All talks

BSidesNYC 2023 · 2023/04

Low Code High Risk: Enterprise Domination via Low Code Abuse

Loading presentation…

Read the abstract and transcript

Abstract

Why focus on heavily guarded crown jewels when you can dominate an organization through its shadow IT? Low-Code applications have become a reality in the enterprise, with surveys showing that most enterprise apps are now built outside of IT, with lacking security practices. Unsurprisingly, attackers have figured out ways to leverage these platforms for their gain. In this talk, we demonstrate a host of attack techniques found in the wild, where enterprise No-Code platforms are leveraged and abused for every step in the cyber killchain. You will learn how attackers perform an account takeover by making the user simply click a link, move laterally and escalate privileges with zero network traffic, leave behind an untraceable backdoor, and automate data exfiltration, to name a few capabilities. All capabilities will be demonstrated with POCs, and their source code will be shared. Finally, we will introduce an open-source recon tool that identifies opportunities for lateral movement and privilege escalation through low-code platforms.

Official agenda abstract for this talk, sourced from DEFCON30

Transcript

AI generated from recording.

Introduction to Low‑Code Threat Landscape; Defining Low‑Code and Business User Impact

00:03 Presenter: Those are the apps that business users are building themselves. And we’re going to see

00:08 Presenter: just how far we can take it to really get where we want to be.

00:12 Presenter: So a quick note about myself. I lead an OWASP group dedicated to low code, no code. So that’s

00:20 Presenter: like the top ten for low code, no code apps. If you’re interested, check it out. We have

00:25 Presenter: I have over 200 people that are kind of part of this group already.

00:29 Presenter: I lead a company called Xenity, which is focused on this area.

00:34 Presenter: We’ve been around for something like two years.

00:37 Presenter: And I’ve actually been focused on security for low code for about four years now.

00:42 Presenter: Started off at Microsoft.

00:44 Presenter: I was part of a team there that created a bunch of new products that are around like Defender 4X.

00:52 Presenter: X, so Defender for APIs, Defender for IoT, and others. And also write in dark reading.

00:59 Presenter: If you’re interested in this topic, there’s a bunch more that I’m going to share, more

01:04 Presenter: than today. So reach out or shoot me an email or something.

01:10 Presenter: Okay. A quick disclaimer. Of course, even though this talk is given from an attacker’s

01:15 Presenter: perspective, the idea, the kind of low code is awesome. This thing is really, and we’re

01:22 Presenter: And local is really putting power in the hands of business users,

01:26 Presenter: which are, of course, the people that are kind of the best to move the business forward.

01:31 Presenter: And we’re going to see just how kind of what those people are able to actually create.

01:38 Presenter: But it’s important to do it in a secure way, and that’s why we’re giving this talk.

01:42 Presenter: So here’s what we’re going to do.

01:44 Presenter: This is a quick outline here.

01:46 Presenter: We’re going to start by making sure that we’re all on the same page on what low-code, no-code is,

01:52 Presenter: attacks that were observed in the wild.

01:55 Presenter: We’ll start off with living-of-the-land attacks.

01:57 Presenter: You’ll find that low-code apps, they have compute,

02:00 Presenter: they run on somebody else’s cloud,

02:02 Presenter: they’re really difficult to monitor,

02:03 Presenter: which makes them the perfect thing for living-of-the-land attacks.

02:07 Presenter: We’ll also see a persistency mechanism,

02:09 Presenter: and we’re going to follow an APT group

02:12 Presenter: that actually used Power Automate specifically

02:15 Presenter: as a persistency mechanism.

02:16 Presenter: And then we’re going to see these predictable misconfigurations.

02:20 Presenter: Just think like OpenS3 buckets.

02:22 Presenter: and how long we’ve tried to solve that problem.

02:25 Presenter: So we’re going to see this pop up again here.

02:26 Presenter: And of course, we’ll drop it off with,

02:29 Presenter: A, how you can protect your organization when you go home,

02:33 Presenter: but also a few tools that you can play around with

02:36 Presenter: to just kind of get a feeling of it.

02:40 Presenter: So let’s start with low code.

02:42 Presenter: The number one slide that’s kind of throughout this presentation,

02:47 Presenter: the most important thing you’re going to see today,

02:49 Presenter: is the next slide.

02:50 Presenter: So here it is.

02:52 Presenter: This is a chart that’s representing a single Fortune 500 organization

02:57 Presenter: and the number of applications that were built by their business users using low-code, no-code.

03:03 Presenter: Of course, this is anonymized, and we are seeing this across multiple organizations,

03:07 Presenter: and the numbers could vary, but when you talk about business users building applications,

03:12 Presenter: or in other words, people are calling this citizen development,

03:16 Presenter: this is taking off in a way that’s really unprecedented to what we know

03:23 Presenter: I mean, how many applications are built in your org every year?

03:27 Presenter: A hundred, a thousand if you’re huge, you won’t find 5,000 or 10,000 applications that

03:34 Presenter: were built by professional developers.

03:36 Presenter: That means that everything that relies on manual operations won’t work.

03:41 Presenter: Security reviews won’t work.

