# Credential Sharing as a Service: the Dark Side of No Code > OWASP Global AppSec Dublin 2023, 2023-02-15. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-02-15-owasp-global-appsec-dublin-2023-credential-sharing-as-a-service-the-dark-side-of-no-code/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-02-15_OWASP-Dublin-2023_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-02-15_OWASP-Dublin-2023_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/slides.pdf) - [Recording](https://www.youtube.com/watch?v=AD0R4qyrh3g) - [Conference agenda](https://owasp2023globalappsecdublin.sched.com/event/1FWLC/credential-sharing-as-a-service-the-dark-side-of-no-code) - [ZapCreds](https://github.com/mbrg/zapcreds) - [Powerful](https://github.com/mbrg/powerful) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-02-15-owasp-global-appsec-dublin-2023-credential-sharing-as-a-service-the-dark-side-of-no-code.md) ## Abstract Why focus on heavily guarded crown jewels when you can dominate an organization through its shadow IT? Low-Code applications have become a reality in the enterprise, with surveys showing that most enterprise apps are now built outside of IT, with lacking security practices. Unsurprisingly, attackers have figured out ways to leverage these platforms for their gain. In this talk, we demonstrate a host of attack techniques found in the wild, where enterprise No-Code platforms are leveraged and abused for every step in the cyber killchain. You will learn how attackers perform an account takeover by making the user simply click a link, move laterally and escalate privileges with zero network traffic, leave behind an untraceable backdoor, and automate data exfiltration, to name a few capabilities. All capabilities will be demonstrated with POCs, and their source code will be shared. Next, we will drop two isolation-breaking vulnerabilities that allow for privilege escalation and cross-tenant access. We will explain how these vulnerabilities were discovered and assess their pre-discovery impact. Finally, we will introduce an open-source recon tool that identifies opportunities for lateral movement and privilege escalation through low-code platforms. _[Official conference abstract](https://owasp2023globalappsecdublin.sched.com/event/1FWLC/credential-sharing-as-a-service-the-dark-side-of-no-code)_ ## Transcript > AI generated from recording. ### Introduction to Low‑Code & No‑Code [00:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=4s) **Presenter:** So thank you very much for that very generous introduction. Hi everyone. Thank you for spending time with me here today. This is going to be somewhat different, I guess, from most of the talks that you've heard so far. The approach is the same, but the subject matter is kind of out there. [00:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=30s) **Presenter:** The one thing that I will promise is that it's going to be interesting, [00:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=34s) **Presenter:** and I hope you learn about new things or get a new perspective. [00:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=41s) **Presenter:** This talk is focused on low-code, no-code applications. [00:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=45s) **Presenter:** Before I dive into what those are and what are we specifically going to see in this talk, [00:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=52s) **Presenter:** this was already covered, but I've been working on the intersection of low-code, no-code, [01:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=60s) **Presenter:** security for the last four years now. [01:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=63s) **Presenter:** And most of my work goes to an OS project that we have started about a year ago, [01:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=71s) **Presenter:** a top 10 for low-code, no-code. [01:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=72s) **Presenter:** We've been very fortunate to have other people join us from Microsoft and Palo Alto [01:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=78s) **Presenter:** and other companies. [01:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=80s) **Presenter:** If you're interested, we are right now looking for contributors. [01:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=83s) **Presenter:** There's a meetup in a couple of weeks. [01:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=86s) **Presenter:** So reach out to me or check out my Twitter. [01:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=90s) **Presenter:** There's an invite there. [01:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=92s) **Presenter:** Okay. [01:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=93s) **Presenter:** This talk is given, of course, from an attacker's perspective on low-code, no-code. [01:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=97s) **Presenter:** But it's important to note that we're all for low-code, no-code. [01:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=102s) **Presenter:** These kind of technologies, putting more power in the hands of business users, [01:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=106s) **Presenter:** is something that we've been trying to do as an industry for, I don't know, for just too long. [01:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=112s) **Presenter:** and this is actually happening. ### Why Low‑Code Matters in the Enterprise; The Dark Side: Attack Vectors & Real‑World Cases [01:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=116s) **Presenter:** So businesses are actually building their own apps. [01:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=118s) **Presenter:** You'll see that in a moment. [02:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=120s) **Presenter:** And so the idea behind this, of course, [02:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=122s) **Presenter:** is to help us as security professionals [02:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=125s) **Presenter:** and help the business do this in a secure way. [02:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=129s) **Presenter:** Here's what we're going to do today. [02:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=131s) **Presenter:** We're going to start with understanding [02:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=132s) **Presenter:** what low-code, no-code applications are. [02:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=135s) **Presenter:** And the idea behind it is just to make sure [02:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=138s) **Presenter:** we are all on the same page. [02:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=140s) **Presenter:** After that, we'll go into basically how low-code, no-code is being attacked [02:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=145s) **Presenter:** or how attackers are using low-code, no-code in the wild. [02:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=148s) **Presenter:** This is all based on real attacks that we've observed in large organizations, [02:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=154s) **Presenter:** mainly large U.S. enterprises. [02:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=157s) **Presenter:** We'll see a whole bunch of attacks living off the land, [02:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=161s) **Presenter:** other attacks, you'll see them in a moment. [02:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=163s) **Presenter:** We'll, of course, finish off with how to defend yourself [02:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=166s) **Presenter:** and what you can do to basically take this further as part of your red tier arsenal [02:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=172s) **Presenter:** and also as part of kind of internal evangelism you can do in your organization. [03:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=180s) **Presenter:** Let's start with low-code, no-code. [03:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=181s) **Presenter:** And before I go to what specifically low-code, no-code is, [03:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=184s) **Presenter:** the reason why it's important and maybe the most important slide in this talk is the following one. [03:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=190s) **Presenter:** This chart represents one organization, one Fortune 500 organization, and you can see the number of low-code, no-code apps developed in that organization within a few years. [03:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=204s) **Presenter:** This chart is really why this talk is important, why this subject is important, and why we as security professionals must be part of the low-code, no-code conversation. [03:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=213s) **Presenter:** These numbers are, of course, anonymous, so I won't tell you the company, but they are real. [03:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=219s) **Presenter:** not an anomaly. We see this again and again [03:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=221s) **Presenter:** with large organizations. So the [03:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=223s) **Presenter:** Fortune 500s would have close to [03:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=225s) **Presenter:** 100,000 applications and the [03:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=227s) **Presenter:** smaller organizations, like a few thousand [03:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=229s) **Presenter:** employees, would have tens of thousands of [03:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=231s) **Presenter:** these applications. Keep in mind, these [03:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=233s) **Presenter:** are small applications. You can call them [03:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=235s) **Presenter:** micro-apps or something like that. They can [03:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=237s) **Presenter:** be like an if-this-then-then rule [03:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=239s) **Presenter:** or a small widget application. [04:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=242s) **Presenter:** But they still have identity. [04:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=243s) **Presenter:** They still access data. [04:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=245s) **Presenter:** So they have the same kind of threats. [04:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=247s) **Presenter:** This, again, is why it's important. [04:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=249s) **Presenter:** And the other fact that most of you in this room are probably aware of, [04:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=254s) **Presenter:** this is, in most cases, not where most of the security professionals spend their time on. [04:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=262s) **Presenter:** This is not where we focus our time. [04:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=264s) **Presenter:** We focus on pro-code applications or applications built by developers. [04:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=269s) **Presenter:** But business users are creating many more applications. [04:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=273s) **Presenter:** And it's about time we get involved in that discussion. [04:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=277s) **Presenter:** Okay, low code, no code, this is basically why it exists. [04:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=281s) **Presenter:** So the reason why people are using it, of course, IT cannot cover all of the needs of the business. [04:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=290s) **Presenter:** And business users are really tired of waiting around and they want to solve their own problems. [04:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=296s) **Presenter:** This is actually not new. ### Credential Sharing as a Service – How It Works; Exploiting Default Environments & Lateral Movement [04:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=297s) **Presenter:** So we've had multiple instances of trying to do just that. [05:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=301s) **Presenter:** And by the way, we've also had success. [05:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=306s) **Presenter:** a great example of empowering [05:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=308s) **Presenter:** business users, right? This is [05:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=309s) **Presenter:** probably the one tool I've been using [05:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=312s) **Presenter:** throughout my career, no matter [05:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=314s) **Presenter:** what I've been learning besides [05:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=316s) **Presenter:** that. But you can [05:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=318s) **Presenter:** see a technology [05:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=320s) **Presenter:** that was used in order to [05:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=322s) **Presenter:** empower business users [05:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=324s) **Presenter:** across this [05:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=325s) **Presenter:** vertical, you'll find that some [05:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=328s) **Presenter:** of these technologies are also our close friends [05:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=330s) **Presenter:** as security professionals, for example [05:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=332s) **Presenter:** macros. We are still having [05:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=336s) **Presenter:** Today, low-code, no-code is kind of the latest iteration on this trend of empowering business users, [05:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=343s) **Presenter:** of decentralizing IT, putting more power in the hands of the people that can actually move the business forward. [05:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=350s) **Presenter:** Low-code, no-code applications, and by the way, I'll be using low-code and no-code interchangeably here, [05:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=356s) **Presenter:** and we can go into the Q&A on how those differ or if they differ. [06:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=364s) **Presenter:** these are a few examples of what low-code and no-code applications are actually doing [06:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=369s) **Presenter:** so there are automations [06:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=371s) **Presenter:** for example if I get an email with this thing in subject [06:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=375s) **Presenter:** then create a ticket in Jira [06:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=377s) **Presenter:** there are integrations [06:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=379s) **Presenter:** so integrations or automations [06:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=381s) **Presenter:** you'll find typically business applications team or automations teams [06:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=384s) **Presenter:** that are plugging in SaaS and on-prem and everything together [06:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=388s) **Presenter:** stitching things together [06:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=390s) **Presenter:** There are business applications, [06:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=391s) **Presenter:** mostly to facilitate business processes. [06:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=393s) **Presenter:** So for example, you want