Your MFA Is a Speed Bump (How Attackers Walk Right Past It)
There are two kinds of MFA. One, attackers beat before breakfast. The other, they can't touch. Almost everyone's running the first one and calling it done. Cody Kretsinger pulls from his red team years to show you which is which... and how an attacker got into the account before the phone even buzzed.
WATCH / LISTENOne attack, told properly. Each episode takes a single breach or backdoor apart: how it was built, who caught it, and what almost happened instead. Part of Galactic's Threat Aware.
Transcript
Auto-generated transcript, apologies for any errors. Download as text
Cold open
The victim did everything right. That should make your ears perk up. A strong password, long, random, not reused anywhere, MFA turned on, that little push notification on your phone where the prompt pops up, you look at it and then approve it. Because you're logging in. Everything we've been preaching for the last up teen years, that victim. They did all of it. And the attacker was already in the account before the phone even buzzed. Because the attacker never wanted the password. Actually, the attacker didn't even care about it. Didn't even try to beat the second factor either.
What they wanted was the thing that you get handed after you pass both. The little token that tells the site, yep, this one's good, let on in. They grabbed that. And a token doesn't care how you prove to who you are. It just opens the door.
Narrator
This is Privilege Escalation. Part of the Threat Aware Podcast Network. Incidents get reported. They rarely get explained. Each episode takes one attack apart from the inside, delivered with the perspective of someone who has spent time on both sides of an attack. How they got in, and how you stop them. Here's your host, Cody Kretsinger.
I'm Cody Kretsinger, and this is Privilege Escalation. And today I'm gonna make some of you mad. We're talking about MFA. The thing that you bought, switched on, and crossed off the list. And I'm gonna tell you why the version most of you are running is the version we stopped as attackers worrying about a long, long time ago. MFA means you prove you are with something more than just a password. Something you know, something you have, something that you are. And it's a good idea, genuinely, turning it on. Still is one of the best moves you can make, but I want you to hold on to two thoughts at once here, because this is where a lot of people fall off.
MFA is good. It's intrinsically good. And the way most people set it up is a speed bump. They're both true at the same time, but they are true more often than not. So do me a favor for a moment. Stop thinking about MFA as a like a wall, right? A wall is up or down. And I want you to think of MFA as a lock. There's always more than one way to get past a lock, including standing there real polite until somebody opens the door and walking in right behind him. That's called tailgating, by the way.
So there are two ways in and neither one breaks your MFA. And that's the entire point. So let's go over those. The first way, the attacker, they sit in the middle. The attacker sends a link, it looks like the login to a page, but it's not. It's actually the attacker's sitting between you and the actual real site, and it's passing everything through. So when you type your password, it goes through and it goes to the real site itself. The site asks for your second factor, so you give it to it, and then that also goes back to the attacker.
Then The real site, happy that you are you, mints a session token and sends it back through the attacker, who then copies it, by the way. Now that they've got the token, they don't need your password again. They don't need your phone. They are, in all intents and purposes, you until that token expires, or somebody notices and actually kills it, but that's a different story. That type of attack is called adversary in the middle. And there are off-the-shelf kits that run the whole thing. This isn't some sophisticated nation state move. It's literally just another day of the week.
You can go onto GitHub right now, clone the repository, set it up in 10 minutes, and you're good to go. But there's a simpler way, the second way in all of this to get in. And they just need to wear you down. That's no fake page at all. They just already Get your password from some link so they just hit you with the MFA push over and over again. Then another. And then another. Sometimes it's two in the morning, or maybe it's their two in the morning, 'cause I get really weird pushes every once in a while on like an old Microsoft account that are just in the evening where I live, but I feel like the attacker thinks that maybe it's like two in the morning.
Anyway, sometimes it's very, very early in the morning or very, very late at night. They d they The whole point of this is that hopefully eventually you just tap approve to make it stop, or because you figure out or figure that the system is glitching or there's a problem with it, and then eventually just hit the approve button. Not because they're careless, but because they're human, right? That's the whole play in all of this is that the victim here just thinks that something else is going wrong. They hit the approve button And then they just want the buzzing and they want the quiet, they just want it to stop.
Either way, those attacks, look at what didn't actually happen. Nobody cracked a password, right? It was either something that was reused from before, or it was the adversary in the middle attack, right? They're not going after the password themselves, they're going after the second factor. And the second factor did exactly what it's built to do. But the attacker It's still in anyway. So let me tell you how the other side, how's the red team side, how the attacker side actually thinks about this. Because back when I was doing offensive work and a red team work penetration testing, finding out that a client had MFA everywhere really wasn't bad news.
