64

MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 2: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

MISSION

Page 3: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

View Targets Location 21“ 84” 12“

cyber satelliteMission View

some text some more text 21“ 84” 12“

top secured locationLocation view

Ground Dok

active

Air Defenseok

active

Space Dok

active

Cyber Dok

active

Mission Impossible CP<R> Mission Plan System**

View targets Location 21“ 84” 12“

Status - OKDefense Systems View

2.G AR BZ ZZ

Level 1 Level 4

Level 2 Level 5

Level 3 Level 6

Target Defenses - Operational

Alert

--------sensitive data---------

WARNING – TOP SECRET

Code view A

Page 4: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 5: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 6: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 7: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 8: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 9: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 10: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 11: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 12: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 13: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 14: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 15: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 16: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 17: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1

Page 18: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1 Victim clicks link

to Login Page2 The hijacked EA Games Page

eaplayinvite.ea.com

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Page 19: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1 Victim clicks link

to Login Page2

EA Gamesmakes request for SSO token

3

The hijacked EA Games Pageeaplayinvite.ea.com

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Page 20: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1 Victim clicks link

to Login Page2

EA Gamesmakes request for SSO token

3

Page redirects to attacker’s

malicious URL.4

The hijacked EA Games Pageeaplayinvite.ea.com

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Page 21: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1 Victim clicks link

to Login Page2

EA Gamesmakes request for SSO token

3

Malicious JavaScript

resends request

for token.

5

The hijacked EA Games Pageeaplayinvite.ea.com Page redirects

to attacker’s malicious URL.4

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Page 22: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

Vulnerable Product 21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Attacker sends victim

malicious link

1 Victim clicks link

to Login Page2

EA Gamesmakes request for SSO token

3

Malicious JavaScript

resends request

for token.

5

The hijacked EA Games Pageeaplayinvite.ea.com Page redirects

to attacker’s malicious URL.4

Token is sent to the

attacker6

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users$5 Billion Revenue

Page 23: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Game ConsoleMission View

21“ 84” 12“

EA GAMESTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

EA GAMES90 Million Users

$5 Billion Revenue

Page 24: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 25: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

DSLR CameraMission View

21“ 84” 12“

Cannon DSLR CameraTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

40% Market Share

20 Million sold Yearly

PTP Support

CANON

DSLR

G.28912 21“ 84” 12“

DescriptionTarget Details

Page 26: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 27: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Provisioning SMSMission View

21“ 84” 12“

Android PhoneTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912G.28912 21“ 84” 12“

DescriptionTarget Details

OTA Provisioning

Samsung/Huawei/LG/Sony

50% of all Android

Provisioning SMS

Page 28: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Provisioning SMSMission View

21“ 84” 12“

Android PhoneTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912G.28912 21“ 84” 12“

DescriptionTarget Details

OTA Provisioning

Samsung/Huawei/LG/Sony

50% of all Android

Provisioning SMS

Page 29: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

Alert – Sensitive Data

21“ 84” 12“

Provisioning SMSMission View

21“ 84” 12“

Android PhoneTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912

MMS Message Server

Browser Homepage

Mail Server

Directory Server

Proxy Server

And More…

G.28912 21“ 84” 12“

DescriptionTarget Details

OTA Provisioning

Samsung/Huawei/LG/Sony

50% of all Android

Provisioning SMS

Page 30: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Provisioning SMSMission View

21“ 84” 12“

Android PhoneTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912G.28912 21“ 84” 12“

DescriptionTarget Details

OTA Provisioning

Samsung/Huawei/LG/Sony

50% of all Android

Provisioning SMS

Page 31: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Provisioning SMSMission View

21“ 84” 12“

Android PhoneTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912G.28912 21“ 84” 12“

DescriptionTarget Details

OTA Provisioning

Samsung/Huawei/LG/Sony

50% of all Android

Provisioning SMS

Page 32: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 33: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

Vulnerability Alert !!

