# Credential Sharing as a Service: the Dark Side of No Code > OWASP Global AppSec DC 2023, 2023-10-30. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-10-30-owasp-globalappsec-dc2023-credential-sharing-as-a-service-the-dark-side-of-no-code/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/slides.pdf) - [Recording](https://www.youtube.com/watch?v=KK_cqEnj8Ks) - [Conference agenda](https://owasp2023globalappsecwashin.sched.com/event/1Os3h/credential-sharing-as-a-service-the-dark-side-of-no-code) - [Source code](https://github.com/mbrg/power-pwn) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-10-30-owasp-globalappsec-dc2023-credential-sharing-as-a-service-the-dark-side-of-no-code.md) ## Abstract Why focus on heavily guarded crown jewels when you can dominate an organization through its shadow IT? Low-Code applications have become a reality in the enterprise, with surveys showing that most enterprise apps are now built outside of IT, with lacking security practices. Unsurprisingly, attackers have figured out ways to leverage these platforms for their gain. In this talk, we demonstrate a host of attack techniques found in the wild, where enterprise No-Code platforms are leveraged and abused for every step in the cyber killchain. You will learn how attackers perform an account takeover by making the user simply click a link, move laterally and escalate privileges with zero network traffic, leave behind an untraceable backdoor, and automate data exfiltration, to name a few capabilities. All capabilities will be demonstrated with POCs, and their source code will be shared. _[Official conference abstract](https://owasp2023globalappsecwashin.sched.com/event/1Os3h/credential-sharing-as-a-service-the-dark-side-of-no-code)_ ## Transcript > AI generated from recording. ### Introduction and Defining No‑Code [00:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=5s) **Presenter:** But it's going to be interesting, I'll tell you that. So let's, like, briefly about me, I've been focused on kind of no-code security and how do you help business users build secure applications for a few years now. I started a company that's focused on this space. We've been around for almost three years now called Xenity. I lead a No-WASP project dedicated to the cloud. [00:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=30s) **Presenter:** to low-code, no-code, and there are probably a couple of people in the audience right now [00:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=34s) **Presenter:** that are part of this project, so please do reach out to them afterwards for questions. [00:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=41s) **Presenter:** And I'm trying to share as much as I can about this space because I feel like we have a really [00:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=47s) **Presenter:** big opportunity at our hands here. So here's, like in a nutshell, what we're going to do today. [00:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=55s) **Presenter:** We're going to start by just making sure we're all on the same page on what no code actually means, [01:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=60s) **Presenter:** or what do I mean when I say no code. [01:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=64s) **Presenter:** Then we're going to shift to the attacker's perspective, [01:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=67s) **Presenter:** and I'm going to share concrete examples of attacks we've observed in the wild, [01:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=72s) **Presenter:** where attackers have leveraged no code for their own purposes. [01:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=77s) **Presenter:** That includes leaving off the land, phishing attacks, and persistency, and much more, depends on time. [01:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=84s) **Presenter:** And, of course, we're going to finish it off with helpful tips on how to defend your organization when you get back to office. [01:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=95s) **Presenter:** So let's start off with no code. ### The Scale of No‑Code Adoption; Security Foundations and Risks of No‑Code [01:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=100s) **Presenter:** This number right now, 5 million, is the number of .NET developers, according to Microsoft, the number of active .NET developers today. [01:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=109s) **Presenter:** So 5 million C-sharp developers active right now. [01:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=114s) **Presenter:** with this number as a reference, [01:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=117s) **Presenter:** think about how many developers [01:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=119s) **Presenter:** are there out there [02:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=120s) **Presenter:** that are building local local apps. [02:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=123s) **Presenter:** Like, just have a number in your head. [02:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=126s) **Presenter:** And so, because we're comparing, [02:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=128s) **Presenter:** because this is the Microsoft ecosystem, [02:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=130s) **Presenter:** let's compare the number of development developers [02:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=132s) **Presenter:** with the number of developers [02:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=134s) **Presenter:** that are using the Microsoft [02:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=135s) **Presenter:** Power Platform ecosystem [02:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=137s) **Presenter:** to build applications. [02:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=138s) **Presenter:** I've actually gone through their earning reports [02:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=141s) **Presenter:** and weeded out the numbers. [02:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=144s) **Presenter:** As you can see here, today there are almost, or according to this regression, there are 8 million active Power Platform developers today. [02:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=153s) **Presenter:** 8 million Power Platform developers, 5 million .NET developers. [02:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=158s) **Presenter:** Now, these numbers are, as you can see, the last number that I actually got a quote on was 7 million. [02:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=165s) **Presenter:** But still, just think about how much we're investing in those professional developers versus business developers. [02:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=171s) **Presenter:** So this is why this is important. [02:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=174s) **Presenter:** thinking about, like, the one thing that is important about these developers is, like, [02:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=178s) **Presenter:** where do they work? [02:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=179s) **Presenter:** They work for you, right? [03:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=181s) **Presenter:** They work for the top organizations in the world because those are the organizations [03:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=185s) **Presenter:** that are using the Microsoft Suite. [03:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=186s) **Presenter:** And so here's an example from one organization, one Fortune 100 organization, on the number [03:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=193s) **Presenter:** of applications that they've seen created with no code throughout the years. [03:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=198s) **Presenter:** And you can see just how fast this thing grows. [03:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=201s) **Presenter:** These are real numbers from a real company, [03:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=205s) **Presenter:** and they are actually not that wild. [03:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=208s) **Presenter:** There are other companies that have many more. [03:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=211s) **Presenter:** And it shows, like, of course, [03:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=213s) **Presenter:** not all of these applications are huge applications. [03:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=215s) **Presenter:** Some of them are very small. [03:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=216s) **Presenter:** Some of them are kind of if this, then that rule. [03:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=219s) **Presenter:** But still, there are applications with identity, [03:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=224s) **Presenter:** with access to data. [03:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=225s) **Presenter:** So it's important for us to understand [03:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=228s) **Presenter:** just the magnitude of this thing. [03:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=232s) **Presenter:** And right now, in the last few months, this thing has been happening, ### Credential Sharing Attacks in the Wild [03:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=236s) **Presenter:** where now we are seeing in every major local platform, [03:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=239s) **Presenter:** we are seeing AI being introduced as a way to lower the bar even more, [04:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=244s) **Presenter:** to more easily create applications, [04:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=247s) **Presenter:** and more than that, to create applications that are more complex. [04:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=250s) **Presenter:** So what you're seeing right now on screen is an experience in the office suite [04:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=255s) **Presenter:** where you talk to the chat, to the AI, and it will generate an application for you. [04:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=262s) **Presenter:** Once you're done with the chat, this application has created a table in a managed SQL server. [04:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=267s) **Presenter:** It has exposed an endpoint inside of your organization. [04:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=272s) **Presenter:** The application is already live. [04:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=273s) **Presenter:** It's already in production. [04:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=274s) **Presenter:** So you understand the magnitude of this. [04:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=276s) **Presenter:** And, of course, it also means that you can build more complex applications very easily. [04:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=281s) **Presenter:** And this is not just a Microsoft thing. [04:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=283s) **Presenter:** This is happening across the industry because AI and no code are very much interconnected in the way that when you think about building Gen.AI application, it's all about these kind of building blocks and new plugin together. [04:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=297s) **Presenter:** And so right now, people have the ability across the organization to just spell out the application that they would like built, to have built, and the AI would build it for them. [05:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=305s) **Presenter:** And of course, assuming that AI would build a secure application is kind of a difficult assumption to make. [05:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=312s) **Presenter:** this is not new [05:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=313s) **Presenter:** this has been happening for a long time now [05:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=316s) **Presenter:** and there have been many [05:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=317s) **Presenter:** cases, like many technologies [05:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=320s) **Presenter:** that have come [05:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=322s) **Presenter:** through that have enabled people [05:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=324s) **Presenter:** to do more, to accomplish more [05:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=326s) **Presenter:** with their digital workspaces [05:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=327s) **Presenter:** Excel comes to mind as one clear example [05:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=330s) **Presenter:** of software that enables [05:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=332s) **Presenter:** people to do more, that empowered them [05:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=334s) **Presenter:** to be able to do more [05:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=335s) **Presenter:** than they were able to do before [05:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=337s) **Presenter:** and right now with NocoNoCode and Gen.AI [05:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=341s) **Presenter:** This is like the next evolution, but it's really taken on quickly. [05:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=346s) **Presenter:** And one important thing to note is that this problem or this space is relevant to all of us [05:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=354s) **Presenter:** because you don't really get to make the decision whether you have no code in your organization or not. [05:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=358s) **Presenter:** It's already there. [05:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=359s) **Presenter:** If you're using any one of these platforms on screen, [06:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=362s) **Presenter:** and most of the SaaS vendors out there have kind of integrated no code directly into their platform. [06:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=369s) **Presenter:** And so you don't get the choice. [06:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=371s) **Presenter:** If you're using Microsoft, ServiceNow, Salesforce, [06:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=374s) **Presenter:** you already have a low-code, no-code platform in your organization, [06:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=377s) **Presenter:** and they have been enabling your business users to build applications, [06:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=381s) **Presenter:** which they try to make secure, [06:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=384s) **Presenter:** on top of business data that's already there. [06:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=387s) **Presenter:** All right. [06:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=389s) **Presenter:** So a quick recap on no-code. [06:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=393s) **Presenter:** We know that no-code is available in every major organization. [06:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=395s) **Presenter:** We know that it has access to both business data and it also powers business processes by design. [06:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=403s) **Presenter:** This is part of your business ecosystem. [06:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=407s) **Presenter:** Of course, because this is based on SaaS, most of it will run on somebody else's infra. [06:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=413s) **Presenter:** Admittedly, there are some platforms that would allow you to run your own, but that's not the norm. [06:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=419s) **Presenter:** And those applications can be built by anyone between a professional developer and a citizen developer, [07:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=425s) **Presenter:** everyone in your organization. [07:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=428s) **Presenter:** And even with professional developers, [07:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=429s) **Presenter:** you'll find that the controls are really not there. [07:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=431s) **Presenter:** But that's kind of a ### Ransomware via Power Automate and Azure [07:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=433s) **Presenter:** recap happening now to make sure that [07:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=435s) **Presenter:** we're all on the same page of what [07:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=438s) **Presenter:** no code is. [07:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=440s) **Presenter:** Now I'm going to switch gears [07:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=441s) **Presenter:** and I'm going to share a few attacks [07:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=443s) **Presenter:** that we've seen in the wild. [07:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=445s) **Presenter:** And also for each one of the attacks, I'm going to [07:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=448s) **Presenter:** recreate it together with you [07:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=450s) **Presenter:** here. And at [07:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=452s) **Presenter:** the end, you'll see that all of this is wrapped [07:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=456s) **Presenter:** access by the end of this talk. [07:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=458s) **Presenter:** By the way, everything that you're seeing on screen, [07:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=460s) **Presenter:** including the deck [07:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=461s) **Presenter:** and the source [07:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=464s) **Presenter:** is already published. [07:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=466s) **Presenter:** You'll see links in a moment. [07:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=469s) **Presenter:** All right. [07:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=470s) **Presenter:** So the first thing I want to... [07:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=472s) **Presenter:** Before we [07:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=474s) **Presenter:** talk about this attack, we need to [07:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=476s) **Presenter:** figure out... We need to have a clear example [07:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=478s) **Presenter:** of how a low-code application looks like. [08:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=480s) **Presenter:** So here's a [08:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=482s) **Presenter:** quick little demo. [08:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=483s) **Presenter:** This is a silly example where there's this annoying thing in Slack [08:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=489s) **Presenter:** where when somebody mentions me in a public channel, [08:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=491s) **Presenter:** I'm expected to reply quickly because other people are watching. [08:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=495s) **Presenter:** And so I'm building here a quick application [08:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=497s) **Presenter:** where every time they subscribe to a notification [08:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=500s) **Presenter:** that somebody mentions me in a public channel, [08:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=503s) **Presenter:** it's going to replace my status as if I'm on a call. [08:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=507s) **Presenter:** So people will know that I'm unavailable right now [08:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=513s) **Presenter:** me alone. And then five minutes later, it's going to switch off to a regular kind of profile [08:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=521s) **Presenter:** to make sure that nobody gets suspicious. Now, this is a silly example, but the important [08:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=526s) **Presenter:** thing here is just to figure out how, A, how easy it is to create this application. You [08:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=531s) **Presenter:** are seeing it on the screen right now. But B, this is a pretty significant piece of application, [08:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=536s) **Presenter:** right? It has to authenticate to Slack. It has to maintain secrets that would somehow [09:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=543s) **Presenter:** to Slack. Note that I'm not providing [09:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=545s) **Presenter:** secrets in any part right here [09:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=547s) **Presenter:** in building this app. [09:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=549s) **Presenter:** It needs to wait for [09:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=551s) **Presenter:** five minutes so there's a state somewhere. [09:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=553s) **Presenter:** It runs [09:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=555s) **Presenter:** on somebody else's cloud. [09:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=557s) **Presenter:** I can share this application. [09:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=558s) **Presenter:** This is a significant piece of software that I get [09:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=561s) **Presenter:** to build very quickly. [09:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=563s) **Presenter:** The number one thing that's important for [09:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=565s) **Presenter:** us to figure out about this app [09:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=566s) **Presenter:** is the identity. How is it [09:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=569s) **Presenter:** connected to Slack? [09:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=570s) **Presenter:** If you think [09:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=573s) **Presenter:** When you think about, when you build an application, [09:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=576s) **Presenter:** I'm showing you an example for Zapier, [09:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=578s) **Presenter:** but this is true for almost any no-code platform. [09:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=582s) **Presenter:** If you think about allowing business users to build applications, [09:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=586s) **Presenter:** the number one thing that would stop them from building applications is permissions. [09:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=591s) **Presenter:** If they would need to ask for a service account [09:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=593s) **Presenter:** every time they wanted to create an application, [09:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=597s) **Presenter:** you would never see the chart that I showed you earlier [10:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=600s) **Presenter:** with the number of applications that get developed. [10:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=603s) **Presenter:** How exactly does this happen? [10:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=604s) **Presenter:** This happens by, so the way this platform circumvent this problem ### Phishing Campaigns Leveraging No‑Code Platforms [10:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=609s) **Presenter:** is that they allow users to basically record their refresh token, [10:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=614s) **Presenter:** their OAuth refresh token, and then share it with others. [10:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=617s) **Presenter:** You're seeing it on screen. [10:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=618s) **Presenter:** So when you create, when you plug in Zapier, for example, to your Slack account, [10:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=623s) **Presenter:** you're seeing the normal OAuth flow here [10:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=625s) **Presenter:** where you're allowing Zapier to operate on your behalf. [10:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=629s) **Presenter:** And then there is something called connection that gets created, which is essentially just a wrapper around credentials. [10:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=636s) **Presenter:** But the important thing is that you get this share button. [10:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=639s) **Presenter:** This share button on top of the connection that allows you to share your identity with others. [10:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=644s) **Presenter:** Now, know that this is not sharing, like this is not providing access the way that OAuth was intended. [10:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=651s) **Presenter:** This is just copying and allowing somebody else to use your refresh token, [10:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=655s) **Presenter:** which means that there is no way to distinguish the application when one user uses it or another user uses it. [11:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=662s) **Presenter:** Everybody is using the same token. [11:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=664s) **Presenter:** Behind the scene, the way that this works is that there are mechanisms where the application is sending requests to the APIs of its choice, [11:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=675s) **Presenter:** and the platform is just replacing the tokens, [11:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=678s) **Presenter:** just making sure that when the Power Automate or Zapier or any other automation platform reaches out to Slack on your behalf, [11:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=686s) **Presenter:** then even though the automation itself doesn't have access to your token, [11:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=689s) **Presenter:** the token gets stored on a proxy between those two points, [11:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=695s) **Presenter:** and the token just gets injected between those two points. [11:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=699s) **Presenter:** This means that every user of the application, every user of the automation, [11:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=703s) **Presenter:** of the automation would use the same credentials [11:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=707s) **Presenter:** through this gateway. [11:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=709s) **Presenter:** They