Une attaque peut en cacher une autre
François Morris · HAL (Le Centre pour la Communication Scientifique Directe) · 2015
Through studying real but anonymised incidents, we will describe how to respond to an incident and to carry out a digital investigation.In order to illustrate our aim, we will use an example of a defacement that exploited a well-known and relatively old flaw in the SPIP CMS.The analysis will reveal that there were two different attackers, with the second attacking as soon as the first published their defacement.We will show that in many cases, analysis does not require significant resources or a high level of expertise. A simple log search can suffice.We will show that behind what can seem like a relatively benign defacement, the hacker fully compromises the system, hiding backdoors that allow them to re-enter the site with full control. We will describe the tools installed by attackers and how they can be detected.A vulnerability study will show that this is trivial to perform. We will see how lax server settings allowed the hacker, once access had been gained to the first site, to modify the other sites hosted on the same machine.We will state some best practices to limit the risks of such incidents occurring, from applying corrective security measures to tightening settings. We will assess the impacts and consequences of the incident. We will also discuss the legal aspect, involving reporting the incident. Throughout the presentation, we will show that beyond this particular case, the same elements can be found in the many incidents of which we are aware.