Feeling bad about your last security audit? Check out what just happened to the US Department of Interior
(2020/09/17)
- Reference: 1600386435
- News link: https://www.theregister.co.uk/2020/09/17/dot_pentesers_expose_wifi/
- Source link:
The US Department of the Interior (DoI) spectacularly failed its latest computer security assessment, mostly for a lack of Wi-Fi defenses.
This is according to a [1]report [PDF] from the department's inspector general (via [2]NextGov ) which found that, among other failings, the DoI internal wireless network could be broken into over the air using a smartphone and less than $200 of gear stuffed into a backpack.
For those unfamiliar, the Department of Interior manages America's natural parks, government-owned lands, and services for indigenous people. It is a massive organization with about 70,000 employees spread around hundreds of different programs.
"These attacks — which went undetected by security guards and IT security staff as we explored department facilities — were highly successful," the penetration-test report noted. "In fact, we intercepted and decrypted wireless network traffic in multiple bureaus."
In short, a red team set up malicious wireless access points that masqueraded as legit Wi-Fi base stations, aka evil twins, and used these to harvest network credentials from unsuspecting users who connected to the gadgets. Thus federal staff joining what they thought were proper wireless networks were connecting to bogus ones that collected their login details.
Using this information, the would-be baddies then logged into internal accounts for two bureau offices. The probers then gained access to the department's enterprise services network, which handles communications between bureaus. From the report:
Our evaluation revealed that the Department did not deploy and operate a secure wireless network infrastructure, as required by the National Institute of Standards and Technology (NIST) guidance and industry best practices. We conducted reconnaissance and penetration testing of wireless networks representing each bureau and office.
To do this, we assembled portable test units for less than $200 that were easily concealed in a backpack or purse and operated these units with smartphones from publicly accessible areas and locations open to visitors. Our attacks simulated the techniques of malicious actors attempting to break into departmental wireless networks, such as eavesdropping, evil twin, and password cracking.
Here's what those units – containing unspecified hardware but likely some kind of Wi-Fi-enabled RaspberryPi-like gizmos attached to batteries – looked like:
[3]
One of the wireless test units and when placed in a bag ... Source: US government. Click to enlarge
The infosec experts also noted other security shortfalls, such as a lack of network segmentation that allowed the intruders to casually move between systems.
"Without network segmentation, an attacker, once inside a bureau’s network, can pivot to other bureaus and their computer networks without restriction or detection," the red team explained. "Credentials collected by evil twin attacks can be used to grant further access to Department and bureau systems."
Ultimately, the pen-testers said, the department's failings came from the top down. Many of the branch offices, it is said, were not given guidance on how to keep their networks secure. A lack of attention to basic security practices cleared the way for outsiders to harvest user credentials, and gain access to the inner-workings of the US government with nothing more than a backpack of electronics from Amazon.
You weren't hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It's far simpler than that [4]READ MORE
"The department’s contradictory and outdated guidance, incomplete inventory, and lack of technical security testing led to its implementation of insecure wireless networks," the report thundered. "We exploited vulnerabilities in the protocols used to authenticate individuals using unique user credentials and those using pre-shared keys. In addition, we gained more access than necessary because the Department did not follow the principle of least privilege and did not have the proper defense-in-depth security controls."
What's worse, the red teamers said they could have done more theoretical damage had it not been for bureaucracy getting in the way. Get these peeps a few more laptops and some expense accounts, stat.
"We were unable to perform additional planned tests due to the lack of a reliable inventory," they noted. "We were also limited in our ability to focus our testing on high-risk networks."
While the watchdog's report involves a government IT setup, its findings and recommendations should be noted by private organizations, particularly those that do contract work for Uncle Sam. Multiple attacks on governments have been carried out by first targeting the networks of contractors. ®
Get our [5]Tech Resources
[1] https://www.doioig.gov/sites/doioig.gov/files/FinalAudit_WirelessNetworkSecurity_Public.pdf
[2] https://www.nextgov.com/cybersecurity/2020/09/interior-ig-team-used-evil-twins-and-200-tech-hack-department-wi-fi-networks/168521/
[3] https://regmedia.co.uk/2020/09/17/public_domain_doi_bug.jpg
[4] https://www.theregister.com/2020/08/13/pentest_networks_fail/
[5] https://whitepapers.theregister.com/
This is according to a [1]report [PDF] from the department's inspector general (via [2]NextGov ) which found that, among other failings, the DoI internal wireless network could be broken into over the air using a smartphone and less than $200 of gear stuffed into a backpack.