to get reimbursed [06:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=397s) **Presenter:** for expenses you make on this trip. [06:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=400s) **Presenter:** You'll have a mini-app that would allow you [06:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=402s) **Presenter:** to upload those receipts and get those returns. [06:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=406s) **Presenter:** There are entire products that are built [06:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=408s) **Presenter:** with low-code, no-code. [06:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=409s) **Presenter:** This is relatively new, but it is happening. [06:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=411s) **Presenter:** So people are creating startups [06:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=413s) **Presenter:** with low-code, no-code as their front-end. [06:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=415s) **Presenter:** Enterprises are building user-facing, [06:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=419s) **Presenter:** applications with low-code and no-code, which is really cool. [07:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=422s) **Presenter:** And of course, mobile apps as well. [07:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=424s) **Presenter:** There are really, you can really do anything with this. [07:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=429s) **Presenter:** And this technology is right at the stage right now where, A, it's been actually been [07:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=434s) **Presenter:** used by these enterprises for many years now. [07:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=437s) **Presenter:** So for three, not many years, but for two, three years now. [07:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=441s) **Presenter:** And some of these applications have become business critical, which is why we're having [07:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=445s) **Presenter:** this talk right now. [07:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=446s) **Presenter:** because, of course, it means that attackers are looking at them, ### Persistency & Automation in the Cloud; Defending Against Low‑Code Threats [07:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=452s) **Presenter:** and we should be doing that too. [07:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=457s) **Presenter:** I'm sure one of the questions that you have in your mind right now [07:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=460s) **Presenter:** is whether this applies to you, [07:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=462s) **Presenter:** so to you in your specific organization with the tools that you're using. [07:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=467s) **Presenter:** And one of the things I wanted to tell you today is that it probably does. [07:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=473s) **Presenter:** Even if you don't know it, it probably does. [07:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=476s) **Presenter:** The reason behind it is that low-code, no-code finds its way into an enterprise, into an organization in multiple ways. [08:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=483s) **Presenter:** Of course, there are some organizations that are going all in on low-code, no-code. [08:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=488s) **Presenter:** The CIO or somebody in digital transformation would say, this is what we're going to do. [08:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=493s) **Presenter:** And we're seeing this in multiple organizations. [08:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=495s) **Presenter:** But for the rest of us, if you're using any one of the services here on this slide or any other major SaaS vendor, [08:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=503s) **Presenter:** you have low-code, no-code already in your organizations. [08:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=506s) **Presenter:** Because these vendors are basically using low-code, no-code as a way to expand from something that is solving a specific need to an application development platform. [08:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=517s) **Presenter:** So consider Salesforce, for example. [08:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=519s) **Presenter:** Once upon a time, you could be thinking about Salesforce as a CRM. [08:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=523s) **Presenter:** Today, that's nonsense. [08:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=524s) **Presenter:** Salesforce is a cloud. [08:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=526s) **Presenter:** It's just a business cloud with different kinds of applications, but it's closer to AWS, Azure, and GCP than it is to a CRM. [08:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=536s) **Presenter:** And that's the main point here. [08:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=538s) **Presenter:** You see, if you're a Microsoft job, you have a large low-code, no-code platform already embedded. [09:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=544s) **Presenter:** People are, I promise you, people are using it. [09:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=546s) **Presenter:** And others as well. [09:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=548s) **Presenter:** And so this is really everyone's problem. [09:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=553s) **Presenter:** So a quick recap before we move forward. [09:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=556s) **Presenter:** This is, so low-code, no-code. [09:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=559s) **Presenter:** A is available on every major enterprise. [09:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=561s) **Presenter:** It has access to business data and business processes. [09:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=564s) **Presenter:** is, well, the reason behind that is that when you looked at the logos before in this slide, [09:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=571s) **Presenter:** these logos also have our data, right? [09:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=575s) **Presenter:** They also have the sensitive business data. [09:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=577s) **Presenter:** And so local and local applications are built on top of that sensitive data. [09:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=582s) **Presenter:** They run as SaaS, so this means that forget about VM monitoring or network monitoring [09:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=588s) **Presenter:** or any of those. [09:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=590s) **Presenter:** and to my point earlier, they are underrated by IT and security in most cases. [09:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=596s) **Presenter:** And this is kind of the premise of why we believe it's important for us to get involved right now. [10:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=606s) **Presenter:** So what I'm going to show you, so we've gone through the kind of low code in a nutshell. [10:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=613s) **Presenter:** We understand what we're talking about right now. [10:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=616s) **Presenter:** The next part, the meat of the talk, is going to be actually talking about specific attacks that we've seen in the wild. [10:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=623s) **Presenter:** If you're interested, I'm not going to tell you how to detect those attacks. [10:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=628s) **Presenter:** If you're interested in that, check out the OWASP project. [10:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=632s) **Presenter:** So OWASP, low-code, no-code, top 10. [10:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=635s) **Presenter:** Before we move to see specific attacks, what I would like to do is show you a concrete example of a low-code application or a no-code application. [10:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=646s) **Presenter:** And I'm going to create it just so you can see how easy it is [10:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=649s) **Presenter:** and so we all understand the same thing. [10:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=653s) **Presenter:** So hopefully this works. [10:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=657s) **Presenter:** Okay, there's this annoying thing in Slack [11:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=660s) **Presenter:** where when somebody mentions you on a public channel, [11:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=664s) **Presenter:** you get this pressure to respond quickly because people are seeing. [11:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=668s) **Presenter:** So I'm creating here a very small automation that does a simple thing. [11:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=672s) **Presenter:** it every time I get mentioned in Slack, it will change my status as if I'm on a call. ### Q&A & Takeaways — Part 1 [11:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=678s) **Presenter:** So the person will kind of know not to bother me. [11:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=681s) **Presenter:** And then a few minutes later, it's going to change my status back to be free. [11:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=685s) **Presenter:** So nobody would be suspicious. [11:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=687s) **Presenter:** And you can see that I'm doing this step by step. [11:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=690s) **Presenter:** This is, of course, a silly example. [11:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=692s) **Presenter:** But it shows you the power of what's actually happening here. [11:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=695s) **Presenter:** One thing to note is that in no way in this demonstration, [11:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=700s) **Presenter:** I'm not authenticated to Slack in any way. [11:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=703s) **Presenter:** We'll cover that in a moment. [11:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=705s) **Presenter:** But you can see that I'm dragging and dropping. [11:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=707s) **Presenter:** I'm choosing parameters, kind of like, for example, the status code that I'm on a call. [11:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=715s) **Presenter:** This is something that is kind of really easy to do. [11:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=718s) **Presenter:** And the interesting thing behind it, think about, so you'll see in a moment, okay, I'm done. [12:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=725s) **Presenter:** When I'll be done, I'll click on that publish button, and that's it. [12:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=729s) **Presenter:** and operating. [12:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=732s) **Presenter:** A few things to note here. [12:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=734s) **Presenter:** One is that this is a pretty complex piece of software. [12:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=739s) **Presenter:** It authenticates to Slack. [12:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=741s) **Presenter:** It needs to somehow maintain that secret. [12:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=744s) **Presenter:** Maybe it needs to roll it. [12:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=745s) **Presenter:** It needs to subscribe to Webhook on the Slack side. [12:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=748s) **Presenter:** It needs to support APIs and their changes. [12:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=751s) **Presenter:** There's a delay step because you need to wait five minutes [12:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=754s) **Presenter:** before I change between status changes. [12:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=759s) **Presenter:** So it needs to be kind of running somewhere. [12:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=762s) **Presenter:** This is a significant piece of software. [12:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=765s) **Presenter:** And you'll see in 30 seconds it will already be ready. [12:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=770s) **Presenter:** And I didn't do anything sophisticated there as a user. [12:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=773s) **Presenter:** This is specifically an example from Zapier, [12:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=776s) **Presenter:** which is a tool that is focused on actual end users. [12:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=779s) **Presenter:** And people are using this. [13:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=781s) **Presenter:** People are using this a lot. [13:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=782s) **Presenter:** And this is also why you get so many applications, [13:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=786s) **Presenter:** just because it's very easy to create them. [13:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=789s) **Presenter:** I was alluding to the authentication part here. [13:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=794s) **Presenter:** One thing that you should be asking yourself is how is this thing running? [13:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=798s) **Presenter:** What is the identity behind this application? [13:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=801s) **Presenter:** When it connects to the Slack API, either through the webhook or through the API later, [13:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=807s) **Presenter:** who's actually making those calls? [13:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=809s) **Presenter:** And so here's the answer. [13:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=815s) **Presenter:** when you create this application [13:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=817s) **Presenter:** the first thing that you need to do is to pick [13:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=820s) **Presenter:** an application you want, so inside of Zapier [13:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=822s) **Presenter:** you need to pick the application you want to work with, for example here is Slack [13:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=825s) **Presenter:** but in all of those platforms there are hundreds of connectors [13:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=829s) **Presenter:** that connect wherever you'd like, it could be SAS, [13:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=832s) **Presenter:** on-prem, through gateways, wherever you'd like really [13:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=835s) **Presenter:** and then the first thing you're going to do after you click on one of them [13:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=839s) **Presenter:** is you're going to connect. [14:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=840s) **Presenter:** And this will be a familiar OAuth experience. [14:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=842s) **Presenter:** So you get the OAuth pop-up. [14:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=844s) **Presenter:** You see a bunch of things that Zapier wants to do with your Slack account. [14:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=848s) **Presenter:** You say