Cybercrime - Fraudes em seguradoras, FENGSEG

33
1 Cyber Crimes Set/16 @bennaton Leandro Bennaton

Transcript of Cybercrime - Fraudes em seguradoras, FENGSEG

Slide 1

1

Cyber Crimes Set/16

@bennaton Leandro Bennaton

LEANDRO BENNATONExecutivo de Segurana do Grupo Telefnica:Chief Security Officer no TERRAChief Security Ambassador na ELEVENPATHSSecurity Mentor na WAYRAProfessor Ps Graduao na FIAP

Ps graduado, com MBA em Gerenciamento de Segurana da Informao e certificaes internacionais como a especializao em Cybersecurity do MIT, Governana Internet do CGI.br e South School of Internet Governance: Cybersecurity and freedom of speech da OEA.

Premiado pelo 3 ano consecutivo como o melhor executivo de Segurana e Risco pela organizao Security Leaders.

Forma tradicional para se cometer um Crime

Forma tradicional para se cometer um Crime

Nova forma para se cometer um Crime

Quem alvo?

Alguns casos

Your BMW or Benz Could Also Be Vulnerable to That GM OnStar Hack : http://www.wired.com/2015/08/bmw-benz-also-vulnerable-gm-onstar-hack/Researchers Hacked a Model S, But Teslas Already Released a Patch http://www.wired.com/2015/08/researchers-hacked-model-s-teslas-already/7

A INTERNET

DEFACEMENT

http://www.zone-h.org

https://www.stopbadware.org/clearinghouse/search

DDoS

DDoS - http://map.norsecorp.com/

VAZAMENTO DE DADOS

Credenciais

http://haveibeenpwned.com/

19

https://goo.gl/ncxvxt

RANSOMWARE

INVESTIGAO SEGUNDO O MCI

http://www.planalto.gov.br/ccivil_03/_ato2011-2014/2014/lei/l12965.htm

Exemplos de investigaes

Exemplos de investigaes

INVESTIGAO SEGUNDO O MCI

Received: from TI-ASIN02-POA.corp.terra.com.br (10.225.0.50) by poasns28b.corp.terra (10.225.0.39) with Microsoft SMTP Server id 8.3.348.2; Sun, 23 Nov 2014 00:01:20 -0200X-NAI-ID: 27fd_0777_b8e599c8_6a39_45fa_8543_d29f6caff5dfReceived-PRA: (Could not find a valid SPF record )Received-SPF: none (te4533.temjumet.com: te4533.temjumet.com does not exist) client-ip=67.228.190.131; [email protected]; helo=te4533.temjumet.com;Received: from te4533.temjumet.com (unknown [67.228.190.131]) by TI-ASIN02-POA.corp.terra.com.br with smtp id 27fd_0766_03e37d7d_bb53_4afe_9b3c_45ed3ccf6f69; Sat, 22 Nov 2014 21:30:26 -0300Received: by te4533.temjumet.com (Postfix, from userid 0) id A71E8524FB; Sat, 22 Nov 2014 18:14:00 -0600 (CST)Subject: Rede de Atendimento - Banco Bradesco S/A.From: To: [email protected]: Date: Sat, 22 Nov 2014 18:14:00 -0600MIME-Version: 1.0Return-Path: [email protected] de e-mail

Received: from TI-ASIN02-POA.corp.terra.com.br (10.225.0.50) by poasns28b.corp.terra (10.225.0.39) with Microsoft SMTP Server id 8.3.348.2; Sun, 23 Nov 2014 00:01:20 -0200X-NAI-ID: 27fd_0777_b8e599c8_6a39_45fa_8543_d29f6caff5dfReceived-PRA: (Could not find a valid SPF record )Received-SPF: none (te4533.temjumet.com: te4533.temjumet.com does not exist) client-ip=67.228.190.131; [email protected]; helo=te4533.temjumet.com;Received: from te4533.temjumet.com (unknown [67.228.190.131]) by TI-ASIN02-POA.corp.terra.com.br with smtp id 27fd_0766_03e37d7d_bb53_4afe_9b3c_45ed3ccf6f69; Sat, 22 Nov 2014 21:30:26 -0300Received: by te4533.temjumet.com (Postfix, from userid 0) id A71E8524FB; Sat, 22 Nov 2014 18:14:00 -0600 (CST)Subject: Rede de Atendimento - Banco Bradesco S/A.From: To: [email protected]: Date: Sat, 22 Nov 2014 18:14:00 -0600MIME-Version: 1.0Return-Path: [email protected] de e-mail

O GMT no est relacionado ao fuso horrio, mas as configuraes do servidor.

ATENO

Exemplos de investigaes

http://dawhois.com/

33

Cyber CrimesSet/16

@bennatonLeandro Bennaton