4 ms·
So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at
by kovrik 8y ago
So the attacker gets autoresponse. What's next? What is the attack vector here?
UPD: also, I guess any attacker could just assume that you're Out of Office at night time.
- toomuchtodo 8y agoEDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely to work as the org scales up in size (think enterprises with their own helpdesk). Once you have email and/or other federated access, you have a toehold. Bonus points if you've cloned their work cell SIM or have rerouted SIP for their desk phone to keep them out of the loop. I have seen weaker phishing attacks on financial/accounting staff who have the authority to move millions of dollars of corporate funds. EDIT: > Whom the would-be attackers send this email to? Phishing target > Do they send this email from their own email address? Throw away address or spoofed address from a familiar-to-the-business domain. > Is there an assumption that sysadmin/support team will blindly reset a password on someone else's request? This is one assumption. > How do attackers bypass corporate VPN? VPN access might not be required to obtain the level of access desired. Do all of your SaaS providers require 2FA? Your business bank accounts?
- kovrik 8y agoSorry, still not clear to me. - Whom the would-be attackers send this email to? - Do they send this email from their own email address? - Is there an assumption that sysadmin/support team will blindly reset a password on someone else's request? - How do attackers bypass corporate VPN?
- vegannet 8y agoAny organisation where “hey I forgot my password, can you reset it?” from an unknown email address is an attack that has chance of success is an organisation where there’s dozens of major problems long before you get to auto-responders identifying who is away from the office.
- toomuchtodo 8y agoYou're assuming I can't hop on the phone (appearing to come from a known number using Caller ID spoofing, using LinkedIn to get a general idea of the org chart) and bluff my way through it with your underpaid, overworked help desk staff. People are the weakest link. This is only a few steps above Indian scammers taking remote control of users’ computers and convincing those users to send them hundreds of dollars of gift cards to prevent legal action by the IRS. Consider your average user, not the HN participant. https://www.youtube.com/watch?v=YVqurfWzB-Q https://www.youtube.com/watch?v=YVqurfWzB-Q (Hacking Humans : Social Engineering Techniques and How to Protect Against Them - Stephen Haunts)
- vegannet 8y agoWe are arguing different points. I’m saying _if_ an organisation _is_ insecure enough for social engineering to work then a vacation auto-responder is not going to represent any meaningful increase in risk.
- toomuchtodo 8y agoI am arguing that _most_ organizations are insecure enough for social engineering to work, and that autoresponders are yet another vector. Orgs that observe proper operational security are still a minority.
- albedoa 8y agoYes, we know what you are arguing. And if auto-responders are yet another vector for an org, then it does not represent a meaningful increase in risk.
- kovrik 8y agoI agree with you that under these circumstances autoresponses could be a security risk. But then I'd better fix the underlying security problem(s) and let everyone use autoresponders if they wish to.
- kryogen1c 8y ago> Impersonate the person out of town to escalate to their privilege level. > Imposter: "My password isn't working, can you help me reset it?" This doesn't have anything to do with being out of town or autoresponses.
- Too 8y agoIf attacker gets info you are out of office for 2 weeks it most likely also means you are traveling and out of home for 2 weeks. Perfect opportunity for burglary. This is not a hypothetical scenario, almost every year there is some idiot saying they going for vacation in those mini-interviews in the local newspaper and then they get their house broken into. However the probability that someone does email you and is a burglar at the same time is extremely small.