allow. [14:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=849s) **Presenter:** And something magical happens. [14:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=852s) **Presenter:** They create an object called a connection. [14:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=855s) **Presenter:** This connection is essentially a wrapper around the OAuth refresh tokens. [14:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=861s) **Presenter:** What they also give you for that connection is a nice little share button. [14:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=865s) **Presenter:** What does this share mean? [14:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=869s) **Presenter:** your wrapped up refresh token with another user. [14:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=873s) **Presenter:** And that's how these platforms operate. [14:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=876s) **Presenter:** This also means that from the Slack perspective, [14:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=880s) **Presenter:** from the network perspective, [14:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=881s) **Presenter:** from all of the existing tools that you have, [14:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=884s) **Presenter:** from all of those perspectives, [14:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=885s) **Presenter:** there's no app. [14:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=887s) **Presenter:** There's no share. [14:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=888s) **Presenter:** This is one user reusing their token again and again [14:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=891s) **Presenter:** from multiple locations. [14:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=893s) **Presenter:** This is a fundamental flaw in the way [14:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=896s) **Presenter:** that this technology works. [14:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=899s) **Presenter:** across platforms. And by the way, the reason behind it is that this is not only [15:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=903s) **Presenter:** a flaw, it's also one of the reasons why this works. [15:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=907s) **Presenter:** Imagine if you wanted to have this graph of so many applications [15:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=911s) **Presenter:** built in the enterprise, but you had to ask for [15:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=915s) **Presenter:** permission for each one of these applications to create an identity for that application. [15:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=919s) **Presenter:** That would never happen. You'll never see that exponential graph. The reason [15:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=923s) **Presenter:** why you have that exponential graph is because you can embed your own identity in those applications. [15:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=929s) **Presenter:** part and the bad part about it. [15:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=930s) **Presenter:** But it also shows you [15:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=932s) **Presenter:** why I was able to create this application [15:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=934s) **Presenter:** before in the demo. I just [15:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=936s) **Presenter:** created this connection beforehand [15:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=938s) **Presenter:** or I could have just picked up that connection [15:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=941s) **Presenter:** that another user created [15:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=942s) **Presenter:** and just reused it. [15:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=944s) **Presenter:** Okay. [15:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=946s) **Presenter:** This is actually... [15:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=948s) **Presenter:** I've kind of explained this, but just to make sure [15:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=951s) **Presenter:** we all understand, when [15:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=952s) **Presenter:** we have the application on the [15:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=955s) **Presenter:** left side and the API on the right [15:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=956s) **Presenter:** side, and essentially [15:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=959s) **Presenter:** and this is actually a picture from Microsoft documentation, [16:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=964s) **Presenter:** there's basically a proxy that sits between those two, [16:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=968s) **Presenter:** and it dynamically changes the token [16:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=971s) **Presenter:** when the request goes to the underlying service. [16:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=975s) **Presenter:** And so they are able to inject the token, the refresh token, [16:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=978s) **Presenter:** so the user never sees the actual token. [16:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=981s) **Presenter:** They don't understand that they're sharing a token. [16:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=982s) **Presenter:** They're sharing something called connection. [16:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=984s) **Presenter:** It looks nice. [16:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=985s) **Presenter:** There's a nice little button then to share. [16:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=989s) **Presenter:** So this is how it works. [16:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=990s) **Presenter:** And when you look at these platforms, [16:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=995s) **Presenter:** because it's so easy to create applications, [16:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=997s) **Presenter:** you get a lot of applications. [16:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=999s) **Presenter:** These are specific examples from marketplaces of different vendors. [16:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1004s) **Presenter:** So these are all things that people are just picking up and using. [16:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1008s) **Presenter:** And you can see the most important thing about this slide [16:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1011s) **Presenter:** is actually the logos, [16:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1012s) **Presenter:** because they indicate where the data comes from, [16:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1015s) **Presenter:** what data these applications are touching. [16:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1019s) **Presenter:** Behind any one of those logos, there's business data or there are business operations. [17:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1024s) **Presenter:** And so behind the tens of thousands of applications that you saw earlier in the chart, [17:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1032s) **Presenter:** there are at least 10x more connections. [17:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1037s) **Presenter:** Connections are refresh tokens that are just there on the platforms. [17:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1040s) **Presenter:** And so when you go to these platforms and you kind of look for those connections, [17:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1046s) **Presenter:** you'll find hundreds of those connections. [17:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1049s) **Presenter:** of the things that is common about these platforms is that they have some notion of a default [17:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1054s) **Presenter:** environment, a way for you to share those connections, not only with one user, but with [17:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1060s) **Presenter:** everyone, with everyone in the organization. [17:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1062s) **Presenter:** And again, there's a reason behind it, because you want to empower people, you want to let [17:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1066s) **Presenter:** them work fast. [17:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1067s) **Presenter:** And so if you go to the default environment in your Office 365 instance, in Zapier, in [17:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1073s) **Presenter:** Workato, and in others, you'll find all of those connections ready for you to use. [17:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1076s) **Presenter:** And so, of course, this is just credential sharing as a service. [18:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1080s) **Presenter:** This is just built-in credential service being facilitated by those platforms. [18:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1086s) **Presenter:** And for us to identify that, there's no real way to do it through network mechanisms [18:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1091s) **Presenter:** or through monitoring the authentication itself. [18:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1095s) **Presenter:** It's only through those platforms. ### Q&A & Takeaways — Part 2 [18:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1099s) **Presenter:** So this is one thing that is very common. [18:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1101s) **Presenter:** So we see attackers using these default environments to just gain all of those credentials. [18:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1107s) **Presenter:** After you just get access to those credentials, the next piece is, okay, what do you do with them? [18:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1112s) **Presenter:** Well, so you can do easy things like ransomware, for example, with a drag and drop. [18:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1117s) **Presenter:** This is very easy. [18:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1119s) **Presenter:** So I go to a specific SharePoint site. [18:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1122s) **Presenter:** I list everything in that SharePoint site. [18:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1124s) **Presenter:** And I encrypt it with a useful encryption function that is provided by the platform. [18:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1129s) **Presenter:** Okay. [18:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1131s) **Presenter:** This is not a one-time thing. [18:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1133s) **Presenter:** I can do this. [18:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1134s) **Presenter:** This continues to run. [18:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1137s) **Presenter:** So this is one kind of nice example. [19:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1140s) **Presenter:** The other example where we, and this one, I think there was, [19:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1144s) **Presenter:** in any organization that we've worked with, this one reoccurred. [19:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1148s) **Presenter:** This is a great way to expel data outside of organizations, right? [19:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1153s) **Presenter:** Because you have, for example, to make sure people are not forwarding business email [19:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1158s) **Presenter:** to their personal Gmail, you have a bunch of things that are preventing that, right? [19:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1163s) **Presenter:** You have things on the client side and on the email server and DLP and many things. [19:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1168s) **Presenter:** So people have found out a new way to bypass DLP. [19:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1171s) **Presenter:** They simply copy the content of the email from one email to another. [19:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1175s) **Presenter:** So the automation is subscribed to every new corporate email. [19:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1180s) **Presenter:** And then when it arrives, they create a draft on their own personal Gmail account with that email. [19:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1185s) **Presenter:** And so there's no real way to know that, again, from the email server, [19:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1191s) **Presenter:** because the content here is being copied. [19:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1193s) **Presenter:** And of course, this is one example with emails, [19:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1195s) **Presenter:** but this happens with files and drives and everything else. [20:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1201s) **Presenter:** So that's, again, that's a very, very, very common example. [20:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1205s) **Presenter:** Let me go into another one, which is a bit less trivial. [20:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1209s) **Presenter:** These platforms also allow you to jump to people's laptops. [20:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1212s) **Presenter:** and this is because low code, no code [20:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1215s) **Presenter:** also has a component called RPA. [20:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1218s) **Presenter:** In some cases, it's kind of a different thing [20:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1220s) **Presenter:** but still RPA is an automation that runs [20:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1223s) **Presenter:** either on servers or on people's laptops [20:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1225s) **Presenter:** like an exe file on the Windows machine. [20:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1229s) **Presenter:** So some of those connections actually allow you [20:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1232s) **Presenter:** to run a command, [20:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1234s) **Presenter:** so any command you'd like on somebody's laptop [20:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1238s) **Presenter:** and you can use it, again, pick it up [20:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1239s) **Presenter:** and use it from the default environment [20:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1242s) **Presenter:** laterally to the machine. [20:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1245s) **Presenter:** So this is actually one of the major things that we see again and again [20:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1251s) **Presenter:** happening with these overshort connections. [20:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1254s) **Presenter:** And one of the things that we did internally when we worked on this is to [20:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1259s) **Presenter:** make our lives easier and find these connections is just create some tooling [21:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1263s) **Presenter:** behind it. [21:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1264s) **Presenter:** So one thing that we have here is a tool called Zapcreds. [21:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1268s) **Presenter:** This is a very simple tool. [21:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1270s) **Presenter:** You can