1 00:00:00,258 --> 00:00:04,038 You found the backup wrap up your go-to podcast for all things 2 00:00:04,038 --> 00:00:06,408 backup recovery and cyber recovery. 3 00:00:06,828 --> 00:00:11,598 In this episode, we look at something most people I don't think have even heard 4 00:00:11,598 --> 00:00:15,828 of, but definitely need to know about, and that's the initial access broker. 5 00:00:16,308 --> 00:00:19,848 These are the bad folks that wanna break into your network, 6 00:00:19,848 --> 00:00:23,688 but then just sell that access to whoever's willing to pay the most. 7 00:00:24,108 --> 00:00:27,378 They pick your lock and then hand the keys to somebody else. 8 00:00:27,828 --> 00:00:32,268 We have Dr. Mike Sailor from Black Swan Cybersecurity, my co-author and of 9 00:00:32,268 --> 00:00:36,978 course, persona to help break down how these guys operate, how they get your 10 00:00:36,978 --> 00:00:41,628 credentials, who buys them, and most importantly, what you can do to stop them. 11 00:00:42,258 --> 00:00:46,188 By the way, if you don't know who I am, I'm w Curtis Preston, AKA, Mr. 12 00:00:46,188 --> 00:00:50,028 Backup, and I've been passionate about backup and recovery for over 13 00:00:50,028 --> 00:00:53,988 30 years, ever since I had to tell my boss there were no backups of the 14 00:00:53,988 --> 00:00:55,728 production database that we just lost. 15 00:00:56,313 --> 00:00:59,223 I don't want that to happen to you, and that's why I do this. 16 00:00:59,463 --> 00:01:04,173 On this podcast, we turn unappreciated admins into Cyber Recovery Heroes. 17 00:01:04,503 --> 00:01:06,603 This is the backup wrap up. 18 00:01:21,719 --> 00:01:23,039 Welcome to the backup wrap up. 19 00:01:23,039 --> 00:01:26,519 I'm your host w Curtis Preston, AKA, Mr. Backup. 20 00:01:26,759 --> 00:01:30,519 And I have with me Judge mc judger face Prasanna. 21 00:01:30,699 --> 00:01:31,749 Molly Yondi. 22 00:01:31,899 --> 00:01:32,469 How's it going? 23 00:01:32,469 --> 00:01:35,909 Prasanna feeling a little judgy today. 24 00:01:36,434 --> 00:01:42,584 Someone needs to judge you and make sure that you are doing the right things and 25 00:01:42,584 --> 00:01:45,284 being most effective with your resources. 26 00:01:45,534 --> 00:01:48,479 I, I, I really appre, I didn't realize that I had appointed 27 00:01:48,479 --> 00:01:52,109 you CFO of my, you know. 28 00:01:52,754 --> 00:01:54,854 uh, do you not know all the other things? 29 00:01:54,854 --> 00:02:02,234 You're non-ad advisor, financial advisor, your non-medical health person. 30 00:02:02,234 --> 00:02:04,154 Shall I continue going down the list? 31 00:02:04,154 --> 00:02:04,664 Curtis? 32 00:02:05,474 --> 00:02:09,314 I, I just, I'm just saying for those that care Okay. 33 00:02:09,464 --> 00:02:12,394 Is that I just had like a five minute phone call with Prasanna 34 00:02:12,674 --> 00:02:17,264 during which I felt very judged for starting a new cloud service. 35 00:02:17,504 --> 00:02:20,264 The, a new AI based cloud service that I'm very excited 36 00:02:20,264 --> 00:02:23,744 about, called Fixer, F-Y-X-E-R. 37 00:02:24,254 --> 00:02:25,169 Um, anyway. 38 00:02:25,499 --> 00:02:27,839 I'm just saying I felt very judged. 39 00:02:28,019 --> 00:02:29,489 Anyway, I'm moving on. 40 00:02:29,909 --> 00:02:35,189 Uh, we also have with us, uh, my, my co-author from the book, 41 00:02:35,219 --> 00:02:38,249 right, right over my left shoulder. 42 00:02:38,559 --> 00:02:43,514 And a blue team expert at Black Swan Cybersecurity. 43 00:02:44,289 --> 00:02:46,419 We have Dr. Mike Sailor. 44 00:02:46,419 --> 00:02:47,229 How's it going, Mike? 45 00:02:48,189 --> 00:02:48,939 It is going well guys. 46 00:02:48,939 --> 00:02:49,629 Thanks for having me 47 00:02:49,989 --> 00:02:50,289 Oh. 48 00:02:50,419 --> 00:02:52,134 Can you judge Curtis now too? 49 00:02:52,464 --> 00:02:55,674 Just, just just start a conversation and I think Curtis needs 50 00:02:55,674 --> 00:02:57,399 that sort of love all around. 51 00:02:58,404 --> 00:02:58,584 sure. 52 00:02:58,584 --> 00:02:59,899 I'll, I'll work that into the conversation. 53 00:03:00,159 --> 00:03:01,839 I feel, I feel so judged. 54 00:03:02,739 --> 00:03:08,319 Um, so today, um, we're gonna talk about, we talked about this a little bit, I 55 00:03:08,319 --> 00:03:13,509 think in a previous episode, but, uh, it looks that like this topic comes up 56 00:03:13,509 --> 00:03:15,219 enough that people just don't understand. 57 00:03:16,119 --> 00:03:20,679 This, this entity or this type of, can we call it a business? 58 00:03:20,679 --> 00:03:20,979 Mike? 59 00:03:20,979 --> 00:03:22,089 Would you call it a business? 60 00:03:22,089 --> 00:03:23,139 It's a business, right? 61 00:03:23,169 --> 00:03:23,349 business. 62 00:03:23,769 --> 00:03:24,219 Yeah. 63 00:03:24,399 --> 00:03:27,609 And that is an initial access broker. 64 00:03:28,119 --> 00:03:33,489 Um, so why don't you start with this story that you had, that you used in the book as 65 00:03:33,489 --> 00:03:37,839 a case study about something that happened with one of your clients back in 2024? 66 00:03:38,799 --> 00:03:39,069 Sure. 67 00:03:39,069 --> 00:03:44,169 We had a client call and say, you know, someone broke into our stuff and we're 68 00:03:44,169 --> 00:03:49,689 not sure how, because, uh, you know, we we're not seeing any failed login attempts 69 00:03:49,689 --> 00:03:52,299 or weird logins from, from other places. 70 00:03:52,299 --> 00:03:53,949 We'd call those risky logins. 71 00:03:54,609 --> 00:03:56,019 Uh, so how did this happen? 72 00:03:56,799 --> 00:03:59,739 And so it takes quite a while to analyze. 73 00:04:00,789 --> 00:04:02,439 Even legitimate logins. 74 00:04:02,589 --> 00:04:04,359 to figure out where the anomalies are. 75 00:04:05,139 --> 00:04:06,189 so you narrow that down. 76 00:04:06,189 --> 00:04:10,659 You find out, you know, who, who patient Zero might've been, and then you go, 77 00:04:10,989 --> 00:04:14,919 you have to go talk to them because you don't have you don't have visibility 78 00:04:14,919 --> 00:04:18,879 or access into their, their whole life, uh, and things they have access to. 79 00:04:18,879 --> 00:04:23,739 But in that conversation, this employee, uh, it turned out and, 80 00:04:23,739 --> 00:04:27,639 and they were very open, uh, and, and almost somewhat, uh, naive about 81 00:04:27,639 --> 00:04:28,929 what they were telling us, which. 82 00:04:29,724 --> 00:04:30,804 That's a whole other problem. 83 00:04:31,254 --> 00:04:35,604 Uh, so this, this user, uh, we'll call them Bob. 84 00:04:35,814 --> 00:04:39,114 Uh, Bob's like, I, I don't, I don't know how my account 85 00:04:39,114 --> 00:04:41,184 could have been compromised. 86 00:04:41,184 --> 00:04:44,244 I don't, I don't think I'm the one that caused this problem here at work. 87 00:04:44,934 --> 00:04:48,264 Uh, but in discussion with him about just weird things that may have happened 88 00:04:48,264 --> 00:04:53,094 over the last several months or year, uh, he says, now, now granted, this, 89 00:04:53,124 --> 00:04:57,234 this event was happening, you know, October, November of a given year. 90 00:04:59,139 --> 00:05:03,069 And talking to this employee, he says, oh yeah, back in like April, you know, 91 00:05:03,069 --> 00:05:07,659 around Easter, my personal email account was compromised and I've just been 92 00:05:07,659 --> 00:05:11,919 fighting with, with Google to, to maintain access to my account and control over it. 93 00:05:11,919 --> 00:05:13,329 You know, I keep changing the password. 94 00:05:13,329 --> 00:05:15,369 It keeps, keeps changing back. 95 00:05:15,369 --> 00:05:19,239 They keep, you know, uh, my, my recovery email keeps changing. 96 00:05:19,989 --> 00:05:25,629 And we thought, okay, well, well, tell us about how you. 97 00:05:26,064 --> 00:05:28,974 How you use that personal account, is it really just like, you know, 98 00:05:29,184 --> 00:05:32,854 uh, you use it when you sign up for stuff like a newsletter or you, you, 99 00:05:33,324 --> 00:05:35,064 you go to Amazon, you buy something? 