the magecart threat and how you can
play

The Magecart threat and how you can mitigate the risk to your - PowerPoint PPT Presentation

15:20 15:40 The Magecart threat and how you can mitigate the risk to your organisation Benjamin Sims Founder Tech City Labs #teissamsterdam1 9 MAGECART: HOW TWO HUGE COMPANIES LOST 450,000 CUSTOMERS DETAILS AND HOW YOU CAN STOP IT


  1. 15:20 – 15:40 The Magecart threat and how you can mitigate the risk to your organisation Benjamin Sims Founder Tech City Labs #teissamsterdam1 9

  2. MAGECART: HOW TWO HUGE COMPANIES LOST 450,000 CUSTOMERS’ DETAILS AND HOW YOU CAN STOP IT HAPPENING TO YOU

  3. ABOUT ME Benjamin Sims - Founder of Tech City Labs DATA - Background in data engineering and security - Advise law firms on litigation around hacking, DETECTIVE phishing on fraud cases

  4. ABOUT THIS TALK - Based on public information and (a little) speculation - No inside knowledge - Check out riskiq.com

  5. TICKETMASTER

  6. BRITISH AIRWAYS

  7. WHO DID IT? - ‘Magecart’ - Background in shopping cart hacks - Actually 6 or 7 groups - Card numbers sold on to carding forums in bulk

  8. MORE AND MORE SOPHISTICATED - Deliberate targeting - SSL certificates - Infrastructure designed to blend in - A whole industry: marketplaces, specialist suppliers

  9. DATA LOST Names ● Addresses ● Credit card numbers ● Phone numbers ● CVC codes ●

  10. 3RD PARTY JAVASCRIPT INJECTION:

  11. EVERY WEBSITE AFFECTED 91

  12. THE TICKETMASTER HACK HACK

  13. WHAT IT WAS SUPPOSED TO DO

  14. INCLUDED ON EVERY PAGE ON THE SITE

  15. … AND SOMEBODY HACKED IT

  16. … TO INCLUDE SKIMMER CODE

  17. PEOPLE START TO NOTICE Text May 10th (46 days) April 12th (28 days)

  18. BRITISH AIRWAYS - Targeted attack, script highly modified to work only on ba.com - Hidden in edited version of the open source Modernizr library - Hosted on BA’s *own website* - Most likely the CMS compromised in some way

  19. PEOPLE START TO NOTICE

  20. PEOPLE START TO NOTICE Text: 6th June (73 days)

  21. THEY REALISE… 130 days, 40,000 sets of user details (in the UK)

  22. BRITISH AIRWAYS 14 days... 380,000 customer details taken

  23. MANY MORE

  24. HOW TO AVOID BEING THE NEXT VICTIM? 1. Who can make changes? 2. Who have you trusted? 3. Listen to your users and partners 4. Technical solutions

  25. WHO CAN MAKE CHANGES? MARKETING? DESIGN?

  26. WHO HAVE YOU TRUSTED?

  27. LISTEN WHEN PEOPLE TELL YOU YOU'VE BEEN HACKED

  28. TECHNICAL SOLUTIONS - iFrame sandboxing - source code monitoring - SRI

  29. SRI Magecart don't want you to know this one simple trick! Subresource integrity checking ● W3C recommendation from 2016 ● Supported by 90% of browsers ●

  30. ALL YOU NEED TO DO srihash.org

  31. Available for questions / consulting @techcitylabs benjamin@techcitylabs.com

Recommend


More recommend