Keys to the Kingdom – Gaining access to the Physical Facility through Internal Access


This is a story of network segmentation and the impact that seemingly trivial misconfigurations can have for your organization. This is one of those occasions.

This particular pen test asked for goals-based assessment focusing on post-compromise activities — an attempt by the client to discover how vulnerable internal systems were to lateral movement by an attacker who had compromised the domain. Among the goals was a request to attempt to compromise the client’s Amazon Web Services (AWS) infrastructure and a secondary request to access and exploit any systems discovered to contain sensitive or critical operational data .

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • Automatic disruption of human-operated attacks through containment of compromised user accounts

    October 11, 2023

    Based on incidents analyzed by Microsoft, it can take only a single hop from the attacker’s initial access vector to compromise domain admin-level accounts. For instance, an attacker can target an over-privileged service account configured in an outdated and vulnerable internet-facing server. Highly privileged user accounts are arguably the most important assets for attackers. Compromised domain ...

  • Cybersecurity’s Importance in Military Maritime Operations

    October 11, 2023

    In an era defined by interconnectedness and digital transformation, the role of cybersecurity in modern maritime warfare has grown. The maritime domain is increasingly vulnerable to cyber threats which can have serious consequences to national security. Cybersecurity is no longer just a matter of protecting data, but also protecting critical defence assets, and the ability ...

  • CISA catalog passes 1,000 known-to-be-exploited vulnerabilities. Celebration time, or is it?

    October 11, 2023

    On September 18, 2023, the Cybersecurity & Infrastructure Security Agency (CISA) announced that its Known Exploited Vulnerabilities (KEV) catalog has reached the milestone of covering more than 1,000 vulnerabilities since its launch in November 2021. This may seem like a lot, but with over 25,000 new vulnerabilities released in 2022 alone, it helps organizations to ...

  • How it works: The novel HTTP/2 ‘Rapid Reset’ DDoS attack

    October 10, 2023

    A number of Google services and Cloud customers have been targeted with a novel HTTP/2-based DDoS attack which peaked in August. These attacks were significantly larger than any previously-reported Layer 7 attacks, with the largest attack surpassing 398 million requests per second. The attacks were largely stopped at the edge of our network by Google’s ...

  • FBI and CISA Release Update on AvosLocker Advisory

    October 10, 2023

    Today, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint Cybersecurity Advisory (CSA), #StopRansomware: AvosLocker Ransomware (Update) to disseminate known indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with the AvosLocker variant identified through FBI investigations as recently as May 2023. This release ...

  • MICITT Seeks To Protect Costa Ricans From Cyber Attacks With The 5G Network

    October 8, 2023

    Protecting the information of citizens, businesses, public institutions and the country in general from constant cyber attacks is the purpose sought by the Ministry of Science, Innovation, Technology and Telecommunications (MICITT) with the “Regulation on Cybersecurity Measures Applicable to Telecommunications Services Based on Fifth Generation Mobile Technology (5G) and Higher. ”This was announced by Paula ...