA’s Research & Innovation efforts, Dan researches emerging offensive security techniques and technologies and helps translate that research into new tooling, methodologies, and client services. His current areas of focus include the application of artificial intelligence and agentic systems to penetration testing, application security, reconnaissance, security research, and the automation and augmentation of offensive security workflows.

Dan contributes to vulnerability research and coordinated disclosure, including SRA’s CVE Numbering Authority activities, and develops and contributes to open-source security tooling. He also regularly publishes technical blog post and presents at industry conferences.

Dan has worked with Fortune 1000 organizations across financial services, healthcare, pharmaceutical, technology, telecommunications, media and entertainment, manufacturing, utilities, and other critical industries. He holds the Offensive Security Certified Professional (OSCP), Certified Red Team Operator (CRTO), and CREST Practitioner Security Analyst (CPSA) certifications.