Living‑of‑the‑Land Attacks and Misconfigurations

03:43 Presenter: Threat modeling won’t work.

03:44 Presenter: Just kind of vulnerability management, if you need to take a look at all of these different

03:49 Presenter: applications, these won’t work.

03:50 Presenter: We need a new approach here.

03:52 Presenter: this is important. You’re also seeing that this chart goes up very rapidly. This is kind

03:58 Presenter: of just with the proliferation of these tools across the enterprise where more and more

04:02 Presenter: business users are becoming aware of it. Of course, not all of these applications are

04:07 Presenter: huge. Many of them are very small. You can call them micro-ups, but they still have identity.

04:11 Presenter: They still touch data. They can still do operations, so they still pose a risk.

04:16 Presenter: All right. So this is essentially trying to capture why local exists, right?

04:22 Presenter: and this is a perennial problem,

04:24 Presenter: we will never have enough IT resources

04:27 Presenter: to target everything that the business needs.

04:30 Presenter: And also, I mean, things get lost in translation, right?

04:33 Presenter: When somebody from the business needs something done

04:36 Presenter: and they need to get somebody convinced

04:38 Presenter: so they can actually go ahead and build it,

04:41 Presenter: things don’t work properly.

04:43 Presenter: And if this sounds familiar,

04:45 Presenter: like this idea of enabling business users,

04:47 Presenter: if this sounds like not a new thing,

04:50 Presenter: well, it’s not a new thing.

04:53 Presenter: sense forever. If you think about Excel, for example, that’s like the perfect low-code tool,

04:58 Presenter: right? Everybody’s using Excel. I’ve been using Excel across my career. I’ve learned a lot of

05:03 Presenter: things, but Excel has always been there. So, and imagine, and think just how many jobs are

05:08 Presenter: fully focused on Excel, are empowered by Excel. What low-code is trying to do is basically bring

05:16 Presenter: you the next generation of Excel. And when you look at this chart, one of the things that’s

05:20 Presenter: obvious is that the risks

05:22 Presenter: associated with these technologies that

05:24 Presenter: are enabling business users, they

05:26 Presenter: have also been with us

05:28 Presenter: since forever. So Excel

05:30 Presenter: had macros, and macros are, of course, a

05:32 Presenter: problem until today. And so

05:33 Presenter: this is part of a trend.

05:36 Presenter: IT decentralization, giving

05:38 Presenter: more power to the business, to the

05:40 Presenter: people that actually move the business

05:42 Presenter: forward. So what are

05:44 Presenter: people building? So let’s try and

05:46 Presenter: think, let’s try and understand

05:47 Presenter: what are the types of things that these

05:50 Presenter: can be. So they actually, they can be whatever people want them to be. So a lot of them are

05:56 Presenter: these like if this, then that automations. So you take, for example, every time you get

06:01 Presenter: an email, you do something. Every time a file arrives on SharePoint, you send it off to

06:05 Presenter: your private Google Drive. These things are kind of the number one scenario. On top of

06:12 Presenter: that, you’ll find integrations. So one system can talk to another. You’ll find business

06:16 Presenter: applications that are facilitating a specific workflow.

06:20 Presenter: So, for example, at Microsoft, they built their marketing team, built an application

06:25 Presenter: that is used to basically coordinate product launches.

06:29 Presenter: So, everything around product launches is built into this app, built by the marketing

06:33 Presenter: team.

06:34 Presenter: You can find all products that have been built with low code, with professional development

06:38 Presenter: teams, and, of course, mobile apps, there’s a lot of them.

06:43 Presenter: now one thing that you could have at the back of your mind right now that would allow you to

06:48 Presenter: kind of try and escape this uh this talk unharmed is to think that this doesn’t apply to you or that

06:53 Presenter: this doesn’t apply to your organization uh so i’m sorry to be the one to to say this but uh you

06:59 Presenter: don’t have a choice if you’re using any of the top sass platforms today the top enterprise sass

07:05 Presenter: platforms low code is being pushed in you don’t get a choice nobody asks you if you have salesforce

07:11 Presenter: you have ServiceNow, if you have Microsoft, they are, in order to make the platforms more

07:17 Presenter: useful to your business users, the capabilities, the automation, the integration, the application

07:23 Presenter: capabilities are being pushed into those platforms, and you’ll get some of them with a basic license.

07:29 Presenter: That means that in most organizations, it’s already there. I’ve actually never seen an

07:33 Presenter: organization, and we do this engagement a lot where we go kind of partner with someone,

07:38 Presenter: and we look at their environment and we try to see what’s already there,

Persistence via Power Automate and APT Techniques

07:42 Presenter: and they’re like, well, yeah, nobody’s doing citizen development here.

07:45 Presenter: We’re a bank or something like that.

07:47 Presenter: Nobody will ever let business users build their own things.

07:50 Presenter: Well, reality is different.

07:52 Presenter: And so I really encourage you to think of this as something that will happen.

07:57 Presenter: It’s very similar kind of in nature to the way that we had to handle a mobile

08:03 Presenter: or bring your own device, where we had some time we thought

08:06 Presenter: that it might not reach the enterprise.

08:08 Presenter: bring your own device in this org.

