# Dominating the Enterprise via Low Code Abuse > OWASP Global AppSec APAC 2022, 2022-08-31. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-08-31-owasp-global-appsec-apac-2022-dominating-the-enterprise-via-low-code-abuse/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-08-31_OWASP-APAC-2022_Dominating_the_Enterprise_via_Low_Code_Abuse/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-08-31_OWASP-APAC-2022_Dominating_the_Enterprise_via_Low_Code_Abuse/slides.pdf) - [Conference agenda](https://whova.com/web/S01MAxzRa49H60XWA6U3vkikTxPUTwLpY4t6Ro00Hx0%3D/Agenda/) - [Source code](https://github.com/mbrg/defcon30) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-08-31-owasp-global-appsec-apac-2022-dominating-the-enterprise-via-low-code-abuse.md) ## Abstract Why focus on heavily guarded crown jewels when you can dominate an organization through its shadow IT? Low-Code applications have become a reality in the enterprise, with surveys showing that most enterprise apps are now built outside of IT, with lacking security practices. Unsurprisingly, attackers have figured out ways to leverage these platforms for their gain. In this talk, we demonstrate a host of attack techniques found in the wild, where enterprise No-Code platforms are leveraged and abused for every step in the cyber killchain. You will learn how attackers perform an account takeover by making the user simply click a link, move laterally and escalate privileges with zero network traffic, leave behind an untraceable backdoor, and automate data exfiltration, to name a few capabilities. All capabilities will be demonstrated with POCs, and their source code will be shared. Finally, we will introduce an open-source recon tool that identifies opportunities for lateral movement and privilege escalation through low-code platforms. _[Official agenda abstract for this talk, sourced from DEFCON30](https://forum.defcon.org/node/242003)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-08-31_OWASP-APAC-2022_Dominating_the_Enterprise_via_Low_Code_Abuse/ebf974fd/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Michael Bargury (@mbrg0) Dominating the Enterprise via Low Code Abuse Zenity github.com/mbrg/talks — slide 1 of 69 ### Slide 2 About me CTO and co-founder @ Zenity Ex MSFT cloud security OWASP ‘Top 10 LCNC Security Risks’ project lead Dark Reading columnist @mbrg0 ft. @UZisReal123 bit.ly/ lcsec — slide 2 of 69 ### Slide 3 Disclaimer This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of Low Code. Low Code is awesome. — slide 3 of 69 ### Slide 4 Outline Low Code in a nutshell Low Code attacks observed in the wild Living off the land – account takeover, lateral movement, PrivEsc , data exfil Hiding in plain sight Leveraging predictable misconfigs from the outside How to defend The latest addition to your red team arsenal — slide 4 of 69 ### Slide 5 Dominating the Enterprise via Low Code Abuse 01 Low Code In A Nutshell — slide 5 of 69 ### Slide 6 Why Low Code? — slide 6 of 69 ### Slide 7 If this sounds familiar, its because it is Tech evolution — slide 7 of 69 ### Slide 8 Build everything If this than that automation Integrations Business apps Whole products Mobile apps — slide 8 of 69 ### Slide 9 Available in every major enterprise — slide 9 of 69 ### Slide 10 Recap Available on every major enterprise Has access to business data and powers business processes Runs as SaaS (difficult to monitor) Underrated by IT/Sec — slide 10 of 69 ### Slide 11 Dominating the Enterprise via Low Code Abuse 02 Low Code Attacks In The Wild: Living off the land — slide 11 of 69 ### Slide 12 youtu.be/5naPxs0fEJc — slide 12 of 69 - Youtube: [defcon30 Ohh sorry I'm on another call](https://www.youtube.com/watch?v=5naPxs0fEJc) ### Slide 13 Step by step — slide 13 of 69 ### Slide 14 https://docs.microsoft.com/en-us/connectors/connectors How does the app authenticate to slack? How do different users get authenticated by the same app? Behind the scenes — slide 14 of 69 ### Slide 15 https://docs.microsoft.com/en-us/connectors/connectors Storing and sharing refresh tokens Behind the scenes — slide 15 of 69 ### Slide 16 Ready, set, AUTOMATE! — slide 16 of 69 ### Slide 17 Power Automate connections inventory showing shared enterprise credentials for services including Azure, Office 365, SQL Server, SharePoint, Dropbox, and SFTP — slide 17 of 69 ### Slide 18 Credential Sharing as a Service — slide 18 of 69 ### Slide 19 Credential Sharing as a Service Privilege escalation — slide 19 of 69 ### Slide 20 Ransomware thru action connections Ransomware — slide 20 of 69 ### Slide 21 Exfiltrate email thru the platform’s email account Data exfiltration — slide 21 of 69 ### Slide 22 Move to machine Lateral movement — slide 22 of 69 ### Slide 23 Introducing ZapCreds github.com/mbrg/ zapcreds — slide 23 of 69 ### Slide 24 Can we fool users to create connections for us? Set up a bait app that does something useful Generate connections on-the-fly Fool users to use it Pwn their connection (i.e. account) Account takeover — slide 24 of 69 ### Slide 25 youtu.be/vJZpNJRC_10 — slide 25 of 69 - Youtube: [defcon30 Power Platform credential harvesting](https://www.youtube.com/watch?v=vJZpNJRC_10) ### Slide 26 Can we get rid of this pesky approve window? — slide 26 of 69 ### Slide 27 Can we get rid of this pesky approve window? https://docs.microsoft.com/en-us/powershell/module/microsoft.powerapps.administration.powershell/set-adminpowerappapistobypassconsent — slide 27 of 69 ### Slide 28 Dominating the Enterprise via Low Code Abuse 03 Low Code Attacks In The Wild: Can I stay