The Beirut Bank Job (2017)
21–30 of 44 posts
Re: The Beirut Bank Job (2017)
#22Blank page again.
Re: The Beirut Bank Job (2017)
#23Where does it say he was in the wrong bank?
Re: The Beirut Bank Job (2017)
#24It's quite possible in pentesting to end up hitting the wrong target unless you're careful. Not as extreme as this case but, I've had cases where customers gave me the wrong IP address range for external work in the past, or where the customer had been told they had a dedicated server, when their web hosting company had actually put them on a shared host.
To avoid that, in the larger orga I worked for we had a checklist for the morning-of: check signature on indemnification agreement, run a WHOIS on the provided IPs and domains. Fewer and fewer people have their own v4 ranges, but the companies that pay our rates are typically large enough to still have it. If not, they had to tell us in advance whom we should expect it to be hosted with.
The team that has initial contact also checks, but we were supposed to double check anyway and it was a good thing, too. Getting caught hacking another company is not a situation you want or be in as a security company.
Re: The Beirut Bank Job (2017)
#25Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…
>and I was never asked back to that clients site ever again. Award for excellence in pentesting.
Well, the report is never empty but in general it's not as if you always hit jackpot, sometimes there's a very small attack surface in a black box test (or if it's a black box because your account credentials are still not arranged...), sometimes there's a mostly default install of something and that's secure by default because a lot of people already looked at the project, or sometimes they just did a good job.
Not being invited back can be more than one thing. Embarrassing the company is one of the most effective way of losing clients, though. It also doesn't help get issues fixed because the manager will prioritize saving face over anything else, including protecting assets.
If you enable them to protect assets without looking bad using good communication... that manager will want you for every test.
Re: The Beirut Bank Job (2017)
#26The full text transcript is here: https://darknetdiaries.com/transcript/6/
> [The bank manager] raised his hand during this whole all-hands meeting and he says what about the free computers? Do we still get the new computers? I'm like no, I was lying to you. I'm a horrible person.
And this one after getting caught at the wrong bank:
> He calls the guy who hired us to rob the bank. They start talking and halfway through the conversation he literally says do we have to split the cost for this? At that point I realized it was probably going to be okay.
Re: The Beirut Bank Job (2017)
#27The wrong bank story is at 18:20 onwards in the podcast. In the transcript, search for "A few years pass. Jason gets another call for another security awareness engagement" and read from there.
Re: The Beirut Bank Job (2017)
#28Tons of great episodes on this podcast. It's really a treasure.
Re: The Beirut Bank Job (2017)
#29Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…
You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.
Re: The Beirut Bank Job (2017)
#30I loved this one especially because of the foreshadowing where he almost targets the wrong bank the first day. Tons of great episodes on this podcast. It's really a treasure.