2023 Pentesting Vision Report – Cody Chamberlain, NetSPI
Cody Chamberlain, NetSPI head of product, shares highlights from NetSPI’s recently released 2023 Offensive Security Vision Report based on over 300,000 anonymized findings from more than 240,000 hours of penetration testing. The report identifies the 30 most prevalent vulnerabilities across various industries. Download the free report at netspi.com/resources/reports/offensive-security-vision-report-2023/
Transcript
This is techstrong tv. Well, the great pleasure being joined again by Cody Chamberlain. Cody's a returning guest on Techstrong tv.
He has had a product with Netsy. Welcome, Cody. Thank you so much for having me.
You bet. Good to have you back. Uh, would you introduce yourself?
Tell us a little bit about Netsy. Absolutely. If you're not familiar with Netsy, we're an offensive security company.
Um, our hearts in penetration testing, but have a lot of really exciting, um, improvements and in changes coming with tech surface management, bridging attacks in relation, really taking our, uh, human-driven ethos and, and scaling that further. And that's really what my role is. How do we take the things that make Netsy so amazing and so great, and continue building them and scaling them and making them as, uh, available and scalable as possible.
That's fantastic. Good to hear you're expanding in those areas. I'd love to talk.
Maybe you come back and talk another time about that too, or we can delve into a limit here. So what's been f testing, right? Um, so I understand you have a new report out, uh, around some of the data that you, you gather through your, your processes and all the work that you would do with customers.
Tell us about the report that you've launched and probably also just, you know, hey, you and I can download any report we want these days, a state of this and that, you know, why, why put another report out there? What, what was sort of the passion and the drive behind it? Absolutely.
So, um, for us it's the next by vision report. Um, and it's really about taking a look back and I look forward, right? And there are a lot, and the reality though, uh, is that a lot of them are heavily focused on incidents and breaches, um, kind of after the fact.
Uh, and I think at Netsy it's really important for us to take advantage of, you know, the 300,000 findings we have a year, the 240,000 hours of testing. How do we take that, make it really actionable for, uh, the industry so that we can kind of maybe get ahead of, you know, the, the breach reports being so helpful, uh, because we're sh you know, shifting that focus a little differently. Um, and just ensuring we incorporate our people into that.
Uh, Andy Acer from a mobile perspective, Ryan Krause, Josh Webber, uh, Thomas Elling, I'm forgetting a few of you. I'm really sorry. Uh, but it was important to bring our service leadership's expertise into the, the message of the report, right?
Not only here's the problems, but these are ways that you can, uh, pragmatically implement solutions. Uh, and how can you maybe get a little bit of support from the industry that we're not alone, right? Like, there, there's a lot of these things that are recurring, so how can we get some support to really try and move the needle?
Uh, break the cycles kind of popped up a little bit, you know, how can we start breaking some of these cycles? And that was really what we were focused on with releasing our report and looking to the future. Really just that year over year, how are we doing?
How are we getting better? How are we continuing to get better? And it also, including the voice of the industry.
Uh, we reached out to the industry and said, why is this happening? And why are some of these things reoccurring? And it's a lack of prioritization, it's a lack of resources, a lot of the things we all talked about.
Uh, but we think it was good to get that all packaged into the report. Inter, you know, it's interesting, uh, the way you position it is, uh, you know, all, all the pen testing I've had done, or a little bit that I've done myself, it, it's all in private, right? We're not doing that out in the public.
We're not releasing the results of that, uh, necessarily to the broader community. So it all kind of happens in isolation, and everybody's, you know, behind their, whatever, you know, green, green drapes or whatever behind the, in the Emerald City, we don't let that stuff out. So it's tough to share and learn, you know, Hey, I'm, I'm probably the thousandth person this month that had that found during a pen test.
So how do we stop that? You know, that cycle of repeating this. That's Exactly it.
What can we learn each other? Yeah. The reality is, is we all have a lot of the same problems, and, and that's okay.
Um, and to your point, it, it, you know, this data is, is really sensitive, obviously, and we went through a lot of, uh, you know, uh, processes to make sure that this was fully anonymized and, uh, respected any kind of contractual obligations we had, uh, in that regard. Uh, but yeah, you're spot on, right? Is is the industry we all kind of lift together.
