SunGard Reconnaissance

Slides:



Advertisements
Similar presentations
Let's say we want to access domain - reliablescribe.com First we need to buy a computer We need to subscribe to an Internet Service Provider (ISP) The.
Advertisements

GP2013 (R2) New features in GP2013 (R2). New Ribbon for windows Edit List is the Print button on the right without the paper background Action pane can.
Introduction The Basic Google Hacking Techniques How to Protect your Websites.
From Students… …to Professionals The Capstone Experience 09/14: Team Status Reports Dr. Wayne Dyksen Department of Computer Science and Engineering Michigan.
 Single sign-on o Centralized and federated passport o Federated Liberty Alliance and Shibboleth  Authorization o Who can access which resource o ACM.
0-1 Team # Status Report (1 of 4) Client Contact –Point 1 –Point 2 Team Meetings –Point 1 –Point 2 Team Organization –Point 1 –Point 2 Team #: Team Name.
Week 2 -1 Week 2: Footprinting What is Footprinting? –Systematic collection of information on an intended target with the goal to create a complete profile.
DePaul Bears Try Your Luck! Plan Methodology. Team Methodology Effective Communication s, phone calls, on-line chats, in-class meetings, outside.
0-1 Team # Status Report (1 of 4) Client Contact –Status Point 1 –Status Point 2 Team Meetings –Status Point 1 –Status Point 2 Team Organization –Description.
Microsoft Passport Waldemar Swiercz.
What’s up? (Delete this slide.) 1.What follows is the required skeleton for your presentation. 2.Do not change the organization or number of slides. Make.
0-1 Team 1 Status Report (1 of 3) Client Contact –Point 1 –Point 2 Team Meetings –Point 1 –Point 2 Team Organization –Point 1 –Point 2 Team 1: Auto-Owners.
0-1 Team ?? Status Report (1 of 3) Client Contact –Point 1 –Point 2 Team Meetings –Point 1 –Point 2 Team Organization –Point 1 –Point 2 Team 1: Auraria.
Introduction to MVNU Technology aka IT 101. Welcome to IT 101! Our plan is to introduce you to a few basic technology items. We designed this to be short.
JobTargetJobTarget Recruitment Tool Ad Posting Process Presented by: Human Resource Services Revised March 2015.
Footprinting Richard Newman “If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the.
Logo Name of Company Search My Account, Contact, Log in HomeLiquorWineBeer Wine Copyright Google Map Location Advertisement WhiskeyBeerBrandy RumVodka.
HOW ACCESS TO WWW Student Name : Hussein Alkhaldi.
Systems Used for Collaboration When to achieve a common goal, result or work product.
Job Search 101 Free Geek Instructor: Wayne Flower.
Google Confidential and Proprietary 1 Advanced Docs Google Apps.
Online Collaborative Tools using Google and Google +
G053 – Lecture 09 Domain Names Mr C Johnston ICT Teacher
End-to-End Methodology. Testing Phases  Reconnaissance  Mapping  Discovery  Exploitation  Repeat…  Report.
October 11, 2015 Managing users.  In this lesson we will cover:  Creating/Modifying users  Defining/Assigning user roles  Password Requirements for.
Trinity Washington University 1 . Trinity –You get a free Google Mail account i.e.,
CIS 250 Advanced Computer Applications Internet/WWW Review.
How do you Google? Collaborating with Google tools Della Shorman, Unit of Online Learning CO Department of Education.
Professional Typing, Data Entry, & Design Service.
IP BROS Presentation by: Amen Ahmed. Mario and Luigi are here to help us find our way through the internet. Mario will act as our browser and Luigi will.
GEOPRIV Experiment at IETF 71 n Goal: Demonstrate GEOPRIV protocols using the IETF network to provide location l Data formats: PIDF-LO and Civic Address.
PARENT CONNECT Parent Connect is a web application that provides parents with direct access to student data via the Internet. Using a confidential PIN.
TCOM Information Assurance Management Casing the Establishment.
Google Tools for your Classroom. 6/15/2009. Agenda 1. Google Accounts 2. What is Web 2.0? 3. Intro to Google calendar 4. Google Docs 5. Google Forms and.
Purchasing Homework Manager Online. First go to the Online Learning Center at
Footprinting and Scanning
JobTargetJobTarget Online Job Ad Distribution Platform Presented by: Human Resource Services Revised November 2015.
Google Accounts MISD. Gmail and Google Drive Tools for students.
Best 20 jobs jobs sites.
WHAT IS FOOTPRINTING?. FOOTPRINTING  Active  Passive - Passive footprinting is a method in which the attacker never makes any contact with the target.
Enhancing Inquiry with Google Collaborative Docs & SMS Session 2 of 4 Get Going with Google Research Apps.
Access to Radiology Information Paul Seifert Agfa HealthCare Co-chair, IHE Radiology Technical Committee.
Mike is the HR manager at Playwicki Financial Services
Helping Students Excel on the
CALL ON  Windows Live Mail is an client, services which is provided by Microsoft.  Live Mail is also a part of Windows live set.
Footprinting and Scanning
First class First class is a kind of client server group First class provide services like : Online conference Voice / fax services There is bulletin.
WHOIS ANALYSIS Reveals Domain ID information Headquarters location
Windows Live Mail Customer Service Phone Number
Google Plus Technical Support Google Plus Toll Free Number Visit:
Windows Live Mail Customer Service Number |
Basic Work-Flow with SQL Server Standard
Unit 5: Providing Network Services
Application of the Internet
Hush mail Customer Tech Support Number Hush mail Customer Tech Support Number Call Now : Toll Free Call Now : Toll Free.
Footprinting and Scanning
Metasploit assignment
Man-in-the-Middle Attacks
RECONNAISSANCE & ENUMERATION
CS101 How the Internet Works.
Google Apps for Education
FIS Career Resource for International Students
SHFC Message Board.
Reconnaissance Report of Lincoln Financial Group
Best Practices On-Line Analysis Tools
Google Hacking Damian Gordon.
ISO9001 and Document Control Awareness Training
Using Google Cloud Search
Presentation transcript:

SunGard Reconnaissance What is SunGard? Provider of information systems to financial companies Acquired by FIS Headquartered in Wayne, PA Tools used for recon: Google hacking – best results ARIN – able to see point of contact for domain Netcraft – identified web server used Job posting boards – not much luck, jobs focusing on financial related areas Ahmed Alkaysi

Arin, Netcraft, and Job Postings Helped identify IP address: 147.249.128.1 Web Server: BigIP ARIN Not a lot of information disclosed Identified one Point of Contact for domain Job posting Limited tech jobs Mostly financial related jobs Account Manager Billing Analyst Compensation Analyst Ahmed Alkaysi

Google Hacking on SunGard Sample queries used site:sungard.com -site:support.sungard.com -site:www.sungard.com -site:financialsystemsjobs.sungard.com Basic query to filter out common results site:sungard.com intext:"confidential“ Returned document with confidential information Explanation on how SunGard systems work Diagrams Email address of a client Possible Account NO site:sungard.com filetype:xlsx Returned excel with client registration information for a presentation Found a login site with no HTTPS Can be prone to man-in-the-middle attack Examples of docs https://www.sungard.com/-/media/fs/wealth-retirement/resources/newsletter-docs/2015-CLT- News/0315-Fee_Unbundling.pdf?la=en https://www.sungard.com/-/media/fs/banking/resources/events/Rethinking-the-Cards-Business- Erick-Ho.pdf?la=en Ahmed Alkaysi