It was time again for the annual RSA Conference. Naturally, we were there too! A number of attack techniques were set out—an important trend we may be dealing with in the coming years. We list the six most dangerous hacking techniques here.
1. Intercepting Kerberos tickets
Kerberos is a network authentication protocol used by default on Windows servers, where the client logs into the Windows domain. It is also possible to use the Kerberos protocol for UNIX-based systems such as OS X, Solaris, AIX and major Linux distributions. The hacking trick is to intercept the ticket exchanged between client and server in the form of a man-in-the-middle attack.
According to experts, it doesn’t matter whether you as a hacker have access to a client or a server, as long as you are inside the domain. You then capture all Kerberos tickets from the client that have been stamped for authentication by the server. They are valid for ten hours, during which the attacker has free rein. More than enough time.
2. Targeted attacks on ICS and SCADA
Industrial systems connected to the internet are rather poorly protected against intruders, and that is being exploited more and more. Attackers now look for specific systems for which they create and buy tailored exploits. They take into account the specific tasks those systems can perform.
Also new is the point of departure for the attack: attackers seek a system that communicates with the ICS and whose network relationship is trusted by the ICS. By taking over that other system, it becomes easier to infiltrate the target ICS system.
This means attackers conduct phishing campaigns against technicians who use their own systems to access the target ICS. So-called watering holes are also created on sites frequently visited by technicians. In addition, attackers look for ways to infect ICS files with trojans intended to hitch a ride with, for example, a system update, so those infections more easily pass through a firewall.
3. Encryption becomes an attack method
Encryption is already used in various types of attacks—just look at the rise in ransomware. But that method is becoming increasingly sophisticated, according to the SANS Institute. Until recently, ransomware attacks were mainly a consumer problem, but there is far more money to be made in the business world. For example, attackers are looking at encrypting backups at large companies, which can currently still replace encrypted hostage data from backup. The first attacks on NAS systems have already occurred!
4. More attacks on the Internet of Things
More and more devices are connected to the corporate network, including employees’ own smartphones, tablets and notebooks. Along with associated printers and Wi-Fi routers, the environment is primed for the hacker. Because each device may run a different software version and, in the absence of a patch policy, remains vulnerable to exploits targeting older weaknesses, it is increasingly easy for an attacker to penetrate to a certain level of the network.
5. Attackers use stolen data more cleverly
Attackers who get hold of data are using it more intelligently. For example, the attackers at Sony opted for periodic publication of information stolen from Sony’s servers, choosing a different publication channel each time. As a result, the affected company never knows when or which information will be released, and there is no viable public relations defense against it.
6. DDoS attacks are becoming heavier and smarter
DDoS attacks on the network? Most companies and organizations know all about them. But attackers are now taking it a step further and targeting specific applications. This can be done with far less data, at what Ullricht calls a layer-7 level of a denial-of-service. The data fired at an application is much less than with a DDoS and often stays under the radar, but the application receives too much information to respond properly. As a result, the application becomes effectively unusable for a time.