Reusing breach data for attack and defence

No ratings

Presented at bsideswellington 2017 by

Data breaches and their disclosure have become commonplace and yet reusing contents from a breach for security testing or enhancing an organisations defences been poorly explored. Whilst technical complexity and time of execution is not comparable to more elegant threats, The accessibility and ease of exploitation of password should be of concern to individuals and businesses. Having collected and analysed such information over the course of two years, it was only natural to start reusing it in penetration testing. This talk will go through through some of the insights into the collection of data, its reuse in security testing, our development of an internal database for material from breaches, as well as how it can be used in a defensive function.