would not have direct access to the credential. [11:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=711s) **Presenter:** They can't fetch out, or in most cases, [11:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=714s) **Presenter:** they can't fetch out the token. [11:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=717s) **Presenter:** However, they are free to use it, right? [12:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=720s) **Presenter:** And so when you look at these platforms, [12:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=725s) **Presenter:** because people are widely using them, [12:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=729s) **Presenter:** people are kind of creating a whole bunch of things with them, [12:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=733s) **Presenter:** examples that I just took off marketplaces for many of the different vendors. The important thing [12:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=739s) **Presenter:** for what you're seeing on screen here to note is actually the logos, because they indicate [12:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=745s) **Presenter:** that these platforms are actually connected on your behalf across your organization. They're [12:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=751s) **Presenter:** connected to G Suite, they're connected to Office, they can be connected anywhere, including on-prem [12:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=755s) **Presenter:** and to your cloud, which means that behind every one of these logos, there's access to data. By [12:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=763s) **Presenter:** only access that could very easily be full access, full control. [12:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=768s) **Presenter:** And the worst thing is that most of these platforms have some way to share these connections. [12:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=776s) **Presenter:** And so pretty soon you end up with a whole bunch of connections. [13:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=780s) **Presenter:** And you're seeing this example on screen where a bunch of connections were created [13:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=783s) **Presenter:** because they just created a bunch of applications that were kind of popular in our organization. [13:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=788s) **Presenter:** And one of the things that you'll see in most of these platforms is a way to collaborate. [13:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=793s) **Presenter:** that these platforms are allowing productivity within your environment. [13:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=797s) **Presenter:** And so there's this notion of a default environment. [13:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=801s) **Presenter:** And the default environment is a way, it's like the place where you log in, [13:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=806s) **Presenter:** everybody has permissions to build things there by default. [13:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=811s) **Presenter:** And in this default environment, you will typically find a large pile of connections [13:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=816s) **Presenter:** that are just waiting around for anybody to use them. [13:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=821s) **Presenter:** Like, you realize what this means. [13:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=823s) **Presenter:** just like a bag of [13:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=825s) **Presenter:** credentials that are waiting for [13:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=827s) **Presenter:** anybody to join in [13:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=829s) **Presenter:** and the only thing that you need in order to [13:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=831s) **Presenter:** get into that [13:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=833s) **Presenter:** pile of gold is just [13:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=835s) **Presenter:** a single user inside of [13:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=837s) **Presenter:** an organization and [13:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=839s) **Presenter:** of course in a large enterprise [14:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=841s) **Presenter:** we need to operate under [14:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=843s) **Presenter:** the assumption that [14:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=844s) **Presenter:** at least one user would [14:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=847s) **Presenter:** eventually be attacked [14:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=849s) **Presenter:** like be compromised right [14:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=850s) **Presenter:** especially when you [14:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=853s) **Presenter:** that most of these platforms allow vendors and guests [14:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=856s) **Presenter:** to have access to your platform as well. [14:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=858s) **Presenter:** And so once you're in, you're able to quickly just pick up those credentials [14:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=862s) **Presenter:** and reuse them for yourself, and we'll see that in a moment. [14:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=868s) **Presenter:** What can you do with these connections? [14:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=870s) **Presenter:** So you can do basically everything that you can do [14:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=873s) **Presenter:** with the credentials behind them. [14:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=875s) **Presenter:** And in most cases, this is full-blown access [14:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=879s) **Presenter:** to those underlying data stores or services. [14:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=883s) **Presenter:** Here's one example. You can build ransomware directly using those connections. [14:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=888s) **Presenter:** In this Power Automate flow here, I'm listing out all of the folders in a specific SharePoint site, [14:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=895s) **Presenter:** and then I'm encrypting every file with the encryption function that is provided by the platform [15:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=903s) **Presenter:** because there are valid use cases to provide an encryption function. [15:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=907s) **Presenter:** Of course, that could also be used for malicious purposes. [15:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=911s) **Presenter:** And so that's one way to do it. [15:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=913s) **Presenter:** You can, of course, as you can see on the right side, [15:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=916s) **Presenter:** there's a whole bunch of connectors here. [15:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=917s) **Presenter:** So you can do that well across the enterprise, [15:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=920s) **Presenter:** not just in SharePoint. [15:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=923s) **Presenter:** One of the things that might be surprising here [15:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=925s) **Presenter:** is that you can also use this [15:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=928s) **Presenter:** to bypass your network mechanisms, your DLP mechanisms. [15:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=933s) **Presenter:** Because this is kind of the latest innovation [15:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=936s) **Presenter:** in exfiltrating email. [15:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=938s) **Presenter:** So users have forever been trying to move data to their personal accounts because most people would rather read their corporate, or a lot of people would rather read their corporate email or have their personal and corporate calendar synced with each other. [15:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=956s) **Presenter:** Of course, this could very easily lead to data leakage from your organization. [16:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=961s) **Presenter:** And so we have different mechanisms to try to stop that with things that sit on the email server or DLP. [16:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=968s) **Presenter:** However, what can happen with no code is that you, like a single application, could use two different identities. ### Backdoor Persistence and Automation Abuse [16:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=975s) **Presenter:** One identity is your corporate identity and the other is your personal identity. [16:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=978s) **Presenter:** And then things get copied from the corporate identity to the personal identity. [16:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=983s) **Presenter:** And the data itself gets copied on the vendor's server. [16:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=988s) **Presenter:** So nothing gets sent on the wire. [16:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=990s) **Presenter:** There's no way for you to catch that through email. [16:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=993s) **Presenter:** This is just an email being read from one place and then stored in another. [16:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=998s) **Presenter:** so that's like data exfiltration [16:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1001s) **Presenter:** through these no-code platforms [16:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1003s) **Presenter:** is a very common scenario [16:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1005s) **Presenter:** that you can see exactly [16:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1007s) **Presenter:** because nothing needs to go on the wire [16:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1010s) **Presenter:** like the no-code vendor [16:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1011s) **Presenter:** who does all of the difficult tasks for you [16:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1015s) **Presenter:** and another thing you can do here [16:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1018s) **Presenter:** is actually move to on-prem [17:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1020s) **Presenter:** so move to workstations [17:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1022s) **Presenter:** because some no-code platforms [17:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1024s) **Presenter:** have also integrated something called RPA [17:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1028s) **Presenter:** that runs on somebody's workstation, [17:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1030s) **Presenter:** in a different kind of technology, [17:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1031s) **Presenter:** but it doesn't really matter, [17:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1033s) **Presenter:** where you are able to send commands from the cloud [17:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1036s) **Presenter:** to your workstation to perform automation tasks [17:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1039s) **Presenter:** on that workstation. [17:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1040s) **Presenter:** And now, of course, [17:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1041s) **Presenter:** if you can send something from the cloud to a workstation [17:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1044s) **Presenter:** and have that workstation accomplish that task, [17:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1047s) **Presenter:** then if those permissions get shared as well, [17:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1052s) **Presenter:** then you have found a way to move from cloud, [17:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1055s) **Presenter:** from those platforms directly to people's workstations. [17:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1058s) **Presenter:** And I've actually given a talk at DEF CON last year [17:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1060s) **Presenter:** on how you can basically take, [17:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1063s) **Presenter:** you could take over that mechanism [17:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1065s) **Presenter:** and then use it as a way to command and control [17:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1068s) **Presenter:** into an organization. [17:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1070s) **Presenter:** This has already been fixed by Microsoft [17:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1072s) **Presenter:** or at least the vulnerability that I've used there. [17:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1075s) **Presenter:** But this is still like an attack vector [17:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1078s) **Presenter:** we need to monitor. [17:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1079s) **Presenter:** And now, up and