find it at this address. [21:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1272s) **Presenter:** you plug in a user for Zapier, [21:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1276s) **Presenter:** and it will give you all of the connections [21:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1277s) **Presenter:** that that user has access to, [21:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1279s) **Presenter:** and also show you which of those connections [21:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1282s) **Presenter:** belong to other users. [21:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1283s) **Presenter:** And we're actually expanding this [21:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1285s) **Presenter:** to support other platforms as well, [21:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1286s) **Presenter:** Workator, Power Platform, and many others. [21:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1290s) **Presenter:** So feel free to check this out. [21:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1295s) **Presenter:** One thing that happened now, [21:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1298s) **Presenter:** we saw only cases where the connections [21:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1300s) **Presenter:** were already available, [21:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1302s) **Presenter:** we want to entice users to create connections? What if we want to create basically a targeted [21:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1308s) **Presenter:** attack within an organization to get users to log in, to share those connections with us? [21:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1315s) **Presenter:** So what I'm going to show you is exactly that. Basically, these applications that are built on [22:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1322s) **Presenter:** top of low-code, no-code, one of the key things behind them is that they operate on the vendor's [22:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1328s) **Presenter:** cloud. And so for example, you can use [22:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1330s) **Presenter:** Office 365 local platform [22:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1332s) **Presenter:** which allows you to create applications [22:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1334s) **Presenter:** in a Microsoft domain. [22:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1336s) **Presenter:** So they'll be trusted by your [22:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1338s) **Presenter:** users. And the users will [22:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1340s) **Presenter:** automatically be authenticated [22:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1342s) **Presenter:** with their Microsoft accounts. [22:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1343s) **Presenter:** So here's a nice little app. [22:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1346s) **Presenter:** I'm going to [22:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1348s) **Presenter:** pick up an [22:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1350s) **Presenter:** application out of the [22:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1351s) **Presenter:** marketplace. [22:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1354s) **Presenter:** This is going to be an application [22:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1356s) **Presenter:** that basically facilitates [22:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1359s) **Presenter:** an out-of-office. [22:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1360s) **Presenter:** So it says your out-of-office message, [22:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1363s) **Presenter:** it declines invites and so on. [22:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1365s) **Presenter:** And so I'm just picking it up out of the marketplace [22:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1369s) **Presenter:** and I'm going to apply one simple change [22:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1372s) **Presenter:** where that application, of course, [22:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1375s) **Presenter:** has access to user emails, right? [22:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1377s) **Presenter:** So I'm going to apply one simple change [22:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1379s) **Presenter:** which is using that email to pawn the account. [23:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1381s) **Presenter:** To basically, in this example, [23:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1383s) **Presenter:** just share an email, [23:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1386s) **Presenter:** use the user's email on their behalf without them knowing. [23:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1390s) **Presenter:** Again, this is just a simple application I took off the marketplace. [23:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1395s) **Presenter:** And what I'm doing here, every application could do that. [23:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1398s) **Presenter:** When an application has access to a user's credentials, [23:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1401s) **Presenter:** it can use it for whatever it wants without the user knowing. [23:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1406s) **Presenter:** And you can see here exactly what I'm doing to add that kind of malicious line. [23:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1411s) **Presenter:** It's one line of code. [23:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1413s) **Presenter:** The crucial piece here is that this is very simple to do. [23:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1417s) **Presenter:** This is running on a Microsoft domain, [23:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1423s) **Presenter:** and this is something that users would automatically trust. [23:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1427s) **Presenter:** Now, okay, it takes me some time to type. [23:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1430s) **Presenter:** So after I create that application, I embed my malicious line in it. [23:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1436s) **Presenter:** I save it. [23:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1437s) **Presenter:** That's it. [23:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1437s) **Presenter:** It's deployed. [23:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1438s) **Presenter:** So there's no, like, CICD, pull request, somebody looking at this. [24:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1443s) **Presenter:** Nothing like that. [24:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1444s) **Presenter:** I share it, and you can see that I'm sharing it with everybody in the organization, [24:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1449s) **Presenter:** which is a nice little feature to have. [24:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1452s) **Presenter:** And then I get this URL that I'm going to plug in here with another user. [24:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1458s) **Presenter:** When I use that user to log into the app, [24:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1460s) **Presenter:** the first thing that I get is asked for credentials. [24:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1463s) **Presenter:** We'll go into that in a moment. [24:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1465s) **Presenter:** And that's it. [24:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1466s) **Presenter:** I'm inside of the application. [24:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1468s) **Presenter:** and, of course, the application has sent an email on my behalf, as I've just shown. [24:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1474s) **Presenter:** So this might have been a bit confusing, [24:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1477s) **Presenter:** so let me take you step by step on what happened here again. [24:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1480s) **Presenter:** I picked up a random application from Microsoft's Marketplace. [24:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1484s) **Presenter:** That application required access to email. [24:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1487s) **Presenter:** So I used that email, other than just to do what the application is doing, [24:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1492s) **Presenter:** to send an email on the user's behalf without them knowing. [24:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1495s) **Presenter:** Now, when I created, I saved that application, [24:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1498s) **Presenter:** which means it's deployed, [25:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1500s) **Presenter:** which means I get a URL on a Microsoft domain [25:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1503s) **Presenter:** that every user in my organization can use. [25:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1507s) **Presenter:** And now when I use it with another user, [25:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1510s) **Presenter:** the application created, sent out that email on the user's behalf. ### Q&A & Takeaways — Part 3 [25:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1516s) **Presenter:** So again, this is not special to local and local applications, right? [25:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1520s) **Presenter:** Every application could use a user's credential to do whatever it wants. [25:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1524s) **Presenter:** There is a difference, and the difference is in the way that these applications get access. [25:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1529s) **Presenter:** This window that we saw when the user entered the application is not the typical OAuth window you're used to seeing, right? [25:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1538s) **Presenter:** This is not telling you what permissions the application needs and asking you to make sure that you're giving it the right permissions. [25:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1545s) **Presenter:** No, it's just telling you, hey, I need a connection to Office 365 and to Office 365 users. [25:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1550s) **Presenter:** These connections are, again, those refresh tokens that we've discussed earlier. [25:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1554s) **Presenter:** And so this is an unbounded permission. [25:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1559s) **Presenter:** This has all of the permissions that Power Platform could ever want. [26:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1563s) **Presenter:** And so when I created that connection, so if you examine the token, [26:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1569s) **Presenter:** you'll see that it has basically all of the available permission set. [26:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1573s) **Presenter:** And so once I click allow here, the application gets my refresh token, [26:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1578s) **Presenter:** and it is able to do whatever it wants with my office credentials. [26:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1584s) **Presenter:** Now, the title here is interesting because what I've basically done here is created a way for us to bait users, [26:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1595s) **Presenter:** to give us their credentials inside of an organization. [26:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1598s) **Presenter:** And the only thing that protects them from falling in my trap is clicking that allow button. [26:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1605s) **Presenter:** So they go into a URL, which I provide, which is in a Microsoft domain, and then they click the allow button and that's it. [26:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1614s) **Presenter:** button, that would be terrible, right? [26:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1617s) **Presenter:** Well, that's also available as part of the platform. [27:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1622s) **Presenter:** So this is actually a flag that admins can just turn on, which [27:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1627s) **Presenter:** removes this window, removes friction from adoption of those [27:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1631s) **Presenter:** applications, but also makes it so that the only thing I need to [27:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1635s) **Presenter:** do in order to own a user's account is just to get them to [27:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1638s) **Presenter:** click on an email, on the URL that is in a Microsoft domain. [27:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1643s) **Presenter:** okay so we saw [27:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1646s) **Presenter:** living of the land attacks for lateral movement [27:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1649s) **Presenter:** for privilege escalation for ransomware [27:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1653s) **Presenter:** and for account takeover the next part [27:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1657s) **Presenter:** and by the way these are just specific [27:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1661s) **Presenter:** examples but there are many more you understand the gist here [27:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1663s) **Presenter:** people are just using this to pick off credentials and [27:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1666s) **Presenter:** be able to move across the organizations very easily [27:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1671s) **Presenter:** is how do you stay once you've owned a local, no-call platform, [27:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1677s) **Presenter:** how do you stay there as an attacker? [27:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1679s) **Presenter:** And in this section, what I'm actually going to do [28:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1682s) **Presenter:** is just show you what hackers have already been doing. [28:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1687s) **Presenter:** This is a real example from an APT group about two years ago. [28:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1693s) **Presenter:** This slide is from Microsoft Detection and Response Team. [28:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1696s) **Presenter:** The APT group owned a large multinational organization. [28:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1701s) **Presenter:** They knew that they have been hacked and they had teams looking for the hackers in the org for more than six months before they were able to kick them out. [28:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1713s) **Presenter:** And the reason why it took so long is that instead of installing malware, moving through the network, doing the things that hackers usually do, [28:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1722s) **Presenter:** they created an automation, a low-code automation that was used as their persistency mechanism. [28:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1731s) **Presenter:** they created one single automation that ran on a schedule. [28:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1736s) **Presenter:** Each time it ran, it used the e-discovery tools to search for passwords and