100 00:05:35,064 --> 00:05:36,654 He said, yeah, I do all that. 101 00:05:36,774 --> 00:05:37,164 Okay. 102 00:05:37,554 --> 00:05:39,864 And, and by the way, this is normal interrogation techniques. 103 00:05:39,864 --> 00:05:41,514 You, you ask the simple questions first. 104 00:05:41,514 --> 00:05:41,634 you 105 00:05:41,634 --> 00:05:45,144 build report, you get up to the the sticky questions. 106 00:05:45,144 --> 00:05:47,724 And eventually I just said, so, you know, what others, what other type 107 00:05:47,724 --> 00:05:51,594 of information do you do you store in your, in your personal account? 108 00:05:51,594 --> 00:05:52,674 He goes, oh, well, everything. 109 00:05:53,634 --> 00:05:54,834 And I said, yeah, like, like what? 110 00:05:54,834 --> 00:06:00,024 Well, you know, I, uh, my, my work email and, and password, my bank information. 111 00:06:00,654 --> 00:06:01,704 I said, okay, well, you know, 112 00:06:01,704 --> 00:06:02,604 that's, that's probably 113 00:06:02,604 --> 00:06:02,964 not good. 114 00:06:05,584 --> 00:06:08,374 And, I said, okay, well, well talk to me about how you do that. 115 00:06:08,374 --> 00:06:09,154 Did you have a question? 116 00:06:09,154 --> 00:06:12,094 So I was like, alright, so how do you, how do you store that stuff in there? 117 00:06:12,094 --> 00:06:13,504 Is it like in a spreadsheet? 118 00:06:13,954 --> 00:06:16,774 Uh, is it a, is it a note to yourself? 119 00:06:16,834 --> 00:06:18,064 Like a draft email? 120 00:06:18,949 --> 00:06:24,289 He says, oh no, I created a Google Docs folder called passwords okay. 121 00:06:24,799 --> 00:06:26,599 Uh, so, so that's what happened. 122 00:06:26,719 --> 00:06:30,889 Uh, bad guys at some point compromised his account likely through phishing 123 00:06:30,889 --> 00:06:32,719 or the compromise of some third party. 124 00:06:33,604 --> 00:06:35,164 Uh, application or website. 125 00:06:35,194 --> 00:06:39,304 'cause you know, it all trickles down and bad guys go for the, they want fish 126 00:06:39,304 --> 00:06:43,414 in a big pond, then when they, when they catch fish out of the big pond, you 127 00:06:43,414 --> 00:06:46,474 know, they cultivate that and see what they have access to and, and et cetera. 128 00:06:46,474 --> 00:06:48,484 So it's all, it's all kind of interconnected. 129 00:06:48,544 --> 00:06:52,204 But long story short, these bad guys are just, you know, going 130 00:06:52,204 --> 00:06:55,534 through the neighborhood, looking for un unlocked doors or doors that 131 00:06:55,534 --> 00:06:57,394 are easy to pick and, and open. 132 00:06:57,784 --> 00:07:02,464 And once they identify those vulnerable and accessible. 133 00:07:02,959 --> 00:07:07,639 Uh, organizations or, or houses in this analogy, that's what they sell. 134 00:07:07,789 --> 00:07:09,169 They're like, Hey, I picked this lock. 135 00:07:09,199 --> 00:07:10,369 I guessed that code. 136 00:07:10,399 --> 00:07:11,659 I've opened this door. 137 00:07:13,009 --> 00:07:15,829 I've established this, this access. 138 00:07:16,249 --> 00:07:17,359 And that's what they're selling. 139 00:07:17,659 --> 00:07:19,219 So they never go in the house. 140 00:07:19,309 --> 00:07:20,959 They never steal anything. 141 00:07:21,439 --> 00:07:27,889 They never use that, that access to, you know, for, for, um, extortion or, 142 00:07:30,864 --> 00:07:33,259 Uh, solicitation or, or even fraud. 143 00:07:33,409 --> 00:07:36,829 They're just gaining the access and selling it. 144 00:07:37,519 --> 00:07:37,669 And 145 00:07:37,789 --> 00:07:41,389 So they're hoping for large volume, I'm guessing at that point, right Where 146 00:07:42,049 --> 00:07:42,739 for, yeah. 147 00:07:42,829 --> 00:07:47,599 Or, or some, you know, exceptionally valuable access, 148 00:07:48,319 --> 00:07:48,679 Gotcha. 149 00:07:48,679 --> 00:07:48,829 like 150 00:07:49,009 --> 00:07:50,359 Like a celebrity or a 151 00:07:50,809 --> 00:07:51,139 right? 152 00:07:52,039 --> 00:07:53,809 or a specific organization type of thing. 153 00:07:54,139 --> 00:07:57,349 or, or a, um, a high value target. 154 00:07:57,949 --> 00:08:02,029 Or like a, like an like an administrative account, for example, at a right. 155 00:08:02,299 --> 00:08:02,989 Like if you 156 00:08:03,229 --> 00:08:03,649 or 157 00:08:03,864 --> 00:08:04,104 Yeah. 158 00:08:04,309 --> 00:08:06,019 Critical infrastructure or something like that. 159 00:08:06,109 --> 00:08:06,349 Yep. 160 00:08:06,799 --> 00:08:08,269 Or a research institution. 161 00:08:08,269 --> 00:08:09,529 We've, we've seen that over the last 162 00:08:09,619 --> 00:08:10,159 Hmm. 163 00:08:10,819 --> 00:08:11,299 Uh, 164 00:08:13,579 --> 00:08:20,629 so this initial access broker found this credential folder sold 165 00:08:20,629 --> 00:08:26,029 it and bad guys bought it and used the credentials to this, uh, this. 166 00:08:26,509 --> 00:08:29,569 Subsequently this, this victim organization that, 167 00:08:29,629 --> 00:08:30,649 that called us for help. 168 00:08:31,339 --> 00:08:36,079 Um, and those bad guys use that access to commit their attack. 169 00:08:37,219 --> 00:08:43,009 Now I'm guessing that these initial access brokers, probably gather up 170 00:08:43,279 --> 00:08:49,429 thousands, tens of thousands, whatever large number of credentials or initial 171 00:08:49,519 --> 00:08:53,809 sort of compromise points at these organizations or with these people. 172 00:08:54,259 --> 00:08:59,599 But it's not like they're just selling it to a single individual, right? 173 00:09:00,259 --> 00:09:03,829 they like take that same package and be like, Hey, I'm gonna sell it to you. 174 00:09:03,829 --> 00:09:05,719 I'm gonna sell it to this other person. 175 00:09:05,929 --> 00:09:10,609 I'm gonna sell it to this third person, where all these sort of buyers might have 176 00:09:10,609 --> 00:09:12,709 access to the same sets of credentials. 177 00:09:13,489 --> 00:09:16,249 so there is a bit of reputation here, believe it or not. 178 00:09:16,249 --> 00:09:21,289 So if, if I had a hundred valid and, and backing up a little bit too. 179 00:09:21,289 --> 00:09:28,219 So, so let's say, let's say bad guys found a, uh, a vulnerable organization, and 180 00:09:28,219 --> 00:09:29,704 maybe that organization is a mobile app. 181 00:09:30,499 --> 00:09:33,619 know, we all, we all downloaded it, you know, a million people downloaded this 182 00:09:33,619 --> 00:09:38,779 mobile app we've created an account a lot of us being human 183 00:09:38,839 --> 00:09:42,409 will use information that we coincidentally use in other places. 184 00:09:42,409 --> 00:09:47,449 So, same password on this app that we use for our bank. 185 00:09:47,959 --> 00:09:50,659 You know, horrible situation, but it happens. 186 00:09:51,259 --> 00:09:52,069 Alright, so bad guys. 187 00:09:52,069 --> 00:09:53,359 Compromise this mobile app. 188 00:09:53,839 --> 00:09:57,649 They collect or harvest all of these, you know, million credentials. 189 00:09:59,059 --> 00:10:01,939 If they want the true value out of those credentials, they 190 00:10:01,939 --> 00:10:03,289 will go and validate them. 191 00:10:03,679 --> 00:10:06,919 So out of a million, 90% still work. 192 00:10:07,339 --> 00:10:09,559 So they can sell 90% of those. 193 00:10:10,669 --> 00:10:14,809 They can either sell it as one big chunk, which is less likely. 194 00:10:14,809 --> 00:10:19,249 What they'll probably do is analyze that data set and look for commonalities. 195 00:10:19,249 --> 00:10:26,659 Like I've got out of, out of 900,000, I've got, um, a hundred thousand, uh. 196 00:10:27,619 --> 00:10:32,539 Edu or, or military or public, public, uh, organization emails. 197 00:10:32,539 --> 00:10:33,649 And they'll, they'll bundle that. 198 00:10:33,649 --> 00:10:36,979 So there's some, you know, uh, relationship with that. 199 00:10:37,279 --> 00:10:40,639 'cause that's sometimes how threat actors work. 200 00:10:40,639 --> 00:10:42,319 They want to target something specific. 