10 ms·
Hackers went undetected in Citrix’s internal network for six months
- m3nu 7y agoSecurity is hard. On the upside, every breach is a chance to learn for everyone else. I hope they release more details on how it happened. Is there any blog or news that summarizes such post-mortem lessons? Could be a nice project to collect that.
- h2odragon 7y agoThere's always https://catless.ncl.ac.uk/Risks/ https://catless.ncl.ac.uk/Risks/
- m3nu 7y agoSubscribed. Also found https://securereading.com/category/news/latest-hacks/ https://securereading.com/category/news/latest-hacks/
- DiffEq 7y agoIt actually is not if you follow a strict Least Privileged model as a basis for your security architecture...But nobody does...not because it is hard, but because they don't understand it. Security is still based around looking for all the bad; it seems this defunct model will never die.
- inapis 7y ago>Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication. Wow. This simply reinforces the fact that humans cannot, and should not, be trusted with actively maintaining security of a system especially if there could be significant economic consequences. Would a password manager help in this? I don't know. Probably a hardware token which controls all and any access to a system. *Removed some ambiguous sentences.
- Godel_unicode 7y agoI was with you up until the last paragraph, but no. That's not 2fa, that's switching one factor for another. People should use a password manager with an rng to generate and store passwords. IT departments should run password spraying attacks themselves as well as blacklisting known-compromised passwords. There's really good tooling for this (likely the same tooling this adversary used!) Separately from this, people should use hardware 2fa tokens whose weakest link isn't the cell phone company support. Edited for clarity.
- inapis 7y agoProbably my wording was wrong. I was thinking more of a system where the password itself was generated and stored on a hardware device. The user need not interact with any application, whatsoever, like 1Password or Lastpass to generate or store a password at all. Everything happens behind the scenes on the device. The user would be responsible only for keeping the hardware device safe. This probably makes 2FA moot for some scenerios. For scenarios where losing the token is a real risk, you would implement 2FA.
- Godel_unicode 7y agoI understood you, my point is that you are sacrificing significant security with a one-factor approach, especially if that one factor is a password! You're open to attacks where the password is exposed in between the keyboard and the requestor, attacks on the distant end system, as well as attacks on the password device itself. Passwords make it tricky to audit if they've been duplicated. Use 2fa everywhere. It's cheap, easy, and significantly more effective. Consider the following attacks which your suggestion provides no coverage for: - Http downgrade (both SSLstrip and export-grade downgrade) - Spear-phish - Key-logger - Spear-phish - Shoulder-surf - Spear-phish - Evil maid (borrows device and compromises passwords) And last but not least, spear-phish
- inapis 7y agoI do not believe that spearphishing would not be prevented by a hardware token. The device would be responsible for authenticating the identity of the service being accessed. If the user can be fooled into handing over their hardware token, I do not see it far fetched that they will not be influenced to not hand over their 2FA token. Again, if a hardware 2FA token can deal with key-loggers, so can a password token. Why would someone be able to shoulder-surf a display-less password token? You log on to the website, insert the device and the website proceeds to authentication without revealing anything. Evil maid is the only legitimate attack I can agree with. >attacks on the distant end system, as well as attacks on the password device itself. This is not something that a hardware 2FA token is also foolproof against. >Passwords make it tricky to audit if they've been duplicated. This is a valid point. My point may not be applicable for super sensitive systems but for a lot of services it should be sufficient enough. I'm saying so because I'm having a hard time getting my family/friends to use a password manager (specifically 1Password). They do not see the need, find it additionally complex and are turned off by the subscription pricing (I'm paying for my family though!). Syncing is also hard. I was hoping that a pure hardware token would make it more convenient and a one time 20-40 USD price is more palatable than 60 USD every year.
- halis 7y agoProbably too busy coming up with rad interview questions about red black trees and other useless shit.
- qaq 7y agoaverage is 206 days
- Godel_unicode 7y agoAccording to whom? That's significantly above what fireeye says (71 until internally discovered): https://content.fireeye.com/m-trends https://content.fireeye.com/m-trends
- qaq 7y agoAccording to Google search snippet I am totally ready to trust that FireEye estimate is much more accurate
- todd3834 7y agoI fully assume there are more hacks we don’t hear about that ones we do. Not only because of cover ups but it can’t be that hard to cover your tracks if you know what you are doing.
- erlangNewb 7y agoJust assume they only catch the dumbest 20%.
- Godel_unicode 7y agoSo you think that 80% of attacks are better than stuxnet?