PII across the office infrastructure [29:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1744s) **Presenter:** and then send it off to an exfiltration endpoint. [29:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1747s) **Presenter:** And because this runs on the office cloud in an area that nobody monitors, that nobody looks at, [29:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1753s) **Presenter:** this was running for six months. [29:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1756s) **Presenter:** And so you can find all of the sources in this link of why this happened [29:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1762s) **Presenter:** There are bits and pieces of information out there. [29:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1767s) **Presenter:** So let's start with just doing what the attackers have done. [29:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1770s) **Presenter:** This is a very simple automation. [29:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1772s) **Presenter:** On a recurrent schedule, I'm going to list a SharePoint directory, [29:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1777s) **Presenter:** and then I'm going to encrypt any one of those files, [29:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1783s) **Presenter:** to dump the encrypted files somewhere, [29:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1786s) **Presenter:** and tweet about it because nobody will find me anyway. [29:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1791s) **Presenter:** attackers have done, but this is actually [29:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1794s) **Presenter:** kind of [29:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1795s) **Presenter:** this runs on a schedule, so this is [29:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1797s) **Presenter:** limited. I want more than that. [29:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1799s) **Presenter:** So here's one [30:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1801s) **Presenter:** step better. This [30:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1803s) **Presenter:** is the same kind of automation, but [30:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1805s) **Presenter:** instead of running on a schedule, it runs [30:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1807s) **Presenter:** off a call to a webhook. [30:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1809s) **Presenter:** So now from the outside in, I can [30:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1811s) **Presenter:** just call that webhook, and every time I do [30:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1813s) **Presenter:** that, I'll exfiltrate the entire SharePoint [30:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1815s) **Presenter:** site, which is nice. [30:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1818s) **Presenter:** But if we're talking about [30:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1819s) **Presenter:** persistency, we actually need much more. So here's a laundry list [30:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1823s) **Presenter:** of the things we might want when talking about persistency. [30:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1827s) **Presenter:** We want to be able to execute things remotely. We want to be [30:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1831s) **Presenter:** able to run arbitrary payloads, which is not something we've seen so far. [30:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1835s) **Presenter:** We want to be able to maintain access even if the user itself [30:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1839s) **Presenter:** is no longer accessible. Of course, we want to avoid detection [30:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1843s) **Presenter:** and avoid attribution in case we get detected, and we want to produce no logs. [30:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1847s) **Presenter:** So let's see how we can accomplish all of this with a non-code app. [30:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1852s) **Presenter:** So this is actually what we've already seen. [30:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1854s) **Presenter:** This HTTP hook is the persistency because we can just continue to call it, [30:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1859s) **Presenter:** even if we don't have the access as a user. [31:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1862s) **Presenter:** These HTTP endpoints in all of the platforms that we've examined [31:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1866s) **Presenter:** are hardcoding some sort of secret in the URL, [31:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1869s) **Presenter:** and so you don't have to be authenticated in order to call them. [31:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1874s) **Presenter:** so here's an examination [31:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1876s) **Presenter:** of what we wanted to achieve [31:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1879s) **Presenter:** there's a remote execution here, that's fine [31:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1881s) **Presenter:** of course this is not an arbitrary payload, this is specific payload [31:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1884s) **Presenter:** of dumping an entire SharePoint site [31:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1887s) **Presenter:** being able to maintain access, I've already discussed this [31:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1890s) **Presenter:** avoiding detection [31:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1891s) **Presenter:** I mean, this is pretty [31:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1894s) **Presenter:** I mean, in order to understand who is calling this endpoint [31:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1898s) **Presenter:** you need to be able to monitor those logs [31:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1902s) **Presenter:** those logs do not exist. [31:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1903s) **Presenter:** And more than that, you cannot attribute it [31:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1907s) **Presenter:** because those endpoints can be called from wherever. [31:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1909s) **Presenter:** In this demo specifically, I'm calling them using Tor. [31:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1914s) **Presenter:** Okay. [31:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1915s) **Presenter:** So logs, the last thing that I wanted to do, [31:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1919s) **Presenter:** I didn't really cover it up until now. [32:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1923s) **Presenter:** So these automations are generating a ton of logs. [32:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1927s) **Presenter:** By logs, I mean every time you plug in data [32:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1932s) **Presenter:** the data gets stored as part of the log. ### Q&A & Takeaways — Part 4 [32:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1934s) **Presenter:** So this is very, very, very noisy, [32:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1936s) **Presenter:** and this is something we're going to need to take care of. [32:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1939s) **Presenter:** So here's another attempt. [32:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1941s) **Presenter:** Instead of hardcoding one payload, [32:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1944s) **Presenter:** I'm going to hardcode a few of them. [32:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1946s) **Presenter:** So here are a few useful functions. [32:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1948s) **Presenter:** Licking an entire SharePoint site, [32:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1951s) **Presenter:** storing attachments from Outlook.com, [32:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1954s) **Presenter:** executing a SQL query, [32:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1957s) **Presenter:** creating ransomware, [32:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1959s) **Presenter:** basically encrypting an entire SharePoint site, [32:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1962s) **Presenter:** So these are all specific payloads, and all of them can be called from a single HTTP endpoint, which is nice. [32:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1970s) **Presenter:** And so for examining our list, actually, we haven't covered both of the things that we wanted to cover, [32:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1979s) **Presenter:** both arbitrary payloads. [33:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1981s) **Presenter:** This is more than one, but it's still not arbitrary, and there are still logs. [33:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1984s) **Presenter:** So let's see how we can cover both of these. [33:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1988s) **Presenter:** and we're going to cover these with one little feature, which is awesome. [33:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=1996s) **Presenter:** And that is the fact that in all of the low-code, low-code platforms, [33:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2000s) **Presenter:** one of their key features is that you can automate the platform itself [33:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2003s) **Presenter:** with low-code, low-code applications. [33:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2005s) **Presenter:** And so you have something called, for Microsoft, for example, [33:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2009s) **Presenter:** you have something called Power Automate Management, [33:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2011s) **Presenter:** which allows you to create, delete, change, [33:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2016s) **Presenter:** do whatever you want with the low-code, no-code applications [33:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2018s) **Presenter:** as a low-code, no-code application. [33:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2020s) **Presenter:** Okay, so you probably see where I'm going with this, [33:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2023s) **Presenter:** but I'll take you through it anyway. [33:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2026s) **Presenter:** So here's what we're going to see right now. [33:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2029s) **Presenter:** It's also available. [33:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2030s) **Presenter:** The source code is available in this address. [33:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2034s) **Presenter:** It's called Powerful, [33:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2035s) **Presenter:** which is kind of a pun over the Microsoft framework. [33:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2038s) **Presenter:** and this is going to solve all of our persistency problems. [34:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2043s) **Presenter:** And it's going to be pretty easy. [34:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2046s) **Presenter:** So I'm going to start off with an HTTP endpoint, [34:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2049s) **Presenter:** but instead of just using it as a trigger, [34:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2053s) **Presenter:** I'm going to accept a definition of an automation. [34:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2056s) **Presenter:** So just tell me what automation you want to build, [34:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2059s) **Presenter:** with which connection you want this automation to be built, [34:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2063s) **Presenter:** and then what this automation is going to do [34:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2065s) **Presenter:** is create that other automation [34:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2067s) **Presenter:** that I've just given it, [34:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2069s) **Presenter:** run it, [34:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2070s) **Presenter:** and then delete it [34:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2071s) **Presenter:** all at the same time [34:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2072s) **Presenter:** or kind of [34:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2073s) **Presenter:** all in a very short period of time. [34:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2076s) **Presenter:** And so I create the automation, [34:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2078s) **Presenter:** I give it a definition, [34:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2079s) **Presenter:** I can choose the specific connections, [34:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2081s) **Presenter:** I can list which connections are available [34:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2084s) **Presenter:** so I can always be using fresh connections. [34:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2087s) **Presenter:** And then I delete the automation. [34:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2089s) **Presenter:** And the nice part about deleting the automation [34:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2091s) **Presenter:** is that this also deletes [34:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2093s) **Presenter:** all of the logs of the automation [34:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2095s) **Presenter:** part of the automation itself, which is also pretty nice. [35:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2100s) **Presenter:** This is the flow of what the tool is actually doing, [35:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2104s) **Presenter:** and this is how the kind of very sophisticated automation looks like. [35:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2108s) **Presenter:** Again, you can see this is all drag and drop, [35:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2111s) **Presenter:** but this is kind of the advanced part of the drag and drop. [35:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2114s) **Presenter:** And of course, because we are security professionals, [35:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2118s) **Presenter:** we don't want to drag and drop things, and we want to look cool. [35:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2122s) **Presenter:** Here's a CLI for you to do that with Python. [35:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2126s) **Presenter:** Okay. So this was kind of expanding beyond what hackers have actually done. [35:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2135s) **Presenter:** But recall that the basis here was something that we've observed in the world. [35:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2141s) **Presenter:** So the APT group has used this as a way to maintain their persistency inside of an organization. [35:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2147s) **Presenter:** And it took the organization six months to find them there. [35:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2151s) **Presenter:** So imagine what would happen with something like this. [35:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2156s) **Presenter:** Okay, so we've seen how to basically stay hidden within those local, no-code platforms. [36:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2162s) **Presenter:** The last thing I