4 ms·
How do they detect MS Word docs being opened?
by jesprenj 2y ago
How do they detect MS Word docs being opened?
- OptionOfT 2y agoOr the mySQL dump?
- CGamesPlay 2y agoThat one appeared to set a replication host and then uses a canary DNS record to do the triggering. The canary payload is just base64 encoded, so it's not hard to reverse engineer if you spot it.
- mdhb 2y agoI don’t know this for sure, I’m just going from memory from an operation the Dutch pulled off when trying to take down some darknet market places where they used this technique. But basically they would embed a remote image inside the file so it would call out to a web server upon loading the image. It also had the added benefit from a LEO perspective that if the users main defence was running TOR browser that it would bypass that and provide the users true IP address. However, as I mentioned in another comment here, I actually think those particular kinds of honeypots are kind of dumb in that they only catch stupid adversaries. Opening those files on your own machine as an attacker while connected to the net is one of those do not pass go, do not collect $200 go directly to jail moves.
- knallfrosch 2y ago> they only catch stupid adversaries. It's enough to catch one guy, one time. Then you follow his physical or digital traces.
- mdhb 2y agoYeah, I mean like a lot of things in security, it’s better than nothing. But you would have to be very undisciplined or uninformed to get caught by this. There’s even an argument that all you’ve done is tipped your hand to the adversary that deception is at play in this scenario and allow them to adjust their approach accordingly. Not even suggesting that would be a horrible thing to happen, even in that scenario you most likely can at least slow them down but if you never know you’re being targeted in the first place it doesn’t matter too much when that clock starts. The ideal scenario I think you should actually be aiming for here is to craft a situation where you know about them but they don’t know that you know. That’s a window of time where you very clearly have an upper hand. That isn’t actually that hard to create. For example one technique I have at that really early stage is to return a 403 auth error on a web service and set a cookie that looks very natural to its environment but is also very obvious as to how you could change it in order to no longer get a 403 response. The moment I get a request with that new cookie value I instantly know I have something I should be paying attention to and I know it’s a real person not a bot. The adversary however has no idea yet what’s going on, they just think they hit a gold mine.
- jabroni_salad 2y agoI have a little guy that notifies if someone is operating Responder on the business network and that is my justification as well. As a defender, you only get to fail once for it to be costly. As an attacker, you can often fail hundreds or thousands of times depending on what they have for observability. Adding offensive elements helps level the playing field.
- tholdem 2y agoAll adversaries are just humans and humans do stupid mistakes. Opsec and maintaining it is really hard. Just one mistake is enough. It's astounding to read about the really stupid mistakes adversaries do to get caught. But there is of course also the bias that we only read about the mistakes of ones that do get caught.
- mdhb 2y agoZero disagreement here whatsoever. I have story after story after story of people who should have known better who got done for really silly shit. I’m only making the argument here that that specific technique has some real limitations and known work arounds to the point that people actively know to look for it and that as a result I would personally look for other techniques that don’t have the same set of trade offs.
- tholdem 2y agoYou can check by creating a Word Canary and check what's inside. I renamed it from .docx to .zip and it seems there is an external image referenced in the footer. I'm not sure how modern Word handles external images, but I believe you have to approve the download of remote content when you open it nowadays.