Depending on the flavor, sometimes it was actually good news because it told me two things. It told me that they thought that they were done, and it told me which game to play. So as an attacker, you stop going after the password the day you realize the password was never really the finish line. The session is the finish line. Everything after you're authenticated is a token sitting in a browser. And a token's just a file. Files can get copy, and that honestly feels like it's too simple, but that is the answer. It's the honest to truth answer.
It is a copyable file. And Honestly, the middle of the hallway, the adversary in the middle move is kind of beautiful from the wrong side, right? From the attacker's side. Because you're not fighting with the security control. You're not actually fighting with the technology. You're leveraging it. You're using it as it's more or less intended to be used. So the user does the hard part for the attacker, for me. They authenticate correctly to the real site. And I just so happen to be in the hallway when they walk through and I get to copy their data, the homework that they've got, by looking at it, right?
So if a vendor ever tells you that like MFA stops account takeovers, it stops this one kind. The actually the simplest and kind of dumbest kind. Nobody serious is still kind of bothering with this. There are much other technical things. Sorry, there are much better technical resources for MFA that don't have this massive gaping security flaw. So what do you actually do? What does this actually hold? I'll give you the real answer. Most people have never really had it put to them as plainly as this. Because there are two kinds of MFA it causes some confusion.
And We actually use the same word for both, and that's part of the problem. There's phishing annoying MFA. Those are the kinds of like you type the code or you press the approve button, right? It's better than nothing. But there's still this human in the loop, and that human can be talked into handing the code over to the wrong people or tapping approve at two o'clock in the morning, as I mentioned. Anything A person can pass along, an attacker in the middle can also pass along as well, or at least grab. And then there's the fishing resistant MFAs.
So that's pass keys, FIDO two, the hardware stuff. Frankly, it's the good stuff. And that's what makes it different isn't that it's fancier, it's that it actually checks who it's talking to. So it's tied to the real site itself. So if you drop a fake page in the middle of that transaction between the victim or the user and the real site, for example, it just doesn't work. There's no code for a tired human being to hand over, because there's no code at all, right? It's just it has to only be able to log into that one site.
That's the move really here is protect one thing this quarter. Just make the accounts that matter phishing resistant. Not the we have MFA resistant, the kind that take a code or you hit approve, the kind that actually can't be handed to the wrong person. Everything else actually backs it up. You can tie sessions to devices, expire tokens faster so that a stolen one dies sooner, and then you can watch for the logins that come off of your CFO's laptop, you know, and four minutes later all the data is somebody else from another continent has and prevent that kind of stuff from happening.
That's the stolen token live. You can actually catch it i if you're actually looking for it itself. This is the part that I think some of you are going to hate and I am going to appreciate the hatred for it. We have MFA, that quote, we have MFA has turned into the thoughts and prayers of cybersecurity. We often say it after everything bad that happens, after those incidents. And we say it before something bad actually happens because it makes us feel like we did the right thing. But it is not the right thing. MFA is not a force field.
The MFA many people are running is a speed bump and attackers brought a truck and they drove that truck around it years ago. They're not out there in front rattling the door that you locked They're already in the hallway holding a copy of the key you handed them yourself wondering why you still think the door is the story. And the part that gets me isn't the users. It's that we sold everybody a checkbox and call it protection. MFA enabled. Green check. Done. Nobody said which MFA. Nobody mentioned the cheap kind is the kind they beat.
We let people believe a buzzing phone was a wall. The whole time it was nothing more than a screen door. I'm not telling you to turn MFA off. Please, please do not turn MFA off. But I am telling you we have MFA is a sentence that should close an audit finding, not stand in for strategy. And if that's The whole answer, then that's not an answer. You've got a feeling, a gut feeling. And the people that I used to be, the bad guys, love it. Absolutely love it when you have a feeling. So if you do one thing after this, don't add another push notification.
Do some research. Figure out what this MFA stuff is, this fishing resistant MFA stuff actually is. Go find some useful accounts that absolutely wreck your month. Maybe that's the admin, some mailbox folks that would you know got company secrets in it, something along those lines i that everybody would regret if somebody got access to any of them that move money around? And make those tougher for the bad guys. Make those fishing resistance. Pass keys, hardware keys, the real stuff. You don't have to do it everywhere. And you certainly don't have to do it all at once.
Just the ones where somebody became you is a catastrophe. You wanna avoid those. Because the goal was never to make the attacker prove they're you. It's to make it so that even when they trick your user, even when they're standing in the hallway with a copy machine. The door, the lock, still knows the difference. We have MFA was never the finish line.