want to show you is how you can exploit local, no-code platforms from the outside looking in. [36:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2172s) **Presenter:** Because up until now, we've been discussing what users of those platforms can do. [36:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2178s) **Presenter:** So you need to first own some user, which is admittedly not that difficult in a large organization. [36:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2184s) **Presenter:** But still, these platforms also allow, [36:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2187s) **Presenter:** we are also seeing hackers that are targeting [36:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2190s) **Presenter:** basically public endpoints [36:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2192s) **Presenter:** that these platforms are putting out on your behalf. [36:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2196s) **Presenter:** So let's see a few examples. [36:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2198s) **Presenter:** Before I give you a few examples, [36:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2200s) **Presenter:** let's just think, let's just recall [36:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2202s) **Presenter:** that this is again not something [36:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2205s) **Presenter:** that is special to low-code, no-code. [36:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2207s) **Presenter:** If you think about S3 buckets, for example, in AWS, [36:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2211s) **Presenter:** This is like a misconfiguration that we know that happens again and again [36:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2215s) **Presenter:** where those S3 buckets are exposed to the public. [36:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2217s) **Presenter:** We've known about it for many years now. [37:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2220s) **Presenter:** AWS has finally put in place things that are preventing it as a default. [37:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2225s) **Presenter:** But it's still happening, right? [37:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2227s) **Presenter:** It's still happening because it's a predictable misconfiguration, [37:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2231s) **Presenter:** which is very easy to do. [37:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2233s) **Presenter:** So the same kind of thing is happening within those local and local platforms. [37:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2237s) **Presenter:** Let me give you a couple of examples. [37:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2240s) **Presenter:** I'm going to give is again about Microsoft. [37:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2244s) **Presenter:** Microsoft has one of the features [37:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2247s) **Presenter:** for their local platform on top of Office [37:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2250s) **Presenter:** is called Portal Apps. [37:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2252s) **Presenter:** Portal Apps is basically a public-facing application. [37:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2256s) **Presenter:** It's used mainly to basically do things [37:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2259s) **Presenter:** like onboard contractors or vendors [37:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2262s) **Presenter:** or people that are coming to your office. [37:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2264s) **Presenter:** For example, if you visit Microsoft offices physically [37:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2267s) **Presenter:** and you need to provide a vaccination proof, [37:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2270s) **Presenter:** You'll do that through a portal app. [37:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2272s) **Presenter:** And so those portal apps, they are basically web pages [37:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2275s) **Presenter:** with a managed SQL instance behind them. [37:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2278s) **Presenter:** And so when you create a portal app, [38:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2281s) **Presenter:** you get a dedicated web application. [38:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2283s) **Presenter:** You can see, note the domain name. [38:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2286s) **Presenter:** So something.powerappsportals.com. [38:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2289s) **Presenter:** This is going to be fun later. [38:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2291s) **Presenter:** And so these applications also have an API [38:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2297s) **Presenter:** that is created for extendability. [38:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2300s) **Presenter:** something called OData. [38:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2301s) **Presenter:** It's always in the same place, so the same path. [38:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2304s) **Presenter:** And why am I talking about these types of applications? [38:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2307s) **Presenter:** Well, because the team at AppGuard, actually a year and a half ago, [38:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2314s) **Presenter:** found that these applications, the default configurations for those applications, [38:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2319s) **Presenter:** meant that the API exposed all of the database behind the applications to anonymous users. [38:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2326s) **Presenter:** That was the default. [38:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2327s) **Presenter:** and nobody noticed that that was the default for about a year until they did. [38:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2333s) **Presenter:** And so once they did, they identified about 40 million data records that were exposed. [38:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2339s) **Presenter:** And so Microsoft was actually very quick to fix the default, [39:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2344s) **Presenter:** but people are still making mistakes because it's difficult not to make mistakes. ### Q&A & Takeaways — Part 5 [39:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2350s) **Presenter:** And so let's see what we can find out by just trying to find those applications [39:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2358s) **Presenter:** here's one concrete application [39:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2360s) **Presenter:** this is a real world example [39:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2361s) **Presenter:** you can see that by going to the [39:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2364s) **Presenter:** OData route [39:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2365s) **Presenter:** I get a list of all of the [39:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2369s) **Presenter:** objects that are available [39:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2370s) **Presenter:** for me to query, the default and the entities [39:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2372s) **Presenter:** form set objects [39:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2374s) **Presenter:** don't have anything interesting [39:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2375s) **Presenter:** but you're also seeing [39:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2378s) **Presenter:** the global variables [39:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2380s) **Presenter:** object which is interesting [39:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2382s) **Presenter:** and when you query the [39:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2384s) **Presenter:** global variables I'm sure you'll understand [39:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2388s) **Presenter:** authentication tokens to Azure, which is kind of nice and available for you out there. [39:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2393s) **Presenter:** This is a real example from a large financial services company. [39:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2397s) **Presenter:** Of course, we've disclosed this vulnerability to them and they've fixed it. [40:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2402s) **Presenter:** And so this is one example, but the question is, [40:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2406s) **Presenter:** can we find those problems repeatedly from the outside looking in [40:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2411s) **Presenter:** without knowing that this specific portal exists? [40:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2414s) **Presenter:** And here's the clue of how we do it. [40:17](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2417s) **Presenter:** very simple subdomain enumeration. [40:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2419s) **Presenter:** All of these apps are using the same domain. [40:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2424s) **Presenter:** And so here's a very lazy way to do subdomain enumeration in a Microsoft product. [40:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2429s) **Presenter:** You just use Bing. [40:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2431s) **Presenter:** It works pretty well. [40:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2433s) **Presenter:** And so you're seeing the amount of results that we got here. [40:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2438s) **Presenter:** You've seen a few examples before, kind of on the last slide. [40:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2443s) **Presenter:** but we found a bunch of PII. [40:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2447s) **Presenter:** We found lots of secrets. [40:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2450s) **Presenter:** We found a lot of business data, [40:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2451s) **Presenter:** so PDFs, contracts, vendor lists, [40:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2456s) **Presenter:** all sorts of business data that was out there. [40:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2459s) **Presenter:** And of course, we disclosed this, [41:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2461s) **Presenter:** but this is just an example of a kind of predictable misconfiguration [41:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2465s) **Presenter:** that can occur, and it's very, very easy to exploit. [41:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2471s) **Presenter:** So let me share another example of the same kind. [41:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2475s) **Presenter:** So this time, instead of just picking on Microsoft, this is Zapier. [41:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2482s) **Presenter:** Zapier has a nice little service called Storage by Zapier. [41:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2485s) **Presenter:** Basically, Zapier is an automation platform, [41:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2488s) **Presenter:** and if you want to maintain any sort of state in your automations, [41:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2492s) **Presenter:** you need a store, right? [41:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2494s) **Presenter:** You need something to store that state in. [41:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2497s) **Presenter:** So they have a key value store, [41:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2499s) **Presenter:** that which they provide for you and you can use it to hold state or secrets or whatever you'd like [41:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2506s) **Presenter:** which is pretty nice the way that it gets that it's protected this key value store is with a [41:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2512s) **Presenter:** guide so you provide a secret and that secret allows you to do whatever you want with the [41:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2516s) **Presenter:** key value store with the keys that you that you own and the secret has to be a good which is [42:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2522s) **Presenter:** I mean, it's fine. [42:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2524s) **Presenter:** It's not perfect, but it's fine. [42:07](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2527s) **Presenter:** Here's, when we looked at this, [42:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2529s) **Presenter:** we looked at the actual API documentation, [42:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2533s) **Presenter:** and you can see when you call the API, [42:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2535s) **Presenter:** you get a bunch of kind of text, [42:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2538s) **Presenter:** but you also get examples. [42:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2540s) **Presenter:** And you can see the examples on the upper right side. [42:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2545s) **Presenter:** They use secrets that are very much not a good. [42:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2548s) **Presenter:** So this kind of triggered us. [42:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2552s) **Presenter:** So we just, actually we just started by plugging in this specific secret that they have in the documentation. [42:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2559s) **Presenter:** And voila, we found, kind of, we got access. [42:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2562s) **Presenter:** And so we just did a very simple dictionary attack and was able to uncover that this is not just one example. [42:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2574s) **Presenter:** There were actually a bunch of those examples. [42:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2578s) **Presenter:** And those examples, when I mean an example, [43:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2582s) **Presenter:** it's basically a secret that revealed the key value store values to us. [43:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2589s) **Presenter:** By the way, we could have also changed them, deleted them. [43:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2592s) **Presenter:** And you can see the types of things that we found here. [43:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2596s) **Presenter:** And actually, working with the Zapier team, [43:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2598s) **Presenter:** what we've discovered is that they indeed today, [43:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2602s) **Presenter:** they force you to use GUIDs, [43:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2604s) **Presenter:** But they didn't used to do that up until two years ago, [43:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2607s) **Presenter:** and they simply never did anything with the old secrets. [43:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2610s) **Presenter:** So they are still there. [43:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2612s) **Presenter:** So you can reuse them, and then you're not secured. [43:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2616s) **Presenter:** So, again, this is a very easy example. [43:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2620s) **Presenter:** You can very quickly enumerate