Live data from Hacker News

The Nearest Neighbor Attack

volexity.com

21–30 of 73 posts

Re: The Nearest Neighbor Attack

#21
post #14

Earlier quoted context omitted.

Russia is quite far away to send a plane small enough to fly low over the building and drop a device onto the roof, and I don't think you're allowed to throw things out of an airliner window anyway

I mean a normal passenger on a normal plane making a normal trip to an office building and finding a hidden location where to tape a small box with an arduino in it. Maybe even on the outside so you can use solar power? Though it only needs to last long enough to compromise a machine inside the network. This would be nothing new, I remember ages ago in the days of WEP that you could buy a small box that would collect…

For the length of time this article covered you would need a power source and to not have your box discovered for months. Probably something out on the street isn't going to fulfill both of those requirements so you'd be trying to enter "Enterprise A" which is unlikely given the presumed elevated security profile this article implies (any guesses who?). With what they pulled off the "box" that ended up being used was something already plugged in next door and very much supposed to be there. Seems easier than any physical attack would have been.

Re: The Nearest Neighbor Attack

#22

So, as I understand it, you 0wn a machine in one organization, then use it to tunnel over to Wi-Fi in the building next door, 0wn another machine there, rinse and repeat until you've created the world's least consensual mesh network?

why do you type 0wn (zero) instead of own?

The best is to never get pwned.

Re: The Nearest Neighbor Attack

#26
post #11

> Volexity now determined the attacker was connecting to the network via wireless credentials they had brute-forced from an Internet-facing service. However, it was not clear where the attacker was physically that allowed them to connect to the Enterprise Wi-Fi to begin with. Further analysis of data available from Organization A’s wireless controller showed which specific wireless access points the attacker was conn…

I think Ubiquiti have that built into their AP/network management software. You can define a floorplan and drop your APs into it to understand dead zones etc, and you have granular data on which clients are connected to which APs

Re: The Nearest Neighbor Attack

#27
Darknet Diaries #151 has an Australian dude explaining a form of this type of attack and how he stole money out of a middle eastern bank for a wealthy client. Maybe it's not exactly the same but it struck me as similar because he uses weak WiFi security as part of the exploit chain as well as hopping between compromised residential networks to obfuscate the origin.

Re: The Nearest Neighbor Attack

#28

So, as I understand it, you 0wn a machine in one organization, then use it to tunnel over to Wi-Fi in the building next door, 0wn another machine there, rinse and repeat until you've created the world's least consensual mesh network?

why do you type 0wn (zero) instead of own?

I think it nicely demonstrates the difference between "own" (legally and appropriately) and "0wn" taking control by hacking but exerting as much control as "own".

Re: The Nearest Neighbor Attack

#29
post #24

Kind of wild they didn’t rotate all the creds after the first, second hacks.

I suspect every organization is as secure as its least secure/capable decision maker.

It's a scary thing as all you have to do is add one decision, one ignorant person and it's bad news.

I've worked in orgs where we made big leaps in security, very proud of our work. Then one ignorant person who had the authority made a decision with no valid benefit to anyone, completely compromised everything.

Seen it time and again.

Not sure if that was the case as far as the credentials went in this situation, but it always seems to be the human element as far as curious choices goes.

Re: The Nearest Neighbor Attack

#30
post #8
post #4

Earlier quoted context omitted.

They are exploiting that Wifi didn't have 2fa, because they couldn't overcome 2fa. A company accross the street had a machine that both was accessible by ethernet and wifi and they used that as a bridge. Conclusions: 1. Anything that doesn't have 2fa is leaking like a sieve. 2. The targeted company needs to implement 2fa for their Wifi as well. Not mentioned, but I assume that their 2fa is using specialised hardware…

> Final conclusion: A network is as strong as the weakest link. Final conclusion: Do not trust a device just because it happens to be on your local network.

Final, final conclusion: if a computer is networked, consider it and the data on it to be semi-public. Make decisions about what to do and store on that computer with that assumption in mind.
Post reply on HN