# Credential Sharing as a Service: the Dark Side of No Code > SANS Cybersecurity Leadership Summit UK 2023, 2023-04-18. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-04-18-sans-cybersecurity-leadership-summit-uk-2023-credential-sharing-as-a-service-the-dark-side-of-no-code/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-04-18_SANS-UK_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-04-18_SANS-UK_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/slides.pdf) - [Conference agenda](https://assets.contentstack.io/v3/assets/blt36c2e63521272fdc/blt52fa5a2315c8634e/643d1c720736ac330839a79b/CSL_Summit_UK_Agenda_2023_v2.pdf) - [ZapCreds](https://github.com/mbrg/zapcreds) - [Powerful](https://github.com/mbrg/powerful) - [Power Pwn](https://github.com/mbrg/power-pwn) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-04-18-sans-cybersecurity-leadership-summit-uk-2023-credential-sharing-as-a-service-the-dark-side-of-no-code.md) ## Abstract Business professionals are no longer waiting for IT to address their needs. Instead, they are increasingly building their own applications with Low-Code/No-Code platforms. Recent surveys show that most enterprise apps are now built outside of IT by business professionals who hold no previous experience in building software. In this presentation, we will share extensive research on the security of Low-Code applications based on scanning >100K applications across hundreds of enterprise environments. We will show how this research led to the creation of the OWASP Top 10 Security Risks for Low-Code/No-Code and showcase those risks. Next, we will demonstrate how most applications get identity, access and data flow wrong, cover a wide range of security issues found in real environments, and share their backstories and implications. _[Official conference abstract](https://assets.contentstack.io/v3/assets/blt36c2e63521272fdc/blt52fa5a2315c8634e/643d1c720736ac330839a79b/CSL_Summit_UK_Agenda_2023_v2.pdf)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-04-18_SANS-UK_Credential_Sharing_as_a_Service_the_Dark_Side_of_No_Code/54647e9d/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Credential Sharing as a Service: the Dark Side of No Code — Michael Bargury, Zenity — SANS Cybersecurity Leadership UK Summit 2023 — slide 1 of 42 ### Slide 2 About me OWASP LCNC Top 10 project lead CTO and co-founder @ Zenity Ex MSFT cloud security Dark Reading columnist @mbrg0 bit.ly/ lcsec — slide 2 of 42 ### Slide 3 Outline Low Code / No Code growth and evolution Attacks observed in the wild Living off the land – account takeover, lateral movement, PrivEsc , data exfil Hiding in plain sight Leveraging predictable misconfigs from the outside How to defend The latest addition to your red team arsenal — slide 3 of 42 ### Slide 4 Business-Led Development Is Here — slide 4 of 42 ### Slide 5 Exponential Growth in Business Development — slide 5 of 42 ### Slide 6 The Low-Code/No-Code Evolution: How did we get here? — slide 6 of 42 ### Slide 7 Business Needs ⋙ IT Capacity — slide 7 of 42 ### Slide 8 If it sounds familiar, its because it is Tech evolution — slide 8 of 42 ### Slide 9 Build everything If this than that automation Integrations Business apps Whole products Mobile apps — slide 9 of 42 ### Slide 10 Available in every major enterprise — slide 10 of 42 ### Slide 11 Build Business Apps Faster How low code / no node accelerates development: Ease of use lowers barrier to entry Off-the-shelf integrated components Key app features are baked-in ( AuthN , AuthZ , ..) Connectors to on-prem, cloud and SaaS “Save” to deploy No infra to maintain — slide 11 of 42 ### Slide 12 COVID health check app by Microsoft https://aka.ms/healthcheck — slide 12 of 42 ### Slide 13 Order-to-cash automation by Slack https://www.workato.com/the-connector/how-slack-automated-order-to-cash/ — slide 13 of 42 ### Slide 14 https://www.microsoft.com/insidetrack/blog/how-citizen-developers-modernized-microsoft-product-launches/ “… A Business Operations program manager, and her team, were searching for a way to optimize the launch process for the 150 employees who ran product launches across the company. … Within months, the app would become a widely used internal tool”… — slide 14 of 42 ### Slide 15 “With Dynamics, …, we also launched this very powerful platform, the Power Platform -- … which acts as the extensibility framework for Microsoft Graph, extensibility framework for Dynamics, as well as Microsoft 365, and embeddable by every SaaS ISV.