News: 1667346726

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

(2022/11/02)


Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials.

The cloud storage locker on Tuesday [1]detailed the intrusion, and stated "no one's content, passwords, or payment information was accessed, and the issue was quickly resolved."

"We believe the risk to customers is minimal," the biz added.

[2]

The security snafu came to light on October 13 when Microsoft's GitHub detected suspicious behavior on Dropbox's corporate account. GitHub let Dropbox know the next day, and the cloud storage outfit investigated. Dropbox determined it had fallen victim to a phisher who had impersonated the code integration and delivery platform CircleCI.

[3]

[4]

Dropbox is a CircleCI user "for select internal deployment." Dropbox employees use their GitHub accounts to access Dropbox's private code repos, and their GitHub login details also get them into CircleCI. You know where this is going: get a Dropbox engineer's GitHub login details by pretending to be CircleCI, use that information to get into the Dropbox GitHub organization, and then rifle through the private repos.

Interestingly, just three weeks before the attack, GitHub [5]warned of phishing campaigns that involved impersonation of CircleCI. Dropbox appears not to have got the memo, because in early October its staff were sent – and one or more bods fell for – emails that masqueraded as legit CircleCI messages.

[6]

"These legitimate-looking emails directed employees to visit a fake CircleCI login page, enter their GitHub username and password, and then use their hardware authentication key to pass a One Time Password (OTP) to the malicious site," Dropbox's explanation states. That site would harvest the entered login details so that miscreants could use the info and log into a victim's GitHub account, and get into the work repos.

This tactic "eventually succeeded, giving the threat actor access to one of our GitHub organizations where they proceeded to copy 130 of our code repositories."

[7]Dropbox unplugged its own datacenter – and things went better than expected

[8]Dropbox absorbs DocSend to add analytics, secure links to document sharing

[9]Alert: This ransomware preys on healthcare orgs via weak-ass VPN servers

[10]Gone phishing: UK data watchdog fines construction biz £4.4m for poor infosec hygiene

Dropbox doesn't appear unduly worried by the incident because the repos "included our own copies of third-party libraries slightly modified for use by Dropbox, internal prototypes, and some tools and configuration files used by the security team."

No code for core apps or infrastructure was accessed, apparently.

Dropbox also said the intruder's access to the GitHub repo silo was revoked on October 14, and that the cloud storage biz has since rotated all developer API credentials to which the intruder had access. The company also hired external investigators to review its findings and all have concluded no abuse of the copied code has been detected.

[11]

The company's write-up said it was already working to combat this sort of incident by upgrading its two-factor authentication systems to WebAuthn multi-factor authentication and will soon use hardware tokens or biometric factors across its entire environment. That effort has been accelerated in the wake of the attack.

Dropbox apologized for the brouhaha and promised to do better – but signed off by stating the biz's security team believes it is inevitable some phishing attacks will succeed, even with the best technical controls in place. ®

Get our [12]Tech Resources



[1] https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2H5cot9ElXAvcFX1v-dkwAAAQM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2H5cot9ElXAvcFX1v-dkwAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2H5cot9ElXAvcFX1v-dkwAAAQM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://github.blog/2022-09-21-security-alert-new-phishing-campaign-targets-github-users/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2H5cot9ElXAvcFX1v-dkwAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/04/27/dropbox_unplugged_datacenter/

[8] https://www.theregister.com/2021/03/09/dropbox_buys_docsend/

[9] https://www.theregister.com/2022/10/24/cisa_fbi_daixin_ransomware/

[10] https://www.theregister.com/2022/10/25/gone_phishing_uk_data_watchdog/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2H5cot9ElXAvcFX1v-dkwAAAQM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Cecil, you're my final hope
Of finding out the true Straight Dope
For I have been reading of Schrodinger's cat
But none of my cats are at all like that.
This unusual animal (so it is said)
Is simultaneously alive and dead!
What I don't understand is just why he
Can't be one or the other, unquestionably.
My future now hangs in between eigenstates.
In one I'm enlightened, in the other I ain't.
If *you* understand, Cecil, then show me the way
And rescue my psyche from quantum decay.
But if this queer thing has perplexed even you,
Then I will *___and* I won't see you in Schrodinger's zoo.
-- Randy F., Chicago, "The Straight Dope, a compendium
of human knowledge" by Cecil Adams