News: 1597302370

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

You weren't hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It's far simpler than that

(2020/08/13)


The continued inability of organizations to patch security vulnerabilities in a timely manner, combined with guessable passwords and the spread of automated hacking tools, is making it pretty easy for miscreants, professionals, and thrill-seekers to break into corporate networks.

This is according to the penetration-testing crew at Positive Technologies, which pored over the results of its 2019 client audits

[1]PDF

and found that 71 per cent of the time – 20 out of 28 pentest contracts – its red team was able to get into their target using tools and tricks available to script kiddies and newbies.

"It is not that unskilled hackers are using methods that more skilled criminals would not need," Ekaterina Kilyusheva, head of Positive Tech's Information Security Analytics Research Group, told The Register last night. "But in most cases, attack complexity was low, meaning that the attack was within the capabilities of a middling hacker with basic skills."

The crews found that bugs in web apps for which patches exist yet were not applied were a particularly easy way to break into networks. In 77 per cent of the cases, web app vulnerabilities and configuration flaws allowed the red teamers to crack a company's defenses; in one case, it took [2]as little as 30 minutes to pwn the target.

These were not exactly obscure, easily overlooked flaws, either. About 60 per cent of the web application holes used were deemed critical – think remote code execution – and should been patched as soon as possible, while mindful of the need for testing and deployment planning. Another 11 per cent were deemed high-risk vulnerabilities, again bugs that would ideally be addressed ASAP.

Pen Test Partners: Boeing 747s receive critical software updates over 3.5" floppy disks [3]READ MORE

The second most common method of break-in was weak login credentials. In those cases, brute-forcing passwords for database management and remote access software worked pretty well. Brute forcing is easy to block yet time and time again it's forgotten about by admins.

What's more, in most of the cases, an attacker did not need to do much, beyond gaining an initial foothold, to command full internal network access: in 68 per cent of the trials, the infiltrators only needed to take one or two steps to have the entire organization at their fingertips. Network compartmentalization, and access controls limiting who can see what, may have helped minimize intruders' reach.

While point-and-pray automated hacking tools – scanners, frameworks, toolkits of exploits, and the like – are easy enough to find and use against targets, you don't always need something that fancy. Positive noted that in seven of its 28 tests, the red team was able to break into web applications using a simple timing attack with the Autodiscover service in Microsoft Exchange Client Access Server.

There were a few success stories to be found. Positive said that in two of its 28 tests last year, the red teamers failed completely to break into the target company's network. The average test time, both for the successful and unsuccessful tests, was around four days (including the aforementioned 30 minute speed run.)

The report shows that performing what some assume is the minimum of effort – timely patching, login monitoring, and network segmentation with access limit policies, for instance – can be rather effective at keeping at least opportunistic crooks out.

"To secure the network perimeter, the first step is to follow basic information security rules," said Kilyusheva. "Web applications are the most vulnerable component on the network perimeter. Companies should perform security analyses regularly." ®

Get our [4]Tech Resources



[1] https://www.ptsecurity.com/upload/corporate/ww-en/analytics/external-pentests-2020-eng.pdf

[2] https://www.ptsecurity.com/ww-en/analytics/external-pentests-results-2020/

[3] https://www.theregister.com/2020/08/10/boeing_747_floppy_drive_updates_walkthrough/

[4] https://whitepapers.theregister.com/

It can hardly be called hacking ...

jake

... if the system has a huge sign on it that says "C'mon in!", now can it ... And especially not when there's a key under the welcome mat, the back doors are unlocked, and all the Windows are wide open.

Re: It can hardly be called hacking ...

Mike 137

This has been the norm for decades now. As a consultant I have rarely found any serious attempts at continuous management of security. "Policies" are written but not verified for efficacy or followed, and ISO 27001 certification is often obtained on the basis of an ISMS that exists only on paper or as electrons somewhere. Most corporate cyber security consists of a mission statement and pure luck so far.

Too hard, too frequent, too unreliable

Pete 2

> About 60 per cent of the web application holes used were deemed critical

It seems to me that the basic problem is that systems are not designed with upgrades and patches in mind. You can play the IT support conversation in your head.

Hi CIO, I.T. here. We need to take the whole corporate internet presence offline to perform a vital security patch

CIO But you did that last week!

No, that was the office system and that was because of a bug in the email server

CIO And the week before that

That one was the database

CIO Dang! So how long will we be offline

It's hard to say, in theory only 30 minutes but more likely an hour. If things go pear shaped maybe a week.

CIO I'm not signing off on that. Cant you check the patches on a non critical computer first?

We tried, but it failed. Our web suite is running version 4.10.122b and the test systems are at 4.10.121a so (obviously) it didn't work

CIO No, you'll have to wait until there are more bug fixes, then we will take the system down and install all of them

Don't you remember last November when we tried that and it took 2 weeks to restore the service?

CIO My mind is made up. We were sold this package on the basis of 99.999% uptime. That's a 25 second outage per month. You lot in IT blow through an entire year's worth of downtime every week. Find another solution

Re: Too hard, too frequent, too unreliable

Evil Auditor

While I partially agree, how about updating the test system to 4.10.122b first?

I wouldn't be too happy either to sign off a patch that hasn't been run on a test system.

Re: Too hard, too frequent, too unreliable

Flywheel

Update the test system?

Hmmm.. that could involve money for an updated licence so probably no.

Re: Too hard, too frequent, too unreliable

Doctor Syntax

" We were sold this package on the basis of 99.999% uptime."

And there's the flaw in the thinking. Start thinking in terms of useful availability and downtime. You're trying to manage for minimum loss of useful availability due to downtime. If downtime isn't planned - you had a hardware failure, you got hacked, whatever - then there's no guarantee of it falling into a time of minimum usage. Planned downtime can be arranged fro when it will have minimum impact and its purpose is to minimise the risk of unplanned downtime. But risk is harder to measure than uptime.

Re: Too hard, too frequent, too unreliable

Stumpy

Furthermore, if five nines (or even four nines) uptime is so important, you should have your systems configured for High Availability so you can take part of it down for the upgrade without affecting the remainder, then flip to do the other half once you've verified the upgrade works.

Frankly, having a complete outage on such a critical system (for performing updates anyway) is inexcusable.

Re: Too hard, too frequent, too unreliable

Giles C

The 5 nines uptime figure is all about availability not downtime.

So if you have have 2 sets of machines where either can handle the full load, you take set 1 down and patch/test.

Then bring that into production and repeat for set 2.

I have seen services run at 99.999% when components have been down for a couple of hours that week for patching, because this was planned maintenance work.

Ah, now I get it

Pascal Monett

All those major companies that get hacked, proclaim that customer data security is their #1 priority and then claim to have installed "top level" security measures, they're just installing the patches now.

Well, if you need to be hacked to get the idea, so be it.

jezza99

In a corporate environment this is a hard to solve problem.

At home I patch now and ask questions later, as is best practice.

But in my last employer they were dependent on software by vendors who did not get computer security at all. And some of them are big names in the field. We were forced to run versions of MacOS and others that we knew were insecure as a result.

Then there’s Windows and Active Directory. Do they support dictionary checking passwords out of the box now? If not, why not?

If I have not seen so far it is because I stood in giant's footsteps.