201 00:10:43,069 --> 00:10:43,309 All right. 202 00:10:43,309 --> 00:10:45,259 So they, they will bundle to some degree. 203 00:10:46,159 --> 00:10:49,759 but then to your, to your question too, if I, if I sold, if I sold 204 00:10:49,759 --> 00:10:54,339 900,000 to Curtis, would I also sell that same 900,000 to Prasanna? 205 00:10:54,649 --> 00:10:55,364 Well, maybe. 206 00:10:55,834 --> 00:11:01,294 Yeah, not likely because if you found out, because maybe Curtis used that 207 00:11:01,294 --> 00:11:04,474 password, that account first, and something happened and it got locked 208 00:11:04,474 --> 00:11:07,564 out, and that happened over a period of time, and then you go try to do it. 209 00:11:07,564 --> 00:11:10,504 And now that now it's not, they're not valid accounts, right? 210 00:11:11,314 --> 00:11:15,364 and so you can often find out that been sold more than once. 211 00:11:15,439 --> 00:11:17,464 Well, then you're not gonna buy from that person again. 212 00:11:17,834 --> 00:11:18,184 Right. 213 00:11:18,184 --> 00:11:19,234 It's a reputation. 214 00:11:19,804 --> 00:11:24,274 Yeah, and I think you had mentioned in a previous podcast episode, sort of if 215 00:11:24,304 --> 00:11:28,084 it's like invalidated email addresses or whatever else, it might sell at 216 00:11:28,084 --> 00:11:32,749 a lower cost sort of things that you know, have been validated and verified. 217 00:11:35,444 --> 00:11:35,724 Interesting. 218 00:11:36,064 --> 00:11:37,834 So very often, um. 219 00:11:39,874 --> 00:11:44,134 Yeah, there's probably only a couple of, of different categories of initial access. 220 00:11:44,134 --> 00:11:46,504 Like there's just normal like email addresses. 221 00:11:46,924 --> 00:11:50,044 Um, there's remote access, and I think I might be getting ahead of, uh, 222 00:11:50,074 --> 00:11:52,594 Curtis's, uh, uh, talking points here. 223 00:11:54,244 --> 00:11:59,824 domain admin level credentials, and then, um, that would give us a, a 224 00:11:59,824 --> 00:12:01,834 broad foothold within an organization. 225 00:12:02,269 --> 00:12:02,389 Hmm. 226 00:12:02,434 --> 00:12:05,014 So those range from $10. 227 00:12:05,764 --> 00:12:09,064 account for just email all the way up to a hundred thousand 228 00:12:09,064 --> 00:12:11,104 plus for an entire organization. 229 00:12:11,379 --> 00:12:14,674 Well, it, it would be, it would be like email and a password. 230 00:12:14,674 --> 00:12:14,914 Right. 231 00:12:14,914 --> 00:12:17,644 Or email in a way to authenticate right. 232 00:12:18,539 --> 00:12:19,444 And, and that's right. 233 00:12:19,444 --> 00:12:21,994 So sometimes these happen in combination because of 234 00:12:21,994 --> 00:12:23,374 multifactor authentication, right. 235 00:12:23,374 --> 00:12:27,484 So maybe I've got, um, a company credential. 236 00:12:27,874 --> 00:12:30,844 And then the multifactor goes to a personal email. 237 00:12:31,144 --> 00:12:33,964 So if I can, if I can, as an initial access broker, put 238 00:12:33,964 --> 00:12:35,374 those two pieces of valuable 239 00:12:35,419 --> 00:12:35,499 Hmm. 240 00:12:35,854 --> 00:12:37,714 together, I can sell that for more money. 241 00:12:39,124 --> 00:12:42,214 Which again, why you don't use email as a method, as 242 00:12:42,214 --> 00:12:45,004 multifactor authentication factor. 243 00:12:45,604 --> 00:12:48,664 Um, so yeah, that's interesting. 244 00:12:48,664 --> 00:12:49,864 I hadn't thought about that. 245 00:12:49,894 --> 00:12:53,674 The, the people could be able to, again, you, this is their job, right? 246 00:12:53,674 --> 00:12:57,664 This, their, their entire, their, uh, I'm gonna mispronounce 247 00:12:57,664 --> 00:13:01,114 this, but the ra, uh, right. 248 00:13:01,204 --> 00:13:01,564 Um. 249 00:13:01,684 --> 00:13:01,924 better. 250 00:13:02,629 --> 00:13:05,419 Um, yeah, the reason for being right. 251 00:13:05,839 --> 00:13:10,519 Um, and so they figured out ways to increase the value of the 252 00:13:10,519 --> 00:13:14,809 different, um, user IDs that they're trying to access, right? 253 00:13:14,809 --> 00:13:19,159 So if they can say, here's Curtis and here's, and we know that Curtis uses 254 00:13:19,159 --> 00:13:25,219 his email address as, um, you know, as is multifactor, then, um, you know, 255 00:13:25,309 --> 00:13:28,999 these two go together and that makes that that package worth even more. 256 00:13:29,444 --> 00:13:30,734 Uh, that's very interesting. 257 00:13:31,194 --> 00:13:31,314 Okay. 258 00:13:32,264 --> 00:13:36,494 So we've talked about so far, primarily username and password, 259 00:13:36,944 --> 00:13:41,384 uh, and perhaps a, you know, a pairing of of of email addresses. 260 00:13:41,804 --> 00:13:46,634 What other access methods might, uh, an IAB sell? 261 00:13:46,634 --> 00:13:46,664 I. 262 00:13:48,044 --> 00:13:50,954 Uh, so it could be information like how to access something. 263 00:13:50,954 --> 00:13:55,094 So that could be, uh, IP address plus port number plus. 264 00:13:55,709 --> 00:14:03,389 Service plus, you know, protocol, uh, plus, the necessary like VPN client. 265 00:14:04,299 --> 00:14:04,419 Hmm, 266 00:14:05,309 --> 00:14:09,149 so information is also, uh, considered access if that's what's 267 00:14:09,149 --> 00:14:11,609 necessary to conduct the access. 268 00:14:11,824 --> 00:14:16,864 So for that one, Mike, would it also be, as an example, say a threat actor 269 00:14:16,864 --> 00:14:21,844 is like, okay, I discovered something new in VMware, or take a software stack. 270 00:14:22,804 --> 00:14:27,964 And so would IAPs be responsible then, or potentially be like, Hey, let me scour 271 00:14:27,964 --> 00:14:32,074 the internet, find all of the public facing VMware servers that are running 272 00:14:32,074 --> 00:14:34,084 X version and give you back a list. 273 00:14:34,084 --> 00:14:37,564 Is that something an IAB would potentially. 274 00:14:37,909 --> 00:14:40,399 so that, that, that's a little higher level. 275 00:14:40,984 --> 00:14:41,104 Okay. 276 00:14:41,449 --> 00:14:43,429 what, what they would do in that case. 277 00:14:43,429 --> 00:14:47,989 So I, as an example, um, let's just say the Fortinet, you know, zero 278 00:14:47,989 --> 00:14:52,039 days that came out that allowed us to, attack a firewall and gain a 279 00:14:52,039 --> 00:14:53,809 foothold and, and all that good stuff. 280 00:14:55,159 --> 00:14:56,959 It would be very easy to run a, 281 00:14:58,039 --> 00:15:02,629 an internet script to find all those vulnerable Fortinet firewalls. 282 00:15:02,719 --> 00:15:08,389 What an internet access broker would do is start to go one by one and 283 00:15:08,389 --> 00:15:10,399 actually exploit that vulnerability. 284 00:15:10,789 --> 00:15:15,049 To gain the access, and then they would sell that persistent access. 285 00:15:15,799 --> 00:15:20,239 So that's not a credential, that's access, it's, it's, it's a live thread. 286 00:15:20,809 --> 00:15:23,839 Maybe it's running on a, running from a, you know, a, 287 00:15:24,019 --> 00:15:27,529 um, a leased server or botnet. 288 00:15:27,949 --> 00:15:29,239 That's what they would then sell. 289 00:15:29,239 --> 00:15:33,379 So instead of credentials, it's a live, it's a live, uh, a 290 00:15:33,499 --> 00:15:34,309 Remote access. 291 00:15:34,759 --> 00:15:34,939 Yep. 292 00:15:35,464 --> 00:15:38,614 So that's a, a vulnerability that was exploited. 293 00:15:38,764 --> 00:15:39,244 Right. 294 00:15:39,249 --> 00:15:42,634 Um, and there's a, there's a whole group of people that they discover 295 00:15:42,634 --> 00:15:43,894 these vulnerabilities, right? 296 00:15:43,894 --> 00:15:45,844 And then these guys watch. 297 00:15:46,444 --> 00:15:49,324 For the announcement of these vulnerabilities and they're like, okay, 298 00:15:49,324 --> 00:15:52,114 we're gonna go scan for open, whatever. 299 00:15:52,204 --> 00:15:52,624 Right. 