08:10 Presenter: Well, today everybody’s doing it, right?

08:12 Presenter: Because there’s no other way.

08:14 Presenter: So it’s really important for us to understand

08:18 Presenter: that this is already something

08:20 Presenter: that our business users have the capability to use.

08:23 Presenter: By the way, this is a good thing.

08:25 Presenter: It’s not a bad thing.

08:26 Presenter: It’s allowing business users

08:28 Presenter: to actually produce more value to your organizations.

08:32 Presenter: So a quick recap.

08:35 Presenter: Low code is available in every major organization,

08:38 Presenter: just saw this. Because these platforms are the platforms that hold your business data,

08:43 Presenter: so imagine your office, your Microsoft 365, your Salesforce, then by definition it has

08:49 Presenter: access to business data and it is able to do business operations. It also powers business

08:54 Presenter: processes because business users are building it to facilitate their operations. It runs

08:59 Presenter: as SaaS and we all know that it makes it challenging to monitor and to control. And as most of

09:08 Presenter: pretty underrated by IT and security teams.

09:10 Presenter: The things that business users

09:12 Presenter: are building, we’re used to think about

09:14 Presenter: them as toys,

09:17 Presenter: as something that they use for their own personal

09:18 Presenter: use. That’s really not the reality

09:20 Presenter: today, and we’ll see…

09:22 Presenter: And one of the largest

09:24 Presenter: things that happened in the last couple

09:26 Presenter: of months, of course, with the introduction of

09:28 Presenter: things like ChatGPT into

09:30 Presenter: low-code, is that business apps

09:32 Presenter: have become even easier to build.

09:35 Presenter: So today, instead of

09:36 Presenter: writing a prompt that will give you

09:38 Presenter: an answer, you can write a prompt that will build an app.

09:41 Presenter: This is actually available in Microsoft 365 today.

09:45 Presenter: And so the number of apps, of course, only gets bigger.

09:49 Presenter: All right.

09:50 Presenter: So we’ve gone through the kind of intro section.

09:58 Presenter: One last thing I want all of us to make sure that we get correctly.

10:05 Presenter: Is this better?

10:09 Presenter: All right.

10:10 Presenter: I’m going to lean in.

10:12 Presenter: Okay.

10:13 Presenter: So we went through the intro.

10:16 Presenter: But one thing that I want us to make sure is that we understand,

10:20 Presenter: we have an intuitive understanding of what these applications are.

10:23 Presenter: And I also want to make sure that you’re convinced that everybody can build these applications.

10:27 Presenter: So let me show you an example.

10:30 Presenter: And hopefully this will work.

10:34 Presenter: All right.

10:35 Presenter: So, yeah, you probably, maybe you’ll see something in a moment.

10:40 Presenter: But while this is working, let me share what I’m actually building here.

10:45 Presenter: So we’re using Slack in my company, and there’s this annoying thing about Slack where if you mention someone on a public channel,

10:52 Presenter: then if somebody mentions you, then they expect you to answer pretty quickly, which is, I mean, this is kind of annoying.

11:01 Presenter: But I’ve noticed that if you have this small icon next to your name that says that you’re on a call,

11:06 Presenter: then they’re fine.

11:07 Presenter: They won’t nudge you.

11:08 Presenter: So here’s the automation.

11:10 Presenter: Every time I get mentioned on Slack, I’m going to change my status as if I’m on a call.

11:16 Presenter: So people won’t bother me.

11:18 Presenter: And five minutes later, I’m going to change the status back to free so nobody will be suspicious.

11:24 Presenter: And so this is a small automation that I’m building.

11:27 Presenter: And while I’m building it, you can see that I’m dragging and dropping.

11:31 Presenter: I’m choosing, I had to choose a specific account on Slack that I’m going to use.

11:35 Presenter: This demo is actually showing you Zapier.

11:39 Presenter: So it’s able to go to the Slack API.

11:42 Presenter: Think about kind of the complexities of this application.

11:45 Presenter: It needs to subscribe to Webhook.

11:47 Presenter: It needs to reach out to the API afterwards.

11:50 Presenter: That five-minute wait period means that there’s some sort of state.

11:53 Presenter: It needs to wait, right?

11:57 Presenter: I’m building this, I mean, there’s nothing sophisticated here on the builder side.

12:02 Presenter: This takes me about two minutes to build this application.

Exfiltration and Ransomware with No‑Code Tools

12:05 Presenter: And I want you to notice a couple of things.

12:08 Presenter: One is that in no point in this, while building this application, do I need to provide access

12:14 Presenter: to Slack.

12:16 Presenter: So how does this work?

12:18 Presenter: How does Zapier connect to my Slack account?

12:20 Presenter: We’ll see that in a moment.

12:21 Presenter: And the other thing is, think about the SDLC and compare it to what you’re seeing on screen.

12:27 Presenter: Right? There’s no SDLC here, right? I’m just building something, and once I click save, it will be deployed in production. And by the way, some platforms also auto-save. So any change that you make is automatically being pushed.

12:44 Presenter: And if you think about this as for a critical process,

12:49 Presenter: then think about all of the things that you lose by not having an SDLC, right?

12:54 Presenter: There’s no review.

