Far Beyond the Perimeter - Exploring External Attack Surfaces

No ratings

Presented at DeepSec 2024 by

Looking for intel in all the right places is an art that adversaries seem to have mastered; but when it comes to their own data, many companies seem to lose interest in examining anything that's outside the "perimeter" - whatever that is suppossed to be nowadays. Credential leaks, shadow IT, unofficial websites with official info - the list of assets far outside the data centers of companies is long and those assets nevertheless pose risks. Instead of turning a blind eye, it's important (and necessary) to get an understanding of what kind of information is out there, ready to be used or abused and protect accordingly. What risks are "out there" and what is meant by "out there"? How can those risks be addressed? What tools are easily available? Gathering information is a valuable tool not only for adversaries, but also for anyone trying to address risks before they become problems. Most companies with more than just a handful of employees sooner or later will find out that not all of their digital assets are behind company firewalls. Any sensitive data that is not controlled by the company itself can become a problem - from leaked credentials to VPN access details being sold on the darknet and other shady places. Knowing something has leaked won't solve the problem, but will give the opportunity to protect against potential attacks leveraging this intel, and also to examine the reasons why it's somewhere it shouldn't be. This talk won't go into details of scanning company servers or whatever goes on in internal networks; we will focus solely on all the things adversaries can and will use to craft spear phishing emails, learn company secrets or to find a scenic back route to internal networks. Hopefully this talk will motivate you to dig deeper into getting to understand the external attack surface of the company you're working for, or help you prepare your next red team engagement. If you're already doing this stuff on a daily basis, there won't be any surprises, but if you never thought about digging into this topic, you'll hopefully learn a ton of new things. Not looking for risks poses a risk in itself. After all, how can something be protected if nobody knows about it?