Almost a year after the Hacking Team hack, the hacker who managed to do it has published the method he used to breach the company's servers. Let's recall that after the breach, he stole all of their data.
Hacker FinFisher, also known as Phineas Fisher, posted on Pastebin over the weekend how he carried out the attack, and what tools he used.
The hacker revealed that the entry point into Hacking Team's infrastructure was a zero-day root exploit on an embedded device located on the company's internal corporate network. He declined to name the exact nature and purpose of the embedded device.
FinFisher says he spent a lot of time scanning the company's network, discovering a vulnerability in the frontend of the website that uses Joomla. In addition to the above, he discovered several security issues affecting email servers, two routers, and some VPNs. The researcher concluded that the zero-day exploit he found was very reliable for further attacks.
After writing and deploying a backdoored firmware on the vulnerable embedded device, it waited, “listening” to internal traffic, scanning and mapping the local infrastructure.
He discovered two vulnerable MongoDB databases that Hacking Team admins didn't password protect (!). There he found details about the company's backup system and where it stored the backups.
The most valuable backup was on the Exchange email server, from which he was able to extract the administrator account password from the BES (BlackBerry Enterprise Server), which was still valid.
This password allowed FinFisher to access the server as an administrator. This allowed him to extract all the passwords from all the users in the company.
Of course, the hacker knew there was a chance he would be caught at some point. So the first thing he did was use Windows PowerShell to get the data that was on the company's email server. For the next few weeks, as long as he had access, he received new emails every day.
After reading some emails, FinFisher realized that there was another hidden network within the company's facilities, where Hacking Team stored the source code for RCS (the company's top surveillance software Remote Control System).
With access to everyone's computers, as well as the administrator's password, FinFisher focused on one of the company's top developers, Christian Pozzi.
He scanned Pozzi's computers and the email accounts he used, and eventually discovered the password for the Web interface of the GitLab source code management system.
“That’s all it takes to bring down a company and stop human rights abuses. That’s the beauty and asymmetry of piracy: With 100 hours of work, one person can undo years of work from a multi-million dollar company,” FinFisher says.
“Hacking gives underdogs the opportunity to fight and win.”
For more details, read the link below
