4 ms·
Scenario 1: Attacker compromises ECOMMERCE_SITE where you have a login. The ECOMMERCE_SITE uses md5 for logins, so the attacker just brute-forces the hash and t
by lordlimecat 5y ago
Scenario 1: Attacker compromises ECOMMERCE_SITE where you have a login. The ECOMMERCE_SITE uses md5 for logins, so the attacker just brute-forces the hash and then uses that password to compromise your logins on other sites.
Scenario 2: The ecommerce site has upgraded to SHA512, so cracking isnt an option. But the site is relying on basic auth, so the attacker simply sniffs your password when you auth.
Scenario 3: the ecommerce site is using a secure zero-knowledge auth against a hashed/salted/peppered/whatever credential. They cannot brute force it, and the server never sees your password. They can mess around with the ECOMMERCE_SITE but cannot pivot to any of your other logins.
>If I was a hacker, I can add JavaScript to send plaintext somewhere.
We've just shifted from "quiet, persistent threat" to "hacker announces to the world that he's in". Changing javascript on a prod website is going to trigger alarms.
- BeefWellington 5y ago> We've just shifted from "quiet, persistent threat" to "hacker announces to the world that he's in". Changing javascript on a prod website is going to trigger alarms. While I'd like that to be true, it really isn't. There have been loads of card skimming operations injected into production sites which weren't noticed for sometimes months.[0][1][2][3] [0]: https://blog.malwarebytes.com/hacking-2/2020/03/criminals-hack-tupperware-website-with-credit-card-skimmer/ https://blog.malwarebytes.com/hacking-2/2020/03/criminals-ha... [1]: https://www.wired.com/story/british-airways-hack-details/ https://www.wired.com/story/british-airways-hack-details/ [2]: https://www.riskiq.com/blog/external-threat-management/magecart-ticketmaster-breach/ https://www.riskiq.com/blog/external-threat-management/magec... [3]: https://sansec.io/research/svg-malware https://sansec.io/research/svg-malware