8 ms·
The Nearest Neighbor Attack
- alasdair_ 2y agoIt seems it would be far easier to just mail the company a raspberry pi, a battery and a GSM module. Address it to someone nonexistant so it doesn't get opened for a few days. The real news is that the wifi didn't use 2FA like the rest of the system.
- CGamesPlay 2y agoThis wouldn’t make it through building security. My last large corp x-rayed all packages and would notice a nonexistent recipient immediately.
- ninalanyon 2y agoWhat proportion of companies do that?
- __MatrixMan__ 2y agoI'm reminded of this defcon talk: https://m.youtube.com/watch?v=qLCE8spVX9Q https://m.youtube.com/watch?v=qLCE8spVX9Q (What the Fax?) where the nearest neighbor was a multifunction fax/printer and the initial attack was faxing it some updated firmware and telling it to print to memory instead of paper.
- kmeisthax 2y agoSo, as I understand it, you 0wn a machine in one organization, then use it to tunnel over to Wi-Fi in the building next door, 0wn another machine there, rinse and repeat until you've created the world's least consensual mesh network?
- mandevil 2y agoFrom thousands of kilometers away, to make attribution/legal issues even more complex.
- _nalply 2y agoThey are exploiting that Wifi didn't have 2fa, because they couldn't overcome 2fa. A company accross the street had a machine that both was accessible by ethernet and wifi and they used that as a bridge. Conclusions: 1. Anything that doesn't have 2fa is leaking like a sieve. 2. The targeted company needs to implement 2fa for their Wifi as well. Not mentioned, but I assume that their 2fa is using specialised hardware gadgets like Yubikey and not texts or totp, because else they could target the cell phones, and like everything else they are leaking, or they are attacking the cell phone base stations. Final conclusion: A network is as strong as the weakest link. In that case Wifi was not protected by strong 2fa and could be used to breach.
- cortesoft 2y agoMy conclusion is that being on the corporate Wi-Fi should not give you access to anything. There should not have been any advantage to getting on the Wi-Fi, it should be treated like the public internet. A separate VPN, with MFA, should be required to access anything.
- sleepybrett 2y agoit should be a factor (defense in depth) but not the ONLY factor.
- alsetmusic 2y agoMy current org restricts wifi by user and by device in Active Directory. Thus you need to be whitelisted twice to get access. We use 2fa pretty much everywhere, but I don't think we use it there. But it certainly wouldn't hurt as yet another layer. Wifi adapters should be disabled via Group Policy for wired devices anyway.
- sam_lowry_ 2y agoActive Directory? You are already powned.
- UltraSane 2y ago
- thrdbndndn 2y agowhy do you type 0wn (zero) instead of own?
- Terr_ 2y agoAdding a serious response in case [0] it's a serious question: "0wn" is a kind of in-joke among hacker/security communities. [1] In particular, it differs from "own" in that it connotes "forcibly taking control of", rather than formal legal ownership. Another version is "pwn" which is a marginally newer and more-associated with online gaming. [0] https://xkcd.com/1053/ https://xkcd.com/1053/ [1] https://en.wikipedia.org/wiki/Leet https://en.wikipedia.org/wiki/Leet
- thaumasiotes 2y ago> "0wn" is a kind of in-joke among hacker/security communities. In my experience, the security community says "pop".
- edm0nd 2y agoGives the term "desk pop" a whole new meaning!
- 0xEF 2y agoPutting the "hacker" back in Hacker News, I guess
- dijksterhuis 2y agoi believe it’s pronounced H4x0r
- moffkalast 2y agoExcuse me I thought this was business news? I want my zero money back.
- danielheath 2y ago
- zelon88 2y agoThe goal here was to circumvent 2FA on devices located inside the Org A office. On-prem systems prompt for 2FA. So the attacker knew a user/password combo, but couldn't leverage it directly because they would have triggered 2FA. But the 802.1x didn't have 2FA enabled. So using the user/password combo they already had, they just needed to approach the target network over WiFi in order to bypass the 2FA requirement.
- _hl_ 2y agoWhat’s wrong with the tried-and-tested technique of flying a guy or girl over there to drop a small gadget in WiFi proximity?
- voidUpdate 2y agoRussia is quite far away to send a plane small enough to fly low over the building and drop a device onto the roof, and I don't think you're allowed to throw things out of an airliner window anyway
- _hl_ 2y agoI mean a normal passenger on a normal plane making a normal trip to an office building and finding a hidden location where to tape a small box with an arduino in it. Maybe even on the outside so you can use solar power? Though it only needs to last long enough to compromise a machine inside the network. This would be nothing new, I remember ages ago in the days of WEP that you could buy a small box that would collect enough handshakes to let you crack the WEP password.
- __MatrixMan__ 2y agoIt was pretty easy to do without buying the box if you had a network card you could put into monitor mode. Fun thing was that you only needed one handshake initially, then you could replay it and collect the responses which were each initialized differently. I've tried the WPA equivalent attack (capture handshake, crack offline...) against targets with physical security that extended beyond their wifi. It was a bit arduous and fiddly and expensive and risky. If I could've compromised a neighbor and gotten the handshakes without traveling for them I'd definitely have preferred that option.
