A good way to demonstrate why plaintext creds are bad. In this case Telnet.
I set up an MITM system to capture traffic: tcpdump -X -s0 port 23 -vv -w telnet.pcap
Logged in over telnet as usual from another system.
Extracted telnet creds from telnet.pcap and they presented in a format perfect for report screenshots:
tshark -r telnet.pcap -Y "telnet.data" -T fields -e telnet.data
I wrote a blog post back in 2020 that's similar to what's happening to MGM right now. Specifically, I covered how to build a security program post-breach. If I were in charge of security at a casino right now, I would be taking a hard look at the threat model, risk assessments, defenses, and incident response.
I would also be thinking about what I covered in this blog post and the activities it takes to start moving in this direction.
#CasinoSecurity #CyberSecurity #Infosec #Ransomware #Breach #CISO #CIO #ThreatModel #SecurityLeadership #incidentresponse #informationsecurity
https://www.sans.org/blog/building-an-information-security-program-post-breach-part-i/