Earlier quoted context omitted.
Russia is quite far away to send a plane small enough to fly low over the building and drop a device onto the roof, and I don't think you're allowed to throw things out of an airliner window anyway
I mean a normal passenger on a normal plane making a normal trip to an office building and finding a hidden location where to tape a small box with an arduino in it. Maybe even on the outside so you can use solar power? Though it only needs to last long enough to compromise a machine inside the network. This would be nothing new, I remember ages ago in the days of WEP that you could buy a small box that would collect…
The Nearest Neighbor Attack
21–30 of 73 posts
Re: The Nearest Neighbor Attack
#22So, as I understand it, you 0wn a machine in one organization, then use it to tunnel over to Wi-Fi in the building next door, 0wn another machine there, rinse and repeat until you've created the world's least consensual mesh network?
why do you type 0wn (zero) instead of own?
Re: The Nearest Neighbor Attack
#23Re: The Nearest Neighbor Attack
#24Re: The Nearest Neighbor Attack
#25Anybody else get a feeling it was Volexity that did all this research? Interesting story none the less
Re: The Nearest Neighbor Attack
#26> Volexity now determined the attacker was connecting to the network via wireless credentials they had brute-forced from an Internet-facing service. However, it was not clear where the attacker was physically that allowed them to connect to the Enterprise Wi-Fi to begin with. Further analysis of data available from Organization A’s wireless controller showed which specific wireless access points the attacker was conn…
Re: The Nearest Neighbor Attack
#27Re: The Nearest Neighbor Attack
#28So, as I understand it, you 0wn a machine in one organization, then use it to tunnel over to Wi-Fi in the building next door, 0wn another machine there, rinse and repeat until you've created the world's least consensual mesh network?
why do you type 0wn (zero) instead of own?
Re: The Nearest Neighbor Attack
#29Kind of wild they didn’t rotate all the creds after the first, second hacks.
It's a scary thing as all you have to do is add one decision, one ignorant person and it's bad news.
I've worked in orgs where we made big leaps in security, very proud of our work. Then one ignorant person who had the authority made a decision with no valid benefit to anyone, completely compromised everything.
Seen it time and again.
Not sure if that was the case as far as the credentials went in this situation, but it always seems to be the human element as far as curious choices goes.
Re: The Nearest Neighbor Attack
#30Earlier quoted context omitted.
They are exploiting that Wifi didn't have 2fa, because they couldn't overcome 2fa. A company accross the street had a machine that both was accessible by ethernet and wifi and they used that as a bridge. Conclusions: 1. Anything that doesn't have 2fa is leaking like a sieve. 2. The targeted company needs to implement 2fa for their Wifi as well. Not mentioned, but I assume that their 2fa is using specialised hardware…
> Final conclusion: A network is as strong as the weakest link. Final conclusion: Do not trust a device just because it happens to be on your local network.