When most people think of hacking, they think of what Hollywood portrays. In a dark basement, a hooded, perhaps tattooed outcast rapidly types nonsensical keystrokes at a flashy computer monitor for several seconds before snidely muttering, "I'm in."
By that representation, the hacking process seems pretty straightforward: find a vulnerability, exploit it and ride off into the sunset with a bunch of credit card numbers, passwords or Bitcoin wallets. Despite its inaccuracy, that's actually the model a lot of companies use to perform penetration tests.
A real cyber attack requires a lot more planning and research. Understanding the target, how it works, and who makes it work gives hackers a much better idea of how to break in. They achieve this by reconnaissance and gathering information from publicly available sources.
Much of that information is harmless by itself. However, when combined, it can provide useful insights to malicious actors.
Is Phishing Possible?
According to research done by PhishMe, 91 percent of cyber attacks and data breaches began with spear phishing attacks (i.e. phishing attacks based on specific targets, and not just executives).
Determining whether or not a target can be easily phished is trivial. Tools like MXToolBox allow anyone to check for email security measures like DMARC, the latest standard for preventing email spoofing. If DMARC isn't implemented on the domain, impersonating someone in the target company and bypassing spam filtering is simple.
By impersonating an executive or team leader, hackers can harm business relationships, get privileged information from unaware employees, and more.
Social Media Faux Pas
Information about a target is hard to gather without finding relationships along the way. Digging through databases and listings can yield many information points, but they aren't useful unless they somehow relate to each other.
Social media makes this easy. Let's say the target is a systems engineer for a particular company based in New York. To make things complicated, the target's name is "John Smith." Searching through listings of people for the right person in New York would be a nightmare without social media.
But since the company has LinkedIn profiles attached to it, we can narrow the search down to a couple of useful criteria if we can find John's profile:
- Age (based on college graduation date)
- Region of residence (based on proximity to company HQ)
Those two data points can turn a search for John Smith in New York from an endless Google results library to a handful of possibilities on Pipl.
Suddenly, searches for people in tools like skiptracer start to yield email accounts, family members and more. With email accounts, checking password leak databases (not linked here for ethical reasons) for those addresses can yield some pretty interesting results.
The target company can only hope he doesn't use the same password on his work email account as he did on his Myspace page he made in 2006.
When Google Is Too Good At Its Job
Google's web crawler is eerily good at its job. You don't become the best at finding relevant information for people without inadvertently indexing some exposed secrets.
It's so good that an entire database of valuable searches and queries was created and is actively contributed to. It can even find passwords.
While the odds of finding a company's passwords via a Google search are low (I hope), the same principles of the Google Hacking Database can be applied to other repositories of information:
- Exposed web server directories
- GitHub source code
- Error pages (i.e. web vulnerabilities)
Reducing your publicly visible attack surface won't necessarily mitigate attacks from determined threats, but it will reduce the likelihood that you'll become someone's low-hanging fruit target.
Ryan Basden
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)