down, [18:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1081s) **Presenter:** I've kind of shared a few examples here, [18:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1085s) **Presenter:** switch gears here and show you. [18:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1088s) **Presenter:** And so, kind of show you how this looks like. [18:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1091s) **Presenter:** And so, what we're going to do right now is accomplish one of these attacks with a tool [18:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1096s) **Presenter:** called PowerPoint. [18:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1097s) **Presenter:** This is a tool that we've published in Black Hat a few months ago. [18:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1102s) **Presenter:** And it's available right now. [18:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1104s) **Presenter:** You can go to the link on screen. [18:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1106s) **Presenter:** And PowerPoint is a tool that's focused on the Power Platform ecosystem, so Microsoft [18:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1110s) **Presenter:** 365. [18:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1111s) **Presenter:** If you're a Microsoft CHOP or if you're doing a penetration testing for a Microsoft CHOP, [18:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1117s) **Presenter:** this is a nice thing for you to use. [18:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1119s) **Presenter:** And we're going to see a few modules of PowerPoint today. [18:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1122s) **Presenter:** And so the first thing I want to show you is those connections [18:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1127s) **Presenter:** and what can you actually accomplish with them. [18:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1129s) **Presenter:** So let me switch off to a quick demo. [18:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1137s) **Presenter:** All right. [18:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1139s) **Presenter:** and hopefully this will be easy. [19:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1145s) **Presenter:** Okay, so I'm just shooting up PowerPoint here [19:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1149s) **Presenter:** and you can see that there is a simple command on screen, [19:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1152s) **Presenter:** PowerPoint dump, which would actually go [19:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1155s) **Presenter:** and I'm providing the tenant that I would like to kind of exfiltrate. [19:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1159s) **Presenter:** And then what would actually happen is that PowerPoint would reach out [19:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1163s) **Presenter:** to the tenant, find all of the connections, applications, [19:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1168s) **Presenter:** that are available to me and then to that user that I have logged in with, [19:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1172s) **Presenter:** and then just dump all of the data behind them. [19:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1175s) **Presenter:** So let's see how this looks like. [19:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1176s) **Presenter:** I'm providing the tenant ID for PowerPoint. [19:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1182s) **Presenter:** It's going to use the device login in order to authenticate, [19:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1186s) **Presenter:** but of course you can provide a token from anywhere else. [19:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1189s) **Presenter:** You can also take a token from other tools like road tools [19:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1195s) **Presenter:** or anything else where you can get a token. [19:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1198s) **Presenter:** We need a bearer here, but you can switch those off. [20:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1203s) **Presenter:** Once you log in, then first of all, it's going to do some recon [20:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1208s) **Presenter:** to find all of the different environments that exist within this specific Power Platform tenant. [20:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1216s) **Presenter:** It's also finding all of the applications and connections [20:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1220s) **Presenter:** that have been shared across an organization. [20:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1223s) **Presenter:** And this is just, again, very easy to do. [20:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1225s) **Presenter:** This is going after that pile of gold that we've just described [20:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1229s) **Presenter:** where people have shared connections with others. [20:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1234s) **Presenter:** It's going to fetch a few definitions that would allow us to use those connections. [20:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1240s) **Presenter:** And then by the end of the script, [20:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1243s) **Presenter:** what happens here is that all of the data behind all of these connections gets dumped to your disk. [20:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1249s) **Presenter:** So you can see that I'm showing the specific... [20:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1256s) **Presenter:** you can see that inside of this dump folder, [20:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1259s) **Presenter:** for which I've listed here, [21:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1262s) **Presenter:** all of the different types of connections that I found. [21:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1265s) **Presenter:** So you can see connections to Azure Blob Storage, [21:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1267s) **Presenter:** to Azure File Storage, Azure Tables, [21:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1270s) **Presenter:** CDS, Common Data Services, Power Apps for Admin. ### Mitigation Strategies and Closing Remarks — Part 1 [21:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1272s) **Presenter:** So these are the different connections [21:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1273s) **Presenter:** that I would be able to use. [21:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1279s) **Presenter:** And now for each one of those types of connections, [21:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1282s) **Presenter:** I can actually look at the actual data, [21:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1286s) **Presenter:** and we provide a nice little applet for you [21:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1288s) **Presenter:** with the command PowerPoint GUI, [21:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1292s) **Presenter:** which creates this little kind of application. [21:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1295s) **Presenter:** And you can see this is an inventory of everything that we found. [21:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1298s) **Presenter:** We found a bunch of credentials, [21:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1301s) **Presenter:** so these are the connections that have been overshared. [21:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1303s) **Presenter:** We found a bunch of automations that you can use [21:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1305s) **Presenter:** and applications that you can pick up and use. [21:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1310s) **Presenter:** So if I click on credentials, [21:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1312s) **Presenter:** then you'll see that there's a whole bunch of credentials here [21:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1315s) **Presenter:** that I can just pick up and use. [21:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1316s) **Presenter:** Some of them are for, again, Azure File Storage, Azure Blob Storage. [21:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1319s) **Presenter:** You can see where these connections are connected. [22:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1322s) **Presenter:** In some cases, we're able to actually extract the host name. [22:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1324s) **Presenter:** So we can see, for example, Enterprise IP Blob Storage [22:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1328s) **Presenter:** or Jamie Redding Customer Data or Enterprise Financial. [22:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1332s) **Presenter:** So these are just connections to underlying SQL servers or Azure resources. [22:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1337s) **Presenter:** And you can see a bunch of information about them, [22:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1339s) **Presenter:** like when was this credential less... [22:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1343s) **Presenter:** If we know of an expiry date, when is it [22:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1345s) **Presenter:** and when was the connection actually less created? [22:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1348s) **Presenter:** And so when you go into... [22:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1351s) **Presenter:** And for each one of those connections, [22:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1355s) **Presenter:** we actually dump all of the data behind them. [22:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1357s) **Presenter:** So for example, with SQL Server, [22:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1359s) **Presenter:** we would list out all of the different tables [22:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1363s) **Presenter:** that are part of the SQL Server. [22:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1365s) **Presenter:** And as you can see, there are three tables here, [22:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1369s) **Presenter:** a couple of tables that are kind of default [22:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1370s) **Presenter:** about the firewall tables. [22:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1373s) **Presenter:** And when you go to the customer table, [22:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1374s) **Presenter:** you actually get a full dub of the table. [22:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1376s) **Presenter:** Don't worry, these are not real social security numbers. [22:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1379s) **Presenter:** This is the chat GPT being helpful. [23:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1382s) **Presenter:** But again, these are like, [23:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1384s) **Presenter:** this is the data behind the connections [23:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1386s) **Presenter:** that was overshared. [23:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1389s) **Presenter:** We can actually do more than that [23:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1391s) **Presenter:** because this is just showing you [23:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1394s) **Presenter:** that you can get to the actual connection, [23:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1397s) **Presenter:** to the actual data behind that connection. [23:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1399s) **Presenter:** But you can also use those connections to perform operations. [23:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1403s) **Presenter:** So for example, with SQL Server, [23:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1405s) **Presenter:** we provide you with an automatedly generated Swagger UI [23:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1408s) **Presenter:** where you can see that there are a whole bunch of actions [23:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1411s) **Presenter:** you can perform on top of this connection. [23:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1413s) **Presenter:** One thing that you can do with a SQL Server [23:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1415s) **Presenter:** is just pass on a SQL query. [23:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1417s) **Presenter:** So you can see that action. [23:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1422s) **Presenter:** So let me move here. [23:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1425s) **Presenter:** All right, so you can see SQL pass through native query, [23:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1429s) **Presenter:** that would just allow me to run any query that I want on top of this server. [23:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1433s) **Presenter:** I'm just going to use the information that I found from the table that you just saw. [23:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1439s) **Presenter:** And I'm going to add a SQL query that's simply going to encrypt [24:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1444s) **Presenter:** some of the social security numbers there on the table. [24:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1447s) **Presenter:** And, of course, this is just