hacking law firms with abandoned - iron bastion...backlinks(dmoz/ ahrefs) 5. register domain 6....

86
Hacking law firms with abandoned domain names “You had better keep your expiring domain names alive”

Upload: others

Post on 23-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Hacking law firms

with abandoned

domain names

“You had better keep your expiring domain names alive”

Page 2: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

gabor:~$ whoami

Gabor Szathmari@gszathmari

Cyber security expert @ Iron Bastion

Privacy advocate @ CryptoAUSTRALIA

Page 3: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Which one is real?

OptusGames.com.au

TheWestPacCentre.com.au

wmWoolworthsMoneyCreditCard.com.au

Page 4: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

@gszathmari

Page 5: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Overview

•How domain names die?

•How to find good domain names?

•Hacking law firms – The examples

•Tips for individuals & red/blue teams

Page 6: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Let’s go!

Page 7: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

How domain names die?

.au domain lapsing:

1. Active

2. ‘Expired Hold’ (30 days)

3. ‘Expired Pending Purge’ (1 day)

4. Purged at 1.00pm (AEST)

5. Available for new registration

Page 8: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 9: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

How to find

good domain names?

Page 10: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

The manual method 1.

$ cat RO_expired-domain-names_au_daily_2018-09-08.csv | grep law

2018-09-04,04:13:42,joshlawelectrical.com.au

2018-09-04,04:30:04,comslaw.org.au

2018-09-04,05:37:05,lawyersforbusiness.net.au

[…]

Page 11: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

KeywordsBacklinks Dmoz rating

The manual method 2.

Page 12: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Workflow

1. Iden.fy good sounding names

2. How the website looked like? à web.archive.org

3. Look up domain reputa.on(for proxy and spam filter bypass)

4. Backlinks (DMoz / Ahrefs)

5. Register domain

6. Profit!

Page 13: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Hacking law firms

with abandoned

domains

Page 14: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Reasons to target law firms

•Merge and get acquired frequently

•Low-security businesses

•Manage sensitive data and high-value

payments

Page 15: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Reasons to NOT target law firms

#1: Tendency to sue people

Page 16: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

What we did

1. Identified valuable expired

domain names

2. Registered domain name

3. Added our MX hosts – ‘catch all’

4. Started receiving emails

Page 17: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Ques%on 1.

What are the auDA

requirements to register

a .com.au domain?

Page 18: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Question 1.

1. Must be one of these:•Registered business •Sole trader• Incorporated association•Trade mark owner

2. Must provide ABN/ACN/ARBN/TM#

3. Be able to tick a box

Page 19: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 20: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Loot #1:

Statements and

no/fica/ons

Page 21: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 22: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 23: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 24: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 25: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 26: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Text-to-email

service

Page 27: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Loot #2:

Legal documents

Page 28: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Family legal matter

Page 29: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Family legal ma*er

Page 30: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Tax invoice

Page 31: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Client enquiry

Page 32: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Negotiation strategy

Page 33: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Nego%a%on strategy

Page 34: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Bank statements

Page 35: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Par-tay! !

Page 36: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Loot #3:

Password

recovery

Page 37: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 38: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Ques%on 2.

What are the domain

verification methods on

‘Havibeenpwned’?

Page 39: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Question 2.

•Email – e.g. postmaster@

•Website – Meta tag and file upload

•DNS – TXT record

Page 40: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 41: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 42: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

SpyCloud.com

Page 43: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 44: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Casual observation

Lawyers are:

•guilty of using crappy passwords

•tend to reuse them across mul7ple

websites

Page 45: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Loot #4:

Password

resets

Page 46: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 47: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 48: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 49: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 50: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 51: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 52: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 53: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 54: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 55: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 56: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 57: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 58: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 59: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 60: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 61: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 62: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 63: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 64: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 65: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Loot #5:

Professional-

specific portals

Page 66: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 67: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 68: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 69: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 70: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 71: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 72: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge
Page 73: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

What else we could’ve accessed?

•NSW Online Registry

•PayPal ([email protected])

•Google AdWords

•G Suite admin panel

•Office 365 admin portal

Page 74: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Recap

•Sensi&ve data in emails

•List of email accounts at

haveibeenpwned

•Passwords from SpyCloud

•Password reset emails

Page 75: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

How to prevent pwnage? (1/2)

•Keep renewing the domain name indefinitely;

•Close user accounts that were registered with the

business email address

(e.g. Dropbox, Commonwealth Courts Portal, PayPal);

•Change or remove the business email address from

online user accounts (e.g. LinkedIn, Facebook);

Page 76: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

How to prevent pwnage? (2/2)

•Unsubscribe from email no0fica0ons that usually features sensi0ve data (Text-to-email services, mobile phone billing no0fica0ons);

•Advise your clients to update their address book;

• Enable two-factor authen0ca0on where the feature is supported for online services; and

•Use unique and complex passwords.

Page 77: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Red Teams

Blue Teams

Page 78: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Abandoned versus new domains

Better reputation:

•Backlinks/SEO on Google

•Proxy category

•Spam – Not flagged as a newly

registered domain

Ideal for phishing

Page 79: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Blue Teams – Protect my organisation

•Phishing against my organisa.on

• Informa.on leakage (via ‘catch all’ email service)

•Shadow IT takeover (e.g. rogue Dropbox accounts)

•www. or *. à Web traffic / API traffic / iframe/

embedded content hijacking

•Haveibeenpwned, SpyCloud

Page 80: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Red Teams – Security assessments

•Ideal for phishing campaigns

•Gather leaked creden5als

•Provides access to 3rd party

online services

Page 81: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Question 3.

Can you name three domain reputation services?** Used by proxy servers

Page 82: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Question 3.

• For$net - h+p://url.for$net.net/rate/submit.php

•McAfee - h+ps://www.trustedsource.org/en/feedback/url

• Trend Micro - h+ps://global.sitesafety.trendmicro.com/index.php

• Symantec WebPulse Site Review -

h+ps://sitereview.bluecoat.com/

• Barracuda Central -

h+p://www.barracudacentral.org/report/website-category

Page 83: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Tooling

•Ubuntu + Pos+ix + Dovecot

•Domain registra6on:

•Manual

•API – Above.com

•Domain backorders

• ‘Drop catch’ services

(e.g. www.dropcatch.com, www.drop.com.au)

Page 84: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Summary

•Expired domains are .ed to your

personal/professional online presence in

unexpected ways

•Overlooked a:ack vector (Red Teams)

•Achilles’s Heel of your organisa.on (Blue Teams)

•ProTip™: Keep your domain names registered

Page 85: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Fun facts

In this research, we:

•Registered six abandoned domain names

•Received approximately 25,000 emails in total

•Won $250,000 from Mark Zuckerberg himself (we are yet to claim the prize)

Page 86: Hacking law firms with abandoned - Iron Bastion...Backlinks(DMoz/ Ahrefs) 5. Register domain 6. Profit! Hacking law firms with abandoned domains Reasons to target law firms •Merge

Questions?

h"ps://blog.gaborszathmari.me/2018/08/22/hacking-law-firms-abandoned-domain-name-a"ack/

@gszathmari