Article 78RRY CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

by
from www.theregister.com - Articles on (#78RRY)
Story ImageWelcome back to PWNED, the weekly column where we warn you about weak security practices. This week's terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Joe Brinkley, who also is known as The Blind Hacker" and has more than two decades of experience in information security. Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire. What he discovered was a huge security hole and an even bigger embarrassment. Brinkley had audited the same law firm the previous year. At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found. I shredded them. They were not in a very good security posture," Brinkley told us. They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition." Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019. BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10. BlueKeep and its related security risks involve a flaw in Windows' Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389. The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm. During his pentest, Brinkley used the BlueKeep vuln to get access to the org's systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. The usernames on the system were cleverly designed for security by obscurity. Instead of using the user's real name or something like admin," they had names like Yellow Banana" and Red Apple" so attackers could not guess which one had the most privileges. Brinkley had no idea who Yellow Banana was, but he found that person's password and it was perhaps the tackiest idea of a login we've ever heard. The password was r3@lg00dp@$$w0rd," which is realgoodpassword" with some symbols and numbers substituted for letters. Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm's execs. While he was explaining that he had managed to penetrate 2,500 of the org's computers, the CISO suddenly dropped an f-bomb. Why the f*** is my password on the screen?" he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea. So what can we learn from this tale of legal embarrassment? Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments