Canary Tokens
canarytokens.org
canarytokens.org
In light of the LastPass breach, it seems like it would be useful if someone had created a few LastPass vaults and seeded them with some canary tokens (and probably canary crypto wallets), so if any of those tokens or wallets were used, it would almost certainly indicate that attackers had breached LastPass and successfully cracked vault passwords.
Any devs want to volunteer? I don't know shit about how to make it work.
EDIT: If anyone wants it and promises to do something like the post above suggested I will transfer the domain, I really did buy it.
EDIT 2: canarychecker.com is the one I registered.
Domain - canarychecker.com 1 year registration $12.00
I immediately thought of a concern which is already highlighted in their FAQ:
> What if attackers blacklist the canarytokens.org domain? Doesn’t that work?
> This would work! That’s why we suggest that you download the canarytokens docker image and run your own server. (You can grab the source to build it yourself from here)
This seems like something that could be highlighted more prominently, since the main site makes it so extremely convenient to use a hosted token (where some knowledgeable attackers can avoid triggering the canary).
Moving that item up to be more prominent does sound like a good idea though
But for the manual ones, like opening a link - it'd probably be better to host them at a much less suspicious sounding domain.
I would bet money that multiple governments already do.
KEK.
So just unpacking an archive and browsing the directory structure in Explorer is a threat to your privacy.
A dozen canary tokens will probably get your security detection program alot further than your first $2M of splunk license
~/.login contains the line:
/usr/local/sbin/sms ...
... where 'sms' calls the twilio API like this:
/usr/local/bin/curl -s -X POST -d "Body=$msg" -d "From=$from" -d "To=$to" "https://api.twilio.com/2010-04-01/Accounts/$accountsid/Messages" -u "$accountsid:$authtoken"I don't doubt they can be useful but I suspect they aren't really used that much
One day, I got a notification the coins have been moved. After realising it wasn't a false positive, I immediately disconnected and imaged the PC, and sure enough, deep investigation found malware.
Small price to pay, as it alerted me to rotate all passwords and sessions, and alert the community about the compromised executable.
To this day, I keep some crypto on every device I use. If not breached, it doesn't cost me anything.
I even have a paper wallet in my physical wallet.
This is just a brilliant principle: Provide some low hanging, easy to identify, inexpensive fruit for thieves, to protect higher hanging fruit.
It could be used instead of more formal rewards for encouraging white hackers to report vulnerabilities: just let everyone know your outer ring of security has a wallet.
Even if more sophisticated hackers would skip the wallet, you are much more likely to find out vulnerabilities if hackers of all shades know there is honey for the taking.
It's related to a home security tactic I heard of: keeping a "pocket change" tray visible on a table just inside your front door, with coins and a few bills.
The theory being that, if a burglar sees it, they'll probably at least grab the bills.
When you enter, if the bills are missing, there might be a burglar still in the house.
Do you know if the $500 was moved 'automatedly' or by a human? If the former, makes you wonder if $0.01 would do it. (I guess network fees don't matter since you'd still see it pending on the block chain and that's good enough)
Within 1 year I found a breach on a developers box and another on a frontend server.
She had the balls to get mad when I yelled at her for it.
Some people don’t know how lucky they are to be in this world.
Edit: it was a first date. She never had physical access.
I got the impression using wifi in airplane mode paired with years of exchanging numbers at hacker cons and academic events influenced my matches in some odd ways.
(Such as having someone freak out you have a weed card and might not forget they do too if that’s the reason you can’t get a job)
Anyways I thought she was just some random divorcè but she worked for the local FFRDC
Edit: it also may have been a catfish who got annoyed I had no idea who the person she was impersonating was absent being fourth author on something outside my area of expertise
Or maybe participating in a dating CTF?
Every screenshot in my screenshots folder had the time created date edited on 1/6 so I suspect someone owned my laptop.
My phone otoh I trust more since Apple signs the code, the diary wasn’t there.
It's like placing unlocked safes all over your (locked) house with stuff that looks valuable to thieves. You know it's worthless so you never touch them. If a thief does however, you will know immediately. The overlap with honeypots here can be a bit fuzzy I guess.
In /etc/pam.d/sshd I set this, which then emails me.
session optional pam_exec.so seteuid ~/login-notify.shSomeone needs to open a document for the canary token to trigger. Even the smallest company with M365 gets MSIP (formerly Azure Information Protection), if you classify your docs right, only people who own or have been shared the document can decrypt it and even without a good classification, you get logs of any M365 document being opened, so why can't I just have a regular but public doc everywhere and monitor when it gets opened from external IPs, user agents,etc....
I struggled to show value for this. Honehashes are more interesting for me: https://github.com/EmpireProject/Empire/blob/master/data/mod...
A separate container monitors all traffic returned by the databases and if those tokens are detected, the databases are essentially shut down by disabling the port of the database until it is manually unlocked again.
Funnily enough, I was working at an auction platform and a few times the databases stopped responding. Everyone way furious until I shared why the databases stopped responding.. :-)
Says he got around Google and MS flagging his CV as malware which I'm unsure how.
I discovered that one of the major 2FA code SMS delivery gateways was actually susceptible to Log4j, where I could have potentially gotten a shell on their were, were I to have made an effort to. That could have allowed me to intercept all 2FA codes from major financial institutions that utilized the service to deliver 2FA codes to their customers.
On the underground fraudsters would have paid handsomely to be able to get past 2FA on accounts they had stolen creds for, without even having to SIM swap.
It goes to show how these services can be used for many purposes, offensive and defensive.