a demo showing how you can use this access [24:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1452s) **Presenter:** to do some sort of a ransomware attack on top of the data that sits behind that connection. [24:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1459s) **Presenter:** This specific example is going to find some of the customer records [24:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1464s) **Presenter:** and encrypt them. [24:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1466s) **Presenter:** Once I click on execute, this goes through the proxy that we saw earlier [24:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1470s) **Presenter:** and actually would encrypt the data there. [24:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1476s) **Presenter:** I'm going to use a get request just to watch the records [24:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1480s) **Presenter:** and make sure that I've actually successfully encrypted them. [24:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1487s) **Presenter:** and again when I click on execute [24:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1489s) **Presenter:** you'll find that I get the information [24:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1491s) **Presenter:** from the tables, this is actually how we perform [24:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1494s) **Presenter:** the dump command [24:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1496s) **Presenter:** and you can see that some of the records [24:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1498s) **Presenter:** indeed were encrypted [24:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1499s) **Presenter:** so the social security numbers indeed were encrypted [25:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1502s) **Presenter:** so this shows you that you can use this tool [25:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1504s) **Presenter:** to perform operations, any operations that you'd like [25:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1506s) **Presenter:** on top of the underlying [25:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1510s) **Presenter:** services behind that connection [25:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1514s) **Presenter:** tool to actually just use the applications and the automations that have been shared [25:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1519s) **Presenter:** that we got access to. [25:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1521s) **Presenter:** So here are the bunch of applications that we were able to detect. [25:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1526s) **Presenter:** And you can just run each one of them. [25:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1528s) **Presenter:** So just here is an example. [25:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1530s) **Presenter:** I'm just going to run one of them, and it lets me into the application. [25:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1534s) **Presenter:** We are actually bypassing a couple of mechanisms here, but that's a story for another day. [25:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1540s) **Presenter:** And you can also look at a bunch of automations that are available here. [25:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1544s) **Presenter:** actually trigger those automations. [25:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1546s) **Presenter:** And so the amount of damage that you can do [25:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1548s) **Presenter:** depends on what the automation allows you to do. [25:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1550s) **Presenter:** But in many cases, you'll find automations [25:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1552s) **Presenter:** that allow you, for example, [25:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1553s) **Presenter:** to gain permissions to something [25:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1555s) **Presenter:** or to change access to something. [25:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1558s) **Presenter:** And so hopefully this gives you kind of a taste [26:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1565s) **Presenter:** of what you can do with PowerPoint here. [26:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1568s) **Presenter:** But actually, the number one thing you can do [26:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1571s) **Presenter:** is just play around with it. [26:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1572s) **Presenter:** So please go to that link [26:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1574s) **Presenter:** plenty more documentation. [26:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1576s) **Presenter:** And if you're looking to learn more, [26:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1578s) **Presenter:** specifically about this issue of overshark credentials, [26:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1581s) **Presenter:** I've actually given a talk at Black Hat [26:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1584s) **Presenter:** that is precisely focused on that issue [26:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1586s) **Presenter:** and what happens when guests in your organization, [26:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1590s) **Presenter:** how can they leverage this issue [26:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1594s) **Presenter:** to actually gain access to SQL servers [26:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1596s) **Presenter:** and Azure storage across your organization. [26:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1599s) **Presenter:** So please do check it out. [26:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1602s) **Presenter:** All right. [26:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1604s) **Presenter:** seen a few [26:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1605s) **Presenter:** living-of-the-land attacks. [26:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1608s) **Presenter:** One, like the next thing I want [26:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1610s) **Presenter:** to show you is phishing. [26:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1612s) **Presenter:** And before I'll [26:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1614s) **Presenter:** show you how you [26:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1616s) **Presenter:** can use no code to do [26:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1617s) **Presenter:** active phishing within an organization, [27:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1620s) **Presenter:** let's consider for a second what [27:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1622s) **Presenter:** would be the ideal [27:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1624s) **Presenter:** capability for [27:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1626s) **Presenter:** an attacker to [27:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1628s) **Presenter:** create a phishing campaign inside of an organization, [27:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1630s) **Presenter:** like a large organization. [27:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1631s) **Presenter:** So you would probably want the [27:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1634s) **Presenter:** to look and feel like something users are used to working with, right? [27:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1639s) **Presenter:** It should look like something that they're operating with every day. [27:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1643s) **Presenter:** You would probably want it, like if you can, [27:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1646s) **Presenter:** hopefully it's already integrated to their SSO, right? [27:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1650s) **Presenter:** That would be amazing because somebody would just need to click a link [27:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1653s) **Presenter:** and that's it. [27:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1653s) **Presenter:** You've owned them because they don't need to provide their credentials. [27:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1657s) **Presenter:** Ideally, it needs to be hosted on somewhere where users would trust it, right? [27:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1661s) **Presenter:** Not just a random URL, but hopefully something that they trust. [27:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1669s) **Presenter:** So I'm going to show you right now how you can use the Microsoft platform to accomplish all of that. [27:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1676s) **Presenter:** Because when you think about, again, the number of applications that we saw earlier, [28:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1680s) **Presenter:** like the huge exponential graph at the beginning of this talk, [28:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1684s) **Presenter:** then you'll just think about an organization that has created so many of these applications. ### Mitigation Strategies and Closing Remarks — Part 2 [28:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1689s) **Presenter:** In an organization that uses these platforms, people are used to using applications that were generated by these platforms a lot. [28:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1698s) **Presenter:** And they always look and feel the same thing, the same way. [28:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1701s) **Presenter:** And so here's the question. [28:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1703s) **Presenter:** Can we take an application? [28:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1706s) **Presenter:** Can we create an application that's actually useful? [28:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1708s) **Presenter:** It does something useful for an organization. [28:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1710s) **Presenter:** Maybe you'll just pick up an application from the marketplace. [28:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1713s) **Presenter:** And then every time a user logs into that application, [28:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1717s) **Presenter:** the user would need to log in, [28:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1719s) **Presenter:** and maybe we can even make them log in automatically. [28:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1723s) **Presenter:** Once they are in and they have provided us with authorization [28:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1727s) **Presenter:** to basically, for example, access email on their behalf [28:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1732s) **Presenter:** to do something that's all right, [28:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1734s) **Presenter:** then we can use their email to do whatever we want, [28:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1736s) **Presenter:** and then we can own their account. [28:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1737s) **Presenter:** And so this is what we're going to try to do. [29:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1740s) **Presenter:** We're going to try to create an application [29:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1743s) **Presenter:** is doing something useful so people actually use it. [29:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1745s) **Presenter:** But every time somebody logs into it, [29:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1747s) **Presenter:** then we've owned them. [29:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1751s) **Presenter:** And so now I'm going to switch directly to a demo. [29:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1759s) **Presenter:** All right, so PowerPoint phishing would allow you, [29:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1764s) **Presenter:** what it allows you to do is first of all, [29:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1767s) **Presenter:** it's basically install a phishing application [29:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1769s) **Presenter:** within an organization. [29:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1770s) **Presenter:** Of course, you need to be authenticated, right? [29:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1773s) **Presenter:** some user inside of the organization [29:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1774s) **Presenter:** in order to be able to create this application. [29:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1777s) **Presenter:** So I'm creating this phishing application, [29:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1779s) **Presenter:** and you can see that the name of the application is shoutout. [29:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1782s) **Presenter:** It's at the end of the command line there. [29:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1785s) **Presenter:** I just picked up a random application from the marketplace [29:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1787s) **Presenter:** and just repurposed it. [29:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1790s) **Presenter:** So I'm just going to run the command. [29:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1796s) **Presenter:** It's going to think for a