Um, there's enough ing to do and, you know, incident response to do in the world. So it doesn't hurt us by, by uh, releasing this and really getting folks to, to get, uh, breaking the cycle. Mm-hmm.
Very good. Well, well, how about move to just what were some of the insights from it? Maybe what did you learn?
And I'm always interested in what came out of it. You weren't expecting, you know, like that's a little bit of a surprise or I knew about that, but it's higher than I thought it might have been. Yeah.
I think the most surprising, um, aspects of the report we're definitely focused on biometrics. Um, um, when we, just to take a quick step back, we kind of bucketed all of the analysis, generally how we would kind of bucket our service lines. Uh, application testing, cloud testing, and network testing.
We did that because they all have relatively distinct methodologies behind them. Mm-hmm. Um, from an app.
So just kind of walking through that from an application perspective, uh, you know, the, the biometric bypass vulnerabilities were really interesting when you think about how many times you used biometrics to access some insanely sensitive, uh, stuff on your phones. And as we, you know, going into the cloud, um, I think what's surprising is the amount of just kind of management ports that are available. Uh, that was my visceral reaction when I saw the data as I thought about it.
It did kind of make more sense in the context of like, you spin up a lot of these workloads and you have to access 'em, right? You have to be able to, to manage them. Um, now the, the key is, is to not have that available to the internet, right?
Uh, expose that kind of attack surface to, you know, your ips or of your organization or your support organizations. Um, and from a network perspective, you know, I was pretty surprised to see that there is a lot of deprecated old services still being out there. Uh, group policy settings are disabled.
Net biles name services. Uh, I always forget the L L M N R one, the link local, uh, can't keep track of all the acronyms, but you know, these are simple group policy updates that can be made. Uh, and for whatever reason they haven't been.
It could be, you know, uh, ignorance to how, uh, susceptible they are to men in middle attacks. Uh, it could be the fact that this was an accepted risk years ago, uh, because there was a need for it and wasn't revisited. And now that, you know, more and more applications have improved their compatibility with newer network protocols, uh, we just haven't gone back.
So it's really important that we go back to those previous risk excepts to understand now is this the time to go back and actually remediate versus having to deal with, um, some susceptible protocols out there. Mm-hmm. I, I know one of the challenges I've had is whenever we talk about shutting something down, deprecating something, all of that there, there's just this hesitancy that you have.
Like, well, I don't wanna shut it down cuz somebody's gonna ask for it as soon as they do. And you know, it's been three years and I'm thinking about shutting this, you know, putting this away, tucking it into bed, let it go. But I don't, you know, or just, there are so many other today priorities going through the work of doing that, but those are just as much an attack service, maybe more so, you know, given the, the changing landscape of, uh, threats and vulnerabilities, et cetera.
So it can be compromised just as easily, maybe more easily than what you're working on. Yeah, that's exactly it because a lot of it, the reality is in our security teams is fires, right? It's the thing in front of us.
Um, that's the, uh, manifestation of the fact that we have the, uh, employment rates we do, which is the benefit, like the bittersweet aspect of our industry. Um, but, you know, things pop up like chat, G P t, ai, blockchain, and we need to respond to those. And it, it's exciting, it's fun and it gets the team built up.
So it's like, how is the balance of saying like, Hey, let's go focus on this, versus the really unsexy the really hard in the weed stuff, which is disabling though understanding effects of the changes throughout really complicated environments. Um, so it's an balance that's difficult to strike, but it is really important that, that we make concerted efforts to do that. Still.
Good point. A new term. I dunno if it's new, but you hear it more often, security debt, just like you're like a technical debt, right?
Things that fall into that category. Exactly. It and, you know, it's easy to, to let things sit in those buckets, you know, as, as in product management, it's easy to ignore tech debt and, uh, you really have to make those concerted efforts of what we are gonna push this maybe revenue generating feature or this, uh, really special client enhancement feature cuz we, you have to make those tough calls and it's, it's abrasive and it's hard, but, um, it pays off in the long run for sure.
Yeah, very true. How about some other, other things that came out of the, the story? Yeah, yeah.
I mean, obviously the, the less surprising is the continued, uh, prevalence of, uh, IOR and, um, uh, missing authentication and authorization functions in applications. Being able to, uh, to break the session man or authorization management of applications. Uh, unfortunately that's, that's still really prevalent.
