Live data from Hacker News

The Beirut Bank Job (2017)

darknetdiaries.com

21–30 of 44 posts

Re: The Beirut Bank Job (2017)

#24

It's quite possible in pentesting to end up hitting the wrong target unless you're careful. Not as extreme as this case but, I've had cases where customers gave me the wrong IP address range for external work in the past, or where the customer had been told they had a dedicated server, when their web hosting company had actually put them on a shared host.

Yep, this. Or the team that arranges the contract (what to test, when to test it) typos the IPs (or misses a digit when copying or so).

To avoid that, in the larger orga I worked for we had a checklist for the morning-of: check signature on indemnification agreement, run a WHOIS on the provided IPs and domains. Fewer and fewer people have their own v4 ranges, but the companies that pay our rates are typically large enough to still have it. If not, they had to tell us in advance whom we should expect it to be hosted with.

The team that has initial contact also checks, but we were supposed to double check anyway and it was a good thing, too. Getting caught hacking another company is not a situation you want or be in as a security company.

Re: The Beirut Bank Job (2017)

#25
post #10

Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…

>and I was never asked back to that clients site ever again. Award for excellence in pentesting.

Some companies need to be tested for legal reasons or because the parent company requires it. It's often easy to tell when you're dealing with one of those from the details being incomplete or coming in late (like get the API docs 7 days into the 5-day test - so we basically didn't test, but we still have to bill the reserved time), but if it's unclear, being a little too happy with an empty report and inviting us to test another thing is another tell-tale.

Well, the report is never empty but in general it's not as if you always hit jackpot, sometimes there's a very small attack surface in a black box test (or if it's a black box because your account credentials are still not arranged...), sometimes there's a mostly default install of something and that's secure by default because a lot of people already looked at the project, or sometimes they just did a good job.

Not being invited back can be more than one thing. Embarrassing the company is one of the most effective way of losing clients, though. It also doesn't help get issues fixed because the manager will prioritize saving face over anything else, including protecting assets.

If you enable them to protect assets without looking bad using good communication... that manager will want you for every test.

Re: The Beirut Bank Job (2017)

#26

The full text transcript is here: https://darknetdiaries.com/transcript/6/

Thank you. I love this bit at the end of a successful demonstration:

> [The bank manager] raised his hand during this whole all-hands meeting and he says what about the free computers? Do we still get the new computers? I'm like no, I was lying to you. I'm a horrible person.

And this one after getting caught at the wrong bank:

> He calls the guy who hired us to rob the bank. They start talking and halfway through the conversation he literally says do we have to split the cost for this? At that point I realized it was probably going to be okay.

Re: The Beirut Bank Job (2017)

#28
I loved this one especially because of the foreshadowing where he almost targets the wrong bank the first day.

Tons of great episodes on this podcast. It's really a treasure.

Re: The Beirut Bank Job (2017)

#29
post #10

Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…

>We did the report and that whole aspect got swept under the carpet and I was never asked back to that clients site ever again.

You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.

Re: The Beirut Bank Job (2017)

#30
post #28

I loved this one especially because of the foreshadowing where he almost targets the wrong bank the first day. Tons of great episodes on this podcast. It's really a treasure.

I listen to a lot of podcasts, but this may be the one I get most excited about when a new episode comes out.
Post reply on HN