4 ms·
Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-p
by wespiser_2018 4y ago
Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-techniques-behind-attacks/ https://www.sentinelone.com/blog/malicious-pdfs-revealing-te...
I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-ronin-security-breach https://roninblockchain.substack.com/p/back-to-building-roni....
To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
- the_gipsy 4y agoI know that document-rendering is much more complex than what it appears on the surface, but surely in this day and age there should be document viewers that don't run scripts and are exploit free.
- gowld 4y agoEvery program is potentially exploutable. The only defense is defense in depth, where an intrustion attempt fails at layer 3 of 5, alarms bells ring, and those 3 compromised layers get hardening upgrades. What usually happens is that layers 1 and 2 of 3 are constantly compromised, no one cares to follow up, and one day layer 3 gets compromised, shock of shocks.
- Volundr 4y agoThe right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
- llaolleh 4y agoI'm in this camp. All employees should be sent a laptop, or work with a remote environment that is isolated from your personal computer.
- rchaud 4y agowhat would stop a developer from checking personal email on a work machine?
- pcthrowaway 4y agoOr more to the point, what would stop someone from sending malicious documents to the employees' work emails? Figure out a company uses <some-saas> register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details. If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?
- Volundr 4y agoAnd this is exactly why your IT department sends out those simulated phishing emails everyone likes to complain about.
- Volundr 4y agoThemselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines. This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
- macintux 4y agoExactly. I was on a meeting a couple of years ago and the co-worker who was presenting his desktop received a personal iMessage that flashed for everyone to see.
- cmeacham98 4y ago> To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. I dispute this: the web browser is one of the most defended pieces of software of all time, especially relative to its complexity. I would find it much safer to open a potentially malicious PDF in my browser's JS-based reader than using a desktop reader. > The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets. It also probably would have been helpful if one employee didn't have access to almost half of the validators, especially on a system they're accessing email with.