For those unfamiliar, the Department of Interior manages America's natural parks, government-owned lands, and services for indigenous people. It is a massive organization with about 70,000 employees spread around hundreds of different programs.
"These attacks — which went undetected by security guards and IT security staff as we explored department facilities — were highly successful," the penetration-test report noted. "In fact, we intercepted and decrypted wireless network traffic in multiple bureaus."
In short, a red team set up malicious wireless access points that masqueraded as legit Wi-Fi base stations, aka evil twins, and used these to harvest network credentials from unsuspecting users who connected to the gadgets. Thus federal staff joining what they thought were proper wireless networks were connecting to bogus ones that collected their login details.
Using this information, the would-be baddies then logged into internal accounts for two bureau offices. The probers then gained access to the department's enterprise services network, which handles communications between bureaus. From the report:
Our evaluation revealed that the Department did not deploy and operate a secure wireless network infrastructure, as required by the National Institute of Standards and Technology (NIST) guidance and industry best practices. We conducted reconnaissance and penetration testing of wireless networks representing each bureau and office.
To do this, we assembled portable test units for less than $200 that were easily concealed in a backpack or purse and operated these units with smartphones from publicly accessible areas and locations open to visitors. Our attacks simulated the techniques of malicious actors attempting to break into departmental wireless networks, such as eavesdropping, evil twin, and password cracking.
Here's what those units – containing unspecified hardware but likely some kind of Wi-Fi-enabled RaspberryPi-like gizmos attached to batteries – looked like:
[3]
One of the wireless test units and when placed in a bag ... Source: US government. Click to enlarge
The infosec experts also noted other security shortfalls, such as a lack of network segmentation that allowed the intruders to casually move between systems.
"Without network segmentation, an attacker, once inside a bureau’s network, can pivot to other bureaus and their computer networks without restriction or detection," the red team explained. "Credentials collected by evil twin attacks can be used to grant further access to Department and bureau systems."
Ultimately, the pen-testers said, the department's failings came from the top down. Many of the branch offices, it is said, were not given guidance on how to keep their networks secure. A lack of attention to basic security practices cleared the way for outsiders to harvest user credentials, and gain access to the inner-workings of the US government with nothing more than a backpack of electronics from Amazon.
You weren't hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It's far simpler than that [4]READ MORE
"The department’s contradictory and outdated guidance, incomplete inventory, and lack of technical security testing led to its implementation of insecure wireless networks," the report thundered. "We exploited vulnerabilities in the protocols used to authenticate individuals using unique user credentials and those using pre-shared keys. In addition, we gained more access than necessary because the Department did not follow the principle of least privilege and did not have the proper defense-in-depth security controls."
What's worse, the red teamers said they could have done more theoretical damage had it not been for bureaucracy getting in the way. Get these peeps a few more laptops and some expense accounts, stat.
"We were unable to perform additional planned tests due to the lack of a reliable inventory," they noted. "We were also limited in our ability to focus our testing on high-risk networks."
While the watchdog's report involves a government IT setup, its findings and recommendations should be noted by private organizations, particularly those that do contract work for Uncle Sam. Multiple attacks on governments have been carried out by first targeting the networks of contractors. ®
Get our [5]Tech Resources
[1] https://www.doioig.gov/sites/doioig.gov/files/FinalAudit_WirelessNetworkSecurity_Public.pdf
[2] https://www.nextgov.com/cybersecurity/2020/09/interior-ig-team-used-evil-twins-and-200-tech-hack-department-wi-fi-networks/168521/
[3] https://regmedia.co.uk/2020/09/17/public_domain_doi_bug.jpg
[4] https://www.theregister.com/2020/08/13/pentest_networks_fail/
[5] https://whitepapers.theregister.com/
Good enough for me
The same attack would work at my house and expose my mother's house as well.
So how does that Deep State stuff work anyway?