Abstract
SDN (Software Defined Network) has attracted the attention of many technology giants from various segments such as VMware, Juniper, Cisco, HP, IBM, Google, China Telecom, Huawei and others by providing more virtualized services that can be scheduled, managed and monitored faster, more efficient and in a less costly manner than the usual solutions. Defining routes, switching, QoS treatment and security policies that happened in stocky and specific hardware now has performed his duties in higher layers of software, installed on virtualized machine. But how can we test this? First, we’ll address an overview of the SDN architecture, soon after, it will be explained how to find SDN controllers, and if present in our network, steal critical information so that we can proceed with our exploitation. In the end, we will take possession of the controllers and make unexpected. There will be a smattering of codes for metasploit that will be demonstrated. Does a controller can control us? We’ll see.
Bio
Roberto Soares is Senior Security Consultant at Conviso Application Security, focused on Research and Secure Development Lifecycle (SDLC). In this role I focused on best practices around application penetration testing, including application vulnerability assessment and source code review, using a combination of static and dynamic analysis to identify vulnerabilities. Have lectured on open-source events and colleges.