300 00:15:53,014 --> 00:15:59,464 Um, and so, so we talk about again, email, password, and now 301 00:15:59,464 --> 00:16:02,314 vulnerabilities of particular services. 302 00:16:02,824 --> 00:16:05,764 Um, any, anything else that there might be selling. 303 00:16:06,454 --> 00:16:08,644 So it could be a compromised machine. 304 00:16:08,764 --> 00:16:12,034 So, you know, let's say someone that, that writes 305 00:16:15,124 --> 00:16:16,414 they get paid for malware. 306 00:16:17,314 --> 00:16:22,684 Someone that wants to, um, gain access to a computer might buy the malware 307 00:16:23,014 --> 00:16:26,644 and hire or conduct phishing exercises. 308 00:16:27,469 --> 00:16:27,769 Right. 309 00:16:27,829 --> 00:16:28,009 So 310 00:16:28,009 --> 00:16:30,709 now someone clicked on the email that got the, that, 311 00:16:30,919 --> 00:16:31,139 Um. 312 00:16:31,159 --> 00:16:34,849 had the malware in it, and now I've got access to a computer 313 00:16:34,849 --> 00:16:36,109 within an organization. 314 00:16:37,069 --> 00:16:41,989 Um, so instead of access at the perimeter, I've got access the internal 315 00:16:41,989 --> 00:16:43,579 network and now I can sell that. 316 00:16:44,674 --> 00:16:50,134 So the IB itself writes malware in that case deploys it, if you will, 317 00:16:50,134 --> 00:16:54,004 and then sells to other people, Hey, I have access to this particular 318 00:16:54,004 --> 00:16:56,554 computer within the organization. 319 00:16:56,644 --> 00:17:01,504 So very similar to like an ev uh, uh, a traditional burglar, right? 320 00:17:01,504 --> 00:17:02,674 They're gonna break into a building. 321 00:17:02,674 --> 00:17:04,024 They've got all these different tools. 322 00:17:04,024 --> 00:17:06,064 They've got, you know, something that can fuzz a camera. 323 00:17:06,064 --> 00:17:10,864 They've got something that can pick a lock or disable alarm systems or social 324 00:17:10,864 --> 00:17:15,364 engineer somebody into letting them in the building pretending to be a vendor, 325 00:17:15,814 --> 00:17:19,684 uh, that now has access to the building to deliver a package that, you know. 326 00:17:19,684 --> 00:17:22,624 So if you, if you kind of think of it in real world terms. 327 00:17:23,149 --> 00:17:29,574 Uh, it is that, um, that burglar, that, that can into a building and, and 328 00:17:29,579 --> 00:17:31,999 facilitate, uh, access to something. 329 00:17:31,999 --> 00:17:33,109 And that's what they're selling. 330 00:17:33,109 --> 00:17:37,009 So they never, they never leave with anything of value. 331 00:17:37,699 --> 00:17:40,159 Uh, they don't, they don't, they don't steal anything. 332 00:17:41,119 --> 00:17:42,019 corrupt anything. 333 00:17:42,019 --> 00:17:43,519 They don't manipulate anything. 334 00:17:43,609 --> 00:17:47,899 They just create the access, or sell the access. 335 00:17:48,949 --> 00:17:51,739 And, you know, another on the, on the delivery part. 336 00:17:51,739 --> 00:17:55,309 'cause we've, we've done, when, when companies hire us to do red teaming, 337 00:17:55,639 --> 00:17:57,109 we've done some creative things too. 338 00:17:57,109 --> 00:18:01,549 One of the creative things that we did was we, we custom configured an iPhone. 339 00:18:01,549 --> 00:18:02,629 This was a long time ago. 340 00:18:03,109 --> 00:18:04,789 Uh, we custom configured an iPhone. 341 00:18:04,819 --> 00:18:08,084 'cause we couldn't, we couldn't gain access through the, the 342 00:18:08,089 --> 00:18:09,259 perimeter of the company. 343 00:18:10,399 --> 00:18:13,429 And it was, it was fairly well guarded as far as a campus goes. 344 00:18:14,239 --> 00:18:16,699 we did is we configured an iPhone and we shipped it to them. 345 00:18:17,434 --> 00:18:23,884 it sat in their mail room turned on, and we hacked their wireless network 346 00:18:23,884 --> 00:18:30,034 from an iPhone gained access to their network over the, the cell cellular 347 00:18:30,034 --> 00:18:31,924 data network through the iPhone. 348 00:18:33,034 --> 00:18:43,714 And so you think of a, um, uh, kind of an out of band, um, access attack, 349 00:18:43,894 --> 00:18:45,639 uh, things like that are, are. 350 00:18:46,504 --> 00:18:50,074 You know, few and far between, but you know, bad guys are creative. 351 00:18:50,914 --> 00:18:56,824 another thing that you could do is, um, as far as the supply chain goes, 352 00:18:56,824 --> 00:19:01,144 is if you know they're ordering a bunch of computers, configure a computer, 353 00:19:01,354 --> 00:19:06,124 brand new, you know, go buy a brand new Dell and put your malware on it. 354 00:19:06,694 --> 00:19:08,644 They did this with picture frames a long time ago. 355 00:19:08,644 --> 00:19:09,904 I don't know if y'all remember that, those 356 00:19:09,904 --> 00:19:14,284 L-E-L-C-D picture frames, they came custom, custom built with malware. 357 00:19:15,184 --> 00:19:15,634 Um. 358 00:19:16,384 --> 00:19:18,484 that they could spy on you and do other weird stuff, but, 359 00:19:20,219 --> 00:19:23,734 I would think I, I would think that with these, these, I, you 360 00:19:23,734 --> 00:19:25,264 know, you talked about that. 361 00:19:26,449 --> 00:19:28,339 They're business, they're going after the stuff. 362 00:19:28,489 --> 00:19:32,659 I, I'm wondering the, the type, the type of stuff you're talking about right there. 363 00:19:32,719 --> 00:19:35,209 It, it seems a a lot more targeted, 364 00:19:35,509 --> 00:19:35,929 mm-hmm. 365 00:19:36,589 --> 00:19:40,699 and where you say, I want to attack this company. 366 00:19:41,344 --> 00:19:41,794 Right. 367 00:19:42,304 --> 00:19:45,604 Um, and so I'm gonna do whatever it is I need to do. 368 00:19:45,754 --> 00:19:46,174 Right. 369 00:19:46,204 --> 00:19:49,564 Um, I'm gonna, you know, like you said, send in and we, we did a whole episode 370 00:19:49,564 --> 00:19:52,894 on this, by the way of, uh, do you remember what the title of that was? 371 00:19:52,894 --> 00:19:53,414 Prasanna? 372 00:19:53,434 --> 00:19:57,694 That there was a whole episode about like creating devices that you put in 373 00:19:57,694 --> 00:20:00,364 there, you know, um, it was a while ago. 374 00:20:00,814 --> 00:20:03,034 Um, but the. 375 00:20:03,469 --> 00:20:07,009 The, the seems very targeted and, and almost personal. 376 00:20:07,339 --> 00:20:10,219 Is that something an IAB would do is, or is that like a 377 00:20:10,219 --> 00:20:12,139 different type of organization? 378 00:20:13,584 --> 00:20:14,904 Uh, it is. 379 00:20:14,934 --> 00:20:20,544 And to your point though, um, or, or maybe to touch on that a little more 380 00:20:20,544 --> 00:20:27,354 is that I, I Bs or, or access brokers operate in a, a few different ways. 381 00:20:27,804 --> 00:20:29,034 Uh, or anything. 382 00:20:29,034 --> 00:20:31,854 I guess it also depends on the threat actor, but so we can. 383 00:20:32,689 --> 00:20:36,679 As an IAB, we can search the internet, right? 384 00:20:36,679 --> 00:20:39,199 For, for weaknesses and, and what's out there. 385 00:20:39,409 --> 00:20:44,359 Sometimes an IAB just buys credentials from someone else that hasn't validated 386 00:20:44,359 --> 00:20:46,189 them, so then I'm gonna go validate them 387 00:20:46,489 --> 00:20:48,889 and resell them as valid credentials. 388 00:20:48,919 --> 00:20:53,659 They do the same thing with credit cards and, PI, I like social security numbers 389 00:20:53,659 --> 00:21:00,739 and so on, but the other part of that is I can asano as a, as a. Uh, a more 390 00:21:00,739 --> 00:21:06,409 involved threat actor, maybe I'm gonna go hire an access broker to find the 391 00:21:06,409 --> 00:21:08,839 access I need to a particular target. 392 00:21:08,899 --> 00:21:09,259 So that 393 00:21:09,259 --> 00:21:10,279 would be more targeted. 394 00:21:10,699 --> 00:21:13,789 So I wanna, I want to break into this defense contractor. 