12:55 Presenter: There’s no security gates.

12:57 Presenter: Kind of forget about shift left.

12:59 Presenter: Okay.

13:00 Presenter: So you just saw that I got kind of this little icon there.

13:03 Presenter: I’m publishing this app.

13:04 Presenter: That’s it.

13:04 Presenter: It’s operational.

13:05 Presenter: And now I’m kind of demoing that it works.

13:08 Presenter: So, again, this was just a couple of minutes.

13:10 Presenter: But you understand just how powerful this application is.

13:16 Presenter: So the number one thing that’s important to us is the identity.

13:19 Presenter: And actually, before I created this application,

13:22 Presenter: I’ve gone through a very small process,

13:25 Presenter: which is called creating a connection.

13:28 Presenter: So what is a connection?

13:29 Presenter: A connection is basically an OA of consent flow for Slack in this case.

13:35 Presenter: And you can see the regular OA of consent flow

13:37 Presenter: that’s asking me for specific permissions.

13:39 Presenter: I can choose a bunch of applications.

13:41 Presenter: These platforms have gone built in with hundreds of different connectors.

13:44 Presenter: Once I go through the OAuth consent flow,

13:46 Presenter: I get this object created which is called the connection.

13:50 Presenter: Okay, what’s important about this connection?

13:52 Presenter: It has this little share button.

13:55 Presenter: This is weird.

13:56 Presenter: It’s an OAuth, I went through an OAuth flow,

13:59 Presenter: I granted consent for Zapier to act on my behalf,

14:02 Presenter: and then I can share that consent,

14:04 Presenter: I can share that thing, that connection,

14:07 Presenter: that active connection with other users.

14:10 Presenter: How does it work?

14:12 Presenter: Okay, on one side we have Zapier or Power Automate or any other automation platform.

14:17 Presenter: This is not picking on a specific vendor.

14:18 Presenter: The entire industry is doing the same thing, and I’ll tell you in a moment why.

14:22 Presenter: The other side, you have REST APIs.

14:25 Presenter: By the way, this could also be your on-prem, your cloud, anything.

14:31 Presenter: Okay, how does it work?

14:33 Presenter: Well, essentially, what they’re doing there is that they are taking the refresh tokens out of the OAuth consent flow,

14:41 Presenter: are allowing you to share those refresh tokens

14:43 Presenter: with other users.

14:45 Presenter: Okay, think about what this means.

14:47 Presenter: This is completely breaking the permission model,

14:50 Presenter: completely breaking the OAuth model,

14:52 Presenter: because this is a user impersonation by design.

14:55 Presenter: The application is impersonating the user,

14:57 Presenter: and you are impersonating the user

14:59 Presenter: when you share those connections with other users.

15:01 Presenter: And so by storing these refresh tokens

15:04 Presenter: and then reusing them,

Credential Sharing and Impersonation in Low‑Code Platforms

15:05 Presenter: you are able to, A, kind of bypass anything that,

15:11 Presenter: personality in the user, but also think about the productivity benefit.

15:14 Presenter: No more asking for permissions.

15:16 Presenter: You can build whatever app you’d like with your own permissions.

15:20 Presenter: As long as you can do it as a user, you can build an app that automates it.

15:23 Presenter: This is very different from your experience as a professional developer, right?

15:27 Presenter: As a developer, you need to ask for permission.

15:29 Presenter: You have an application.

15:30 Presenter: It has a service account or something like that.

15:32 Presenter: Not here.

15:33 Presenter: I mean, you can do it, but in many cases, you don’t.

15:36 Presenter: Now, because you’ve seen the chart with so many applications,

15:43 Presenter: and it’s so easy to create those applications,

15:46 Presenter: then you get a whole bunch of applications.

15:48 Presenter: And these are just examples from templates provided by the different vendors.

15:54 Presenter: The important thing about this is the logos next to the names of these applications.

15:59 Presenter: Why are the logos important?

16:01 Presenter: because that means that there’s an active connection

16:04 Presenter: to each one of these systems.

16:06 Presenter: So when you have lots of different applications

16:07 Presenter: behind each application,

16:09 Presenter: there is a trail of connections,

16:11 Presenter: connections that can be shared,

16:12 Presenter: connections that can be overused.

16:13 Presenter: And so when you look at each one of these platforms,

16:17 Presenter: what you’ll typically find

16:18 Presenter: is some notion of a default environment,

16:21 Presenter: somewhere where everybody can go into this platform,

16:24 Presenter: they can create applications, automations, connections,

16:27 Presenter: and they can share them with others.

16:31 Presenter: is one click away.

16:32 Presenter: In some platforms, in some cases,

16:33 Presenter: it can be shared with the entire org by default.

16:36 Presenter: And when I say the entire org,

16:38 Presenter: I mean everybody, for example,

16:40 Presenter: everybody in your Azure AD tenant.

16:42 Presenter: So that includes guests, by the way,

16:44 Presenter: or contractors and vendors.

16:46 Presenter: So when you go into one of those platforms,

16:49 Presenter: again, they are basically providing you

16:51 Presenter: credential sharing as a service, right?

