SharePoint Security. Advanced SharePoint Security Tips and Tools. Presented by: Francis Brown Stach & Liu, LLC www.stachliu.com.



Similar documents
SharePoint Security. Advanced SharePoint Security Tips and Tools. Presented by: Francis Brown Stach & Liu, LLC

Saving SharePoint. Presented By: Sean McDonough Product Manager, SharePoint Products Idera

Thomas Röthlisberger IT Security Analyst

How to move a SharePoint Server bit environment to a 64-bit environment on Windows Server 2008.

Microsoft SharePoint Technologies Solution Architecture

Advanced IT Pro Course for Office SharePoint Server 2007 and SharePoint Services 3.0

BlackBerry Universal Device Service. Demo Access. AUTHOR: System4u

Who is SharePoint Joel?

Joomla Security Report

SQL Best Practices for SharePoint admins, the reluctant DBA. ITP324 Todd Klindt

Project Server 2010 Migration

SharePoint User Management

SHAREPOINT ARCHITECTURE FUNDAMENTALS

WorkEngine Pre-Deployment Checklist

Craig Carpenter MCT. MCSE, MCSA

Tuning Microsoft SQL Server for SharePoint. Daniel Glenn

Quick Start Guide Mobile Entrée 4

SharePoint 2010 Dev Vs. Microsoft Quest Software

Backup, Restore, High Availability, and Disaster Recovery for Microsoft SharePoint Technologies

Implementing and Administering an Enterprise SharePoint Environment

How to Scale out SharePoint Server 2007 from a single server farm to a 3 server farm with Microsoft Network Load Balancing on the Web servers.

On-premise and Online connection with Provider Hosted APP (Part 1)

Implementing and Administering an Enterprise SharePoint Environment

SharePoint 2010 Performance and Capacity Planning Best Practices

EMC Documentum Repository Services for Microsoft SharePoint

SharePoint 2013 Syllabus

SHAREPOINT 2010 DEVELOPMENT : IN THE CLOUD. Faraz Khan Senior Consultant RBA Consulting

Meeting the SLA challenge of Enterprise Backup and Restore for SharePoint. European Microsoft SharePoint Conference 2007

SharePoint Governance Execution

Igotta, LLC Resource Reservation SharePoint 2013 Server App and SharePoint 2013 Online App Solution. Guide for Administrators

How to Configure a Stress Test Project for Microsoft Office SharePoint Server 2007 using Visual Studio Team Suite 2008.

What s New and Exciting in SharePoint Server 2016

ArcGIS for Server in the Amazon Cloud. Michele Lundeen Esri

How to configure Incoming Enabled Libraries in MOSS2007 RTM using Exchange 2007 in an Active Directory Domain.

EXAM TS: Microsoft SharePoint Server 2010, Configuring. Buy Full Product.

SharePoint Disaster Recovery Options. Sean P. McDonough Product Manager, SharePoint Products Idera

Alarm DB Logger Object for Wonderware Application Server Demo Guide Ver 1.0 Rev 1.0

The Essential Guide to Meeting Administrative Challenges in Multi-Tiered SharePoint Environments

Integrating Business Portal 3.0 with Microsoft Office SharePoint Portal Server 2003: A Natural Fit

solution brief solution brief storserver.com STORServer, Inc. U.S. (800) : STORServer, Europe 0031 (0)

Microsoft Services Exceed your business with Microsoft SharePoint Server 2010

This module explains the Microsoft Dynamics NAV architecture and its core components.

SharePoint MVP Independent Consultant and Owner of Falchion Consulting, LLC.

File Share Navigator Online 1

Microsoft Project Server Integration with SharePoint 2010

SharePoint How To s / Team Sites 1of 6

Introduction to Records Management in SharePoint 2013

Capacity Planning for Microsoft SharePoint Technologies

Service Applications. Bye-Bye SSP Hello Service Applications. Presented By: Elijah Van Eenwyk

How to configure Incoming Enabled Libraries in MOSS2007 RTM using Exchange 2003 in an Active Directory Domain.

