Live data from Hacker News

Hackers went undetected in Citrix’s internal network for six months

techcrunch.com

51–60 of 122 posts

Re: Hackers went undetected in Citrix’s internal network for six months

#51
post #48

Earlier quoted context omitted.

That's a really defeatist attitude. There are different levels of "value" and different levels of protection. Not everything is internet facing. Not everything is managed like a corp where turnover requires lots of access changes. Not everything allows you persistence in the network. And not all access is "access". I really wish we moved past the "everybody's owned" idea. Your defence should be proportional to the va…

I don’t think the grandparent says that everyone is owned, but that if your data is interesting enough, your threat model must include employees that are willingly exhilarating data, sometimes for nation states. That your first barriers are therefore assumed to be breached to those attackers. This of course does not apply if you are not holding on to anything interesting, but it’s very easy to become interesting at a…

My response was triggered by "If you have anything of value". I agree with "if your data is interesting enough". Because let's be honest, barely any company qualifies for nation state embedding a worker with them. If they do, they know. But everybody has something of value.

Re: Hackers went undetected in Citrix’s internal network for six months

#52
post #18

Having worked with Citrix, I'm shocked. Shocked that they detected it at all...

You can't just make a statement like that without adding colourful anecdotes about your time there!

I'm especially interested because I had an offer from Citrix that I eventually turned down.

Re: Hackers went undetected in Citrix’s internal network for six months

#53

Has anyone gotten that kind of call from the FBI and can shed light on how the process works? Would be fascinating for a outsider and provide a guide on what next steps look like for those poor souls that receive the call in the future.

I've been on this call (both sides of it) probably a dozen times by now. Gov agencies are decent at doing research so it's pretty unlikely that the FBI just called their 1800 number or whatever.

Most small start ups don't get to the level where anyone that "big" is looking at them but in the event that something does get flagged the agency will go find their CEO/CTO/counsel on LinkedIn and either message them there or email them. I've never seen an actual vulnerability disclosed in email, if it's a potential legal issue (hello SEC and fintech) they may ask that your lawyer responds to them in writing but more often it's just "this is Agent XYZ with ABC. I have information about your company, please call me immediately."

For someone bigger (like Citrix) the company is hopefully big enough to have a team that is connected to the agencies in someway. Either the agency knows someone who knows them, or they have a designated Security and Compliance team that can handle these inquires.

The real problems come when you're in the middle of sizes - too big to have eyes on every email but too small to have a real security team.

About 5 years I was working for a SaaS company and one of our clients accidentally discovered a pretty serious hole in another company's product. This client wasn't overly tech savy and was basically like "hey is this how this is supposed to work?" when it very much was not... so we killed the API connection and told the client we'd take care of it. It's about 7pm ET by the time we figure out what's going on so we call and email the other company but couldn't find anyone. In the end we got the home phone number of their CTO and had our CTO call him at around 10pm. He thought it was a prank call but once our CTO convinced him this was a problem he was able to get their on call eng to patch it within hours.

Nowadays almost any company involved in security work either has a direct line to FBI/DHS or has a vendor who does. ie if I'm some medium consumer platform I probably don't get to talk to the FBI directly, but if I called up Crowdstrike or any security consulting firm they could do that. In the event that my medium consumer platform was infiltrated by Fancy Bear (and the government decided to tell me, sometimes they don't) an FBI agent would email/call the most likely point of contact for the fastest resolution without causing panic. Lots of time the damage is already done, two vs four hours on a response won't make a big difference in the long term so no need to email info@ or anything.

Over the past 6-8 years the corporation on public/private cyber investigations has definitely changed as red tape has decreased in sharing of info has increased - even more the last 4ish years since the DNC email hacks. I've had a clients get a casual "just a heads up, you should check this out" from the government without no paperwork and no follow up, something that would have been virtually unheard of 8 years ago.

DHS gets a lot of shit in the media (lots of which is deserved) but they've done a pretty good job just opening basic lines of communication and training other agencies that spending 20 minutes looking at a random tip, and following up if needed, is actually a pretty good use of time.

Re: Hackers went undetected in Citrix’s internal network for six months

#54

Earlier quoted context omitted.

Just assume they only catch the dumbest 20%.

So you think that 80% of attacks are better than stuxnet?

Correct me if I’m wrong but stuxnet was designed for a purpose and it accomplished that purpose. Eventually being discovered was no doubt an understanding from the authors.