16:54 Presenter: Which bypasses the entire security mechanism.

16:56 Presenter: Think about the SOC,

16:57 Presenter: trying to figure out what’s the difference

17:01 Presenter: using your refresh token and yourself.

17:03 Presenter: I mean, it’s just, it’s very difficult.

17:05 Presenter: Now, of course, once we have that,

17:08 Presenter: then you can see the first attack here,

17:10 Presenter: which is just kind of privilege escalation.

17:12 Presenter: This is basic.

17:14 Presenter: So the end result here

17:16 Presenter: is that when I have a single account in your org,

17:20 Presenter: again, this can be a guest account as well,

17:22 Presenter: and I go to each one of those platforms,

17:24 Presenter: there’s a bunch of connections

17:25 Presenter: that are waiting for me to pick them up and use them.

17:27 Presenter: You’ll find FTP connections,

17:31 Presenter: to people’s outlook and teams.

17:33 Presenter: You’ll find connections to people’s cloud environment,

17:36 Presenter: Azure and AWS and GCP.

17:39 Presenter: So this is a lot.

17:42 Presenter: Now, other than just using those connections,

17:47 Presenter: other than just kind of getting those connections

17:49 Presenter: and being able to escalate your privileges,

17:51 Presenter: you can also just use those connections

17:53 Presenter: to actually get what you want.

17:55 Presenter: So for example, here’s one ransomware built with no code.

18:01 Presenter: I’m iterating, so I click a button,

18:05 Presenter: and then I’m iterating over a SharePoint site.

18:07 Presenter: For each file in that SharePoint site,

18:08 Presenter: I’m going to encrypt that file

18:10 Presenter: using a handy encrypted function

18:12 Presenter: provided by the platform, right?

18:14 Presenter: Because there are valid business use cases

18:15 Presenter: to encrypt files.

18:16 Presenter: And then I’m going to simply override the file

18:20 Presenter: with the encrypted version.

18:22 Presenter: So ransomware, again, using no-code tools

18:25 Presenter: and just, again, think about all of the protections

18:27 Presenter: you have in your org targeting ransomware

18:31 Presenter: they won’t really find this.

18:34 Presenter: And we’ll see in a moment how this goes well beyond SaaS.

18:38 Presenter: Here’s another example.

18:40 Presenter: This one is, I think, in almost every organization I’ve worked with,

18:44 Presenter: I’ve seen this example in some form or another.

18:47 Presenter: We’ve tried to block business users or users in general

18:51 Presenter: from using their own personal accounts in a work context.

18:56 Presenter: I mean, we’re all guilty of that as well, right?

18:57 Presenter: or everybody wants their calendar events in their personal Gmail.

19:01 Presenter: There are solutions to do that.

Misconfigurations and Open‑S3/Power Pages Exploits

19:03 Presenter: You can use DLP.

19:05 Presenter: You can do something on the email server.

19:07 Presenter: A bunch of things you can do.

19:08 Presenter: But what if the business user creates an app that on one side connects to their corporate email

19:15 Presenter: and on the other side with a separate connection connects to their own Gmail account

19:21 Presenter: and simply copies the content?

19:23 Presenter: The content is being copied on the SaaS vendor’s cloud

19:28 Presenter: So no network security appliance will help you there

19:32 Presenter: No monitoring will help you there

19:33 Presenter: The only thing you can do is look at the platform itself

19:36 Presenter: Because it’s the only one that’s aware that this application even exists

19:39 Presenter: Now, you’re seeing here an example of email exfiltration

19:42 Presenter: And again, this is very common

19:44 Presenter: But we’ve seen this with other things as well

19:46 Presenter: So syncing up a corporate drive with a personal drive

19:52 Presenter: By mistake, I mean, they build an application that other business users are starting to use.

19:58 Presenter: It’s useful.

19:58 Presenter: And it uses, for example, an Excel spreadsheet as a database.

20:02 Presenter: But where is that Excel spreadsheet stored?

20:05 Presenter: Because as easily as you can plug in your corporate account, you can plug in your personal account, and that’s it.

20:09 Presenter: And the application is, the database behind the application is being stored in your personal account.

20:15 Presenter: Here’s a thing that’s kind of very non-trivial.

20:19 Presenter: you can jump to people’s laptops through these platforms.

20:24 Presenter: Because there’s a component or a version of low-code

20:27 Presenter: that’s called RPA, robotic process automation,

20:29 Presenter: which is basically about emulating the mouse and the keyboard,

20:32 Presenter: the inputs by the user on the user’s own machine.

20:36 Presenter: And it’s a type of automation that’s used for legacy systems

20:40 Presenter: that don’t have a proper API.

20:42 Presenter: Now, again, imagine a SOC analyst trying to distinguish

20:46 Presenter: a bot that’s doing that and a user that’s doing that.

20:49 Presenter: is a bot that’s running on a user context. Now, these connections allow you to send a payload,

20:55 Presenter: or in the world of a platform, like a task, from cloud to somebody’s laptop and run it on somebody’s

21:03 Presenter: laptop. And actually, at last DEF CON, I showed how these exact capabilities by Microsoft can be

21:10 Presenter: used to create malware with no code and with completely trusted services and executables.