Installation & User Guide

Manage Office. A SharePoint solution. Executive Summary. About our Client. Business Situation

HOWTO: Installation of Microsoft Office SharePoint Server 2007

50 Best Practice Tips for Microsoft Dynamics CRM Christmas Lunch & Learn

DocuSign Connect for Salesforce Guide

About SharePoint Server 2007 My Sites

Mirjam van Olst. Best Practices & Considerations for Designing Your SharePoint Logical Architecture

ThorApp s. License Activation Guide. No nonsense tools, apps and add-ons for SharePoint. Author: Adrian Bear. Date: 22 Sep Version: 1.

Scaling out a SharePoint Farm and Configuring Network Load Balancing on the Web Servers. Steve Smith Combined Knowledge MVP SharePoint Server

Develop a Native App (ios and Android) for a Drupal Website without Learning Objective-C or Java. Drupaldelphia 2014 By Joe Roberts

MS SharePoint Server Backup - User Guide

TABLE OF CONTENTS. Features - SharePoint Server idataagent. Page 1 of 72 OVERVIEW SYSTEM REQUIREMENTS - SHAREPOINT SERVER IDATAAGENT INSTALLATION

Business Portal for Microsoft Dynamics GP Field Service Suite

The Core Pillars of AN EFFECTIVE DOCUMENT MANAGEMENT SOLUTION

Cloudfinder for Office 365 User Guide. November 2013

Sisense. Product Highlights.

SSRS Reporting Using Report Builder 3.0. By Laura Rogers Senior SharePoint Consultant Rackspace Hosting

MS-55115: Planning, Deploying and Managing Microsoft Project Server 2013

SSC2016: SharePoint 2016 Administrator s Survival Camp

Intelligent Dashboards made Simple! Using Excel Services

Getting a handle on SharePoint security complexity

UF Health SharePoint 2010 Introduction to Content Administration

MCTS SharePoint 2010, Configuring

NetSpective Global Proxy Configuration Guide

SharePoint 2010 Interview Questions-Architect

Using Microsoft Operations Manager To Monitor And Maintain Your Farm. Michael Noel.

Microsoft SharePoint 2010 Administration

AD Self-Service Suite for Active Directory

Safewhere*Identify 3.4. Release Notes

EVault Software Microsoft SharePoint Plug-in 7.1 User Guide

Upgrading to Websense Web Security v7.6

DocAve 6 Service Pack 1 Administrator

STEALTHbits Technologies, Inc. StealthAUDIT v5.1 System Requirements and Installation Notes

Transcription:

SharePoint Security Advanced SharePoint Security Tips and Tools 05 Oct 2010 Presented by: Francis Brown Stach & Liu, LLC www.stachliu.com

Agenda O V E R V I E W Brief Intro to SharePoint Overview of Major Components SharePoint Security Security Tips and Tools 2

Background G E T T I N G U P T O S P E E D 3

Background MS SharePoint Products & Technologies Windows SharePoint Services (WSS) Office SharePoint Server 2007/2010 (MOSS) SharePoint Designer 2007/2010 (SPD) 4

Background MS SharePoint Products & Technologies 5

Background MS SharePoint Products & Technologies 6

Background MS SharePoint Products & Technologies 7

Background MS SharePoint Products & Technologies 8

Site Hierarchy Intro to SharePoint 9

SharePoint Site Hierarchy Intro to SharePoint Base Site URLs: http://learnsouth/ http://learnsouth/media/ http://learnsouth/revisions/ http://learnsouth/schools/ http://learnsouth/schools/schoola/ http://learnsouth/schools/schoolb/ http://learnsouth/schools/schoolc/ 10