- lawnchair_larry 7y agoThey never caught the stuxnet attacks. They caught the malware that was spreading far outside of its target. Not quite the same thing.
- Godel_unicode 7y agoSo you're saying they caught the attackers using one of the most sophisticated pieces of malware ever created. Good, we agree.
- giancarlostoro 7y agoThey caught the malware not the attackers. Otherwise we would be talking about the authors.
- arthurcolle 7y agoI thought it was pretty well-established that Stuxnet was created/authored by TAO within the NSA.
- empath75 7y agoIf you have anything of value, I absolutely guarantee you that there are hackers in your network right now. One thing that frustrates me more than anything else is people assuming that their corporate network is safe. Your firewall and your vpc or whatever is a speed bump at best. You have to assume that you have an attacker on the desk right next to you, because you will eventually.
- Spooky23 7y agoThat phenomenon is worse in environments with lots of compliance, as the security people tend to think like auditors instead of security professionals.
- viraptor 7y agoThat's a really defeatist attitude. There are different levels of "value" and different levels of protection. Not everything is internet facing. Not everything is managed like a corp where turnover requires lots of access changes. Not everything allows you persistence in the network. And not all access is "access". I really wish we moved past the "everybody's owned" idea. Your defence should be proportional to the value you can lose. You can monitor for the rest. And you can't guarantee the are hackers in my network. (Unless you're saying you're guilty of breaking in? ;-) )
- hibikir 7y agoI don’t think the grandparent says that everyone is owned, but that if your data is interesting enough, your threat model must include employees that are willingly exhilarating data, sometimes for nation states. That your first barriers are therefore assumed to be breached to those attackers. This of course does not apply if you are not holding on to anything interesting, but it’s very easy to become interesting at a certain size, or if you have interesting customers. Still, not everybody.
- viraptor 7y agoMy response was triggered by "If you have anything of value". I agree with "if your data is interesting enough". Because let's be honest, barely any company qualifies for nation state embedding a worker with them. If they do, they know. But everybody has something of value.
- rmason 7y agoIf you'd like a full perspective of the Citrix hack three security people from Detroit discussed it on a recent episode of their show, How they got hacked: https://www.youtube.com/watch?v=fMgdrq0xMLk https://www.youtube.com/watch?v=fMgdrq0xMLk
- IncRnd 7y agoDid you watch that? They mentioned that they don't know any more than is publicly disclosed how the attack occurred and that they were speculating. That was literally their first sentence about the attack.
- benmarks 7y ago> Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication. How did Citrix not have 2FA in place?
- yellowapple 7y agoIt's Citrix. That's how.
- SCHiM 7y agoHaven't read the article, don't know anything about their network. Assuming they use a Windows domain for their corp infrastructure. Lower level Windows authentication mechanisms can't be configured for 2FA. If your active directory domain is functional at all then at the very least your systems need to be able to talk via SMB and ldap to a domain controller. With sufficient privileges you're able to execute code on other machines via either protocol. You only need an infected machine, not even user credentials, to be able to perform password spraying or kerberoasting attacks.
- sbr464 7y agoNot sure what you meant by lower level mechanisms, but you can protect console logins and RDP with 2FA: https://duo.com/docs/rdp https://duo.com/docs/rdp https://help.duo.com/s/article/1084?language=en_US https://help.duo.com/s/article/1084?language=en_US
- amaccuish 7y agoThose don't apply to "SMB and ldap", nor kerberos. The only way to get 2FA on an Active Directory domain is with PKI.
- w8rbt 7y agonet commands, kerberos tickets, etc. You can really only 2FA web interfaces, VPNs, RDP and interactive console logons. You can 2FA LDAP, but it's a real pain to do so (I've seen it done). Just think of any backend protocol that the system uses. The vast majority of those can't be 2FA'ed. This is not Windows specific either. The same is true for most all protocols. This is why most companies buy firewalls and VPNs and only 2FA the VPN. That meets most compliance requirements and is simple to do. Is it secure? Probably not, but it checks the box (makes audit happy), so buy compromise insurance and move on.
- axaxs 7y agoHaving worked with Citrix, I'm shocked. Shocked that they detected it at all...
- da_chicken 7y agoI was going to say the same thing, but it sounds like it was the FBI that noticed it: > [T]he hackers had “intermittent access” to its internal network from October 13, 2018 until March 8, 2019, two days after the FBI alerted the company to the breach.
- axaxs 7y agoOh, this is gold, thank you. I'm sorry I missed it, but at least answers my very serious skepticism.
- da_chicken 7y agoBelieve me, your skepticism in this matter is not unique!