21:19 Presenter: into every Windows 11 machine.

21:21 Presenter: So if you have Windows 11, open it up,

21:24 Presenter: search for Power Automate, you’ll find it.

21:27 Presenter: It’s trivial for an attacker to subscribe,

21:31 Presenter: to attach the Power Automate instance

21:34 Presenter: you have on your laptop to their own malicious cloud.

21:36 Presenter: And from then on out, they can send payloads

21:39 Presenter: to your machine through trusted channels

21:42 Presenter: facilitated by Microsoft.

21:44 Presenter: So if you’re looking for network IOCs,

21:47 Presenter: these would be Microsoft domains.

21:49 Presenter: you’re looking for executables, this would be Microsoft executables, right? Now, again, this is

21:54 Presenter: not picking on Microsoft. This is a problem with this entire space where impersonating the user is

21:59 Presenter: kind of the mainstream. All right. So the one thing that we wanted to do in order to make it easier

22:06 Presenter: for you to check kind of your own status and also to play around with this is to give you a tool

22:11 Presenter: that you can work with. So this is a tool that’s available right now. You can check it out on

22:17 Presenter: GitHub. Basically, it’s

22:19 Presenter: very simple. It’s using the Zapier

22:21 Presenter: unofficial API

22:22 Presenter: to provide you with all of the connections that

22:25 Presenter: are available to a specific user.

22:27 Presenter: So you give it access to a specific user, and

22:29 Presenter: we show you all of the connections that

22:31 Presenter: this user can use, and who

22:33 Presenter: created those connections, and

22:34 Presenter: where are they leading.

22:36 Presenter: We are working on similar tools for other platforms

22:39 Presenter: as well. So if you’re interested,

22:41 Presenter: start the repo. You’ll

22:42 Presenter: get the notifications.

22:44 Presenter: All right.

22:45 Presenter: So the next thing I want to do is a bit more sophisticated.

22:49 Presenter: One of the, up until now, we were focused on a scenario where these connections already exist.

22:55 Presenter: But what if I want to entice the user to make user create those connections for us?

23:00 Presenter: Essentially, here’s the idea.

23:01 Presenter: I’m going to build an application that’s useful inside an org.

23:04 Presenter: Let’s say I have an account for somebody inside an org.

23:08 Presenter: Again, could be a guest.

23:09 Presenter: And then I want to get to the, I don’t know, to the CEO.

23:14 Presenter: that the CO would like to use.

23:15 Presenter: And then once the application is running,

23:20 Presenter: I can do whatever I want with the connections provided to me.

23:23 Presenter: And then I will, alongside doing the thing

23:28 Presenter: that is expected of this application to do,

23:30 Presenter: I’m just going to steal the account.

23:32 Presenter: So I’m going to continue to describe it while I do it.

23:36 Presenter: So again, you’ll get a notion of just how easy it is.

23:39 Presenter: But essentially, this thing is not new.

23:44 Presenter: when a user logs into an application,

23:47 Presenter: the application can do whatever it wants

23:49 Presenter: with the permissions that the user has provided.

23:51 Presenter: This is not new.

23:53 Presenter: However, this is the first time

23:55 Presenter: that somebody from HR can do it,

23:56 Presenter: that a guest can do it,

23:57 Presenter: that anybody in the org can do it.

23:59 Presenter: And more than that,

24:00 Presenter: when these applications run,

24:02 Presenter: they are not telling the user,

24:05 Presenter: hey, here’s the list of permissions

24:06 Presenter: we’re going to use on your behalf.

24:08 Presenter: They’re telling them,

24:09 Presenter: hey, give me a connection to Outlook.

24:10 Presenter: What do you think are the permissions

24:12 Presenter: behind that connection?

Defense Strategies and OWASP Low‑Code Guidance — Part 1

24:13 Presenter: Everything in Outlook, right?

24:15 Presenter: Everything in Teams, everything in everywhere else.

24:18 Presenter: So this specific application that I’m building right now,

24:20 Presenter: I just took off a random application from the marketplace.

24:25 Presenter: This is an application for an out-of-office,

24:27 Presenter: to facilitate out-of-office,

24:29 Presenter: so it will auto-decline calendar events for you.

24:33 Presenter: And so it needs access to your email.

24:35 Presenter: So what I’m doing here right now

24:37 Presenter: is just typing a single line of code

24:40 Presenter: that will use this connection

24:41 Presenter: to send an email on the person’s behalf

24:43 Presenter: my account saying I’ve been pwned.

24:45 Presenter: Now, of course, I could have done lots of other things,

24:48 Presenter: but the crucial piece here is that there’s no way

24:51 Presenter: for the user to know what I’m actually doing

24:53 Presenter: with their account because they’re providing me

24:54 Presenter: with a connection, which essentially is an asterisk

24:57 Presenter: over all of the permissions for that specific application.

25:01 Presenter: Now, I’ve created this application.

25:02 Presenter: I’m publishing it.

25:04 Presenter: You’ll note it’s difficult to see,

25:05 Presenter: but if you can see the URL, what you’ll spot

25:09 Presenter: is that this application is going to be hosted

25:11 Presenter: on a Microsoft domain.

