Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Saturday, 7 May 2016

Red Team Case Study

A red team exercise involves completely reimagining the traditional penetration test and vulnerability analysis. Rather than examining individual components of the security model in isolation, red teaming simulates a real criminal attack under controlled conditions. These tests mimic the real-world targeted attacks that businesses face on a daily basis, using a goal-based engagement that delivers the true business impact of a breach.

Our client engagement started with a threat and risk analysis, personalised to the business, to identify real-world attackers, their motivation, their skills and likely avenues of attack. Once the most likely and damaging threats had been identified, scenarios were created that the staff of the organisation would recognise as real and pertinent to their company.

Each scenario began with an information gathering and reconnaissance phase to identify potential weaknesses in physical premises, staff members and Internet-facing technology. Premises were located and reviewed online to produce a short-list for further examination in person. On-site reconnaissance of selected buildings was used to plan a more detailed, multi-staged operation.

The organisation’s registered domains, address ranges and Internet hosts were examined, exposing the software in use, and finding public-facing systems such as Outlook Web Access. Internet searches harvested email addresses and associated employee information from sites such as LinkedIn. Emails were sent to elicit responses containing the company’s official style and layout.

A spear phishing campaign was mounted, using email addresses discovered in the information gathering phase, with fake domain names and cloned sites facilitating password theft.

The stolen credentials were then deployed in an on-premises attack against a branch office. Physical access to premises was facilitated through a combination of impersonation and telephone pretexting. Subsequent network access using the phished passwords permitted theft of information from a variety of servers and also demonstrated persistent remote access through technical exploits.

More sophisticated on-premises attacks were then designed to test visitor controls and desktop security at head office. Scenarios were developed with team members having fully-developed ‘legends’ (back stories) for each engagement. The stories selected entailed impersonation of a potential customer requiring a tour of a facility, and another masquerading as a member of the press researching the charitable activities of the business. Carefully planned emails and phone calls resulted in a legitimate appointment at head office. Once on site, one team member kept staff occupied in a business meeting while another excused themselves for a ‘comfort break’ and took the opportunity to look for unprotected computers and to plant a remote control device on the network. That team member was never challenged during their excursion and found unlocked offices containing unattended and logged-on computers.

This threat-based approach highlighted vulnerabilities that otherwise would have been missed or perhaps not even considered during a typical ‘due diligence’ exercise. It delivered critical results for a modest outlay in time and expenditure. Red teaming is not an alternative to traditional testing, but it is a very valuable additional activity.

There was also the opportunity to use the results of the red team exercise as the basis for world-wide security awareness training. Presentations based on these simulated criminal attacks engaged people in a fashion completely unlike traditional training. Because the audience was following a story, and because that story was genuinely relevant to their organisation, it was possible to raise the bar on that most difficult of security controls - the human firewall. Security awareness at all levels was increased significantly and staff members became security evangelists in their own right.

Further red team exercises will build on this exciting precedent and provide more engaging stories to continue the education of everyone in the organisation.

Tuesday, 17 April 2012

After a year of blogging apathy, I decided it's time to write a new entry. What prompted me is an interview I did for Infosecurity Europe about social engineering and blended attacks just recently. It's now up on YouTube, so take a peek and let me know what you think!

Tuesday, 21 April 2009

It's that time again!

Once again it's almost time for Infosecurity Europe and this year I seem to have a very full diary for all three days!

On Tuesday 28th April at 12:00 I'm giving a talk on "Cloud Computing: 50 Ways to Lose Your Data" closely followed by a press conference on a nasty new trend in compromising e-commerce sites.

On Wednesday 29th at 15:00 I'm wearing my white-hats.co.uk and ISACA hats and chairing a security expert panel on "Social Engineering: Techniques and Mitigation", a topic very close to my heart!

Then finally on Thursday 30th, again wearing my white-hats.co.uk hat, I'm facilitating two different discussions in the new Security Cafe one on "Laptop Security - Understanding The Threats & Countermeasures" and the second on "Wireless Security - The Real State Of Play" which is about threats to corporate security through insecure home wireless networks.

I'll be ready for the long weekend after all that!

Friday, 6 June 2008

Exposing yourself for the summer

As you'd expect, like all Brits, I'm trying to convince myself that we're actually having a summer. This put me in mind of social events, and specifically social networking. Everyone and their dog (literally) is now on Facebook it seems.

