News: 1712765707

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

SharePoint logs are easily circumvented and Microsoft is dragging its heels

(2024/04/10)


SharePoint users should beware since audit logs on the platform have proved relatively simple to circumvent, meaning malicious actors could exfiltrate your data without tipping off your security team.

If you're hoping that Microsoft will act quickly to fix the matter, don't. [1]According to bug hunters from Varonis Threat Labs, who reported the matter to Redmond in November, it's been deemed a moderate security issue and is waiting in the "patch backlog program" to be addressed at the Windows maker's convenience.

"We're aware of this report and our customers do not need to take action. We have confirmed that the product is performing as expected, by detecting a file accessed and reporting that through the audit log," a Microsoft spokesperson told The Register .

[2]

"Security products and vendors should be using FileAccessed, FileDownloaded, plus two potential sync-related signals, FileSyncDownloadedFull and FileSyncDownloadedPartial audit events to monitor for file access."

[3]

[4]

In short, you're on your own, so best figure out how to make good use of the relatively poor state of SharePoint download logs.

SharePoint "download logs are unreliable and easy to bypass," Varonis said, reporting it found two fresh methods of doing so. These trick the platform into logging downloads of SharePoint files as access or file sync events. Both actions, Varonis noted, involve file downloads but neither are logged as such.

[5]

The first method, which triggers a file access log entry, involves opening SharePoint files in an app on a machine, which creates a local copy but isn't recorded on the system's server as a download. If an attacker writes a PowerShell script that combines this with a SharePoint client object model, the team suggests, then they can download data to their heart's content.

"This script can be extended to map an entire SharePoint site and, using automation, download all the files to the local machine," the Varonis team said. "While this method does not generate download logs, it does create access logs, which can be used to detect such activities."

[6]Microsoft called out as big malware hoster – thanks to OneDrive and Office 365 abuse

[7]Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew

[8]Microsoft 365 guest accounts + Power Apps = security nightmare

[9]Oh, really? Microsoft worries multicloud complicates security and identity

The second method, which generates file sync logs instead, involves misusing OneDrive to sync SharePoint files, again replicating them to a local machine without any record of a file download. Key to making use of this method without triggering a "FileSyncDownloadedFull" log entry – which would give the game away to a smart security team – is altering the User-Agent used to handle sync events.

"By altering the browser's User-Agent, it's possible to download files via conventional methods, like the GUI or Microsoft Graph API, and have them appear in logs as sync event," the Varonis squad said. "This tactic is particularly effective if malicious file download detections are configured to ignore sync events."

Varonis noted that both of these exploits rely on misconfigured SharePoint permissions, which isn't reassuring given how common [10]this issue is in Microsoft's complicated ecosystem of apps. According to Varonis research

[11]PDF

, it's not uncommon for a tenth of a company's cloud data to be accidentally exposed to all employees, and thus anyone with malicious intent who manages to gain permissions as limited as those of a regular user.

[12]

Until Microsoft decides to patch the issue, Varonis recommends that SharePoint users review their systems for large amounts of access or abnormal audit logs that could signal trouble. There are still traces left behind when intruders use these exploits – you just need to know where to look. ®

Get our [13]Tech Resources



[1] https://www.varonis.com/blog/sidestepping-detection-while-exfiltrating-sharepoint-data

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZhcL@zWt3L4xvaWttn9xbgAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhcL@zWt3L4xvaWttn9xbgAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhcL@zWt3L4xvaWttn9xbgAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhcL@zWt3L4xvaWttn9xbgAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/10/18/microsoft_malware_brand/

[7] https://www.theregister.com/2024/01/12/microsoft_sharepoint_vuln_exploit/

[8] https://www.theregister.com/2023/08/10/microsoft_365_guest_accounts_power/

[9] https://www.theregister.com/2023/03/29/microsoft_mulitcloud_identities_risk/

[10] https://www.theregister.com/2021/08/23/power_shell_records/

[11] https://info.varonis.com/hubfs/Files/docs/research_reports/Varonis-The-Great-SaaS-Data-Exposure.pdf?hsLang=en&_gl=1*1i2hfln*_gcl_au*MTIxNjI5MDA2OC4xNzEyNjczODE1

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhcL@zWt3L4xvaWttn9xbgAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Zippy´s Sausage Factory

So Microsoft's reaction to a threat to a key product like Sh**epoint is "can't reproduce, who cares, lol"? Not a good look.

Charlie Clark

They just look at the reams of "satisfied" customers who have to put up with it and keep counting the dollars. It's a terrible product for customers but for Microsoft it does its job perfectly: stops them wanting to use something else.

When developers stayed up longer than the software

Notas Badoff

Looong time ago, a bug report noted that a famous database product had timers that would overflow at around 4 days uptime. And then crash the database. And Microsoft closed the report with "not a problem, working as designed". At the time, between the prevailing uptime spans of the database and underlying OS, staying up for 4 days was only a 'theoretical' possibility. So the database people shrugged it off.

Scott 26

I loathe SPO.... but when you are an MS shop, what it is the alternative? (semi-serious question)

Dan 55

MediaWiki? XWiki?

<sct> Anyone want the new supermount? :)
<klogd> whats new about it
<sct> klogd: It cleans whiter than white. :)
-- Seen on #Linux