50p 2018

50p 2018

India's first independent conference on payments and the payment ecosystem

Akash Mahajan

@makash

OSINT Techniques for Pwning Fintech

Submitted Nov 17, 2017

Attackers have been using OSINT techniques against HVT successfully to identify and exploit information assets. Unfortunately, conventional security assessment and guidance doesn’t address these exposures very well. This talk delves into what are some of the techniques Fintech companies should be using to build a complete picture of its Internet exposed assets. Once this big picture is available, they can figure out ways of staying secure.

Based on the techniques described, we will also share some of our findings. We will present aggregates around the various security issues discovered and general mitigations for those.

Outline

We will demonstrate OSINT techniques to:

  • Discover Internet exposed assets
  • Fingerprint and gather technical details
  • Correlate information to plan attacks
  • Threat Modeling with table top scenarios

Speaker bio

Akash is a Director at Appsecco, a company that specializes in Web Application Security. He is an accomplished security professional with over a decade’s experience of providing specialist application and infrastructure consulting services at the highest levels to companies, governments and organisations around the world.

He has a deep experience of working with clients to provide cutting edge security insight that truly reflects the commercial and operational needs of the organisation from strategic advice to testing and analysis to incident response and recovery.

Akash has also authored a book titled “BurpSuite Essentials” that comes recommended by the creator of BurpSuite itself and is an active participant in the international security community and conference speaker both individually, as chapter lead of the Bangalore chapter of OWASP the global organisation responsible for defining the standards for web application security and as a co-founder of NULL India’s largest open security community.

Comments

{{ gettext('Login to leave a comment') }}

{{ gettext('Post a comment…') }}
{{ gettext('New comment') }}
{{ formTitle }}

{{ errorMsg }}

{{ gettext('No comments posted yet') }}

Hosted by

50p, formerly an annual conference held in 2017 and 2018 on digital payments - is turning into round-the-year forum for conversations and collaborations on the #payments ecosystem, and associated #fintech topics. Follow 50p on Twitter. more