395 00:21:13,789 --> 00:21:18,229 I'm gonna hire an IAB to figure out the best way to do that, and 396 00:21:18,229 --> 00:21:19,939 then sell me the access they get. 397 00:21:21,264 --> 00:21:24,564 So we had talked on a previous podcast episode about. 398 00:21:25,794 --> 00:21:27,084 ransomware as a service. 399 00:21:27,319 --> 00:21:27,619 Mm-hmm. 400 00:21:27,894 --> 00:21:34,554 And so do these ransom as a service organizations also have their own IAB 401 00:21:35,424 --> 00:21:41,574 as an offering within that package, or do they typically sort of contract 402 00:21:41,574 --> 00:21:45,624 with other IABs that exist to gain that initial foothold and then, 403 00:21:45,684 --> 00:21:47,484 or foothold and then they start? 404 00:21:48,694 --> 00:21:49,534 Yeah, it depends. 405 00:21:49,594 --> 00:21:54,274 Uh, some, some threat actors have a, a whole enterprise 406 00:21:54,274 --> 00:21:55,384 that, that does everything. 407 00:21:55,384 --> 00:21:57,304 You know, you're just, you're in the IAB department. 408 00:21:58,069 --> 00:21:59,089 Uh, but then 409 00:21:59,229 --> 00:22:00,049 So bonkers. 410 00:22:01,429 --> 00:22:04,969 others, others will go out and source information based on the, 411 00:22:05,059 --> 00:22:07,459 the, the, requirements or the need. 412 00:22:07,519 --> 00:22:13,579 So you could hire me as a ransom, as a service, um, threat actor. 413 00:22:14,629 --> 00:22:18,199 Part of that onboarding or, or that discussion will be determining if, if you 414 00:22:18,199 --> 00:22:20,419 have a target or a particular objective. 415 00:22:20,659 --> 00:22:24,589 If so, then I can go source that, you know, I, I've got my Rolodex of 416 00:22:24,589 --> 00:22:28,384 bad guys and I'll, I'll go find a. Access broker that can help me with 417 00:22:28,384 --> 00:22:29,914 whatever your particular needs are. 418 00:22:30,124 --> 00:22:34,564 If not, then I'll just go buy a, a blind list off the dark web for, 419 00:22:34,714 --> 00:22:38,704 you know, whatever, because you've already paid me my money as a, as a 420 00:22:38,704 --> 00:22:39,304 service. 421 00:22:39,634 --> 00:22:44,044 Um, I'm not, I'm not too concerned if all that information's been validated or not. 422 00:22:44,899 --> 00:22:45,319 Gotcha. 423 00:22:45,784 --> 00:22:48,904 So let's talk about some of the ways that this happens, right? 424 00:22:48,904 --> 00:22:55,024 So with the stolen credentials, uh, is this primarily phishing? 425 00:22:55,804 --> 00:22:58,384 Um, and, and similar activities? 426 00:23:01,009 --> 00:23:01,729 It's not. 427 00:23:01,969 --> 00:23:04,969 Um, so when to collect, um, 428 00:23:05,089 --> 00:23:05,209 I, 429 00:23:05,599 --> 00:23:10,999 to be most effective at collecting credentials, you're gonna go after a 430 00:23:10,999 --> 00:23:12,349 source that has a lot of credentials. 431 00:23:13,029 --> 00:23:13,319 okay. 432 00:23:13,414 --> 00:23:17,854 and so like shiny hunters is a threat actor group that's active right now, 433 00:23:17,854 --> 00:23:19,414 and they've been active for a while. 434 00:23:19,894 --> 00:23:25,624 And their claim to fame, um, is I believe one of the largest data 435 00:23:25,624 --> 00:23:29,074 compromises in history, part of it. 436 00:23:29,074 --> 00:23:32,404 Uh, it may have been them in another group working together, but what 437 00:23:32,404 --> 00:23:36,454 they, what they've done is, again, realizing that we're all human and 438 00:23:36,454 --> 00:23:38,344 we reuse information all the time. 439 00:23:39,079 --> 00:23:44,089 Instead of attacking your phone or your bank or your email 440 00:23:44,329 --> 00:23:48,409 for the one at, you know, one at a time type of value, 441 00:23:48,859 --> 00:23:53,599 they've gone to, uh, mobile apps and third party apps that are 442 00:23:54,079 --> 00:23:56,029 really just for entertainment. 443 00:23:57,499 --> 00:24:00,499 Realizing that an entertainment app's not gonna have as much 444 00:24:00,499 --> 00:24:02,089 security as a banking app. 445 00:24:02,929 --> 00:24:05,149 And so if I can go and compromise that. 446 00:24:05,149 --> 00:24:09,859 A company that built that game, like talking Tom as an example. 447 00:24:12,439 --> 00:24:17,059 if I can compromise that and get access to the millions of people that have 448 00:24:17,059 --> 00:24:22,189 signed up for that app over time, very likely, high percentage wise. 449 00:24:22,249 --> 00:24:25,879 Uh, and, and I've actually got a chart for this that I did several years ago, so it's 450 00:24:25,879 --> 00:24:32,209 dated, but I think it's representative, the vast majority of credentials used 451 00:24:32,209 --> 00:24:34,669 in third party apps, mirror identically. 452 00:24:35,629 --> 00:24:40,489 to the credentials people use at work, not just, not just the 453 00:24:40,489 --> 00:24:42,109 password, but also the email. 454 00:24:42,589 --> 00:24:45,499 So they didn't sign up for talking Tom with their personal email. 455 00:24:45,499 --> 00:24:51,049 They signed up for it with their military email or their edu or whatever, and 456 00:24:51,094 --> 00:24:52,144 Why. 457 00:24:52,249 --> 00:24:53,509 password because you know what? 458 00:24:53,509 --> 00:24:54,654 We're lazy and it's just easy. 459 00:24:55,009 --> 00:24:58,609 Well, and, and also, I mean, doesn't that also mean that there's some 460 00:24:58,609 --> 00:25:02,059 vulnerability And I, you know, you started by saying that, that, that that 461 00:25:02,059 --> 00:25:07,579 app possibly is not as security focused, but this means that if they're getting 462 00:25:07,579 --> 00:25:11,689 the username and password, that means that there's also vulnerability in how 463 00:25:11,689 --> 00:25:13,969 they're storing the passwords, right? 464 00:25:13,969 --> 00:25:17,329 Because you normally, you're gonna get salted and hashed passwords, right? 465 00:25:18,019 --> 00:25:19,269 This wouldn't be within the app. 466 00:25:19,269 --> 00:25:19,789 This would be the. 467 00:25:20,524 --> 00:25:23,824 Uh, an attack on the data store in the backend at the company. 468 00:25:23,884 --> 00:25:26,374 So they're not attacking the app, they're attacking the company. 469 00:25:26,914 --> 00:25:27,604 that makes sense. 470 00:25:27,784 --> 00:25:30,274 But again, the same concept applies, right? 471 00:25:30,274 --> 00:25:34,204 That, that perhaps they didn't use the best cybersecurity when 472 00:25:34,204 --> 00:25:37,624 storing the, when creating the, the backend infrastructure, right? 473 00:25:37,834 --> 00:25:38,104 Right. 474 00:25:38,104 --> 00:25:42,394 Well, and, and I know a little bit about the mobile app. 475 00:25:42,754 --> 00:25:47,014 Ecosystem and you know, it's all, you know, how much, how much can I make with, 476 00:25:47,254 --> 00:25:48,754 you know, doing as little as possible. 477 00:25:48,814 --> 00:25:52,534 And with AI these days, I mean it's, it's crazy, but a lot of those 478 00:25:52,534 --> 00:25:57,574 apps aren't focused on security because there's really no security. 479 00:25:57,634 --> 00:26:00,574 And, and the only reason they're asking for credentials is so they can track 480 00:26:00,574 --> 00:26:03,724 you as a user to push advertising to you, which is how they make their money. 481 00:26:04,924 --> 00:26:07,714 Uh, so they're, they're not security focused at all. 482 00:26:07,714 --> 00:26:07,774 Um. 483 00:26:10,309 --> 00:26:14,059 So, yeah, it's, it's usually pretty, pretty easy, or, or it has been, uh, 484 00:26:14,059 --> 00:26:17,939 to compromise those, those software companies to get access to the data. 485 00:26:18,499 --> 00:26:22,159 All right, so you've got this, this, you're going after these third party apps 486 00:26:22,159 --> 00:26:24,739 and sites and whatnot to get credentials. 487 00:26:25,189 --> 00:26:28,579 Uh, and that, I get that because that's gonna be like a large 488 00:26:28,579 --> 00:26:33,409 source of a, of a large number of, you know, names and passwords. 489 00:26:33,919 --> 00:26:39,079 Uh, and then after that, is this now where we're talking about things like phishing. 