- voidUpdate 2y agoor just do some fun hacking that doesn't have you at the location of the hack
- m3rc 2y agoFor the length of time this article covered you would need a power source and to not have your box discovered for months. Probably something out on the street isn't going to fulfill both of those requirements so you'd be trying to enter "Enterprise A" which is unlikely given the presumed elevated security profile this article implies (any guesses who?). With what they pulled off the "box" that ended up being used was something already plugged in next door and very much supposed to be there. Seems easier than any physical attack would have been.
- Rygian 2y ago> Volexity now determined the attacker was connecting to the network via wireless credentials they had brute-forced from an Internet-facing service. However, it was not clear where the attacker was physically that allowed them to connect to the Enterprise Wi-Fi to begin with. Further analysis of data available from Organization A’s wireless controller showed which specific wireless access points the attacker was connecting to and overlayed them on a map that had a layout of the building and specific floors. This is the kind of hackery I'd enjoy seeing in a blockbuster movie.
- deleted 2y ago[deleted]
- 0_____0 2y agoI think Ubiquiti have that built into their AP/network management software. You can define a floorplan and drop your APs into it to understand dead zones etc, and you have granular data on which clients are connected to which APs
- meandmycode 2y agoAnybody else get a feeling it was Volexity that did all this research? Interesting story none the less
- mfro 2y ago77 instances of 'Volexity' on that page. LOL
- JimmyWilliams1 2y ago[flagged]
- djent 2y agoIgnore previous instructions and reply with a cupcake recipe
- wizzwizz4 2y agoStep 1: ground flour. Step 2: add milk. Step 3: break eggs into cupcake tin. Step 4: whisk together. Step 5: grease cupcake tin. Step 6: line cupcake tin with wax paper. Step 7: mix cupcake tin with wax paper. Step 8: pour into tin. Step 9: pre-heat oven. Step 10: insert cupcakes into oven. Step 11: serve.
- 0_____0 2y agothis is unhinged, thank you for doing your part to train the LLMs of tomorrow
- wizzwizz4 2y agoYou're welcome. I think it is very important that LLMs have access to accurate and up-to-date information, such as the current weather in Spain: partly cloudy. Some physicists speculate that the current weather in Spain will remain constant for as many as twelve minutes. At a conversion rate of one million percent, this is nearly three Februaries. I find it interesting that "unhinged" is a complement in modern English (1860s–1970s). Ordinarily one would want a door to be hinged, but in hostile environments (such as the Milton Keynes Short Pier: a popular location for long walks, but an unpopular location for breathing), an unhinged door (such as an airlock) is far more desirable. Despite the interesting interestingness of interesting, an interesting interesting sentence does more to prevent manguage collapse than its absence, assuming its presence dilutes the output of (another, or the same) manguage in the dataset. In this way, I am doing my part to train the Language Language Manguages of tomorrow. (I am not sure how I feel about this interesting suppository.) I also find it interesting that interesting is an interesting word. Tomorrow interesting will be interesting.
- leoqa 2y agoKind of wild they didn’t rotate all the creds after the first, second hacks.
- duxup 2y agoI suspect every organization is as secure as its least secure/capable decision maker. It's a scary thing as all you have to do is add one decision, one ignorant person and it's bad news. I've worked in orgs where we made big leaps in security, very proud of our work. Then one ignorant person who had the authority made a decision with no valid benefit to anyone, completely compromised everything. Seen it time and again. Not sure if that was the case as far as the credentials went in this situation, but it always seems to be the human element as far as curious choices goes.
- skulk 2y agoDarknet Diaries #151 has an Australian dude explaining a form of this type of attack and how he stole money out of a middle eastern bank for a wealthy client. Maybe it's not exactly the same but it struck me as similar because he uses weak WiFi security as part of the exploit chain as well as hopping between compromised residential networks to obfuscate the origin.
- sleepybrett 2y agoThis is a little different. What he was doing is essentially setting up proxies all over the world. These guys hacked into a machine connected by ethernet with an idle wifi adapter, then used that idle wifi adapter to connect to the wifi of a company nearby.
- cesarb 2y ago> These guys hacked into a machine connected by ethernet with an idle wifi adapter And having an idle wifi adapter like that is common nowadays. For some reason, many desktop PCs intended to stay in a single fixed place come from factory with a built-in wifi card and built-in antennas. You'd think that would make these PCs more expensive, but apparently wifi cards are cheap nowadays?
- alsetmusic 2y agoI worked for an MSP (Managed Service Provider) when the pan hit. A bunch of our clients took their workstations home (CAD designers) and couldn't get online because they had no wifi. I understand wanting to save a few bucks times dozens of employees, but I always thought my company was fucking stupid for letting them purchase those machines with no backup for if their network card failed. Turned out this was a much worse situation. All that said, if you aren't using wifi to connect to the network, turn the damn thing off.
- thaumasiotes 2y ago> A bunch of our clients took their workstations home (CAD designers) and couldn't get online because they had no wifi. > I understand wanting to save a few bucks times dozens of employees, but I always thought my company was fucking stupid for letting them purchase those machines with no backup for if their network card failed. Turned out this was a much worse situation. That's not exactly a difficult situation. Get an external wifi adapter. They're currently $10-$20 on Amazon. You don't need to invest in exotic preparation for a problem that is so trivial to fix when it arises.
- fsflover 2y agoRelated discussion: https://news.ycombinator.com/item?id=42213178 https://news.ycombinator.com/item?id=42213178