Um, testing manually works far more effectively, uh, to do that, to identify those vulnerabilities, which makes sense that they're kind of manifested out of the nets buy, uh, methodology and processes. You know, in order to do a lot of that testing, you need the two identities and then be able to cross those identities in the testing, uh, process. Uh, so, you know, manual testing is still really important.
Um, there are places for, uh, the automated scanning and, and testing, uh, but having humans, uh, creatively try to alter these applications is, is really vital. And one of the things, um, that our, uh, services leadership has mentioned is, you know, we really gotta focus on that utilizing things that have already been built, right? There's a lot of good frameworks with authentication and authorization management built into the frameworks, uh, insecurity, I should say in development.
It can be easy and exciting to kind of reinvent fire, so to speak. Uh, we don't need to do that. There's a lot of people who have solved really hard problems.
Uh, authentication authorization, session management are hard problems to solve. Um, and when you're not an expert in those, you can make bad decisions just because it's so hard. So let the experts through focus on that, really do that and let them help you, uh, by, by utilizing those.
Um, and that has helped organizations a lot, uh, in just very quickly in iteratively improving authorization management and applications. Um, as far as, uh, you know, thick applications in that space, still a thing, right? Like thick applications, the client server model is still out there.
Um, you know, whether they're, uh, refactored kind of mainframe applications or, um, you know, as we said before, it's just too hard to change sometimes. So there's still a lot out there. Uh, and a lot of these have poor encryption between client server.
Sometimes they have goofy, um, like vendor built, uh, encryption that that is, you know, easy to break, hasn't been improved with, um, cryptographic improvements over the ye over the years. Um, ensuring, you know, there's kind of that assumption made that because it's in the internal network, you can trust it and therefore the integrity checking and stuff like that, uh, between client server has, has been there, uh, on the cloud side, you know, IM mismanagement is, is, is rampant. And it's understandable, you know, for those of us who have had the ability to go into these consoles and look at how complicated, uh, public cloud IM management is, it's, it's, it's horrible.
Mm-hmm. Um, so having people that are, um, experts in that, having people that, uh, have the ability to say they're not a hundred percent sure they did it right. So can you please help in, let's do some iterative testing as we build this.
Um, you can see like when you build a cloud formation template or ucls and you can build an entire infrastructure pretty quickly, it's also pretty quick to have one little bit flip missing that inherits, you know, global admin down through, uh, the workload. And unfortunately, um, it's still un not uncommon, uh, for people to not keep these systems patched. Uh, e c two instances or virtual machines and, you know, depending on which, uh, cloud environ you're in are pretty consistently unpatched.
Um, in my history, I, I had a, an IT leader I worked with who said, well, we just go the cloud, it's more secure, right? The these kind of just like generic statements and you know, when you run everything in virtual machines, you know, Azure, AW ws, they're just really big, right? Uh, you still have to do all of the things in the shared responsibility model of patching the systems, making sure you have, uh, you know, just in time access and privileged credentials and all that.
So just because you're moving to the cloud, uh, doesn't mean you're inheriting all of the security that Google, Microsoft, Oracle, whoever, uh, produces. There's still a lot of responsibility. Um, yeah, that I, I think that's kind of covers the, the big hitters of the, the different areas, you know, cloud again, uh, actually, uh, you know, just public disclosure of, of, of sensitive data, how same kind of thing as the I am thing.
It's a, it's a very simple, uh, configuration tick to, to miss sometimes. You know, g ccp, aws, they've put in a lot of guardrails, right? Um, they've got enough breaches that you have to work pretty hard to, to buy default, make S3 buckets, or I should say storage, uh, resources available.
Uh, but they still happen. Um, and it, it is something that is also recurring in, in our testing. Great.
I'm, I'm curious, Um, I don't know the report specifically covered this, but you know, so one of the new things people are talking about is Passwordless and PA Paske is a technology. Google is now recommending that for their workspace products. Apple just had part of their announcement this week, um, adding some more capabilities for that.
Is that something, are other technologies like that or maybe some others, you, you think are gonna be on the rise or you're starting to see pickup steam? Absolutely. I mean, when you look at, uh, continued, uh, in the report, there were aspects of weak credentials, weak passwords, um, guessable passwords still really rampant in, in, in environments and especially on external networks.
