Live data from Hacker News

Hackers shoveled snow for company, were rewarded with network admin access

theregister.com

41–50 of 81 posts

Re: Hackers shoveled snow for company, were rewarded with network admin access

#41
post #28

Earlier quoted context omitted.

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

And content limits. Why can't my password contain the % character? No special characters? What makes a character "special"? Why can't it contain emoji? So many password systems go to great lengths to remove potential entropy and randomness from passwords with their rules. The usual excuse is "blah blah blah legacy systems" which is not a good reason.

Personally, I wouldn't use anything beyond ASCII in a password. I don't want encoding bugs to lock me out of my encrypted partition or bank account, thank you very much.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#42
post #10

What always gets me about these red team attacks is the same thing that gets me about internal phishing test emails. My company sent an internal phishing test last week. Several people immediately reported it to a cybersecurity engineer, posted about it in Slack, saying they were surprised that such a sophisticated phishing attack was happening. I too was surprised - Google is usually much better about catching these…

> Theoretically, someone could craft a perfect phishing attack, but who would go to all that trouble? Spray-and-pray, low precision, high surface area, attacks are the ones I end up reading about.

I've been at a company that was well targetted. I forget which group it was, but they were got into a lot of customer service sites that week; not ours, but we had some near misses. Almost got me, sent me an email from the boss with 'The blog is down' and a link ... I was checking my mail on mobile as I was out the door, but of course mobile doesn't show any useful headers like from address.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#43
post #4

Earlier quoted context omitted.

1. Open a web browser and do a search 2. Read until you find a sentence that you like. 3. Use it as your password

I like the last line of your comment My password is now password

That's cool. Yours comes up as stars (*). Must be a HN thing.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#44
post #32

Earlier quoted context omitted.

Probably a RADIUS server setup. Basically staff machines get a certificate to present to the server and the server controls the network. So, if your machine does nothing, it's on the guest vlan and has limited access. If it presents a valid certificate that network port is reassigned to the staff vlan and you get full access. If someone leaves, you just revoke the certificate and they have guest access again. Not roc…

Still better to do that same thing (cert based auth) at the application layer instead of the network layer.

Yes, you can do it by MAC address instead but that can be changed so you can spoof a legitimate device.

Edit: oh wait, you mean have the applications check the certificate? Yes, but then you need support from the application. Does your printer do that, for example? You need to make sure everything does. You can of course do both.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#45
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

Replying to my own post: wait a minute, why are there so many accounts with the same password in the first place? Oh, because "dozens" of people are tired of changing their password every 90 days, and someone piped up on an email thread (with the subject line: "Changing passwords all the time is bullshit!", I'm sure) and said, "I just set it to $SEASON$YEAR'!'. Easy to remember, fits the policy."

And now you have a system that is far less secure than if you just ditched the expiration policy to begin with.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#46
post #32

Earlier quoted context omitted.

Probably a RADIUS server setup. Basically staff machines get a certificate to present to the server and the server controls the network. So, if your machine does nothing, it's on the guest vlan and has limited access. If it presents a valid certificate that network port is reassigned to the staff vlan and you get full access. If someone leaves, you just revoke the certificate and they have guest access again. Not roc…

Still better to do that same thing (cert based auth) at the application layer instead of the network layer.

That's great when you have control of your applications. For most corporate IT you're stuck with COTS applications and whatever their built-in auth functionality is. Sure, you can probably bolt a reverse proxy in front (if you're lucky enough for it to be a web app and not a thick native code client) but you get to argue with the vendor when they refuse support because you're not using their recommended configuration.

802.1x certificate-based authentication at layer 2 is a good defense in depth strategy.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#47
> There are a lot of lessons here, but they start with training every member of the team to be suspicious of people coming from the outside, without badges, no matter what they say or do. Schloss noted that, if someone looks and acts like they belong in a space, most people will treat them that way.

> “First and foremost, what most people believe is crime is not crime. It's a Hollywood myth of what crime looks like,” Schloss told us. “I call it the ski mask bias. Everyone assumes you're not getting robbed until a person comes in with a ski mask and a gun yelling.”

I call this "Trained By Hollywood Syndrome". It's a huge problem, and far beyond mere computer security.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#48
post #32

Earlier quoted context omitted.

Still better to do that same thing (cert based auth) at the application layer instead of the network layer.

That's great when you have control of your applications. For most corporate IT you're stuck with COTS applications and whatever their built-in auth functionality is. Sure, you can probably bolt a reverse proxy in front (if you're lucky enough for it to be a web app and not a thick native code client) but you get to argue with the vendor when they refuse support because you're not using their recommended configuration…

Use envoy or some other reverse proxy and do per-app auth there

Re: Hackers shoveled snow for company, were rewarded with network admin access

#49
post #32

Earlier quoted context omitted.

Still better to do that same thing (cert based auth) at the application layer instead of the network layer.

Yes, you can do it by MAC address instead but that can be changed so you can spoof a legitimate device. Edit: oh wait, you mean have the applications check the certificate? Yes, but then you need support from the application. Does your printer do that, for example? You need to make sure everything does. You can of course do both.

Reverse proxy

Re: Hackers shoveled snow for company, were rewarded with network admin access

#50
post #24
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

Expiring passwords are one of my biggest gripes, and I still see them everywhere

Due to corporate IT working its fingers into everything vaguely computer related, I now have to annually change the passwords that operators use to log onto the HMIs on my OT network (which has no connection to the greater Internet.)

That means I now get calls after hours for a couple weeks (allowing for all shifts to cycle through) from operators who are locked out of their ops stations. I can't send the password via email, obviously, and word-of-mouth is inconsistent at best. So I'm left with the sticky note under the keyboard or stuck to the monitor, which the operators won't read anyway.

Post reply on HN