Hacker Uses of Obfuscation – Tony Lauro, Akamai
Tony Lauro, Akamai Director of Security Technology & Strategy, discusses three of the key obfuscation techniques attackers use to break down defenses and exploit systems through undetectable means, including impersonation, trusted site, and human ingenuity techniques.
Transcript
This is Textron TV. Of the great pleasure of being joined by Tony Laro Tony is director of security technology and strategy at Akamai. Welcome, Tony.
Thank you, Matt. Thanks for having me. You bet always love talking to you.
Would you quick just do an introduction to yourself just about you and I hope everybody knows you welcome my is but if you say something about your your part of rock, come on, yeah. Yeah, so I've been without my for about nine years. I've been in infosec and security since the late 90s when I work for a US based Telecom provider basically at any role that I've ever had.
I'm always looking for the security angle. You know, how can we make security better? How can we improve what we're doing?
And now I get to do that at Akamai not just for our clients, but for the products that we're developing to make sure that the direction we're going is into the future not the past. A fantastic. What's great talking with you and so much traffic flows through optimized network.
Of course, you see a lot of things. I've talked to different researcher folks there about all the great great things that you see in Trends. So we we were gonna talk about obfuscation and some of the techniques that are applications about obfuscation that folks you're using Chris.
The hardest things is the fixes their blocker or whatever the ones you don't know about. Right? So kind of yeah and detected is is obviously a goal of any exploit hackers that are trying to exploit that so it tell us a little bit about it.
Yeah. Well, you know, it's you know, as as I said before being in security for so long, you're kind of always preparing for something to happen and lots of times it never happens. Right like not every company you work for gets hacked or has a big incident but since coming to Akama, I have had the pleasure of kind of looking through data and sifting through data and working with customers.
Who are getting hacked every single day right? These companies are kind of the Pinnacle of the the companies on the web on the internet. And then Akamai sits in front of them.
So we're kind of the tip of the spear for this type of you know, malicious traffic. So what I thought would be interesting is to instead of talk about you know, hey all the great stuff. It's a really look at hey, what are some cases where we see where attackers are specifically saying you have a control?
You know a blue team control and I as an attacker want to bypass that control. So lots of times they do it through obfuscation, you know, one real quick instance is what I like to call a trusted site obfuscation which in in the sense if I'm an attacker, and I have a large scale attack campaign going on. Um, there's two things I want to do one.
I want to make sure that my payload as it is as readily available as possible. Right? So if I'm doing a remote file inclusion, and I'm calling out to a malicious payload, or if I have malware drop that I want you to be able to download the the payload Etc.
I'm gonna put that on a low cost CDN or at least get it up into the you know into the cloud and some manner so when I'm sending a hundred thousand emails or I'm doing a large scale attack campaign the probability of that file being extracted. I don't want it to come back to some web server that I'm renting and you know in some data center. I want it to be massively distributable.
Yeah. So we see attackers leveraging one hosting their their files up in the cloud somewhere but to directly calling, you know exploit code from trusted sites like GitHub. So in this particular case I talked about.
At black hat the URL is or the URI has a remote file inclusion vulnerability in it. com. And then the whole path to this PHP shell script, right?
So this you know, this comes into playing a couple ways one probably if you're looking through logs and you're looking at you know URLs that are being accessed. You're probably not going to be blocking GitHub right be developers you do that. Absolutely.
Yeah. So so it comes into this play where you really have to have that Fidelity that when you're looking at remote falling inclusion, you know, what is the risk tolerance level there? And how many different ways and and planes can You have identifiers that set off alarm bells and Trigger and say hey, even though this is a trusted site.
This is you know a call out that may or may not have been caught in the first place. What is the the adverse effect of that? So as the payload starts execute into the web service.
Can you see that? Can you identify that? So that's one example, and we see the same thing people scripting things from Google user content through Google Sheets, you know, another interesting case where it they're sending Google bot user agent.
com So it was is the as part of the point Tony that there are nuances like that of what the domain actually is that can tell you that maybe not what you think it is but also that we do have to look at the payload because that payload is referring to a PHP script or something else, you know, or or some odd directory on some place where I like where you're keeping code is that part of the point? You have to look at the payload to just not headers of where things are coming. Yeah.