here forever? — slide 28 of 69 ### Slide 29 This has been done before zenity.io/blog/hackers-abuse-low-code-platforms-and-turn-them-against-their-owners/ — slide 29 of 69 ### Slide 30 Dump files and tweet about it on a schedule — slide 30 of 69 ### Slide 31 Encrypt on command — slide 31 of 69 ### Slide 32 Persistency What do we want? Remote execution Arbitrary payloads Maintain access (even if user account access get revokes) Avoid detection Avoid attribution No logs — slide 32 of 69 ### Slide 33 Persistency v1 Persistency — slide 33 of 69 ### Slide 34 Persistency v1 What do we want? — slide 34 of 69 ### Slide 35 What do we want? Remote execution Arbitrary payloads Persistency v1 — slide 35 of 69 ### Slide 36 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access — slide 36 of 69 ### Slide 37 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Somebody else’s cloud — slide 37 of 69 ### Slide 38 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution Somebody else’s cloud Call endpoint anonymously to execute — slide 38 of 69 ### Slide 39 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs Somebody else’s cloud Call endpoint anonymously to execute — slide 39 of 69 ### Slide 40 Persistency v2 — slide 40 of 69 ### Slide 41 Persistency v2 What do we want? Arbitrary payloads No logs — slide 41 of 69 ### Slide 42 Solving persistency Our current state: Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs — slide 42 of 69 ### Slide 43 Executing arbitrary commands https://docs.microsoft.com/en-us/connectors/flowmanagement/ — slide 43 of 69 ### Slide 44 Introducing Powerful! github.com/mbrg/powerful — slide 44 of 69 ### Slide 45 Power Automate Flow Factory workflow that receives an HTTP request and creates a new flow from attacker-controlled command parameters — slide 45 of 69 ### Slide 46 Create a flow List authenticated sessions to use Delete a flow — slide 46 of 69 ### Slide 47 Expanded Power Automate Flow Factory workflow with branches for creating and deleting flows and listing connections — slide 47 of 69 ### Slide 48 github.com/mbrg/powerful — slide 48 of 69 ### Slide 49 Powerful (persistency v3) What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs Set up your flow factory Control it though API and a Python CLI github.com/mbrg/powerful — slide 49 of 69 ### Slide 50 Dominating the Enterprise via Low Code Abuse 04 Low Code Attacks In The Wild: From the outside looking in — slide 50 of 69 ### Slide 51 The Internet (managed Azure SQL instance) Power Portals/Pages? — slide 51 of 69 ### Slide 52 Browser showing a publicly reachable Microsoft Power Pages portal with a sample company home page — slide 52 of 69 ### Slide 53 What’s ODATA and why should we care “An open protocol to allow the creation and consumption of queryable and interoperable RESTful APIs in a simple and standard way.” Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: portal.powerappsportals.com/_ odata — slide 53 of 69 ### Slide 54 What’s ODATA and why should we care “An open protocol to allow the creation and consumption of queryable and interoperable RESTful APIs in a simple and standard way.” Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: portal.powerappsportals.com/_ odata zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ — slide 54 of 69 ### Slide 55 The fun begins Goal: find misconfigured portals that expose sensitive data w/o auth. Real world example: — slide 55 of 69 ### Slide 56 Nothing to see here /_ odata / globalvariables : — slide 56 of 69 ### Slide 57 Can we scale it? Recall the portal url: — slide 57 of 69 ### Slide 58 Let’s use Bing! zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ Can we scale it? Recall the portal url: — slide 58 of 69 ### Slide 59 ODATA leak - what we found Vulnerability disclosures are in progress Found PII – emails, names, calendar events Secrets – API keys, authentication tokens Business data – sales accounts, business contacts, vendor lists zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ — slide 59 of 69 ### Slide 60 Can we find more exposed data? — slide 60 of 69 ### Slide 61 Can we find more exposed data? Secrets are secured by a random GUID — slide 61 of 69 ### Slide 62 Storage by Zapier API — slide 62 of 69 ### Slide 63 Storage by Zapier API ‘12345’ is not a GUID… — slide 63 of 69 ### Slide 64 Let’s see what happens.. — slide 64 of 69 ### Slide 65 Let’s see what happens.. profit! Auth tokens, API keys, emails, phone no., crypto wallet IDs.. 400$ bounty zenity.io/blog/zapier-storage-exposes-sensitive-customer-data-due-to-poor-user-choices/ — slide 65 of 69 ### Slide 66 Summary Low Code is Huge in the enterprise Underrated by security teams Attackers are taking advantage of it by Living off the land – account takeover, lateral movement, PrivEsc , data exfil Hiding in plain sight Leveraging predictable misconfigs from the outside The latest addition to your red team arsenal ZapCreds – identify overshared creds Powerful – install a low code backdoor How to defend your org — slide 66 of 69 ### Slide 67 Dominating the Enterprise via Low Code Abuse 05 How To Stay Safe — slide 67 of 69 ### Slide 68 Do these 4 things to reduce your risk Review configuration Bypass consent flag (Microsoft) Limit connector usage Review and monitor access for external-facing endpoints Webhooks ODATA (Microsoft) Storage (Zapier) Review connections shared across the entire organization Learn more at OWASP , Dark Reading , Zenity blog — slide 68 of 69 ### Slide 69 Michael Bargury (@mbrg0) Dominating the Enterprise via Low Code Abuse Zenity github.com/mbrg/talks — slide 69 of 69