while. [30:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1800s) **Presenter:** Loading a bit. [30:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1803s) **Presenter:** generate an application for me. [30:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1806s) **Presenter:** And you can see, [30:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1807s) **Presenter:** so you can see the application run URL. [30:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1810s) **Presenter:** All right. [30:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1810s) **Presenter:** The most important thing about this URL [30:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1813s) **Presenter:** is that it lives in the Microsoft TECA system. [30:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1815s) **Presenter:** Note the domain, apps.powerapps.com. [30:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1817s) **Presenter:** This would be trusted by any enterprise user [30:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1820s) **Presenter:** in any enterprise organization. [30:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1822s) **Presenter:** And more than that, [30:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1823s) **Presenter:** this is already plugged into your Office 365 single sign-on. [30:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1827s) **Presenter:** So this is the link that I need users to click. [30:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1831s) **Presenter:** If they click on this link, [30:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1833s) **Presenter:** What happens is that they're just going to go into my app. [30:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1838s) **Presenter:** And so let's see how this looks like. [30:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1844s) **Presenter:** All right. [30:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1845s) **Presenter:** So I'm going to go to the – I'm logging into this application. [30:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1849s) **Presenter:** The other thing that you saw me do there is share this application. [30:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1851s) **Presenter:** So I need to share it, and specifically here I've shared it with the entire organization. [30:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1855s) **Presenter:** So everybody could use it. [30:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1857s) **Presenter:** All right. [30:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1858s) **Presenter:** So this is loading the application. [31:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1861s) **Presenter:** and once I'm in, this is an application [31:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1864s) **Presenter:** from the Microsoft Marketplace. [31:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1866s) **Presenter:** This is like you can shout out for somebody [31:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1868s) **Presenter:** to give them helpful feedback or positive feedback [31:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1871s) **Presenter:** for something that they've done. [31:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1873s) **Presenter:** In order to kind of send out those shout outs, [31:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1878s) **Presenter:** this application requires access to your email [31:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1880s) **Presenter:** and as you've seen at the beginning [31:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1883s) **Presenter:** of when this was loaded, [31:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1885s) **Presenter:** this was kind of provided automatically [31:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1890s) **Presenter:** just going to use this application. [31:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1891s) **Presenter:** This is just a normal application that somebody [31:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1893s) **Presenter:** can use. And here specifically, I'm [31:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1896s) **Presenter:** going to send a shout out to [31:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1897s) **Presenter:** Alicia, which is the chief financial [31:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1900s) **Presenter:** officer of my company. Again, [31:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1901s) **Presenter:** I'm doing that as a normal [31:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1903s) **Presenter:** user in the organization, as like a binan user. [31:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1907s) **Presenter:** That's [31:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1908s) **Presenter:** the entire experience for me. So I've just [31:50](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1910s) **Presenter:** used this application. It's probably [31:52](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1912s) **Presenter:** done what I wanted it to do. [31:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1914s) **Presenter:** All right. Logging in as Alicia. [31:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1916s) **Presenter:** You can see that I got a shout out [31:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1918s) **Presenter:** email, which is cool. [32:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1920s) **Presenter:** So this is like a cool email that Microsoft generates for me. [32:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1923s) **Presenter:** And now Alicia would, like she gets this email. [32:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1927s) **Presenter:** So of course, why not she would log into that application as well [32:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1930s) **Presenter:** because she wants to give shout out to somebody else. [32:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1932s) **Presenter:** Once Alicia is logged in, [32:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1934s) **Presenter:** then she's now another user inside of my application. [32:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1938s) **Presenter:** And so she would continue to send out those emails. [32:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1944s) **Presenter:** And on the hacker side, [32:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1945s) **Presenter:** you can see that while this was happening, [32:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1950s) **Presenter:** both Alicia and the first user that I was logged into [32:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1953s) **Presenter:** was sending their entire email inbox to my own inbox, [32:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1957s) **Presenter:** was just forwarding their emails. [32:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1959s) **Presenter:** Because at the moment they were using the application, [32:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1962s) **Presenter:** I got access to their email, I could do whatever I want with it, [32:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1964s) **Presenter:** and they have no idea that this is actually happening. [32:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1967s) **Presenter:** And again, if I go back a bit, you can see the URL here. [32:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1973s) **Presenter:** it's a Microsoft [32:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1974s) **Presenter:** provided domain. [33:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1982s) **Presenter:** All right. [33:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1985s) **Presenter:** So [33:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1987s) **Presenter:** there's plenty more [33:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1988s) **Presenter:** information that we could have gone to [33:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1990s) **Presenter:** with this demo, but if you're [33:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1992s) **Presenter:** looking for more of these examples, there's another [33:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1994s) **Presenter:** talk at Black Hat that was [33:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1996s) **Presenter:** directly related on this [33:18](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=1998s) **Presenter:** type of quirk, so if you're interested [33:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2000s) **Presenter:** just check it out. [33:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2003s) **Presenter:** Okay, we have time for one more, and it's going to be, I might kind of skip some of it. [33:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2011s) **Presenter:** But one of the things that, so you understand how powerful, like being an attacker and being able to access those platforms, you understand how powerful it is. [33:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2020s) **Presenter:** So of course, attackers would want a way to stay in once they're in. [33:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2025s) **Presenter:** And so what I'm going to show you right now [33:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2027s) **Presenter:** is a way for an attacker to create a backdoor [33:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2029s) **Presenter:** into an organization so they have access to a user [33:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2033s) **Presenter:** and they would like to maintain that access. [33:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2036s) **Presenter:** And they will be able to maintain that access [33:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2038s) **Presenter:** even if the user they initially used gets deleted. [34:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2042s) **Presenter:** Their resources still remain. [34:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2044s) **Presenter:** They can still use the backdoor that they have created. [34:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2046s) **Presenter:** This is actually not something that we... [34:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2048s) **Presenter:** This was actually observed being done by an APT group [34:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2054s) **Presenter:** a few years now, a few years back. [34:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2057s) **Presenter:** And you can see some information about this here. [34:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2060s) **Presenter:** But essentially what they've done [34:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2062s) **Presenter:** is that they were able to compromise an admin account. [34:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2065s) **Presenter:** And then they set up an information which, [34:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2069s) **Presenter:** on recurrence, used Office features [34:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2072s) **Presenter:** to search around Office for PII and secrets [34:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2075s) **Presenter:** and just send it to the random endpoint. [34:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2076s) **Presenter:** And nobody was looking at that place for a while. [34:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2080s) **Presenter:** So if you're interested in that, [34:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2082s) **Presenter:** just check out this blog. [34:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2085s) **Presenter:** so I'm gonna [34:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2088s) **Presenter:** let me switch [34:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2089s) **Presenter:** let me kind of [34:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2091s) **Presenter:** quickly jump in here because I [34:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2093s) **Presenter:** think we can go directly [34:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2095s) **Presenter:** to show you what is actually happening [34:57](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2097s) **Presenter:** so here's what the attackers [34:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2099s) **Presenter:** have done, they have created [35:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2102s) **Presenter:** to my point an application [35:03](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2103s) **Presenter:** that runs on recurrence that would [35:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2105s) **Presenter:** kind of do something that's malicious ### Mitigation Strategies and Closing Remarks — Part 3 [35:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2107s) **Presenter:** on their behalf, what you can actually [35:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2109s) **Presenter:** do if you take this a step further [35:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2111s) **Presenter:** is you can create [35:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2122s) **Presenter:** application, you can create an application that does three things. [35:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2126s) **Presenter:** One is that automation does three things. [35:28](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2128s) **Presenter:** So instead of accepting a specific payload, like something to do, [35:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2134s) **Presenter:** like