25:14 Presenter: creating an internal phishing campaign

25:16 Presenter: where all I need to do in order

25:18 Presenter: to get somebody’s

25:20 Presenter: account is to get them to click

25:22 Presenter: on a link that is facilitated by

25:24 Presenter: Microsoft to log in with their own corporate account,

25:26 Presenter: which is something they will be used to

25:28 Presenter: doing because they’re using these kind of applications,

25:30 Presenter: and then I will do whatever I

25:32 Presenter: want with their connection.

25:34 Presenter: Alright, then you can see

25:35 Presenter: that once a user

25:37 Presenter: connects to it, I get the email that I’ve been

25:39 Presenter: pwned. Now, the number

25:41 Presenter: one thing that is

25:44 Presenter: only constraint here in this

25:46 Presenter: entire kind of internal phishing campaign

25:49 Presenter: is this

25:50 Presenter: window. When a user

25:52 Presenter: uses the app, they get

25:54 Presenter: prompted with this window that is

25:56 Presenter: telling them, hey, this application is going

25:58 Presenter: to use these connections.

26:00 Presenter: Again, notice that this is

26:02 Presenter: not the O of consent flow. You’re not seeing

26:04 Presenter: the permissions that I’m asking for. You’re just

26:06 Presenter: seeing the services.

26:08 Presenter: If I get rid of

26:10 Presenter: this window, if this window

26:13 Presenter: I’ve reached a point where I can create an internal phishing campaign

26:19 Presenter: that requires a user to click a link provided by Microsoft, and that’s it.

26:24 Presenter: So this would be very bad, right?

26:26 Presenter: This shouldn’t happen.

26:29 Presenter: Unfortunately, it’s an option provided by the platform.

26:33 Presenter: So there’s actually a valid reason to do this.

26:37 Presenter: So because business users could be used to using those applications,

26:41 Presenter: and then you don’t want to create hurdles for them to actually do it,

26:43 Presenter: So some organizations are choosing to remove this consent window, which is, of course, very dangerous.

26:50 Presenter: If you’re a Microsoft shop, I strongly encourage you to make sure that this flag is off.

26:56 Presenter: All right.

26:57 Presenter: So we’re done with the living of the land stuff.

27:00 Presenter: The next thing I want to show you is persistency.

27:04 Presenter: And this is actually pretty interesting because what we’re going to do is we’re going to follow through footsteps of an APT group

27:11 Presenter: that used Power Automate, Microsoft automation feature inside of Office,

27:15 Presenter: to remain persistent within an organization.

27:18 Presenter: And basically what happened there, the name of the organization wasn’t disclosed,

27:22 Presenter: but what happened there is that there were a few different malware families in this organization,

27:28 Presenter: so they knew they were breached, they were looking for more infections,

27:32 Presenter: and the investigative team took about six months to find that this automation was actually active,

27:41 Presenter: code. And what is actually automation, and what happened is that the attackers, they

27:46 Presenter: were able to gain access to an admin’s account. And then, I mean, the next logical step is

27:51 Presenter: typically kind of installing malware, moving laterally through the network, right? So they

27:55 Presenter: didn’t do all of that. Instead, they created a single automation. This automation ran on

28:00 Presenter: a schedule, and every day it used the e-discovery feature, form office, to find secrets and PII

28:07 Presenter: inside of the organization

28:08 Presenter: and just send it off to a random endpoint,

28:11 Presenter: to a specific exfiltration endpoint.

28:13 Presenter: This simple automation was there for six months

28:15 Presenter: without anybody noticing,

28:17 Presenter: because again, how would you notice?

28:19 Presenter: You don’t have logs for this.

28:20 Presenter: You don’t know this is impersonating your user,

28:24 Presenter: and this is also not something you would typically expect.

28:27 Presenter: So let’s try to rebuild this on our own.

28:31 Presenter: Here’s a very rudimentary version.

28:34 Presenter: on a recurrence, I’m going to go to a specific SharePoint site.

28:39 Presenter: I’m going to loop through all of that SharePoint site.

28:42 Presenter: I’m going to encrypt each and every file,

28:45 Presenter: dump them to a random HTTP endpoint,

28:47 Presenter: and then tweet about it, because why not?

28:49 Presenter: I mean, nobody will catch me.

28:51 Presenter: Okay, so this is actually what the attacker did,

28:55 Presenter: but let’s take it up kind of a few steps forward.

28:59 Presenter: One thing that I want to do is I want to have the capability

29:04 Presenter: whenever I want.

29:05 Presenter: And I want this capability to be detached from the fact

29:09 Presenter: that I still have a user to that organization.

29:11 Presenter: So instead of doing this on a schedule,

29:13 Presenter: I can create an HTTP webhook, an HTTP endpoint

29:16 Presenter: that would allow you that every time I hit that endpoint,

29:20 Presenter: this automation will run.

29:21 Presenter: And these endpoints typically use some sort of a hardcoded

29:25 Presenter: string as their secret.

29:26 Presenter: So you can connect to it from anywhere.

29:28 Presenter: We don’t have to be authenticated.

29:29 Presenter: So again, this is very easy.