Lately there's been a lot of news about Facebook using personal details for profit and now Canada's federal privacy commissioner has launched an investigation into Facebook. Apparently four students complained that the popular Web site violates Canadian law by disclosing personal information to advertisers without proper consent.

This in turn reminded me of a wonderful YouTube video - definitely worth watching and passing on to your less security-aware friends and family!

Friday, 7 March 2008

More silver bullets?

With Infosec Europe approaching fast (22-24 April) my thoughts turned to the inevitable release of even more products, products, products. Everyone in IT loves gadgets, but is this really the future of information security? As penetration testers we spend a large proportion of our time trying to break into networks, with continued success unfortunately. However, when we analyse the reasons that networks remain vulnerable, we find that it's not about Zero Day exploits but rather mistakes that could have been avoided.

The same techniques I used to break into a Windows network in 1996 still work today, for example. Why? Because, despite manufacturers such as Microsoft and Oracle spending huge efforts to improve the security of their products, organisations still use stupid passwords, fail to understand security best practice and don't think outside of the box.

Just this week we again found Windows domain administrator accounts with pathetically weak passwords and business-critical infrastructure with default SNMP read/write strings. It took just just minutes to gain complete control of a global company's network with no prior knowledge at all. Every time we are asked to conduct a social engineering exercise - walking in the back door with the smokers, strolling past reception carrying a sandwich at lunchtime, or phoning the help desk and getting remote access - we find the same thing. No security awareness amongst staff at all.

So imagine my delight when five major clients all approached me to assist with staff awareness training this year. It seems that large organisations are finally getting to grips with the "human firewall" concept and realising that they need to invest in people, not just technology. Let's hope this trend continues!

Monday, 21 January 2008

The future of (ethical) hacking?

This post is not about where the hacking community is going (whatever that means), but more what I'd like organisations to think about.

I'm particularly proud of one aspect of our service: that we are pragmatic. By this I mean our ability to focus on genuine threats without being lost in the testosterone-driven "I've found the most obscure vulnerability ever" mindset. Wearing a white hat is much more than digging deeper than the next penetration tester - it's also about helping clients to understand where they should put their effort and their budget to get the most appropriate defence.

For me the most obvious illusion is that the important attacks will come from outside the organisation and that they will come via the interweb. If an organised criminal is going to target your organisation, then they're going to take the route that combines the best return on their investment with the highest probability of success (and to some degree the lowest risk). This is a typical business model - just an immoral one in their case.

So where do I believe organisations should focus? On what I'm calling blended attacks - attacks that combine technical skills with social engineering. These are the types of attack which we find work time after time, in the fastest way, with the highest return and with little risk of detection. There's nothing new in this sort of approach (just read Kevin Mitnick), yet the majority of organisations do little or nothing to test for these vulnerabilities.

Here's an example from my own team's experience. Recently, a UK-based insurance company asked us to test their physical security, with the objective of stealing as much information as possible. Andy and I rented a car close to their offices, then I parked in their car park and waited, having dropped Andy off at the side of the building. He was wearing a suit without a jacket, so he looked as if he had just come out from the office. At the rear of the building was a door with a proximity card access control. This door was used by the smokers who (as usual these days) had to visit a little shelter at the rear of the building to get their fix. When one employee finished her cigarette and walked back towards the door, Andy ran after her and, complaining about the weather, asked her to hold the door for him - which of course she did. He was then able to open the door from the inside and let me in. We then played our assigned roles - Andy was the employee and I was the consultant, there to conduct a security audit (of course!). We found the usual suite of meeting rooms and selected one which was empty. Within a couple of minutes I had hooked up my laptop to a network port in the floor, obtained a DHCP address and started my network discovery software. After an hour or so, some genuine employees arrived to use the meeting room - we of course apologised for the double booking and found ourselves another empty room. In total we were on site for five hours and able to grab just about anything we wanted from the network. We were never challenged or asked to show a badge, and at the end of the day we left by the same route we came in. Game over.

There really is no substitute for the "human firewall" and there's definitely no patch for ignorance (it is ignorance, not stupidity in many cases, you know). Using the results of this type of exercise demonstrates to everyone how easy this devastating style of attack can be, and allows the organisation to start the difficult process of security awareness education. And they not only have to educate the office staff, they have to educate the IT folks and the senior managers and board members too.