Babadook: Connectionless, Persistent Powershell “Backdoor”
wroot.org
wroot.org
Plus if you don't know who is entering your room you don't have a problem with the keyboard but with your door lock. And if one team member is going rogue, well, he already has the passwords.
If the company has decided that computers need to be locked when away from keyboard there will be a policy and procedure for reporting and dealing infractions. This won’t be it. While in this case the program might have been mostly harmless, one never knows when a programming error might spin things out of control. It’s clever, funny to some, but if it accidentally resulted in downtime the stuff the flows downhill would come fast and be unpleasant in some organizations. Plus, annoying your teammates isn’t the best idea long term. I know this may seem harsh, but from my experience organizations with the most need for this security would be the least likely to approve of this method.
I think people are too focused on working for military and paranoïa, we need a range of behaviors, from the paranoid to the welcoming, that guy watching your screen could start an interesting discussion about your project, and give you the contact to the right person to help you. You don't want that in a military context, you highly desire it when you're building a vegan pet food marketplace for hipsters.
Not everyone needs to develop like in Aerospace, not everyone needs to develop like in video games, not everyone needs de behave like a NSA agent, and not everyone needs to behave like a farmer's market salesman, we need a range of behaviors.
And whatever the policy, you never, ever, let co-workers be dicks to each others, no "pranks", no public shaming, no sending a prank email from each other's computer. If security is really an big issue, then not locking a computer is a strike, it goes between the boss, the offender and HR, not a matter of joke.
Security is a trade-off, but things like locking your machine are so trivial and painless that they should be routine for everyone, no exception.
That said, I use padlock[1] on my laptop, especially in 'hostile' environments and I'm pretty happy with it.
Maybe you have a new hire in the office building, or a visitor, or the janitor.
It is good practice to always lock your machine. But yes i do agree that he is very lucky that upper management was awesome in this scenario.
--
At my last office job we would just flip the mouse buttons, and rotate the display screen. This proved to be very effective, and didn't cause issues with the team.
In this instance, the coworkers don't seem to be particularly clever, or even worried about security. They were terminating the powershell process, which was obviously doing unauthorized actions, then proceeding as usual? Who does that?!
For the company in question, security seems to be very important as shown by the fact that each computer sits on its own VLAN. Maybe they should consider using something like wireless tokens that lock the workstation if the token is too far away (e.g. http://www.gkchain.com).
I've also worked in companies where lots of doors require a key card, which also unlocks the computer (by means of a card reader at the workstation). So if you leave the room, you take the card with you anyway and the computer gets locked automatically.
I like this story in that it's a bit of coworkers policing themselves a bit. We have a similar situation in my workplace, where smartcard authentication is used. We're all taught to pull our cards when we get up from our desks, and this is followed pretty well. The odd email has gone out under someone else's name (usually with accompanying embarrassing text) but more often than not, we'll simply pull that person's card, hold onto it, and then enjoy the few minutes of panic as they try to determine if they lost it or not. Both the customer and the security officer are none too pleased when cards go missing, so it serves as a good reminder.
Long story short, watch and remind one another frequently of good security practices, and encourage others to as well. You may think you're being a jerk at first, but as more catch on and not only adhere, but help encourage those rules, it'll be less uncool to call them out and more uncool to deviate from them.
Interestingly, the author pretty much delivered half of a Malware Writer 101 here. I had to deal with methods like these when removing crap from non-tech computer users more time than I would like.
Any time he saw an unlocked and unattended workstation he would set the home page of the browser to a hard core porn site.
Then later after the person was back at the desk he would claim to need to check on something real quick. He'd fire up the web browser, and up comes the porn site.
Then he'd pretend to be all pissed off and start yelling at the person for browsing porn at work.
Eventually, he'd explain what happened and made his point.
If my boss did that, I'd probably quit. So yeah, I guess it's "effective".
Also, the IT provider has put a lot effort into security for a reason. The second any employee starts shell coding of any type, it becomes a risk to the company. Management, as always, is blind to this and is probably why they rewarded the author. What they should have done is fire the person for breaching the company's User Access policy. (You do have one, right?)
It may be the employees lunch hour, but it's not their right to abuse company property.
It really depends. All too often the reason for various restrictions IT set up is to limit their own workload. It sometimes goes to the point of making everyone else's work harder. It's especially irritating in schools and universities, where I could swear IT departments often live by the idea of "if we make a system X completely unusable, nobody will use it, so we won't have people breaking things".
Any and all restrictions are there to prevent risk, to both data security and operational costs. There's nothing worse than allowing a user to do as they please because as Bruce Schneier once said, "A user will choose dancing pigs over security every time."
This is why we work with management to show them the costs of allowing users the ability to roam free. Management makes the decisions, IT implement it.
Security is hard. It is highly invasive to usability. It's not your IT department's fault, it's actually yours.
I did a demonstrator a couple of years ago of why we should be using 2FA for everything. We added a single binary to the post-build event in Visual Studio and checked it and the binary into the VCS. The binary grabbed the person who did the build's Chrome password database and used powershell to POST it to a private address. Then we chucked it through some shareware that reads the file and mailed the password back to the engineer we were demonstrating it to.
It's pretty easy to backdoor a machine without even having console access.
Be careful people.
Often small changes can have huge benefits, the smallest effective security hack I can remember was a one word change:
We changed "last person to leave for x activates lock" to "first person to leave for x activates lock".
I can see the necessity of locking when you go home, so the maintenance staff does not have access, but presumably this happened during the day.
But primarily, it's not about distrust towards your cow-orkers - it's because not locking your workstation leaves you (and the company) vulnerable to external attackers that made their way to the office via acting confident. Social engineering is extremely effective and quite easy to perform, if you can keep your cool.
Yes, exactly this. Why is that surprising? Why bother with user accounts with audit trails; why not just use user:GUEST pass:GUESS for everything?
There's a bunch of places where you want to make sure that trusted employees are not gaining access to things they shouldn't. EG health care providers.
It's scary how many people don't take their machine's (or their network) security seriously.
I used to run reverse shells on machines that my coworkers left unlocked (easier as our network is more relaxed) - after launching annoying things they got the point very quickly and now nobody leaves their machines unlocked.
Deleted comment
This really shouldn't be considered a prank. He might have deserved it, I have no idea. I wasn't there. But that's playing with someone's personal life.