this from the outside looking in. [43:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2623s) **Presenter:** Imagine the business user that used the secret equals 1, 2, 3, 4, 5. [43:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2631s) **Presenter:** they don't really know that it's insecure [43:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2634s) **Presenter:** and it's really not their job to know that. [43:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2638s) **Presenter:** Okay. [44:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2640s) **Presenter:** So I'm going to pause for a bit [44:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2642s) **Presenter:** and let's do a quick summary of what we've seen so far. [44:06](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2646s) **Presenter:** We've seen that low-code, no-code is huge in the enterprise [44:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2650s) **Presenter:** and we've seen the ways in which it's a bit underrated by security teams. [44:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2655s) **Presenter:** We've seen the ways that attackers are taking advantage of it [44:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2660s) **Presenter:** hiding inside of those platforms, [44:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2662s) **Presenter:** leveraging predictable misconfigurations. [44:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2665s) **Presenter:** You've also seen two tools [44:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2666s) **Presenter:** that you can use as part of your education process. [44:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2671s) **Presenter:** There are others. [44:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2672s) **Presenter:** I encourage you to look at the links. [44:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2674s) **Presenter:** There's a link in the last slide [44:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2675s) **Presenter:** with a bunch of tools that you can use. [44:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2678s) **Presenter:** And the last thing I'm going to do [44:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2679s) **Presenter:** before we finish off [44:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2682s) **Presenter:** is just to give you a few tips on how to stay safe [44:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2685s) **Presenter:** or what can you do [44:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2688s) **Presenter:** basically onboard [44:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2689s) **Presenter:** local NOCAD into your application [44:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2692s) **Presenter:** security mandate. [44:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2695s) **Presenter:** So [44:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2696s) **Presenter:** some of these things here are [44:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2698s) **Presenter:** very concrete, but others are [44:59](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2699s) **Presenter:** more strategic. In terms [45:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2702s) **Presenter:** of concrete things, you need to review [45:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2703s) **Presenter:** configurations. So you need to be aware of the [45:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2705s) **Presenter:** platforms that are being used inside of your organization. [45:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2708s) **Presenter:** Specifically, [45:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2709s) **Presenter:** look at the bypass consent flag for [45:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2711s) **Presenter:** Microsoft, which allows users to create these [45:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2713s) **Presenter:** beta applications. Look at [45:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2716s) **Presenter:** and make sure that you're limiting which connectors can be used. [45:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2720s) **Presenter:** Monitor those endpoints. [45:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2722s) **Presenter:** You need to know which external endpoints are being put out by those platforms on your behalf. [45:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2727s) **Presenter:** Of course, review the shared connections inside organizations. [45:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2730s) **Presenter:** I can't tell you how many organizations. [45:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2732s) **Presenter:** Just start a conversation with them. [45:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2734s) **Presenter:** The first thing we did is I told them, okay, go to this address, [45:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2738s) **Presenter:** look at the shared environment, [45:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2739s) **Presenter:** and we are seeing SQL servers and FTP servers and shared teams, tokens, [45:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2745s) **Presenter:** and whatever you'd like. [45:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2747s) **Presenter:** And from a more strategic perspective, check out the OAS Low-Code, No-Code Top 10. [45:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2752s) **Presenter:** That should give you a framework on how do you think about Low-Code, No-Code, [45:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2756s) **Presenter:** and how can you take it under the application security umbrella. [46:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2760s) **Presenter:** Thank you very much. ### Q&A & Takeaways — Part 6 [46:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2768s) **Presenter:** Okay, Michael, I have a question to start with. [46:11](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2771s) **Presenter:** Sorry. [46:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2772s) **Presenter:** You want to start off? [46:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2774s) **Presenter:** Yeah. [46:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2774s) **Presenter:** Yeah. [46:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2779s) **Presenter:** Yeah, we've been working with Microsoft on this for a couple of years, [46:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2782s) **Presenter:** and we're really pushing them to change things. [46:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2784s) **Presenter:** The fact that the connectors are so hard to trace, [46:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2788s) **Presenter:** the fact that they have so many permissions, [46:30](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2790s) **Presenter:** the fact that it's very hard to audit the permissions. [46:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2793s) **Presenter:** There are other things you can do as well. [46:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2795s) **Presenter:** You can set the DLP to make sure that your business connectors [46:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2797s) **Presenter:** and your other connectors don't mix. [46:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2799s) **Presenter:** You can set policies in cloud app security. [46:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2802s) **Presenter:** you can monitor the audit logs and the office activity logs in Sentinel. [46:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2809s) **Presenter:** So we've been monitoring these things and detecting these things, [46:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2811s) **Presenter:** but we realized that it is a huge task to do. [46:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2815s) **Presenter:** So thank you. [46:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2816s) **Presenter:** It was a very interesting talk. [46:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2817s) **Presenter:** Thank you. [46:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2817s) **Presenter:** Thank you. [46:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2818s) **Presenter:** I'm glad to hear that you've been working with Microsoft on that. [47:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2821s) **Presenter:** By the way, this is not a decent Microsoft. [47:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2823s) **Presenter:** They are doing a good job, but this is still limited. [47:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2828s) **Presenter:** And some of Microsoft's teams are actually part of the OWASP group, [47:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2832s) **Presenter:** working together with them. [47:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2833s) **Presenter:** One thing I'll note on the Power Platform DLP, which is important to note, [47:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2838s) **Presenter:** today we know of seven or eight ways to bypass it. [47:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2843s) **Presenter:** Those are really simple, like, for example, instead of plugging in the URL, [47:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2849s) **Presenter:** which can be filtered, just put it in a variable, and then they cannot filter it. [47:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2853s) **Presenter:** So it's very basic. [47:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2855s) **Presenter:** They're making changes. [47:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2857s) **Presenter:** Hopefully soon. [47:40](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2860s) **Presenter:** okay michael i mean i have two i mean specific questions i would like you to clarify i'm sure i [47:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2867s) **Presenter:** mean i have this doubt and maybe the audience has a similar kind of thought so who's actually [47:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2872s) **Presenter:** responsible for a low code no code application what is that very simple question second is uh [47:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2878s) **Presenter:** you know uh what essentially what you feel is the difference in terms of securing a low code [48:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2885s) **Presenter:** no-code application vis-a-vis a traditional commercial application [48:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2889s) **Presenter:** that we look at. [48:13](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2893s) **Presenter:** So the first question is the most challenging. [48:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2898s) **Presenter:** We are used to work [48:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2900s) **Presenter:** as application security teams, we focus on applications that developers [48:25](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2905s) **Presenter:** are building. And that has been fine up at the end now. But the [48:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2909s) **Presenter:** rate at which these applications are being built by business [48:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2912s) **Presenter:** means that in a few years, I mean, this is the mainstream, not what we are doing. [48:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2919s) **Presenter:** You saw the chart. [48:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2921s) **Presenter:** There are no, the numbers, like 70,000 different applications. [48:45](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2925s) **Presenter:** There are no, there's no way for developers to create the same kind of amount of applications. [48:52](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2932s) **Presenter:** And so we have to be in charge there. [48:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2935s) **Presenter:** We need to help those business users build those applications correctly. [49:00](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2940s) **Presenter:** And if we don't put ourselves out there, they're just going to do it without us. [49:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2945s) **Presenter:** And this is going to leave us, A, exposed to risk, and B, a bit irrelevant. [49:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2950s) **Presenter:** So we really have to get going there and to be part of the conversation. [49:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2954s) **Presenter:** In terms of how different this is from what we've been doing, [49:18](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2958s) **Presenter:** the most important thing to understand about low-code and no-code in terms of technically [49:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2962s) **Presenter:** is that you don't have any of the fundamental building blocks you're used to building your security strategy on. [49:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2969s) **Presenter:** no code to scan, there's no [49:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2971s) **Presenter:** runtime logs or no way to plug [49:33](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2973s) **Presenter:** into runtime, [49:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2975s) **Presenter:** there is no CICD [49:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2976s) **Presenter:** in most cases, and there's no security [49:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2979s) **Presenter:** surveillance from the side of developers. So you need to [49:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2981s) **Presenter:** really reinvent the way that you do application [49:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2983s) **Presenter:** security. [49:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2986s) **Presenter:** Okay, we are [49:47](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2987s) **Presenter:** open to any other questions. [49:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2991s) **Presenter:** Do we have any? [49:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2995s) **Presenter:** Oh, it's been too heavy for us. [49:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=2997s) **Presenter:** Yeah, we've got one. [50:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3004s) **Presenter:** Just a short question. [50:05](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3005s) **Presenter:** On your slide about Jyapur, it said $400 pointy. [50:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3009s) **Presenter:** Is that all it gave you? [50:12](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3012s) **Presenter:** Yes, and we've actually found, on the same week, [50:16](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3016s) **Presenter:** we found a sandbox escape, and they gave us $300. [50:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3021s) **Presenter:** What's for a party then? [50:26](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3026s) **Presenter:** yeah what questions how can we communicate to colleagues through those apps about the security [50:32](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3032s) **Presenter:** issues they might not be aware of because you know i just showed that it's all gooey you can [50:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3039s) **Presenter:** just click and play okay how can we communicate to them the security implications of building such [50:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3044s) **Presenter:** tools? I find that the easiest way to communicate the risks here is just to show them. So here's a [50:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3053s) **Presenter:** way to drag and drop information outside of the organization, and