This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The quest for better pentest reports: Introducing Missing Security Controls

Download resources

About this session

Maxime Nadeau, director of ethical hacking at GoSecure, presents Missing Security Controls, a way to report absent defences that CVSS scores as informational and customers therefore never fix. After a CVSS primer he lists its weaknesses: it strains in cloud-native contexts, has no metric for safety, clusters scores at 7.5, 7.8 and 8.8, invites gamification, and rates controls like HSTS inconsistently. A red-team story shows the gap: two physical intrusions, cloned RFID badges and a conference room with no network access control led straight to a mainframe, yet each root cause would score zero. He draws the line between a control and a vulnerability (a weak password policy versus a weak password found by spraying), and uses a browser-autofill credential-theft technique found by a colleague to show how one XSS yields recommendations for developers, web admins, security admins and architects. GoSecure's method strips impact from the CVSS formula and keeps exploitability (attack vector, complexity, privileges, user interaction, scope); the exploitability drop a control would cause, from 0.2 to 4.2, maps to low, medium or high. A calculator is public, and questions cover score distributions, CVSS versions, conflicting vendor reports and outreach to FIRST.

Offensive security professionals are good at breaking into thing, but we often fail at properly communicating our findings to the various stakeholders involved in the projects. Tools like CVSS can be useful at communicating risk but have major limitations. This talk focuses on some of those shortcomings and introduces a possible solution to bridge some of the communication gaps between intrusion testers and management.

Key takeaways

  • Report missing controls (NAC, segmentation, CSP, HSTS, MFA) in a separate section from vulnerabilities so they stop being buried as informational.
  • Rate a missing control by the exploitability it removes: keep the CVSS attack vector, complexity, privileges, interaction and scope metrics, drop impact, and map the delta to low, medium or high.
  • Do not use the new rating to inflate findings you disagree with; anything with a real impact on confidentiality, integrity, availability or safety stays a CVSS vulnerability.
  • For each finding, name the stakeholder layer that can act (developer, web admin, security admin, architect) so remediation does not stall on ownership.
  • Re-score vendor CVSS values yourself against the specification and challenge the vendor when the reasoning does not hold; most testers apply CVSS loosely.

Speakers

Maxime Nadeau
Maxime Nadeau
Director of Ethical Hacking · GoSecure
Maxime is currently the Director of Ethical Hacking at GoSecure. Jack of all trades, master of some, he does have a pronounced interest in adversary simulation and physical security. Originally a software engineer, he is now conducting intrusion… Read moreRead less

Maxime is currently the Director of Ethical Hacking at GoSecure. Jack of all trades, master of some, he does have a pronounced interest in adversary simulation and physical security. Originally a software engineer, he is now conducting intrusion tests and built service offerings that include physical security intrusion and testing. He is a returning presenter at the GoSec conference, cybersecurity competition winner and NorthSec challenge designer.

Resources

Tags

More from GoSec 2022

Also from Maxime Nadeau

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.