490 00:26:40,444 --> 00:26:40,744 Nope. 491 00:26:41,104 --> 00:26:42,124 Oh, you're killing me. 492 00:26:42,394 --> 00:26:42,604 on the 493 00:26:42,784 --> 00:26:43,294 Really? 494 00:26:43,474 --> 00:26:43,954 Okay. 495 00:26:44,014 --> 00:26:44,524 harvesting 496 00:26:44,554 --> 00:26:46,864 I, it's just, we talk about it so much. 497 00:26:47,719 --> 00:26:56,689 Well, so phishing is, is, uh, it's usually for delivery, um, or, or affiliate, um, 498 00:26:58,444 --> 00:26:59,344 Oh, I see what you're saying. 499 00:26:59,344 --> 00:27:03,904 Getting you, getting you to download the, the, the, um, the payload. 500 00:27:03,934 --> 00:27:04,294 Right. 501 00:27:04,489 --> 00:27:05,179 Yep, yep. 502 00:27:05,494 --> 00:27:05,884 Okay. 503 00:27:05,944 --> 00:27:06,454 All right. 504 00:27:06,589 --> 00:27:09,379 Or, or to, to redirect you to a website. 505 00:27:09,379 --> 00:27:10,729 So an affiliate gets paid, 506 00:27:10,879 --> 00:27:11,629 Yeah. 507 00:27:11,809 --> 00:27:12,529 site or something 508 00:27:12,529 --> 00:27:12,949 Okay. 509 00:27:13,189 --> 00:27:13,459 All right. 510 00:27:13,459 --> 00:27:14,689 That's why we talk about it so much. 511 00:27:14,689 --> 00:27:15,079 All right. 512 00:27:15,679 --> 00:27:16,369 Um. 513 00:27:16,609 --> 00:27:22,009 so when you think about phishing, um, and, and I mentioned this uh, in a prior 514 00:27:22,009 --> 00:27:25,669 episode too, and, and the numbers have changed, but it's, it's relatively, 515 00:27:25,669 --> 00:27:30,019 and so I'm just gonna say around, but give or take, you know, maybe 5%. 516 00:27:30,499 --> 00:27:33,439 The success rate at phishing is, is around 22%. 517 00:27:34,789 --> 00:27:37,729 The success rate at, you know, collecting a million. 518 00:27:38,959 --> 00:27:42,799 by attacking a low security third party app developer is pretty high. 519 00:27:43,952 --> 00:27:44,089 Hmm. 520 00:27:46,339 --> 00:27:46,729 Yeah. 521 00:27:46,759 --> 00:27:47,659 that's disheartening. 522 00:27:48,079 --> 00:27:48,409 Okay. 523 00:27:48,409 --> 00:27:51,889 If so, if, if phishing isn't next, what is next? 524 00:27:52,789 --> 00:27:56,299 After the, going after the giant database of username and 525 00:27:56,299 --> 00:27:57,979 password, what's next after that? 526 00:27:58,304 --> 00:28:01,459 those would be the onesie, twosie large organizations. 527 00:28:01,549 --> 00:28:04,609 Um, but it, it, it's all the same strategy. 528 00:28:04,609 --> 00:28:07,039 It's how many, you know, the, the one to many. 529 00:28:07,534 --> 00:28:12,574 Strategy, how many, how many of these one, you know, singular attacks will result 530 00:28:12,574 --> 00:28:15,484 in this, know, volume of credentials? 531 00:28:16,744 --> 00:28:19,264 you know, I'm not gonna attack a small company with 10 employees. 532 00:28:19,264 --> 00:28:24,514 I'm gonna attack a large company with a thousand employees or 200,000 employees. 533 00:28:25,234 --> 00:28:29,284 Um, and so the access broker then is going to strategize on the best 534 00:28:29,284 --> 00:28:34,594 way to do that is that, maybe I get hired there, so now I'm an insider. 535 00:28:34,954 --> 00:28:38,674 Um, and I just, you know, steal all the, you know, the, the password 536 00:28:38,674 --> 00:28:45,334 database, the SAM database, or I go to work for a, uh, IT support company. 537 00:28:45,814 --> 00:28:47,374 And now, so that's one to many, right? 538 00:28:47,374 --> 00:28:54,004 So I'm an, I'm an MSP that supports multiple clients, and so I have access 539 00:28:54,004 --> 00:28:55,714 into all these different environments, 540 00:28:56,434 --> 00:29:01,234 Yeah, there, there was a few years ago, there was that, uh, service 541 00:29:01,234 --> 00:29:03,604 provider for dentists, right? 542 00:29:03,634 --> 00:29:07,834 That, um, that they got hacked and then basically you had access 543 00:29:07,834 --> 00:29:09,004 to all these dentists, right? 544 00:29:09,739 --> 00:29:09,979 Yep. 545 00:29:11,149 --> 00:29:20,269 And so, um, you know, that, that remote access, you know, the, um, remote desktop 546 00:29:20,269 --> 00:29:22,669 access, uh, into those environments in. 547 00:29:23,839 --> 00:29:25,819 Yeah, there is a problem with that too, because a lot of 548 00:29:25,819 --> 00:29:27,499 times it's the same password. 549 00:29:27,589 --> 00:29:31,489 So as a support company, you know, maybe I'm supporting Curtis's 550 00:29:31,489 --> 00:29:33,169 Company and Prasannas company. 551 00:29:33,409 --> 00:29:36,559 My, my credentials to log into your environments are the same. 552 00:29:37,204 --> 00:29:37,424 Ugh. 553 00:29:38,869 --> 00:29:39,379 We see that a 554 00:29:39,574 --> 00:29:40,294 That's just wrong. 555 00:29:40,984 --> 00:29:44,164 Uh, you brought up, you brought up my ears. 556 00:29:44,239 --> 00:29:47,989 P picked up or picked up there, I heard remote desktop. 557 00:29:48,499 --> 00:29:54,679 RDP is like my favorite, uh, tool to pick on from a, from a, you know, please 558 00:29:54,739 --> 00:29:56,929 stop using this the way you're using it. 559 00:29:56,929 --> 00:29:58,339 You want to talk about that a little bit. 560 00:29:59,509 --> 00:30:01,369 So RDP and, and there's 561 00:30:01,399 --> 00:30:04,124 Wait, and by the way, that's the, that's the, I call it the 562 00:30:04,129 --> 00:30:08,179 ransomware deployment protocol, but it's the Remote Desktop Protocol. 563 00:30:08,479 --> 00:30:09,049 So. 564 00:30:10,279 --> 00:30:10,994 Copyright pending. 565 00:30:11,914 --> 00:30:14,914 has some inherent issues that they've gotten better over time. 566 00:30:14,914 --> 00:30:19,354 I mean, back in the day, uh, when an admin RD would use RDP to a server, 567 00:30:19,354 --> 00:30:25,984 you could capture those keystrokes live across the network, and just replay it. 568 00:30:26,194 --> 00:30:27,779 Uh, but. 569 00:30:28,939 --> 00:30:33,589 in general is, is a pretty insecure protocol, uh, on its own. 570 00:30:33,889 --> 00:30:40,129 Well, what we've seen a lot and, and bad guys understand this too, is, is cis 571 00:30:40,129 --> 00:30:45,799 admins are using RDP across the internet, uh, when connecting in to, to do remote 572 00:30:45,799 --> 00:30:47,569 support after hours or on the weekends. 573 00:30:47,569 --> 00:30:49,399 You know, I don't wanna drive to the office and do this. 574 00:30:49,399 --> 00:30:50,629 I can just RDP. 575 00:30:50,989 --> 00:30:55,699 And so, I mean, it's, it's, it's not a good solution, um, for remote 576 00:30:55,699 --> 00:30:57,799 support, but we still use it. 577 00:30:58,144 --> 00:31:01,534 Or in, actually, even in environments where we don't use it, that service 578 00:31:01,534 --> 00:31:02,914 is still turned on and available. 579 00:31:03,364 --> 00:31:03,904 And so 580 00:31:03,994 --> 00:31:07,804 And, and of, and accessible via the internet, which is just wrong. 581 00:31:07,804 --> 00:31:09,154 All kinds of wrong, right? 582 00:31:09,814 --> 00:31:10,084 yep. 583 00:31:10,084 --> 00:31:14,314 So if, if you haven't, if you haven't customized your firewall to prevent 584 00:31:14,314 --> 00:31:19,444 certain protocols like RDP or FTP or Telnet through your firewall, 585 00:31:19,504 --> 00:31:22,594 um, yeah, that's, that's something bad guys will find pretty quick. 586 00:31:22,834 --> 00:31:26,014 There's a search engine, and I don't think we've, we've talked about it, but 587 00:31:26,014 --> 00:31:27,724 there is a search engine called Show Dan. 588 00:31:28,159 --> 00:31:28,379 Hmm. 589 00:31:28,999 --> 00:31:32,329 and you know, there's free accounts and then there's, you know, the 590 00:31:32,329 --> 00:31:35,089 premium accounts, but you can search for any vulnerability, 591 00:31:35,089 --> 00:31:36,139 anything you're looking for. 592 00:31:36,229 --> 00:31:40,339 Shodan has already mapped, the internet, the entire world internet. 