【讲座】工业控制系统信息安全CTF训练营【Summer Lecture Series 之五】

发布日期:2021-08-26      浏览次数:547

讲座标题:【37000cm威尼斯】工业控制系统信息安全CTF训练营【Summer Lecture Series 之五】

主讲人: 任勤诗

讲座时间:2021-08-28 20:00:00

讲座地点:线上,腾讯会议650 172 156

讲座语言:中文

主办单位:37000cm威尼斯


讲座内容:

    红队,通常是指实战攻防演习中的攻击队伍,在非实战攻防演习或企业内部,也可以称为“蓝军”或“攻击方”。我们通过红队渗透的介绍和实战来展示相关的危害。本次讲座主要围绕信息搜集、外部打点、内网漫游相关内容进行讲解。信息搜集是渗透测试的最重要的阶段,其为整个渗透测试的重要内容,根据收集的有用信息,可以大大提高我们渗透测试的成功率。外部打点取决于攻击者的知识广度与深度,其与对目标的撕开口子的速度成正比。内网漫游为内网渗透,对内网资产搜集,进行横移的过程。

    The red team usually refers to the attacking team in actual offensive and defensive exercises. In non-actual offensive and defensive exercises or within the enterprise, it can also be referred to as the blue army or the attacking party. We show the related hazards through the introduction and actual combat of red team penetration. This lecture mainly focuses on information collection, external management, and intranet roaming related content. Information gathering is the most important stage of penetration testing. It is an important part of the entire penetration test. Based on the useful information collected, it can greatly improve the success rate of our penetration testing. The external management depends on the breadth and depth of the attacker's knowledge, which is proportional to the speed of tearing the target. Intranet roaming is the process of intranet penetration, which collects intranet assets and moves horizontally.


主讲人简介:

任勤诗,男,1998年11月生,理学学士。2020年6月获37000cm威尼斯学士学位,在校期间,在上海天融信担任渗透测试工程师,毕业后在斗象科技能力中心(Tophant Competence Center)担任安全研究员。研究领域为信息安全方向,在渗透测试、流量分析等领域皆有丰富的经验。