That's, that's hoor horrifying, right? If, if you miss, uh, multifactor authentication, right? Um, so I, I think that is much more prevalent when you look at the Okta of the world and the, the big identity providers.
Um, they're, they're investing heavily in it. And I very strongly believe that the connectivity to biometric kind of authentication tied to things like past keys are gonna be far more fundamental and ubiquitous starting now on the consumer level just because it's easier, right? Um, it's far, far less impactful.
Um, but that's definitely gonna push into the enterprise. It's just necessary, uh, to incorporate these modern authentication mechanisms because just making passwords longer, just make some password, password one instead of password one. Um, we're just kind of, uh, you know, uh, shifting, shifting the bad behaviors.
Mm-hmm. It's interesting too, I'm just mentioning Apple cuz they originally had their, you know, developer conference. They also, uh, are adding some enhancements to the web browser safari to be able to have your, here's your profile while I'm working.
Here's my private profile. I'm trying to keep your accounts and data. And I'm not saying it solves all the problems, but it's just interesting that at an operating system, browser level, company's starting to think about how to separate, you know, those different domains from one machine, one profile that you're working on.
Yeah. There are technologies and products that do that too, but now you're talking to embedded in the, the OS that you're using early starting to, Well, it just shows how work is becoming a bigger part of like, the fabric of people's lives, right? I mean, we work from our personal devices on our phones, we work, you know, we'll maybe sit down, I'm just logging into Salesforce, right?
So I don't necessarily maybe need to get on my work laptop, on my work vpn, I can just open a tab. Uh, but that introduces a level of risk, right? Like we've mm-hmm had the benefits of understanding how capable folks are working remotely working from home.
Um, but there, there are risks associated with it. And that's one of 'em, right? Is, is this kind of merging of people's family and personal lives with work lives.
And I think, uh, organizations like Apple and Google, you know, they'll certainly continue doing that because it's, it's so important to, to do our best to keep that separated. Very cool. I'm curious, just kind of as the last question, it's a little bit of a left field, but I'm curious if, if netsy or companies like yours are getting more involved in the supply chain security aspect of things, and think of specifically of the tool chain you might use in a DevOps workflow, right?
This isn't pen testing from, you know, getting into some cloud service. It may be in, you know, GitHub or something, but that obviously is a whole new attack surface. Um, and developers may not be the best folks to make sure that that's as secure as it needs to be, right?
Their, their skills lay elsewhere, they're busy doing other things. Yeah, I think if you were to look at not only just right now, but the future, you know, as bombs are big right now, um, all of the aspects of that. So that is something that Nets Buy has invested really heavily in.
Um, the Nabil Hanan, our field, cci, excuse me, um, has brought a lot of expertise in that regard in really kind of maturing our services offerings to help organizations find that, right? There's the organizations that are developing products that may be delivered in their customers environments, which have been, you know, heavily, um, uh, attacked and, and got a lot of attention obviously, but organizations utilize a lot of libraries. You know, it's really easy to import module, import module, import module.
Um, so it's, it's becoming a, a much bigger attack surface. It's not an attack surface that, that people naturally think of when you think of like IPS being spun up on an external interface. But the reality is, is if you can poison these libraries, you can have a very scalable attack scenario.
Um, so, you know, nets buy is certainly, you know, well-equipped. I know our competitors and our, our friends in the industry are investing really heavily in it. Um, there's been a lot of, uh, investments in, you know, series funding for organizations that are heavily focused on it because it's such an important part of the organization.
Um, you know, certainly would be happy to, to come back another time and really dive deep into that for sure. Great. Love to do that.
We'll have to do that. I'd love to hear some more about kind of tax surface management. Appreciate you coming by.
Uh, can folks download the report and I'm sure find out other great things that, uh, Netsy is doing on your website? com. Download it.
I'm also on LinkedIn. Please feel free to reach out with any questions. com/careers.
We're always hiring, we're a a hypergrowth company. Um, so if you wanna come join the exciting ride we're on, always, uh, open to that too. Okay, very good.
Thanks. Cody Chamberlain, who is head of product with Netsy, thanks for coming by again and uh, we'll have you back soon. Thank you so much.
It's Your honor. You bet.