4 ms·
> Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing fro
by benmarks 7y ago
> Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication.
How did Citrix not have 2FA in place?
- yellowapple 7y agoIt's Citrix. That's how.
- SCHiM 7y agoHaven't read the article, don't know anything about their network. Assuming they use a Windows domain for their corp infrastructure. Lower level Windows authentication mechanisms can't be configured for 2FA. If your active directory domain is functional at all then at the very least your systems need to be able to talk via SMB and ldap to a domain controller. With sufficient privileges you're able to execute code on other machines via either protocol. You only need an infected machine, not even user credentials, to be able to perform password spraying or kerberoasting attacks.
- sbr464 7y agoNot sure what you meant by lower level mechanisms, but you can protect console logins and RDP with 2FA: https://duo.com/docs/rdp https://duo.com/docs/rdp https://help.duo.com/s/article/1084?language=en_US https://help.duo.com/s/article/1084?language=en_US
- amaccuish 7y agoThose don't apply to "SMB and ldap", nor kerberos. The only way to get 2FA on an Active Directory domain is with PKI.
- w8rbt 7y agonet commands, kerberos tickets, etc. You can really only 2FA web interfaces, VPNs, RDP and interactive console logons. You can 2FA LDAP, but it's a real pain to do so (I've seen it done). Just think of any backend protocol that the system uses. The vast majority of those can't be 2FA'ed. This is not Windows specific either. The same is true for most all protocols. This is why most companies buy firewalls and VPNs and only 2FA the VPN. That meets most compliance requirements and is simple to do. Is it secure? Probably not, but it checks the box (makes audit happy), so buy compromise insurance and move on.
- ynniv 7y agoYou can firewall the backend services and use 2fa to temporarily open them for a specific workstation.
- gwd 7y agoThey have had 2FA for years.