instead of doing something like the attackers have done in this APT group [35:38](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2138s) **Presenter:** where they have exfiltrated the information outside of the organization, [35:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2142s) **Presenter:** you can accept the definition to build a new automation. [35:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2145s) **Presenter:** So that's the create flow operation. [35:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2148s) **Presenter:** And then you can run that automation, [35:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2151s) **Presenter:** and then you can delete that automation together with all of its logs. [35:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2155s) **Presenter:** And so this is essentially an automation that is a factory to create other automations. [36:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2160s) **Presenter:** And this is what we've done here. [36:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2162s) **Presenter:** And again, I'm going to show you with, like, I'm not sure we have time, [36:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2167s) **Presenter:** But what essentially we were able to do here is when you create, you know what? [36:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2176s) **Presenter:** I'm just going to show you. [36:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2179s) **Presenter:** And so it's a bit difficult to read the audience. [36:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2185s) **Presenter:** So let me show you exactly how this looks like with PowerPoint. [36:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2195s) **Presenter:** All right. [36:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2197s) **Presenter:** I'm running a PowerPoint backdoor. [36:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2199s) **Presenter:** Again, this is the first command. [36:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2202s) **Presenter:** This needs to be authenticated. [36:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2203s) **Presenter:** The first command is installing the factory. [36:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2205s) **Presenter:** That factory would be our backdoor. [36:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2209s) **Presenter:** And you can see that I'm kind of providing some information here. [36:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2213s) **Presenter:** That right now is just creating an automation [36:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2216s) **Presenter:** that would accept definitions of other automations [36:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2219s) **Presenter:** that we would like to create. [37:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2221s) **Presenter:** Once I'm done with creating this automation, [37:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2224s) **Presenter:** I get, you can see that the flow was successfully installed [37:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2228s) **Presenter:** And now I get a webhook URL [37:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2231s) **Presenter:** That webhook URL is my backdoor [37:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2233s) **Presenter:** And you can spot on that URL [37:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2237s) **Presenter:** That there's actually a secret there [37:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2239s) **Presenter:** At the end of that URL [37:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2240s) **Presenter:** This is the URL that is going to [37:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2242s) **Presenter:** This is the mechanism that is going to allow us to continue to [37:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2245s) **Presenter:** Hit that backdoor endpoint [37:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2246s) **Presenter:** Even though a user gets deleted [37:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2249s) **Presenter:** Now you can use a PowerPoint backdoor [37:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2251s) **Presenter:** To use that backdoor [37:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2253s) **Presenter:** and you can see that through that vector [37:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2254s) **Presenter:** you can do a couple of things. [37:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2256s) **Presenter:** You can create an automation, create a flow. [37:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2259s) **Presenter:** You can delete that flow to remove [37:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2262s) **Presenter:** every kind of, every track behind you [37:44](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2264s) **Presenter:** and you can also get connections [37:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2266s) **Presenter:** which would allow you to see [37:48](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2268s) **Presenter:** what that flow would be able to use, [37:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2269s) **Presenter:** like pick up and use things that were created [37:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2271s) **Presenter:** after you've already left the organization. [37:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2276s) **Presenter:** So in this example, first of all, [37:58](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2278s) **Presenter:** I've used, this is the user that I've used [38:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2282s) **Presenter:** What I'm going to do is disable that user. [38:05](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2285s) **Presenter:** So once I disable that user, [38:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2287s) **Presenter:** you would think that I would lose access to everything [38:09](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2289s) **Presenter:** that this user has created, [38:12](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2292s) **Presenter:** but you'd be wrong [38:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2294s) **Presenter:** because those automations would still operate. [38:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2299s) **Presenter:** So let's see that in action. [38:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2301s) **Presenter:** Now I can use that backdoor to get connections. [38:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2305s) **Presenter:** That allows me to see all of the different credentials [38:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2309s) **Presenter:** that are available for me to use. [38:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2312s) **Presenter:** through the webhook URL that I received earlier, my backdoor. [38:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2316s) **Presenter:** And you can see that it is run successfully, [38:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2319s) **Presenter:** even though the user that has created this automation has been disabled. [38:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2323s) **Presenter:** I get this list of connections. [38:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2326s) **Presenter:** And in this list of connections, I'm going to find an Azure file storage. [38:51](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2331s) **Presenter:** And I want to be able to connect an Azure queue. [38:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2336s) **Presenter:** And I want to be able to connect to that Azure queue. [39:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2340s) **Presenter:** So here's what I'm going to do. [39:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2342s) **Presenter:** the endpoint to create an automation. [39:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2344s) **Presenter:** Again, the backdoor would create an automation for me. [39:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2347s) **Presenter:** And that automation, once I run PowerPoint, [39:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2353s) **Presenter:** that automation is going to use the connection [39:16](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2356s) **Presenter:** to that Azure queue to create a SAS token [39:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2359s) **Presenter:** that would allow me to read that queue. [39:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2361s) **Presenter:** So what I'm actually doing here [39:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2363s) **Presenter:** is just exfiltrating outside of Power Platform [39:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2366s) **Presenter:** the credential to that queue. [39:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2369s) **Presenter:** So you can see that I've successfully created [39:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2372s) **Presenter:** new automation through my vector automation. [39:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2375s) **Presenter:** I got a new web URL, [39:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2377s) **Presenter:** which would allow me to run this new automation. [39:42](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2382s) **Presenter:** Now I'm just going to use KRL to hit that endpoint, [39:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2387s) **Presenter:** which would actually trigger the automation [39:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2389s) **Presenter:** and provide me with information behind it. [39:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2396s) **Presenter:** And what I've actually created in this, [39:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2399s) **Presenter:** so this specific automation that I've created [40:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2402s) **Presenter:** that allows me to, again, to read that queue. [40:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2404s) **Presenter:** So I've just exfiltrated outside the connection there. [40:07](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2407s) **Presenter:** And now I want to make sure that nobody would ever find me. [40:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2411s) **Presenter:** So in order to do that, [40:13](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2413s) **Presenter:** all I need to do is use PowerPoint backdoor delete flow, [40:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2419s) **Presenter:** which would delete the automation that I've created, [40:22](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2422s) **Presenter:** thus deleting the logs that are part of the same object. [40:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2426s) **Presenter:** And so this backdoor allows you to... [40:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2429s) **Presenter:** This was one example of an automation that I was able to create, [40:33](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2433s) **Presenter:** to create, run, and delete through this endpoint, this vector endpoint. [40:36](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2436s) **Presenter:** But I could have done this with any other automation, [40:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2440s) **Presenter:** like your imagination is the only limit. [40:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2445s) **Presenter:** All right. [40:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2446s) **Presenter:** So we're kind of at the end. [40:49](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2449s) **Presenter:** So I want to make sure that I give you enough. [40:55](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2455s) **Presenter:** I want to show that I leave you in a better place than you've started. [41:01](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2461s) **Presenter:** So I'm going to share a few concrete things that you can do tomorrow morning [41:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2468s) **Presenter:** to help secure your organization. [41:11](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2471s) **Presenter:** And with each of them, I'm just going to kind of describe it, [41:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2475s) **Presenter:** but you'll see a link below in a moment [41:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2477s) **Presenter:** which would give you all of the relevant information, [41:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2480s) **Presenter:** like including configuration and everything else that is required. [41:24](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2484s) **Presenter:** This is going to be just pretty simple. [41:26](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2486s) **Presenter:** The first thing is, of course, you need to build secure applications, right? [41:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2489s) **Presenter:** And one thing that's pretty obvious is that you don't want to share connections [41:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2494s) **Presenter:** that are essentially your identity with other users within your organization. [41:39](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2499s) **Presenter:** You especially don't want to share it with everyone, [41:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2501s) **Presenter:** which would include everyone in your tenant. [41:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2503s) **Presenter:** And