Site Structure Intro to SharePoint 11

Site Navigation Intro to SharePoint 12

Security Tips W H A T Y O U S H O U L D K N O W 13

Security Tips S H A R E P O I N T S E C U R I T Y # Security Tip 1 Know your external exposure 2 Beware of normal users with excessive access 3 Spot check user permissions and inheritance 4 Beware third-party plugins/code BUT not too much 5 Backup every which way from Sunday 14

Security Tip #1 K N O W Y O U R E X T E R N A L E X P O S U R E 15

External Exposure F I N D I N G H O L E S 1. Google Hack yourself 1. Search Google for exposed SharePoint admin pages 2. E.g. inurl:"/_catalogs/wt/ 3. NEW: SharePoint Google Regexs for S&L SearchDiggity 109 queries 2. SharePoint URL Brute-forcing 1. Forceful browse to common SharePoint extensions to test access 2. NEW: Tool to bruteforce SharePoint URLs 89 known extensions 3. Nmap for other SharePoint administrative apps 1. E.g. Central Administration, Shared Service Providers (SSP) 16

External Exposure G O O G L E H A C K I N G S H A R E P O I N T 17

S H A R E P O I N T H A C K I N G T O O L S DEMO 18

Security Tip #2 B E W A R E U S E R S W I T H E X C E S S I V E A C C E S S 19

C O N T I N U E D S H A R E P O I N T H A C K I N G DEMO 20

Excessive User Access M O R E T H A N Y O U B A R G A I N E D F O R... Web Services examples Admin.asmx Permissions.asmx User Administration examples People and Groups Add Users PeoplePicker 21

Security Tip #3 C H E C K P E R M I S S I O N S A N D I N H E R I T A N C E 22

User Permissions S E C U R I T Y T I P S 23

User Permissions S E C U R I T Y T I P S 24

User Permissions S E C U R I T Y T I P S 25

Security Tools U S E R P E R M I S S I O N S 26

Security Tools U S E R P E R M I S S I O N S 27

Security Tools U S E R P E R M I S S I O N S 28

Security Tip #4 B E W A R E T H I R D- P A R T Y C O D E N O T T O O M U C H 29

Third-Party Plugins N E C E S S A R Y E V I L SharePoint without third-party plugins is like an iphone with no apps Solutions, Features Web Parts, Templates If too strict, people will circumvent you 30

Third-Party Plugins S O L U T I O N S 31

Third-Party Plugins S O L U T I O N S 32

Third-Party Plugins F E A T U R E S 33

Third-Party Plugins F E A T U R E S 34

Third-Party Plugins F U T U R E S E C U R I T Y SharePoint 2010 has sandboxed solutions Minimize risk of running untrusted third-party plugins 35

Third-Party Plugins S A N D B O X E D S O L U T I O N S 36

Security Tip #5 B A C K U P E V E R Y W H I C H W A Y F R O M S U N D A Y 37

Backups M A N Y M E T H O D S A L L T E R R I B L E 1. Windows 2003/2008 Server backups 2. Stsadm.exe cmdline tool backups 3. Central Administration v3 backups 4. SharePoint Designer backups 5. Site and List template backups 6. Raw MS SQL database backups 38

Backups S H A R E P O I N T D E S I G N E R 39

Backups S T S A D M / C E N T R A L A D M I N I S T R A T I O N 40

Backups S I T E A N D L I S T T E M P L A T E S 41

Backups S I T E A N D L I S T T E M P L A T E S 42

Backups R A W S Q L D A T A B A S E S Farm Central Administration Console/ Custom Backup Application Config DB File Server Content DB Content DB SSP DB Search Index Full Back up SQL Backup/Restore Differntial 43

Questions? Ask us something We ll try to answer it. For more info: Email: contact@stachliu.com Project: diggity@stachliu.com Stach & Liu, LLC www.stachliu.com

Thank You Stach & Liu SharePoint Hacking Diggity Project info: http://www.stachliu.com/index.php/resources/tools/sharepoint-hacking-diggity-project/ 45