21“ 84” 12“

WinRARMission View

21“ 84” 12“

Archive SoftwareTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912

Proprietary Compression

Algorithm

Created in 1991

MOSTLY Unmaintained

Supported by

WinRAR ONLY21“ 84” 12“

DescriptionTarget Details

500 Million Users

19 Years Old

>30 Supported Types

WinRAR

Page 34: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

WinRARMission View

21“ 84” 12“

Archive SoftwareTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

500 Million Users

19 Years Old

>30 Supported Types

WinRAR

Page 35: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 36: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 37: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 38: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 39: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 40: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 41: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 42: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 43: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

MMC ConsoleMission View

21“ 84” 12“

Management ConsoleTarget View

21“ 84” 12“

DescriptionTarget Details

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

MMC

G.28912

Administrative Tool

Downloadable Addons

Runs on ALL Win>98

Page 44: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

MMC ConsoleMission View

21“ 84” 12“

Management ConsoleTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

MMCAdministrative Tool

Downloadable Addons

Runs on ALL Win>98

Page 45: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

MMC ConsoleMission View

21“ 84” 12“

Management ConsoleTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

MMCAdministrative Tool

Downloadable Addons

Runs on ALL Win>98

Page 46: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 47: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

PXEMission View

21“ 84” 12“

Windows ServerTarget View

21“ 84” 12“

DescriptionTarget Details

Active Directory

/ WDSPre-Boot Execution

Dozens of Flavors

Bundled with ALL

Windows Server

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

PXE

G.28912

Page 48: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

PXEMission View

21“ 84” 12“

Windows ServerTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

Pre-Boot Execution

Dozens of Flavors

Bundled with ALL

Windows Server

PXEActive Directory

/ WDS

Page 49: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

PXEMission View

21“ 84” 12“

Windows ServerTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

Pre-Boot Execution

Dozens of Flavors

Bundled with ALL

Windows Server

PXEActive Directory

/ WDS

Page 50: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

PXEMission View

21“ 84” 12“

Windows ServerTarget View

View Targets Location

Mission Impossible CP<R> Mission Plan System**

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

Pre-Boot Execution

Dozens of Flavors

Bundled with ALL

Windows Server

PXEActive Directory

/ WDS

Page 51: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 52: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

SQLiteMission View

21“ 84” 12“

Embedded DatabaseTarget View

21“ 84” 12“

DescriptionTarget Details

Light Database

“Embedded DB”

1-e12 Installs

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

SQLite

G.28912

Page 53: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

SQLiteMission View

21“ 84” 12“

Embedded DatabaseTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

Light Database

“Embedded DB”

1-e12 Installs

SQLite

Page 54: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

SQLiteMission View

21“ 84” 12“

Embedded DatabaseTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

Light Database

“Embedded DB”

1-e12 Installs

SQLite

Page 55: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 56: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 57: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

OOOPS

Page 58: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 59: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Cloud InfrastructureMission View

21“ 84” 12“

Microsoft AzureTarget View

21“ 84” 12“

DescriptionTarget Details

Workload

Workload

Workload

Workload

Workload

Workload

MS Cloud Solution

Top 3 Cloud I/S

Millions of Users

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

AZURE

G.28912

Page 60: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Cloud InfrastructureMission View

21“ 84” 12“

Microsoft AzureTarget View

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

MS Cloud Solution

Top 3 Cloud I/S

Millions of Users

AZURE

Page 61: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Cloud InfrastructureMission View

21“ 84” 12“

Microsoft AzureTarget View

Workload Workload

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

MS Cloud Solution

Top 3 Cloud I/S

Millions of Users

AZURE

Page 62: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

21“ 84” 12“

Cloud InfrastructureMission View

21“ 84” 12“

Microsoft AzureTarget View

Workload

Workload

Workload

Workload

Workload

Workload

Mission Impossible CP<R> Mission Plan System**

View Targets Location

Vulnerable Product

G.28912 21“ 84” 12“

DescriptionTarget Details

MS Cloud Solution

Top 3 Cloud I/S

Millions of Users

AZURE

Page 63: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to
Page 64: MISSION - community.checkpoint.com€¦ · Mission Impossible * CP * Mission Plan System View Targets Location Attacker sends victim malicious link 1 Victim clicks link to

THE END_CPRESEARCH_

RESEARCH.CHECKPOINT.COM