so that's just kind of one best practice. [41:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2507s) **Presenter:** But actually, there are a bunch of things that business users can do [41:54](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2514s) **Presenter:** can do when they build these low-code, no-code applications [41:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2516s) **Presenter:** that end up creating vulnerabilities [42:00](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2520s) **Presenter:** that could be exploited by an attacker. [42:02](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2522s) **Presenter:** And because of the scale of these applications, ### Mitigation Strategies and Closing Remarks — Part 4 [42:06](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2526s) **Presenter:** the number of applications that gets created, [42:08](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2528s) **Presenter:** it would be very difficult. [42:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2530s) **Presenter:** So it would be like you could very easily gamble [42:14](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2534s) **Presenter:** that an organization would probably have [42:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2537s) **Presenter:** at least one of these vulnerabilities in their environment. [42:20](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2540s) **Presenter:** And so there's a dedicated OWASP top 10 list. [42:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2545s) **Presenter:** That's a project that I'm guessing a couple of people in the room have contributed to, [42:30](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2550s) **Presenter:** which is focused on the problems that occur with these types of applications. [42:34](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2554s) **Presenter:** And we are focused on logical problems, [42:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2557s) **Presenter:** on things that just don't make sense when you allow everyone to build applications. [42:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2563s) **Presenter:** So please do check that out. [42:46](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2566s) **Presenter:** We also have a talk tomorrow for project sessions in the project showcase, [42:53](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2573s) **Presenter:** so please reach out to us tomorrow as well. [42:56](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2576s) **Presenter:** The other thing I recommend you do is harden your environment. [42:59](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2579s) **Presenter:** And I think if you take one thing from this talk, [43:04](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2584s) **Presenter:** we can't expect to have so many developers using low-code, no-code, [43:10](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2590s) **Presenter:** and to invest so little security effort into helping them do their job [43:15](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2595s) **Presenter:** not have a bunch of vulnerabilities out there [43:17](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2597s) **Presenter:** and not be owned by hackers. We really [43:19](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2599s) **Presenter:** need to step up application security [43:21](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2601s) **Presenter:** for local and local applications and the [43:23](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2603s) **Presenter:** things that citizen developers are building [43:25](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2605s) **Presenter:** and I'll leave it at that but there's [43:27](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2607s) **Presenter:** plenty more to say about that so [43:29](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2609s) **Presenter:** please check out the link. And the last [43:31](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2611s) **Presenter:** thing I'll say is [43:32](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2612s) **Presenter:** hack your environment because other people [43:35](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2615s) **Presenter:** are trying and if you're looking for [43:37](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2617s) **Presenter:** a resource please check out PowerPoint [43:40](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2620s) **Presenter:** everything you've [43:41](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2621s) **Presenter:** seen today and other things [43:43](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2623s) **Presenter:** can be accomplished [43:45](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2625s) **Presenter:** and it's all open source. [43:47](https://www.youtube.com/watch?v=KK_cqEnj8Ks&t=2627s) **Presenter:** With that, thank you very much. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/15746fa6/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 OWASP 2023 Global AppSec Washington, DC conference title card - slide 1 of 66 ### Slide 2 Michael Bargury @mbrg0 — Zenity — mbgsec.com - slide 2 of 66 ### Slide 3 About me — 👋 — CTO and Co-founder @ Zenity — OWASP LCNC Top 10 project lead — Dark Reading columnist — OWASP, — BlackHat — , Defcon, — BSides — Hiring top researchers, — engs — & — pms — ! — mbgsec.com - slide 3 of 66 ### Slide 4 Outline — No Code in a nutshell — No Code attacks observed in the wild and recreated with — POWERPWN — Living off the land – account takeover, lateral movement, — PrivEsc — , data exfil — Phishing made easy — Hiding in plain sight — How to defend — The latest addition to your red team arsenal - slide 4 of 66 ### Slide 5 No-Code in a Nutshell — mbgsec.com - slide 5 of 66 ### Slide 6 Credential Sharing as a Service: The Dark Side of No Code — Michael Bargury — RSAC 2023 — C# devs today - slide 6 of 66 ### Slide 7 ~8M active Power devs today! — Credential Sharing as a Service: The Dark Side of No Code — Michael Bargury — RSAC 2023 - slide 7 of 66 ### Slide 8 Exponential Growth in Citizen Development - slide 8 of 66 ### Slide 9 Why No Code? - slide 9 of 66 ### Slide 10 “Everyone is a developer” — Tech evolution - slide 10 of 66 ### Slide 11 Build everything — If this than that automation — Integrations — Business apps — Whole products — Mobile apps - slide 11 of 66 ### Slide 12 Power Apps editor demonstrating Copilot-assisted app creation, animated from a source by Reza Dorrani - slide 12 of 66 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/15746fa6/media/image29.gif) ### Slide 13 Available in every major enterprise - slide 13 of 66 ### Slide 14 Recap — Available on every major enterprise — Has access to business data and powers business processes — Runs on somebody else’s infra — Built by citizen devs - slide 14 of 66 ### Slide 15 No Code Attacks In The Wild: — Living off the land — mbgsec.com - slide 15 of 66 ### Slide 16 youtu.be/5naPxs0fEJc - slide 16 of 66 ### Slide 17 Step by step - slide 17 of 66 ### Slide 18 https://docs.microsoft.com/en-us/connectors/connectors — How does the app authenticate to slack? — How do different users get authenticated by the same app? — Behind the scenes - slide 18 of 66 ### Slide 19 https://docs.microsoft.com/en-us/connectors/connectors — Storing and sharing refresh tokens — Behind the scenes - slide 19 of 66 ### Slide 20 Ready, set, AUTOMATE! - slide 20 of 66 ### Slide 21 Power Platform connection inventory showing credentials shared across Azure, Microsoft 365, SQL, Salesforce, Dropbox, FTP, and other services - slide 21 of 66 ### Slide 22 Credential Sharing as a Service - slide 22 of 66 ### Slide 23 Credential Sharing as a Service — Privilege escalation - slide 23 of 66 ### Slide 24 Ransomware thru action connections — Ransomware - slide 24 of 66 ### Slide 25 Exfiltrate email thru the platform’s email account — Data exfiltration - slide 25 of 66 ### Slide 26 Move to machine — Lateral movement - slide 26 of 66 ### Slide 27 Introducing — powerpwn — Find us on GitHub! — github.com/mbrg/power- — pwn - slide 27 of 66 ### Slide 28 Black Hat USA 2023 title card for All You Need Is Guest by Michael Bargury - slide 28 of 66 ### Slide 29 PowerPwn demonstration of harvesting and using overshared Power Platform connections - slide 29 of 66 - Video: [Embedded video](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/15746fa6/media/powerdump.mp4) ### Slide 30 No Code Attacks In The Wild: — Phishing made easy — mbgsec.com - slide 30 of 66 ### Slide 31 Can we fool users to create connections for us? — Set up a bait app that does something useful — Generate connections on-the-fly — Fool users to use it — Pwn — their connection (i.e. account) — Account takeover - slide 31 of 66 ### Slide 32 PowerPwn demonstration of a trusted Power Apps phishing application - slide 32 of 66 - Video: [Embedded video](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/15746fa6/media/phishing.mp4) ### Slide 33 Black Hat USA 2023 title card for Sure, Let Business Users Build Their Own. What Could Go Wrong? by Michael Bargury - slide 33 of 66 ### Slide 34 No Code Attacks In The Wild: — A backdoor that survives user deletion — mbgsec.com - slide 34 of 66 ### Slide 35 This has been done before — zenity.io/blog/hackers-abuse-low-code-platforms-and-turn-them-against-their-owners/ - slide 35 of 66 ### Slide 36 Dump files and tweet about it on a schedule - slide 36 of 66 ### Slide 37 Encrypt on command - slide 37 of 66 ### Slide 38 Persistency — What do we want? — Remote execution — Arbitrary payloads — Maintain access (even if user account access get revokes) — Avoid detection — Avoid attribution — No logs - slide 38 of 66 ### Slide 39 Persistency v1 — Persistency - slide 39 of 66 ### Slide 40 Persistency v1 — What do we want? - slide 40 of 66 ### Slide 41 What do we want? — Remote execution — Arbitrary payloads — Persistency v1 - slide 41 of 66 ### Slide 42 Persistency v1 — What do we want? — Remote execution — Arbitrary payloads — Maintain access - slide 42 of 66 ### Slide 43 Persistency v1 — What do we want? — Remote execution — Arbitrary payloads — Maintain access — Avoid detection — Somebody else’s cloud - slide 43 of 66 ### Slide 44 Persistency v1 — What do we want? — Remote execution — Arbitrary payloads — Maintain access — Avoid detection — Avoid attribution — Somebody else’s cloud — Call endpoint anonymously to execute - slide 44 of 66 ### Slide 45 Persistency v1 — What do we want? — Remote execution — Arbitrary payloads — Maintain access — Avoid detection — Avoid attribution — No logs — Somebody else’s cloud — Call endpoint anonymously to execute - slide 45 of 66 ### Slide 46 Persistency v2 - slide 46 of 66 ### Slide 47 Persistency v2 — What do we want? — Arbitrary payloads — No logs - slide 47 of 66 ### Slide 48 Solving persistency — Our current state: — Remote execution — Arbitrary payloads — Maintain access — Avoid detection — Avoid attribution — No logs - slide 48 of 66 ### Slide 49 Executing arbitrary commands — https://docs.microsoft.com/en-us/connectors/flowmanagement/ - slide 49 of 66 ### Slide 50 Power Automate flow factory handling a createFlow command and returning success or failure - slide 50 of 66 ### Slide 51 Create a flow — List authenticated sessions to use — Delete a flow - slide 51 of 66 ### Slide 52 Power Automate flow factory handling createFlow, deleteFlow, and getConnections commands - slide 52 of 66 ### Slide 53 powerpwn — (persistency v3) — What do we want? — Remote execution — Arbitrary payloads — Maintain access — Avoid detection — Avoid attribution — No logs — Set up your flow factory — Control it though API and a Python CLI - slide 53 of 66 ### Slide 54 DEF CON 30 title card for Low Code High Risk: Enterprise Domination via Low Code Abuse - slide 54 of 66 ### Slide 55 PowerPwn demonstration of a persistent Power Platform backdoor that survives account disablement - slide 55 of 66 - Video: [Embedded video](https://media.mbgsec.com/decks/2023-10-30_OWASP_DC_CREDENTIALSHARINGASASERVICETHEDARKSIDEOFNOCODE/15746fa6/media/powerdoor.mp4) ### Slide 56 Summary — No Code is — Huge in the enterprise — Underrated by security teams — Attackers are taking advantage of it by — Living off the land – account takeover, lateral movement, — PrivEsc — , data exfil — Phishing made easy — Hiding in plain sight — powerpwn — - the latest addition to your red team arsenal — How to defend your org - slide 56 of 66 ### Slide 57 How To Stay Safe — mbgsec.com - slide 57 of 66 ### Slide 58 Protect your org! — Build secure apps - slide 58 of 66 ### Slide 59 Protect your org! — Build secure apps — Don’t overshare — Links —  — mbgsec.com/blog/owasp-dc-links - slide 59 of 66 ### Slide 60 Protect your org! — Build secure apps — Don’t overshare — OWASP LCNC Top 10 — Links —  — mbgsec.com/blog/owasp-dc-links - slide 60 of 66 ### Slide 61 Protect your org! — Build secure apps — Don’t overshare — OWASP LCNC Top 10 — Harden your env — Links —  — mbgsec.com/blog/owasp-dc-links - slide 61 of 66 ### Slide 62 Protect your org! — Build secure apps — Don’t overshare — OWASP LCNC Top 10 — Harden your env — AppSec — Links —  — mbgsec.com/blog/owasp-dc-links - slide 62 of 66 ### Slide 63 Protect your org! — Build secure apps — Don’t overshare — OWASP LCNC Top 10 — Harden your env — AppSec — Hack your env — Links —  — mbgsec.com/blog/owasp-dc-links - slide 63 of 66 ### Slide 64 Protect your org! — Build secure apps — Don’t overshare — OWASP LCNC Top 10 — Harden your env — AppSec — Hack your env — powerpwn — Links —  — mbgsec.com/blog/owasp-dc-links - slide 64 of 66 ### Slide 65 Credential Sharing as a Service closing title slide with Michael Bargury's portrait - slide 65 of 66 ### Slide 66 OWASP 2023 Global AppSec Washington, DC thank-you slide - slide 66 of 66