then they all of a sudden get [50:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3058s) **Presenter:** the realization. Or here's a way to impersonate another user or to create an application, embed [51:03](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3063s) **Presenter:** your own identity within the application, and then everybody can impersonate you. But this is a [51:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3068s) **Presenter:** conversation we need to have with business leaders. [51:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3070s) **Presenter:** In most cases, from what I see, [51:14](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3074s) **Presenter:** business leaders understand the people that are managing those platforms, [51:19](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3079s) **Presenter:** the admins of those platforms. [51:21](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3081s) **Presenter:** They understand that security is important, [51:23](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3083s) **Presenter:** and they do whatever they can in order to secure those applications, [51:27](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3087s) **Presenter:** but they don't have the tools. [51:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3088s) **Presenter:** And they also, to be frank, [51:29](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3089s) **Presenter:** they kind of just do what the platform tells them to do. [51:34](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3094s) **Presenter:** So the platform gives them best practice. [51:38](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3098s) **Presenter:** That's fine. [51:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3099s) **Presenter:** But there is a shared responsibility model here, right? [51:42](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3102s) **Presenter:** You cannot really rely. [51:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3104s) **Presenter:** Some of the vendors are still in a mindset where they're telling their people, [51:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3109s) **Presenter:** hey, everything you're building on top of these platforms will be secured. [51:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3114s) **Presenter:** This is not going to happen. [51:56](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3116s) **Presenter:** There's no way. [51:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3117s) **Presenter:** We've tried that in cloud. [51:58](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3118s) **Presenter:** We've tried to say that AWS is in charge of everything we're building in cloud. [52:02](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3122s) **Presenter:** That failed dramatically. [52:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3124s) **Presenter:** There's a shared responsibility model, and we own part of the responsibility. [52:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3128s) **Presenter:** The same thing happens here. [52:10](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3130s) **Presenter:** Just today, in most cases, we simply don't do our part. [52:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3140s) **Presenter:** The most favorite topic, I guess, for each security team, [52:24](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3144s) **Presenter:** how do you manage asset inventory for low-code, no-code apps? [52:28](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3148s) **Presenter:** Okay, so here I have somewhat better news. [52:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3151s) **Presenter:** because before low-code, no-code, [52:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3157s) **Presenter:** business users have been doing whatever they wanted, [52:41](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3161s) **Presenter:** mostly through copy and paste. [52:43](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3163s) **Presenter:** So there's this nice little phrase I heard once, [52:46](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3166s) **Presenter:** copy and paste integration. [52:48](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3168s) **Presenter:** This is what people have been doing, right? [52:50](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3170s) **Presenter:** And we've been trying to get a hold of it, [52:51](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3171s) **Presenter:** shadow IT, DLP, all sorts of this. [52:54](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3174s) **Presenter:** We haven't succeeded in doing that. [52:57](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3177s) **Presenter:** When people start to use low-code, no-code platforms, [53:01](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3181s) **Presenter:** up with APIs that you can just ask questions. [53:04](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3184s) **Presenter:** And you can ask a question like, what are all of the applications that I have that were [53:08](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3188s) **Presenter:** built on top of Office 365? [53:09](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3189s) **Presenter:** Now, of course, in those large numbers, specifically with Microsoft, inventory is not easy. [53:15](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3195s) **Presenter:** Even if there's an API, it gets flaky when you get to over, I don't know, a thousand [53:20](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3200s) **Presenter:** applications. [53:22](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3202s) **Presenter:** But at least there's someone to ask that question. [53:31](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3211s) **Presenter:** Do we have any more questions? [53:35](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3215s) **Presenter:** Okay. [53:36](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3216s) **Presenter:** Thank you, Michael. [53:37](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3217s) **Presenter:** And great talk. [53:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3219s) **Presenter:** Thank you. [53:39](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3219s) **Presenter:** You know, this topic is very nascent to most of us, actually. [53:44](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3224s) **Presenter:** And to learn and grow into this particular field, it's an ask. [53:49](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3229s) **Presenter:** And I'm sure some thoughts would have come to our mind after listening to him. [53:53](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3233s) **Presenter:** So great talk. [53:55](https://www.youtube.com/watch?v=AD0R4qyrh3g&t=3235s) **Presenter:** And request for a round of applause for him, please. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-02-15_OWASP-Dublin-2023_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/44cbad5f/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Credential Sharing as a Service: the Dark Side of No Code — Michael Bargury — OWASP Global AppSec Dublin 2023 — slide 1 of 70 ### Slide 2 About me OWASP LCNC Top 10 project lead CTO and co-founder @ Zenity Ex MSFT cloud security Dark Reading columnist @mbrg0 bit.ly/ lcsec — slide 2 of 70 ### Slide 3 Disclaimer This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of Low Code. Low Code is awesome. — slide 3 of 70 ### Slide 4 Outline Low Code in a nutshell Low Code attacks observed in the wild Living off the land – account takeover, lateral movement, PrivEsc , data exfil Hiding in plain sight Leveraging predictable misconfigs from the outside How to defend The latest addition to your red team arsenal — slide 4 of 70 ### Slide 5 Low-Code/No-Code in a Nutshell github.com/mbrg/talks — slide 5 of 70 ### Slide 6 Exponential Growth in Business Development — slide 6 of 70 ### Slide 7 Why Low Code? — slide 7 of 70 ### Slide 8 If this sounds familiar, its because it is Tech evolution — slide 8 of 70 ### Slide 9 Build everything If this than that automation Integrations Business apps Whole products Mobile apps — slide 9 of 70 ### Slide 10 Available in every major enterprise — slide 10 of 70 ### Slide 11 Recap Available on every major enterprise Has access to business data and powers business processes Runs as SaaS (difficult to monitor) Underrated by IT/Sec — slide 11 of 70 ### Slide 12 Low Code Attacks In The Wild: Living off the land github.com/mbrg/talks — slide 12 of 70 ### Slide 13 Demo of an automation that mentions a user in Slack, starts a call, and sends an email so the user does not forget — slide 13 of 70 - Youtube: [defcon30 Ohh sorry I'm on another call](https://www.youtube.com/watch?v=5naPxs0fEJc) ### Slide 14 Step by step — slide 14 of 70 ### Slide 15 https://docs.microsoft.com/en-us/connectors/connectors How does the app authenticate to slack? How do different users get authenticated by the same app? Behind the scenes — slide 15 of 70 ### Slide 16 https://docs.microsoft.com/en-us/connectors/connectors Storing and sharing refresh tokens Behind the scenes — slide 16 of 70 ### Slide 17 Ready, set, AUTOMATE! — slide 17 of 70 ### Slide 18 Screenshot of Microsoft Power Platform connections in the Zenity Stage environment, including enterprise databases, cloud storage, mail, CRM, collaboration, and file-transfer services — slide 18 of 70 ### Slide 19 Credential Sharing as a Service — slide 19 of 70 ### Slide 20 Credential Sharing as a Service Privilege escalation — slide 20 of 70 ### Slide 21 Ransomware thru action connections Ransomware — slide 21 of 70 ### Slide 22 Exfiltrate email thru the platform’s email account Data exfiltration — slide 22 of 70 ### Slide 23 Move to machine Lateral movement — slide 23 of 70 ### Slide 24 Introducing ZapCreds github.com/mbrg/ zapcreds — slide 24 of 70 ### Slide 25 Can we fool users to create connections for us? Set up a bait app that does something useful Generate connections on-the-fly Fool users to use it Pwn their connection (i.e. account) Account takeover — slide 25 of 70 ### Slide 26 Power Platform credential harvesting demonstration shown inside the Microsoft Power Apps interface — slide 26 of 70 - Youtube: [defcon30 Power Platform credential harvesting](https://www.youtube.com/watch?v=vJZpNJRC_10) ### Slide 27 Can we get rid of this pesky approve window? — slide 27 of 70 ### Slide 28 Can we get rid of this pesky approve window? https://docs.microsoft.com/en-us/powershell/module/microsoft.powerapps.administration.powershell/set-adminpowerappapistobypassconsent — slide 28 of 70 ### Slide 29 Low Code Attacks In The Wild: Can I stay here forever? github.com/mbrg/talks — slide 29 of 70 ### Slide 30 This has been done before zenity.io/blog/hackers-abuse-low-code-platforms-and-turn-them-against-their-owners/ — slide 30 of 70 ### Slide 31 Dump files and tweet about it on a schedule — slide 31 of 70 ### Slide 32 Encrypt on command — slide 32 of 70 ### Slide 33 Persistency What do we want? Remote execution Arbitrary payloads Maintain access (even if user account access get revokes) Avoid detection Avoid attribution No logs — slide 33 of 70 ### Slide 34 Persistency v1 Persistency — slide 34 of 70 ### Slide 35 Persistency v1 What do we want? — slide 35 of 70 ### Slide 36 What do we want? Remote execution Arbitrary payloads Persistency v1 — slide 36 of 70 ### Slide 37 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access — slide 37 of 70 ### Slide 38 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Somebody else’s cloud — slide 38 of 70 ### Slide 39 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution Somebody else’s cloud Call endpoint anonymously to execute — slide 39 of 70 ### Slide 40 Persistency v1 What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs Somebody else’s cloud Call endpoint anonymously to execute — slide 40 of 70 ### Slide 41 Persistency v2 — slide 41 of 70 ### Slide 42 Persistency v2 What do we want? Arbitrary payloads No logs — slide 42 of 70 ### Slide 43 Solving persistency Our current state: Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs — slide 43 of 70 ### Slide 44 Executing arbitrary commands https://docs.microsoft.com/en-us/connectors/flowmanagement/ — slide 44 of 70 ### Slide 45 Introducing Powerful! github.com/mbrg/powerful — slide 45 of 70 ### Slide 46 Power Automate flow-factory logic that creates flows from received HTTP commands and returns success or failure — slide 46 of 70 ### Slide 47 Create a flow List authenticated sessions to use Delete a flow — slide 47 of 70 ### Slide 48 Expanded Power Automate flow-factory logic for creating flows, deleting flows, and listing connections based on an HTTP command — slide 48 of 70 ### Slide 49 github.com/mbrg/powerful — slide 49 of 70 ### Slide 50 Powerful (persistency v3) What do we want? Remote execution Arbitrary payloads Maintain access Avoid detection Avoid attribution No logs Set up your flow factory Control it though API and a Python CLI github.com/mbrg/powerful — slide 50 of 70 ### Slide 51 Low Code Attacks In The Wild : Outside Looking In github.com/mbrg/talks — slide 51 of 70 ### Slide 52 The Internet (managed Azure SQL instance) Power Portals/Pages? — slide 52 of 70 ### Slide 53 Example Microsoft Power Pages site in a browser with a sample company landing page — slide 53 of 70 ### Slide 54 What’s ODATA and why should we care “An open protocol to allow the creation and consumption of queryable and interoperable RESTful APIs in a simple and standard way.” Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: portal.powerappsportals.com/_ odata — slide 54 of 70 ### Slide 55 What’s ODATA and why should we care “An open protocol to allow the creation and consumption of queryable and interoperable RESTful APIs in a simple and standard way.” Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: portal.powerappsportals.com/_ odata… — slide 55 of 70 ### Slide 56 The fun begins Goal: find misconfigured portals that expose sensitive data w/o auth. Real world example: — slide 56 of 70 ### Slide 57 Nothing to see here /_ odata / globalvariables : — slide 57 of 70 ### Slide 58 Can we scale it? Recall the portal url: — slide 58 of 70 ### Slide 59 Let’s use Bing! zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ Can we scale it? Recall the portal url: — slide 59 of 70 ### Slide 60 ODATA leak - what we found Vulnerability disclosures are in progress Found PII – emails, names, calendar events Secrets – API keys, authentication tokens Business data – sales accounts, business contacts, vendor lists zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ — slide 60 of 70 ### Slide 61 Can we find more exposed data? — slide 61 of 70 ### Slide 62 Can we find more exposed data? Secrets are secured by a random GUID — slide 62 of 70 ### Slide 63 Storage by Zapier API — slide 63 of 70 ### Slide 64 Storage by Zapier API ‘12345’ is not a GUID… — slide 64 of 70 ### Slide 65 Let’s see what happens.. — slide 65 of 70 ### Slide 66 Let’s see what happens.. profit! Auth tokens, API keys, emails, phone no., crypto wallet IDs.. 400$ bounty zenity.io/blog/zapier-storage-exposes-sensitive-customer-data-due-to-poor-user-choices/ — slide 66 of 70 ### Slide 67 Summary Low Code is Huge in the enterprise Underrated by security teams Attackers are taking advantage of it by Living off the land – account takeover, lateral movement, PrivEsc , data exfil Hiding in plain sight Leveraging predictable misconfigs from the outside The latest addition to your red team arsenal ZapCreds – identify overshared creds Powerful –… — slide 67 of 70 ### Slide 68 How To Stay Safe github.com/mbrg/talks — slide 68 of 70 ### Slide 69 Do these 4 things to reduce your risk Review configuration Bypass consent flag (Microsoft) Limit connector usage Review and monitor access for external-facing endpoints Webhooks ODATA (Microsoft) Storage (Zapier) Review connections shared across the entire organization Leverage the OWASP LCNC Top 10 — slide 69 of 70 ### Slide 70 Closing slide for Credential Sharing as a Service: the Dark Side of No Code — slide 70 of 70