15:20 – 15:40 The Magecart threat and how you can mitigate the risk to your organisation Benjamin Sims Founder Tech City Labs #teissamsterdam1 9
MAGECART: HOW TWO HUGE COMPANIES LOST 450,000 CUSTOMERS’ DETAILS AND HOW YOU CAN STOP IT HAPPENING TO YOU
ABOUT ME Benjamin Sims - Founder of Tech City Labs DATA - Background in data engineering and security - Advise law firms on litigation around hacking, DETECTIVE phishing on fraud cases
ABOUT THIS TALK - Based on public information and (a little) speculation - No inside knowledge - Check out riskiq.com
TICKETMASTER
BRITISH AIRWAYS
WHO DID IT? - ‘Magecart’ - Background in shopping cart hacks - Actually 6 or 7 groups - Card numbers sold on to carding forums in bulk
MORE AND MORE SOPHISTICATED - Deliberate targeting - SSL certificates - Infrastructure designed to blend in - A whole industry: marketplaces, specialist suppliers
DATA LOST Names ● Addresses ● Credit card numbers ● Phone numbers ● CVC codes ●
3RD PARTY JAVASCRIPT INJECTION:
EVERY WEBSITE AFFECTED 91
THE TICKETMASTER HACK HACK
WHAT IT WAS SUPPOSED TO DO
INCLUDED ON EVERY PAGE ON THE SITE
… AND SOMEBODY HACKED IT
… TO INCLUDE SKIMMER CODE
PEOPLE START TO NOTICE Text May 10th (46 days) April 12th (28 days)
BRITISH AIRWAYS - Targeted attack, script highly modified to work only on ba.com - Hidden in edited version of the open source Modernizr library - Hosted on BA’s *own website* - Most likely the CMS compromised in some way
PEOPLE START TO NOTICE
PEOPLE START TO NOTICE Text: 6th June (73 days)
THEY REALISE… 130 days, 40,000 sets of user details (in the UK)
BRITISH AIRWAYS 14 days... 380,000 customer details taken
MANY MORE
HOW TO AVOID BEING THE NEXT VICTIM? 1. Who can make changes? 2. Who have you trusted? 3. Listen to your users and partners 4. Technical solutions
WHO CAN MAKE CHANGES? MARKETING? DESIGN?
WHO HAVE YOU TRUSTED?
LISTEN WHEN PEOPLE TELL YOU YOU'VE BEEN HACKED
TECHNICAL SOLUTIONS - iFrame sandboxing - source code monitoring - SRI
SRI Magecart don't want you to know this one simple trick! Subresource integrity checking ● W3C recommendation from 2016 ● Supported by 90% of browsers ●
ALL YOU NEED TO DO srihash.org
Available for questions / consulting @techcitylabs benjamin@techcitylabs.com
Recommend
More recommend