Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders
krebsonsecurity.com
krebsonsecurity.com
Here is an example of one in node where I set up an endpoint /admin to both redirect back to the homepage and set a cookie that says key: authz value: unset
That should be enough to turn up in any kind of automated scan looking for endpoints they could attack.
I then (not shown in the pic) set up a piece of middleware that looks for anyone coming in with a cookie that has the key of authz and the value of anything besides unset because that’s the moment I will know that this is no longer an automated scan and that I should probably look into this so it hooks up directly with my cloud providers security alerting system and that takes care of the rest like showing me all the activity associated with that IP address etc.
Here’s the code if anyone is interested. It’s a super high signal to noise ratio and easy to build. https://media.infosec.exchange/infosecmediaeu/media_attachme...
To top it off, we should have the phone's UI around this photo (so clock and 2% battery on the top left, network name on the top right...).
TLDR: Ransomware does reconnaissance on infected computers, invest in canary tokens!
But the concept is interesting and sounds reasonable, and is novel (to me anyway). I'm assuming Krebs deems this worthwhile to share and he has sufficient cred not to instantly assume this is content marketing.
One of the reasons are discussed here: https://news.ycombinator.com/item?id=29911195
The rest of this is security theater brought to you by Kevin McAllister. A trap needs to either contain or kill the prey to be effective. Canary objects do neither and are a waste of fucking time; if the predator isn't interested in your bait enough to trip anything, you're going to assume you're safe when in reality you just failed to anticipate their behavior and appetite. The competent ones already know to check for sandboxed environments.
There are only so many ways in and out of your environment. Anybody intruding got in somehow, and will attempt to exfiltrate something or call home for payloads or further instructions at some point. Be the apex predator-- look up. Position yourself to stalk them from above by getting your network logs in order and implementing DPI. Be able to account for where the intruder came from, where they went, and how they exited. Your CISO will ask you these questions when you report that there was an intrusion. Being able to identify which canaries were molested provides zero actionable intelligence.
I’ve never heard anyone talk about them this way and I say this as someone who is also a bit skeptical of them but things like your last sentence just don’t compute with me at all.
I’m kind of curious as to what you see their role as to begin with?
Forgetting to look up means missing out on the world around you.
Also you need to avoid the drop bears. They’re vicious.
I was on the beach in preschool, and just walking along the sand, enjoying my day, and gazing at the sky, because what obstacles could there be on a flat, sandy beach?
Well, apparently I stepped on a jellyfish or something. It was a big deal and everyone made a scene and I remember having no pain or ill effects from the thing at all. My foot was fine.
But I never heard the end of the incident because my mom shamed me for years about staring up at the sky and not watching where I was going. So I basically developed a downcast gaze where I scrutinized every inch of the sidewalk as I strolled along. Sad.
Is it normal for the security team to be hated at a company?
If you don't get hacked, everything we asked you to do was a waste of time and resource. If you do get hacked, we were incompetent.
Our security team also engages in social engineering - making practices deemed insecure gradually more and more difficult through artificial roadblocks (e.g., adding y/n dialogues to commands that previously had none). Doesn't do a whole lot to build goodwill
One good way to communicate and discuss security requirements is using threat models. A nice data flow diagram or architecture diagram showing the threat actor and attack vector helps a lot, along with any controls that exist.
Unfortunately, security often doesn't seem to feel the need to explain themselves or discuss anything if they have a magic edict to wave about. I think that's a mistake, we should try to bring people along with us. And even find out we were wrong occasionally!
Sounds like better PR might be in order. If you're quietly averting disaster that's not enough, you have to make sure people are aware of that. Easier said than done, I know.
In that kind of environment making assumptions like that could often mean the difference between jail or not in some cases. If it were me… I’d certainly see what I could find out about the binary before I ran it.
However I do think trying to make the sha256sum and or strings binary to both work and log (ideally silently and externally) would be a neat idea.