HOSTED BY CODY Threat Aware // PRIVILEGE ESCALATION // EP02

Your MFA Is a Speed Bump (How Attackers Walk Right Past It)

There are two kinds of MFA. One, attackers beat before breakfast. The other, they can't touch. Almost everyone's running the first one and calling it done. Cody Kretsinger pulls from his red team years to show you which is which... and how an attacker got into the account before the phone even buzzed.

WATCH / LISTEN

One attack, told properly. Each episode takes a single breach or backdoor apart: how it was built, who caught it, and what almost happened instead. Part of Galactic's Threat Aware.

Transcript

Auto-generated transcript, apologies for any errors. Download as text

Cold open

The victim did everything right. That should make your ears perk up. A strong password, long, random, not reused anywhere, MFA turned on, that little push notification on your phone where the prompt pops up, you look at it and then approve it. Because you're logging in. Everything we've been preaching for the last up teen years, that victim. They did all of it. And the attacker was already in the account before the phone even buzzed. Because the attacker never wanted the password. Actually, the attacker didn't even care about it. Didn't even try to beat the second factor either.

What they wanted was the thing that you get handed after you pass both. The little token that tells the site, yep, this one's good, let on in. They grabbed that. And a token doesn't care how you prove to who you are. It just opens the door.

Narrator

This is Privilege Escalation. Part of the Threat Aware Podcast Network. Incidents get reported. They rarely get explained. Each episode takes one attack apart from the inside, delivered with the perspective of someone who has spent time on both sides of an attack. How they got in, and how you stop them. Here's your host, Cody Kretsinger.