Yeah. There's a lot of security controls that kind of work at this good enough level where you don't want to negatively affect the user experience. You want to negatively fat the business processes.
So they're tuned in such a way that it really would have to be a very loud and and obvious exploit for it to be able to be seen in this particular case, especially if you have a safe list of sites that are used for callouts. This might go under the radar and all the subsequent rule triggering would not happen because it's in a safe list, right? So sounds like a certificate authorities might be a good and safe list of people to attack.
If you can get in there you can get to a lot of people right? Absolutely. Yeah.
Very interesting. And by the way, you mentioned your talk. This is from this is content that you talked about at blackhat right this year.
Yeah. Yeah, and you know again it's kind of an interesting approach on the conversation. You know, I feel like red team conversations get so much more hype than blue team conversations and and noticeably so because it's cooler, right, you know, I'm sitting down with a client and we're going through all of this, you know these bypass techniques and I'm like look how cool that is.
Look what they did and they're like it's not cool at all and I'm like, it would be cool if it wasn't happening to you, right? Yeah, we're sense of cool and their perspective, right? Yeah.
Exactly. Exactly. Yeah, so it's it's fun to walk through those things and and to really make sure and identify not just what they've done in this particular instance from their own security configuration.
As we create new tooling are we doing them in mind? Of you know, the layout ttps and bypass techniques, we've got to make sure of that of course, so it puzzle that game of cat and mouse right? That's the that's fun the challenge of it.
If you are the Intriguing part of it. Well, we'll talk about some more some other obfuscation techniques. Yeah, well one was kind of interesting.
This was actually found by one of our security researchers Larry cash dollar. He got a phishing email that said. com.
I'm like, wow, they could not have messed this up any greater. But what's funny is when you you were to click through the link on a mobile device. It takes you to a Google login page that has a Google certificate looks legit.
But if you were to log into it, it would be capturing data and sending it off via form email to the bad guys what they did here what was interesting and in terms of obfuscation is they were taking their web page running it through Google Translate. co or something like that. But because it was running through Google translate if you're to look at a web browser, you've got your lock you've got everything kind of looks legit.
google. So it's a valid, you know, legitimate domain, but what it was presenting was the malicious fishing domain, so he was able to kind of obviously suss this out prior to you know, falling for it and did a whole like, you know expose on why this was illegitimate. He even broke down the the code and the fishing page that showed this Gamers email address.
I think one of them even had like this scanner scammers name or handle to kind of further, you know research and then the form that actually captures all the data he was able to break that down and even show a sample no, Larry Larry just enough. No, you don't mess with Larry when it comes to security and yeah, yeah, absolutely. No doubt.
Very interesting what and again it's it's that theme of trusted sites right or what appears to be trusted sites and which is in this case a fishing, you know exercise but it's also that front in that that domain yeah and from social engineering term a terminology. I mean there was pre-taxing which was kind of giving the context for for why are you getting this message? And then some of the validation around?
Hey, I'm a you know, I'm a there's a legitimate problem here, right? So pretexting and baiting and debating part was saying hey, there's a problem with your account. You've got to fix it right away.
There's always whenever there's an urgency to to an email. You can almost a hundred percent or maybe 98% assume that it might be some sort of fish or or at least maybe a sales tactic at the very least, like don't miss, you know times running out. Yeah.
So, yeah, but Right, there's more. Yeah, exactly because techniques okay. I think you had a third example.
Yeah, the third example and this is something that is evolving kind of rapidly is the idea of saying hey, I want to look like a legitimate user so that I can buy goods from your online store. Whether this be you know, $800 sweater that says the word no on it, you know some fancy. I don't obviously I don't know fashion well enough to to buy something like that, but you know high-end retailers shoe stores shoe re you know, she vendors directly they're getting hit with this type of Bot called an all-in-one bot and we've talked about this, you know in the past before but it was kind of interesting to look at just how detailed the the bot mechanics are one.
