Hackers hide credit card stealing script in favicon metadata
bleepingcomputer.com
bleepingcomputer.com
In a hypothetical scenario, what would I need to learn to be able to pull something like this off, from conceiving of it to actually executing it?
As far as conceiving the attack, you would just need to "think outside the box", as much as I hate that expression. These attacks are derived from someone thinking "Huh, I wonder if this would work" about some crazy idea, and then trying it out.
As far as execution, if I were running this attack I would probably set up a site like [1] (No endorsement, this is just the first thing that popped up in a search). I would take peoples pictures, spit out their favicon, along with the JS embedded in the exif data. They would then put it on their site, and wind up serving it to their customers.
[1] https://www.favicon-generator.org/
edit: forgot to actually link the site.
The entry point of the attack vector is interesting though. I wouldn't have considered a third-party service "innocuously" causing the problem as I was trying to think of a sexier direct exploit into the website's system.
Indeed. Honestly, I only realized it because I saw that site when I looked up favicon. Otherwise, I would have been doing the same thing.
Disclaimer: I'm not particularly good at this, so whatever comments I make are well intentioned but may be of varying accuracy.
...
Online sources: * OWASP.org is a good place to find info. If you look something up, there's a good chance you will find it here.
* https://owasp.org/www-project-web-security-testing-guide/ Thanks to redis_mic for this one, I didn't know it existed until today.
* overthewire.org Similar to HTS, but you don't need an account. The subject matter covered is also slightly different.
* https://0x00sec.org/ A forum dedicated to security. There's a lot of script kiddies, but also some gold.
* https://www.hackerone.com/ What better way to learn then practice on live targets? That being said, I would do some of the others first.
...
I do a lot of learning through reading, so books:
* Network Security Assessment by Chris McNab. I have second edition, which is a good and instructive read, but quite outdated.
* Real-World Bug Hunting by Peter Yaworski. Web security 101. Good read, and fairly useful.
* Advanced Penetration Testing by Wil Allsop. Outdated, but interesting. You will never use flash again after reading this.
* Social Engineering, The Science of Human Hacking by Christopher Hadnagy. This is a very interesting read. Also, one of the few that can't go out of date.
...
This should be enough to get you started. There's a couple more books I can think of, but they tend to be more specialized into certain fields of security and less approachable/generally applicable. If you want these recommendations as well, feel free to email me, my email's in my bio.
2) The OWASP guide is a good HOWTO.
3) During daily work, ask yourself, "How would I get around this?"