5 ms·
If the term Credential Stuffing is new to anyone, we’ve done a deep dive into what it is and the tools that are used here: https://breachinsider.com/blog/2017/c
by graystevens 8y ago
If the term Credential Stuffing is new to anyone, we’ve done a deep dive into what it is and the tools that are used here: https://breachinsider.com/blog/2017/credential-stuffing-how-breached-credentials-are-put-to-bad-use/ https://breachinsider.com/blog/2017/credential-stuffing-how-...
We saw this pretty regularly at my old job, with attacks almost daily. They range from ‘script kiddie’ who just use the default tool settings and do it all from one IP making it easy to spot, to persistent attackers who would play cat and mouse with our live defences. They’d switch IPs using huge proxy lists found online every few minutes, as well as learn our alerting thresholds and attempt to fly just under the radar. For some reason though, they always seems to user UserAgents that were ancient, or weren’t real, allowing us to identify attack traffic compared to our normal user activity.
- namibj 8y agoDid you try to find attackers in the set of unconspicious UAs? If you did not try hard to look for more skilled adversaries, expect some to be hiding from your analysis. Once you don't see anything in a large range of skill/sophistication, you can assume there to be no adversaries that don't have the ability to pull a Stuxnet off. And if you need to guard against those, and have the ressources to do so, you already know this.
- graystevens 8y agoAgreed, based on other thresholds and alerts, we certainly saw some more advanced actors - using in-country home broadband lines to conduct the attacks. This made tracking and blocking them much harder, as there was a risk of blocking genuine customers who simply didn’t conform to our idea of ‘normal’. We ended up finding another way to fingerprint them, but thank you for calling that out, as you are entirely right that there is almost always someone trying to be truly covert. If anyone is suffering with these types of attacks (or isn’t and you think you’re missing something) feel free to reach out, more than happy to help - email is in my profile
- namibj 8y agoI hope you have more than one distinct way to identify these more sophisticated attacks, as you would want to be able to ensure there are no others that are only a few steps better than them. As said, you need to vet a range of sophistication above the most sophisticated example you actually encountered, to assume there are no others that you could reasonably detect with the techniques you could deploy. Always make sure to know you'd see anyone who is only one level better than the best you encountered, where the size of such a level should be estimated from the density you see in the distribution of attacks. You are also good if you don't automate defense with the best detection you have, so that you prevent an attacker from automatically judging the quality of your detection capabilities with you then believing the attacker got stopped when he just deployed a technique you can no longer see. I.e., make sure you don't alert an attacker that you can still see him when you are just barely still able to do so, as you would not want him to up his camouflage to the point where you won't see him anymore.
- jstarfish 8y agoUAs are often hardcoded into compiled malware binaries that get shared/leaked amongst actors and groups. Latter users dont have access to the source so at best all they can do is dick around with hex editors and maybe change a character or two instead of the whole string.