字号 ·· | 护眼
theregister

CISO以为他有个“r3@lg00dp@$$w0rd”密码,却忘了打补丁CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

点「原文对照」整页切到原文,或双击某段只看那段的原文。

欢迎回到 PWNED——这个每周都会提醒您注意安全漏洞的专栏。

Welcome back to PWNED, the weekly column where we warn you about weak security practices.

本周我们要讲述的故事,涉及一家律师事务所在网络安全方面的严重疏忽:他们没有及时安装重要的安全补丁,而且该机构的技术安全负责人使用的密码极其简单、容易被破解。

This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network?

如果您知道类似的安全漏洞,请通过 pwned@sitpub.com 与我们分享您的发现;我们承诺为您保密。

Share it with us at pwned@sitpub.com. Anonymity is available upon request.

这个故事由 Joe Brinkley 提供,他也被称为“The Blind Hacker”,在信息安全领域拥有超过二十年的经验。

Our story comes courtesy of Joe Brinkley, who also is known as “The Blind Hacker” and has more than two decades of experience in information security.

几年前,一家大型律师事务所聘请 Joe 对他们即将收购的一家小型企业进行渗透测试。

Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire.

他发现这家企业的安全防护体系存在严重漏洞,这不仅导致了系统被入侵,还给该公司带来了巨大的声誉损失。

What he discovered was a huge security hole and an even bigger embarrassment. Brinkley had audited the same law firm the previous year.

事实上,Joe 在几年前曾对该律师事务所进行过审计,当时就发现了许多安全问题;不过律师事务所并未采取任何措施来修复这些问题,反而花费了大量资金(约五十万美元)购买 Reliaquest 和 Dell 等公司的安全软件来试图弥补这些漏洞。

At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found.

Brinkley 评价道:“他们的安全防护措施非常薄弱。”

“I shredded them. They were not in a very good security posture,” Brinkley told us.

不幸的是,即便他们投入了大量资金,该公司仍然未能及时修补其 Windows 系统中的 BlueKeep 漏洞——这个漏洞早在 2019 年就被发现并发布了补丁,但该公司却仍未对其进行修复。

“They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition.”

BlueKeep 漏洞会影响多个版本的 Windows 系统(包括 Windows 2000、Windows Server 2008 R2 和 Windows 7);另一个相关的漏洞 DejaBlue 也会影响 Windows 10。

Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019.

BlueKeep 漏洞利用了 Windows 的远程桌面协议(Remote Desktop Protocol)中的安全缺陷,使攻击者能够通过端口 3389 侵入系统并执行远程代码。

BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10.

此外,这个漏洞还具有“蠕虫传播”能力(即攻击者可以将其从一台系统传播到另一台系统)。

BlueKeep and its related security risks involve a flaw in Windows’ Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389.

然而,这些安全问题竟然没有被这家律师事务所视为优先处理的事项……在本次渗透测试中,Brinkley利用了 BlueKeep 漏洞入侵了该组织的系统。

The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm.

他发现系统中的密码都是以明文形式存储的,因此可以直接将这些密码复制到文件中(无需进行任何解密操作)。

系统中的用户名虽然设计得看似“安全”(即通过使用一些看似随机的字符串来代替真实的用户名),但实际上这种设计反而增加了密码被猜测的风险。

During his pentest, Brinkley used the BlueKeep vuln to get access to the org’s systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. The usernames on the system were cleverly designed for security by obscurity.

例如,有些用户名被设置为 “Yellow Banana” 或 “Red Apple” 等,这使得攻击者无法判断哪个用户拥有最高的权限。

Instead of using the user’s real name or something like “admin,” they had names like “Yellow Banana” and “Red Apple” so attackers could not guess which one had the most privileges.

Brinkley并不知道 “Yellow Banana” 是谁,但他还是找到了这个用户的密码——那确实是一个极其糟糕的密码(密码内容为 “r3@lg00dp@$$w0rd”,实际上就是 “realgoodpassword” 加了一些符号和数字)。

Brinkley had no idea who Yellow Banana was, but he found that person’s password and it was perhaps the tackiest idea of a we’ve ever heard. The password was “r3@lg00dp@$$w0rd,” which is “realgoodpassword” with some symbols and numbers substituted for letters.

由于不知道是谁犯下了这个安全失误,Brinkley将这个密码以及相关的截图收录到了他向律师事务所高管们展示的关于系统漏洞的报告中。

Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm’s execs.

就在他解释自己已经成功入侵了该组织 2,500 台电脑时,该组织的首席信息安全官(CISO)突然爆了一句粗口:“为什么我的密码会出现在屏幕上?”

While he was explaining that he had managed to penetrate 2,500 of the org’s computers, the CISO suddenly dropped an f-bomb.

这暴露了他就是 “Yellow Banana” 这个用户的事实,同时也说明他认为 “r3@lg00dp@$$w0rd” 确实是一个“安全”的密码……那么,从这个令人尴尬的安全事件中我们可以学到什么呢?

“Why the f* is my password on the screen?” he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea. So what can we learn from this tale of legal embarrassment?

首先,新安全补丁一发布就应该立即安装到 Windows 系统上;其次,绝对不要使用任何过于简单、容易被猜测的密码;最后,启用双重身份验证(2FA)并对密码进行加密也会大大提升系统的安全性。

Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too. ®