593 00:31:40,879 --> 00:31:43,969 Uh, so when a new vulnerability comes out, you can go shodan and go, Hey, show 594 00:31:43,969 --> 00:31:46,099 me, show me all these Fortinet firewalls, 595 00:31:46,399 --> 00:31:49,549 and it will show you all of them what ports are open and 596 00:31:49,549 --> 00:31:50,719 what services are running. 597 00:31:50,719 --> 00:31:52,309 And yeah, 598 00:31:52,594 --> 00:31:53,374 It is scary. 599 00:31:53,629 --> 00:31:53,899 if you're. 600 00:31:54,934 --> 00:31:57,694 If you're not maintaining good hygiene, someone's gonna, someone's 601 00:31:57,694 --> 00:31:59,194 gonna suggest you buy some deodorant. 602 00:32:02,869 --> 00:32:07,669 Um, so I, I like, you know, basically stolen credentials from various, 603 00:32:07,794 --> 00:32:11,899 the, the, the one, it, it just kills me the, the statement you made, and 604 00:32:11,899 --> 00:32:14,534 I, and I know that, and I guess I shouldn't be surprised the idea that. 605 00:32:15,799 --> 00:32:20,029 People use the same username and password, you know, everywhere, right? 606 00:32:20,089 --> 00:32:28,789 Um, and especially across personal and, um, you know, um, corporate, right? 607 00:32:29,269 --> 00:32:33,409 Um, and you know, we all know that we, you should not be having 608 00:32:33,409 --> 00:32:38,179 RDP publicly accessible, uh, you know, via the internet, right? 609 00:32:38,209 --> 00:32:40,009 Um, there are other ways to do that. 610 00:32:40,429 --> 00:32:41,029 Um. 611 00:32:41,584 --> 00:32:44,434 What, c Can you think of other ways that they're grabbing? 612 00:32:44,794 --> 00:32:48,934 Uh, and, and by the way, that's just in general, I'd say any remote access 613 00:32:48,934 --> 00:32:53,974 thing like that, that isn't designed to be publicly accessible shouldn't be. 614 00:32:54,124 --> 00:32:57,994 So I, I, I'm looking at a list of of concerns and I see web shells. 615 00:32:57,994 --> 00:32:59,159 You wanna talk about that a little bit? 616 00:33:00,064 --> 00:33:04,624 So a web shell is, you know, well first of all, a shell is, is like a command prompt. 617 00:33:04,624 --> 00:33:06,904 So if you can, we call it pop in a shell. 618 00:33:06,904 --> 00:33:12,844 So you can get root, you know, shell level access to a computer, uh, a command line, 619 00:33:12,934 --> 00:33:17,044 uh, which is usually more effective than, than the normal interface that we're, 620 00:33:17,074 --> 00:33:20,224 we're accustomed to clicking around and opening folders and that kind of thing. 621 00:33:20,554 --> 00:33:24,454 So shell access, is that c prompter or admin prompt. 622 00:33:25,099 --> 00:33:30,379 Uh, the web shell is, is just access to a web-based environment. 623 00:33:30,379 --> 00:33:34,279 So whether that's, like a cloud infrastructure like Azure 624 00:33:34,369 --> 00:33:40,429 or AWS, or it could be that, that cloud-based system, uh, so maybe 625 00:33:40,429 --> 00:33:45,649 your, your financial system or your, your ERP is cloud hosted or, uh. 626 00:33:46,369 --> 00:33:52,129 Your, your bank account or, or whatever it is, your bank system, inventory systems. 627 00:33:52,579 --> 00:34:00,199 And so the web shell or web session would be a compromise of how that, that system, 628 00:34:00,289 --> 00:34:06,349 that, that website, that web portal, that web infrastructure, uh, uh, authenticates. 629 00:34:06,379 --> 00:34:12,769 So it's you, you stole someone's session cookies, and you can replay those or, 630 00:34:12,769 --> 00:34:15,439 or, or copy them or re uh, or sell them. 631 00:34:16,504 --> 00:34:20,404 Or it's, um, uh, persistent access. 632 00:34:20,404 --> 00:34:24,874 So for example, if I sit at Starbucks with my, my rogue wireless access point 633 00:34:24,874 --> 00:34:29,674 that says, Starbucks, this, this, you know, 5G plus, so you're gonna use that 634 00:34:29,674 --> 00:34:31,654 one 'cause it's faster than regular 5G. 635 00:34:32,044 --> 00:34:35,764 Or I knock everybody off of the Starbucks one and they rejoined my fake one. 636 00:34:36,154 --> 00:34:39,814 Uh, and now all of that traffic is flowing through my fake. 637 00:34:39,859 --> 00:34:41,689 A access point. 638 00:34:42,139 --> 00:34:44,629 And I can capture, especially if I am, I'm watching you. 639 00:34:44,659 --> 00:34:46,789 'cause I'm sitting next to you at Starbucks and you're logging 640 00:34:46,789 --> 00:34:49,099 into your bank or, that website. 641 00:34:49,489 --> 00:34:53,839 Uh, I know traffic as it's flowing and I can capture that stuff and 642 00:34:53,839 --> 00:34:56,689 potentially replay it, uh, or hijack it. 643 00:34:56,959 --> 00:34:59,749 And so now I'm, I'm in your session and I kick you off. 644 00:34:59,749 --> 00:35:00,949 And now it's just me. 645 00:35:01,429 --> 00:35:03,019 Uh, so there's a lot you can do. 646 00:35:04,504 --> 00:35:08,494 Over the internet, uh, whether you're, we, we've call some of those man in 647 00:35:08,494 --> 00:35:11,794 the middle attacks where you started it, and I can see where you're going. 648 00:35:11,794 --> 00:35:16,414 I inject myself in the middle and, and manipulate traffic or, or replay traffic. 649 00:35:16,894 --> 00:35:20,224 Uh, so those are types of things you can do, but at the end of the 650 00:35:20,224 --> 00:35:23,284 day, it's what, what can I do to get me access to something that's 651 00:35:23,284 --> 00:35:25,054 valuable enough for me to resell 652 00:35:25,564 --> 00:35:25,984 and. 653 00:35:26,579 --> 00:35:30,389 The other question you mentioned about other things that, that they sell, um, 654 00:35:30,599 --> 00:35:32,459 and some of 'em based on vulnerabilities. 655 00:35:32,459 --> 00:35:37,769 So vulnerabilities in, you know, Cisco VPN or Fortinet, VPN or Citrix, or, 656 00:35:38,249 --> 00:35:40,289 uh, some of these insecure protocols. 657 00:35:40,649 --> 00:35:44,909 Uh, again, it's just spending the time to do the research to figure out who's, 658 00:35:44,999 --> 00:35:46,919 who's vulnerable to these things. 659 00:35:47,819 --> 00:35:52,139 Validating it by actually compromising the security through 660 00:35:52,139 --> 00:35:54,089 a vulnerability or, or known. 661 00:35:54,509 --> 00:36:01,019 Um, known method, establishing some persistent access there and selling it. 662 00:36:01,739 --> 00:36:07,034 Yeah, so philosophical question, or maybe theoretical. 663 00:36:07,994 --> 00:36:11,294 If so, ransomware is prevalent, right? 664 00:36:12,164 --> 00:36:15,644 The number of attacks right, have gone through the roof. 665 00:36:16,814 --> 00:36:22,694 If we focused all the efforts on eliminating IABs, would 666 00:36:22,694 --> 00:36:23,594 that make a difference? 667 00:36:24,059 --> 00:36:24,329 Nope. 668 00:36:26,009 --> 00:36:29,129 It'll just make the other threat actors have to work harder. 669 00:36:29,489 --> 00:36:30,644 'cause right now they're just outsourcing it. 670 00:36:31,724 --> 00:36:33,584 You know, it's like being a general contractor. 671 00:36:33,584 --> 00:36:34,544 You don't do all the work. 672 00:36:34,544 --> 00:36:39,254 You find the subcontractors to, to make your life easier and you just put money. 673 00:36:39,254 --> 00:36:40,574 You just, you know, you mark it up. 674 00:36:40,934 --> 00:36:41,294 Yeah, 675 00:36:41,864 --> 00:36:42,044 Yep. 676 00:36:43,334 --> 00:36:44,759 Yeah, it's like the, yeah. 677 00:36:44,924 --> 00:36:47,864 the IABs go away, then you just bring everything in-house. 678 00:36:49,274 --> 00:36:50,564 Well, and that's the way it used to be. 679 00:36:50,924 --> 00:36:55,484 Um, everybody was kind of siloed in their, in their profession. 680 00:36:55,964 --> 00:36:58,874 Uh, they, they were less capable because they were more focused 681 00:36:58,874 --> 00:37:00,194 on their skillset and their. 682 00:37:00,674 --> 00:37:03,884 Um, their, their preferred attack methods and that kind of thing. 683 00:37:03,884 --> 00:37:09,014 And so then, uh, you know, as, as the, the criminal, cyber, criminal organ, 684 00:37:09,074 --> 00:37:13,544 uh, ecosystem grew, uh, you, you started having these kind of like cyber 685 00:37:13,544 --> 00:37:17,234 criminal conferences and we got to know each other and, uh, what can you do 686 00:37:17,234 --> 00:37:18,704 and how can we work better together? 