- lawnchair_larry 7y agoThis is extremely common. 6 months is not that long, even among competent companies that have good security. You usually hear about it from the FBI. I think the FBI forwards tips from agencies like the NSA, but they don’t tend to give much information.
- axaxs 7y agoIt may be common, but I'll disagree it's common for companies with "good security." Password spraying doesn't work with good 2FA, nor sane login limits. I set off a flag anytime logging in from a new IP, for example.
- dub 7y ago2FA and login limits alone aren't likely to stand in the way of state-sponsored hackers. Lots of companies still haven't upgraded to zero trust / BeyondCorp AuthN, and lots of companies don't have reproducible signed build artifacts from CI/CD with automatic policy enforcement regarding the properties that those build artifacts must have before they can be deployed. High-profile companies that think VPNs and networking rules are a security solution have probably already been hacked and just don't know it yet.
- robbiet480 7y agoHas anyone gotten that kind of call from the FBI and can shed light on how the process works? Would be fascinating for a outsider and provide a guide on what next steps look like for those poor souls that receive the call in the future.
- 4s2A1tD5 7y agoI've been on this call (both sides of it) probably a dozen times by now. Gov agencies are decent at doing research so it's pretty unlikely that the FBI just called their 1800 number or whatever. Most small start ups don't get to the level where anyone that "big" is looking at them but in the event that something does get flagged the agency will go find their CEO/CTO/counsel on LinkedIn and either message them there or email them. I've never seen an actual vulnerability disclosed in email, if it's a potential legal issue (hello SEC and fintech) they may ask that your lawyer responds to them in writing but more often it's just "this is Agent XYZ with ABC. I have information about your company, please call me immediately." For someone bigger (like Citrix) the company is hopefully big enough to have a team that is connected to the agencies in someway. Either the agency knows someone who knows them, or they have a designated Security and Compliance team that can handle these inquires. The real problems come when you're in the middle of sizes - too big to have eyes on every email but too small to have a real security team. About 5 years I was working for a SaaS company and one of our clients accidentally discovered a pretty serious hole in another company's product. This client wasn't overly tech savy and was basically like "hey is this how this is supposed to work?" when it very much was not... so we killed the API connection and told the client we'd take care of it. It's about 7pm ET by the time we figure out what's going on so we call and email the other company but couldn't find anyone. In the end we got the home phone number of their CTO and had our CTO call him at around 10pm. He thought it was a prank call but once our CTO convinced him this was a problem he was able to get their on call eng to patch it within hours. Nowadays almost any company involved in security work either has a direct line to FBI/DHS or has a vendor who does. ie if I'm some medium consumer platform I probably don't get to talk to the FBI directly, but if I called up Crowdstrike or any security consulting firm they could do that. In the event that my medium consumer platform was infiltrated by Fancy Bear (and the government decided to tell me, sometimes they don't) an FBI agent would email/call the most likely point of contact for the fastest resolution without causing panic. Lots of time the damage is already done, two vs four hours on a response won't make a big difference in the long term so no need to email info@ or anything. Over the past 6-8 years the corporation on public/private cyber investigations has definitely changed as red tape has decreased in sharing of info has increased - even more the last 4ish years since the DNC email hacks. I've had a clients get a casual "just a heads up, you should check this out" from the government without no paperwork and no follow up, something that would have been virtually unheard of 8 years ago. DHS gets a lot of shit in the media (lots of which is deserved) but they've done a pretty good job just opening basic lines of communication and training other agencies that spending 20 minutes looking at a random tip, and following up if needed, is actually a pretty good use of time.
- markholmes 7y agoThis might not be the right place for this, but where should one get started with security research?
- rando444 7y agoI feel like an answer to this would depend largely on your age, background, and what you are looking to learn.
- ngcc_hk 7y agoYou need network sniffer and pattern recognition. Otherwise basically you hope some of the unusual activities will affect ids/ips (or touch internet). However if it is normal account you need some sort of intelligence to recognise and alert. Not many software can do this.
- 6wKZhFkquv 7y agoThrowaway, worked at Citrix. The unfortunate thing about this comment is that they sell Citrix Cloud as having the intelligence to detect anomalies exactly like this in your network.
- zild3d 7y agoOuch. This page [0] hurts a little bit to read now. Feel free to grab their free ebook though! You'll learn how advanced analytics can help IT identify user behaviors, determine risk profiles, and assess and address potential threats [0] https://www.citrix.com/analytics/prevent-security-breaches.html https://www.citrix.com/analytics/prevent-security-breaches.h...