“ Satya Nadella, Microsoft Build 2018 A Humble Beginning – Low Code as Extendibility — slide 15 of 42 ### Slide 16 “Anyone can be a developer, completely transforming how your business operates” “… we need to empower citizen developers with tools that are low-code/no-code tools so that they can build out these applications …. In fact, there are already 2.5 million citizen developers using Power Platform …” “Once Excel was introduced, a lot of people were able to… — slide 16 of 42 ### Slide 17 “By 2025, 70% of new applications deployed for the enterprise will use low-code or no-code tools, up from less than 25% in 2020.” “With Power Platform, we have the leading business process automation and productivity suite for domain experts in every industry, with 20 million monthly active users.” Satya Nadella, Microsoft Inspire 2022 Business Users are… — slide 17 of 42 ### Slide 18 Demo of an automation that mentions a user in Slack, starts a call, and sends an email so the user does not forget — slide 18 of 42 - Youtube: [defcon30 Ohh sorry I'm on another call](https://www.youtube.com/watch?v=5naPxs0fEJc) ### Slide 19 Big vendors have a strong incentive to empower business users Companies are lacking IT resources and need a solution for accelerated development The tech is already there – business users are actually using it The Race for a New Excel — slide 19 of 42 ### Slide 20 Recap Available on every major enterprise Has access to business data and powers business processes Runs as SaaS (difficult to monitor) Underrated by IT/Sec — slide 20 of 42 ### Slide 21 Low Code Attacks In The Wild Living off the land — slide 21 of 42 ### Slide 22 Wait. What? — slide 22 of 42 ### Slide 23 Step by step — slide 23 of 42 ### Slide 24 Behind the scenes https://docs.microsoft.com/en-us/connectors/connectors How does the app authenticate to slack? How do different users get authenticated by the same app? — slide 24 of 42 ### Slide 25 Behind the scenes https://docs.microsoft.com/en-us/connectors/connectors Storing and sharing refresh tokens — slide 25 of 42 ### Slide 26 Ready, set, AUTOMATE! — slide 26 of 42 ### Slide 27 Screenshot of Microsoft Power Platform connections in the Zenity Stage environment, including enterprise databases, cloud storage, mail, CRM, collaboration, and file-transfer services — slide 27 of 42 ### Slide 28 Credential Sharing as a Service Shared identities: ZapCreds Power Platform default env Workato shared creds — slide 28 of 42 ### Slide 29 Credential Sharing as a Service Shared identities: ZapCreds Power Platform default env Workato shared creds Privilege escalation — slide 29 of 42 ### Slide 30 Ransomware thru action connections Ransomware — slide 30 of 42 ### Slide 31 Exfiltrate email thru the platform’s email account Data exfiltration — slide 31 of 42 ### Slide 32 Move to machine Lateral movement — slide 32 of 42 ### Slide 33 Can we fool users to create connections for us? Set up a bait app that does something useful Generate connections on-the-fly Fool users to use it Pwn their connection (i.e. account) Account takeover — slide 33 of 42 ### Slide 34 Power Platform credential harvesting demonstration shown inside the Microsoft Power Apps interface — slide 34 of 42 - Youtube: [defcon30 Power Platform credential harvesting](https://www.youtube.com/watch?v=vJZpNJRC_10) ### Slide 35 Saved by the prompt? — slide 35 of 42 ### Slide 36 Saved by the prompt? No. https://docs.microsoft.com/en-us/powershell/module/microsoft.powerapps.administration.powershell/set-adminpowerappapistobypassconsent — slide 36 of 42 ### Slide 37 Hiding in plain sight Persistence — slide 37 of 42 ### Slide 38 This has been done before zenity.io/blog/hackers-abuse-low-code-platforms-and-turn-them-against-their-owners/ — slide 38 of 42 ### Slide 39 Summary Low Code is huge in the enterprise Probably already in your org Shift focus to business users Attackers are taking advantage of it by living off the land Account takeover Lateral movement PrivEsc Data exfil Persistence How to defend your org — slide 39 of 42 ### Slide 40 How To Stay Safe? — slide 40 of 42 ### Slide 41 Do these 4 things to reduce your risk Leverage the OWASP LCNC Top 10 Expand Secure Development standards to low-code / no-code Approved use cases Training Security assurance Threat modeling Inventory low-code / no-code applications Identities used Data accessed Leverage Open-Source tools ZapCreds – identify overshared credentials on Zapier… — slide 41 of 42 ### Slide 42 Closing slide for Credential Sharing as a Service: the Dark Side of No Code — slide 42 of 42