687 00:37:18,704 --> 00:37:23,474 And so there was a little bit of, uh, you know, entrepreneurial, you know, uh, 688 00:37:23,504 --> 00:37:28,094 demarcation, uh, uh, activities going on. 689 00:37:28,094 --> 00:37:29,084 So now you've got this. 690 00:37:29,669 --> 00:37:32,519 Uh, almost, uh, diversification. 691 00:37:32,519 --> 00:37:37,649 So, and, and, and there was at the same time a, a bit of, integration, uh, uh, 692 00:37:37,679 --> 00:37:39,599 physical security and cybersecurity. 693 00:37:39,599 --> 00:37:42,269 People that were really good at breaking into buildings and social engineering 694 00:37:42,269 --> 00:37:44,519 people and extorting them in real life. 695 00:37:44,939 --> 00:37:49,529 Uh, can now work with cyber, uh, and, and to the benefit of one or the other. 696 00:37:50,669 --> 00:37:54,269 so now you've got, you know, a, a more dynamic, multi-layer threat. 697 00:37:54,749 --> 00:38:00,959 Um, but yeah, uh, once, once the bad guys started to recognize other bad guys and 698 00:38:00,959 --> 00:38:02,729 their skillsets, they started to go, well, 699 00:38:02,779 --> 00:38:06,799 I know, I know Bob, Bob, the bad guy knows how to do that better than me, and I'm. 700 00:38:07,249 --> 00:38:10,099 Yeah, I can imagine that once you, you know, you get really good, if you're 701 00:38:10,099 --> 00:38:13,609 really good at like getting credentials and gaining access and stuff, you know, 702 00:38:13,609 --> 00:38:15,169 you're like, Hey, I'm just gonna do this. 703 00:38:15,514 --> 00:38:19,324 Um, I actually know one of those, uh, entry guys by the way. 704 00:38:19,774 --> 00:38:23,044 Um, that does physical, uh, penetration testing. 705 00:38:23,494 --> 00:38:27,814 Um, basically his job is to get into a room where he's not supposed 706 00:38:27,814 --> 00:38:31,504 to be and then, uh, take a, take a selfie and then get the hell out. 707 00:38:31,984 --> 00:38:32,554 Um. 708 00:38:32,614 --> 00:38:32,854 Yep. 709 00:38:33,314 --> 00:38:36,854 But, um, so we're, we're, we're kind of getting a little longer 710 00:38:36,854 --> 00:38:38,564 than I, than I had intended. 711 00:38:38,564 --> 00:38:40,544 Let's talk about like, the things that we can do. 712 00:38:40,544 --> 00:38:42,974 I think we've, we've, if you've been listening, if you've been paying 713 00:38:42,974 --> 00:38:46,124 attention, obviously please don't, for the love of God, don't use the 714 00:38:46,124 --> 00:38:47,534 same password everywhere, right? 715 00:38:48,014 --> 00:38:51,494 Um, and, and the more sensitive the thing is, the more that thing 716 00:38:51,524 --> 00:38:53,024 needs to have its own password. 717 00:38:53,024 --> 00:38:55,094 I mean, everything should have its own password, needs to be using 718 00:38:55,094 --> 00:38:59,144 password managers, but whatever, you know, let's, please don't use. 719 00:38:59,774 --> 00:39:02,144 The same password, you know, sensitive stuff. 720 00:39:02,144 --> 00:39:02,474 Right. 721 00:39:02,894 --> 00:39:07,184 Um, and then also don't put RDP accessible via the internet. 722 00:39:07,664 --> 00:39:08,654 Uh, what was that? 723 00:39:08,654 --> 00:39:09,084 Prasanna 724 00:39:09,724 --> 00:39:10,084 Patching 725 00:39:10,814 --> 00:39:11,474 and patching. 726 00:39:11,504 --> 00:39:11,834 Yeah. 727 00:39:11,834 --> 00:39:14,834 And, and you know, vulnerabilities as they are, they're going 728 00:39:14,834 --> 00:39:16,604 to continue to, to happen. 729 00:39:17,084 --> 00:39:20,894 Monitor the CBSS, like for the full, for the, uh, the CVEs, for the 730 00:39:20,894 --> 00:39:22,484 vulnerabilities for your environment. 731 00:39:23,024 --> 00:39:27,804 Um, and, you know, I can think of a, there was, the big story that 732 00:39:27,804 --> 00:39:32,004 we covered with Rackspace a few years ago where they were attacked. 733 00:39:32,469 --> 00:39:38,679 Simply because they didn't on a timely basis, patch a, uh, 734 00:39:38,679 --> 00:39:40,359 an advertise vulnerability. 735 00:39:40,659 --> 00:39:44,889 And with, you know, within a matter of days, uh, the, you know, the bad guys 736 00:39:44,889 --> 00:39:48,759 were in their environment and it destroyed their entire hosted exchange environment. 737 00:39:49,359 --> 00:39:51,429 Um, that was a bad, bad story. 738 00:39:51,609 --> 00:39:55,089 You have any other, um, takeaways, Mike, in terms of, 739 00:39:55,119 --> 00:39:56,769 you know, dealing with these iab. 740 00:39:58,299 --> 00:40:01,209 So change your credentials as soon as you think they're compromised. 741 00:40:01,329 --> 00:40:04,484 Don't wait until your employer calls and asks about your personal life. 742 00:40:05,544 --> 00:40:09,354 Uh, don't store your credentials in plain text anywhere. 743 00:40:10,584 --> 00:40:15,294 use a, use a scheme for, you know, hints, you know, to help 744 00:40:15,294 --> 00:40:16,554 you remember what the password is. 745 00:40:16,554 --> 00:40:17,634 Don't write your password down. 746 00:40:17,844 --> 00:40:19,764 Use a password manager if you can. 747 00:40:20,184 --> 00:40:22,404 Uh, and don't use coincidental passwords. 748 00:40:22,464 --> 00:40:23,574 I did find the data I 749 00:40:23,679 --> 00:40:26,199 What's a, what's a coincidental password, by the way? 750 00:40:26,814 --> 00:40:29,814 so a coincidental password is, or even credentials, is something that 751 00:40:29,814 --> 00:40:31,344 you use in more than one place. 752 00:40:31,644 --> 00:40:32,124 So. 753 00:40:32,529 --> 00:40:34,389 If I use, I love my dog at work. 754 00:40:34,449 --> 00:40:36,579 I don't use, I love my dog anywhere else. 755 00:40:38,109 --> 00:40:38,379 Alright. 756 00:40:38,559 --> 00:40:45,759 Uh, I did find the, I was talking about where the, the data was, uh, compromised. 757 00:40:45,969 --> 00:40:50,109 So in 20, 20, 30 7 billion records were compromised, which is more 758 00:40:50,109 --> 00:40:51,879 than the prior six years combined. 759 00:40:52,629 --> 00:40:56,619 And it was primarily one, uh, and at the, at the time, it was 760 00:40:56,619 --> 00:40:58,029 the largest data breach ever. 761 00:40:58,029 --> 00:41:01,239 Over 80 million emails and PII records. 762 00:41:02,319 --> 00:41:09,549 And it was conducted by shiny hunters, uh, who then sold 564 million record 763 00:41:09,549 --> 00:41:14,799 bundle, uh, which was compromised across 49 different databases. 764 00:41:16,329 --> 00:41:20,619 and they sold for roughly 10 they broke it into three buckets 765 00:41:20,649 --> 00:41:22,299 and sold it for $10,000 each. 766 00:41:22,629 --> 00:41:29,259 But out of, out of 564 million records, 1.12 million. 767 00:41:30,174 --> 00:41:34,494 Were unique email addresses related to where that person worked. 768 00:41:36,594 --> 00:41:36,804 So 769 00:41:36,849 --> 00:41:37,479 That's not good. 770 00:41:37,704 --> 00:41:40,764 s and p, one hundred.gov, dot edu, et cetera. 771 00:41:43,659 --> 00:41:45,039 Um, all right. 772 00:41:45,039 --> 00:41:47,979 Any final thoughts on ibs? 773 00:41:49,369 --> 00:41:50,979 Turn it off when you're not using it. 774 00:41:53,019 --> 00:41:53,649 Turn what off? 775 00:41:53,649 --> 00:41:54,699 When you're not using it? 776 00:41:54,989 --> 00:41:55,659 Everything. 777 00:41:55,869 --> 00:41:56,199 anything? 778 00:41:56,719 --> 00:41:56,939 Yep. 779 00:41:58,944 --> 00:41:59,484 All right. 780 00:41:59,634 --> 00:42:00,234 All right. 781 00:42:00,954 --> 00:42:01,194 All right. 782 00:42:01,194 --> 00:42:02,094 Well, thanks a lot. 783 00:42:02,094 --> 00:42:03,174 Thanks for being on Mike. 784 00:42:04,164 --> 00:42:04,584 Anytime. 785 00:42:05,094 --> 00:42:06,374 Thanks for being on Prasanna, 786 00:42:07,579 --> 00:42:07,699 I 787 00:42:07,974 --> 00:42:08,124 Judgey. 788 00:42:11,724 --> 00:42:12,174 All right. 789 00:42:12,174 --> 00:42:13,194 That is a wrap.