They have full documentation that specify how to interact with the website. You're about to attack what how their apis function what kind of information they're looking for and then within the bot, you know program interface itself. It has different profiles for different payment cards in case one fails you can switch over different shipping locals and then different personas, which I thought was really interesting because again, Yours I bought management is a very very sophisticated field much more now than it was, you know, four years ago five years ago, but still these things are very very tricky because they're going through residential proxies.
They're coming from home IP addresses. They're switching all the time. They're not sending more than a few requests from each residential IP at the same time.
So now you have this real cat Mouse where the Fidelity of you as a Defender has to be I Absolutely cannot put a security roadblock in front of a good user who's buying something. But from the business aspect. I don't want to be the security team that let you know all of our you know, high price game consoles go on the on the day of the of the launch right or the shoes that just dropped or whatever.
So this this it and there's even things built in like captcha captures, right? So people You know and for years people have been saying hey, I'm just gonna put a caption in front of this. It can't be a bot if there's not someone to click through, you know, well, they're using a bot but it's a human driven automated bot.
Right? So those responses for capture come up and they even have walkthroughs and say hey log into Google log into YouTube with your your Gmail account or a fake one and then start watching YouTube videos because that gives you like user liveliness tokens so that when you get a capture response instead of saying, you know, click on this the boxes with the street sign, you know, and you're kind of sweating because there's one box that has a little sliver of a street sign. It just says, I'm not a robot and you just get the boom you click click click click all the way down and all of a sudden you bypass that that security mechanism.
I think that's one thing that many people don't and me we should be able to say we can tell the difference between an automation a bot and when it's a human and that line is definitely blurring by both the hybrid techniques Talking about and even some of the automated techniques of really driven by a Persona like you're talking about now, it looks like a real buyer because they looked at you know accessories after buying, you know, something for their car that they might also add to it or whatever the products are. Yeah. Yeah, they moved around it the the walk through the FAQ told them.
Hey a few hours before the launch go to the site click around show some activity have some you know, some real liveliness on this site prior to you know connecting with with the bot, right? So they they thought of it all but at any given moment, you know, we're trying to say one step ahead how we're evolving those detection techniques, you know, even looking at things like instead of saying is this a human or is this a bot validating? Is this the right human the last time Tony logged in?
What did it look like when he logged in? Where did he connect from and those? Of things that you know, as you're creating fake personas are harder to to replicate especially when you mix things like account takeover.
Am I logging in using stolen credentials for Tony's, you know online account or is this a fresh account? That was just made right? So tracking that is is helpful.
But again, you know, they're always gonna try something new and and that's the fun of the of the of the business I'd say. It's not fun, you know until you fix a problem, but it's fun to to track that right so you can say intriguing or yeah, I sure probably back away from the word fun. Yes, you know.
I'm trying to lead you to do at your back on that Tony. No no problem was is pleasure. I love talking with you and hearing about the latest things you're finding and you know, it's just fascinating how many things are put together in new and different ways or new Techs on top techniques on top of old.
In this world that we live in of cyber tax and defense. I know you all do a lot of research probably will have a lot of information that you publish working folks go to on the archimai side or or someplace to find out kind of the latest blog information or whatever you might have available. Yeah.
com slash security Dash research. com slash blog slash security. So a lot of really interesting stuff and we're we're seeing malicious attacks not just, you know from the internet into companies, but with our zero trust portfolios and our install base we're seeing real, you know, now we're driven attacks lateral movement that we have, you know a whole team that's looking for this type of activity and and Reporting on it and you know, obviously protecting our customers against Attack.
So again, it's never a dull day at akmai. Most fun habit RSA or black hat is when I get to sit down with one of the Akamai researchers and try to understand, but they're telling me about talk about and I opening experience for sure. Is it definitely is well.
Thank you Tony. Appreciate you joining us today folks. Please check out Akamai sites that he mentioned.
There's some great information, and they produce a quarterly report a lot of good things about things that OCC. My seeds going and cross its Network and security related topics. So Tony come back again.
Look forward to it. I will thank you. Have a good day.