Compare that to unauthorized access to a machine and cleaning the logs behind you... One doesn’t have to be more brilliant than the authors of stuxnet to do something illegal without getting caught.

Re: Hackers went undetected in Citrix’s internal network for six months

#55

Earlier quoted context omitted.

I thought it was pretty well-established that Stuxnet was created/authored by TAO within the NSA.

Thats the belief but was it truly ever confirmed? I dont doubt it it sounds like a meme worthy of belief and I lean towards it but I dont recall ever finding a confirmation. Also saying they were caught implies the law caught them and arrested them.

As far as I know Stuxnet didn't break any US/Isreal laws. Of course it broke Iranian laws, though.

I think Obama said "no comment" to reporters, but then basically admits it by talking about how he regrets that this information got out into the public.

Re: Hackers went undetected in Citrix’s internal network for six months

#56

Earlier quoted context omitted.

I thought it was pretty well-established that Stuxnet was created/authored by TAO within the NSA.

Thats the belief but was it truly ever confirmed? I dont doubt it it sounds like a meme worthy of belief and I lean towards it but I dont recall ever finding a confirmation. Also saying they were caught implies the law caught them and arrested them.

What would you consider as a confirmation? Without someone coming out and saying "we're the ones who did it", it's very unlikely that it'll be ever be confirmed.

The best you can do is to make some educated guesses (by looking at the timestamps, coding patterns, comments in the code, who might be interested in hacking the target, political connotation to the attacks etc.). That's usually how state-sponsored attacks get attributed.

For example, "Guccifer" used GTM+3 settings and attacked DNC a few hours after Trump publicly "hoped" that Russians will find the emails. That doesn't confirm that it was sponsored by Russia, but it makes it an educated guess.

Re: Hackers went undetected in Citrix’s internal network for six months

#58
post #31

Earlier quoted context omitted.

This is extremely common. 6 months is not that long, even among competent companies that have good security. You usually hear about it from the FBI. I think the FBI forwards tips from agencies like the NSA, but they don’t tend to give much information.

It may be common, but I'll disagree it's common for companies with "good security." Password spraying doesn't work with good 2FA, nor sane login limits. I set off a flag anytime logging in from a new IP, for example.

2FA and login limits alone aren't likely to stand in the way of state-sponsored hackers.

Lots of companies still haven't upgraded to zero trust / BeyondCorp AuthN, and lots of companies don't have reproducible signed build artifacts from CI/CD with automatic policy enforcement regarding the properties that those build artifacts must have before they can be deployed.

High-profile companies that think VPNs and networking rules are a security solution have probably already been hacked and just don't know it yet.

Re: Hackers went undetected in Citrix’s internal network for six months

#59
post #15

Earlier quoted context omitted.

Probably my wording was wrong. I was thinking more of a system where the password itself was generated and stored on a hardware device. The user need not interact with any application, whatsoever, like 1Password or Lastpass to generate or store a password at all. Everything happens behind the scenes on the device. The user would be responsible only for keeping the hardware device safe. This probably makes 2FA moot fo…

I understood you, my point is that you are sacrificing significant security with a one-factor approach, especially if that one factor is a password! You're open to attacks where the password is exposed in between the keyboard and the requestor, attacks on the distant end system, as well as attacks on the password device itself. Passwords make it tricky to audit if they've been duplicated. Use 2fa everywhere. It's che…

2FA only helps if it's a 2-way authentication mechanism like U2F.

TOPT codes are completely phish-able using ridiculously easy to setup kits out there like CredSniper[0]. Set up a MITM proxy authentication site, get the user to live authenticate through the proxy, steal the session cookie, game over.

Some of the feedback that has come out of internal campaigns has been things like "I thought the URL looked weird, but the email said it was a beta site, and I got the Duo push notification for the second factor so it seemed legitimate."

That's the real danger in 2FA mechanisms outside of U2F: people believe it protects against phishing, and it absolutely does not.

[0]https://github.com/ustayready/CredSniper

Re: Hackers went undetected in Citrix’s internal network for six months

#60
You need network sniffer and pattern recognition. Otherwise basically you hope some of the unusual activities will affect ids/ips (or touch internet). However if it is normal account you need some sort of intelligence to recognise and alert.

Not many software can do this.

Post reply on HN