29:31 Presenter: And this is a snapshot from a different platform,

29:35 Presenter: Okay, so you see where I’m going with this.

29:37 Presenter: I’m going to try and create a more sophisticated persistency mechanism.

29:41 Presenter: So here’s a laundry list of all of the things that I would like to do.

29:44 Presenter: So for full persistency, I would like to have the ability to run code remotely.

29:52 Presenter: That’s obvious.

29:53 Presenter: I’d like to be able to run arbitrary payloads, not just one payload like you’ve seen a moment ago.

29:58 Presenter: So I’d like to be able to maintain access even if the user is revoked or deleted or whatever.

30:05 Presenter: Of course, avoid detection, avoid attribution, and I want to leave no logs behind.

30:10 Presenter: The question is, can I do this with low code?

30:14 Presenter: Okay, so this is the first version.

30:16 Presenter: We’ve already seen this.

30:17 Presenter: This is basically a persistency mechanism, this HTTP endpoint.

30:22 Presenter: Let’s see what it covers and what it doesn’t cover.

30:25 Presenter: So it does cover remote execution, right?

30:28 Presenter: I execute it remotely.

30:30 Presenter: This is a single payload, so we don’t get arbitrary payloads.

30:35 Presenter: I can maintain access.

30:36 Presenter: You can see the, well, you might be able to see,

30:39 Presenter: the URL with the hard-coded secret there that allows me to actually go to this endpoint and trigger it.

30:46 Presenter: Avoiding detection, this is somebody else’s cloud.

30:48 Presenter: You don’t get logs on this endpoint.

30:50 Presenter: I mean, unless you’re very sophisticated and try to do something kind of, well, not out of the box anyway.

30:59 Presenter: Avoiding attribution is easy

31:00 Presenter: because you can just call this root door.

31:02 Presenter: I mean, nobody’s blocking you.

31:03 Presenter: There’s nothing protecting.

31:04 Presenter: There’s typically nothing sophisticated

31:06 Presenter: protecting this endpoint.

31:08 Presenter: And no logs, well, not at all.

31:11 Presenter: These platforms can generate a whole bunch of logs

Defense Strategies and OWASP Low‑Code Guidance — Part 2

31:13 Presenter: for each application,

31:14 Presenter: for each execution of those automations.

31:17 Presenter: This is actually a problem in and of itself

31:19 Presenter: because the platforms can log actually the data

31:22 Presenter: that goes through these automations.

31:24 Presenter: So let’s see if we can do something better.

31:26 Presenter: Here’s a second attempt.

31:28 Presenter: So instead of having an HTTP endpoint

31:31 Presenter: that’s going to use one payload,

31:33 Presenter: I’m just, I’ve created a bunch of payloads here.

31:36 Presenter: You can see leak SharePoint,

31:40 Presenter: ransomware SharePoint,

31:41 Presenter: execute a SQL stored procedure somewhere

31:43 Presenter: so you get the point.

31:44 Presenter: I can do whatever I want here with this.

31:47 Presenter: But again, I didn’t really solve anything,

31:49 Presenter: not the arbitrary payloads and not the logs.

31:51 Presenter: So let’s try and see how we can solve

31:53 Presenter: everything we wanted.

31:55 Presenter: Now the crucial piece in order to do this

31:58 Presenter: would be something which is the management features of those local platforms.

32:05 Presenter: So if you are trying to manage a local platform,

32:10 Presenter: what would be the best technology for you to do it with?

32:14 Presenter: Well, local, right?

32:15 Presenter: So you can build local applications to manage the local platforms themselves,

32:21 Presenter: which would require this interface, which is about management of these applications.

32:28 Presenter: to use the Power Automate Management connector,

32:31 Presenter: which allows me to create automations,

32:34 Presenter: delete automations, execute automations, et cetera.

32:37 Presenter: So here’s a new tool I’m going to introduce to you today.

32:40 Presenter: What it’s going to do is install a backdoor

32:43 Presenter: within an organization, within the Power Automate instance,

32:46 Presenter: if they’re using Microsoft, which is kind of

32:48 Presenter: most organizations, and it will allow you to basically send

32:52 Presenter: every payload imaginable, execute it,

32:59 Presenter: Here’s how it works.

33:00 Presenter: It has a single HTTP endpoint, which it installs.

33:04 Presenter: Behind that HTTP endpoint, I’m going to send the definition of the automation I’d like to build.

33:13 Presenter: So here’s an automation.

33:15 Presenter: Here’s like a JSON file I need to send with all of the details about this automation.

33:20 Presenter: What this tool is actually going to do is it’s going to create the automation, run the automation,

33:25 Presenter: and then delete the automation along with all of the logs of that specific automation.

33:31 Presenter: And it’s going to do this one after the other.

33:33 Presenter: Of course, the tool also provides some convenience mechanisms for you.

33:36 Presenter: So we will handle errors and a whole bunch of things that you don’t need to worry about it.

33:41 Presenter: So this is the final kind of automation that this tool will install on your target.

33:48 Presenter: And here’s a kind of nice Python script around it because, well, we don’t,

33:52 Presenter: where hackers or retimers usually prefer code to drag and drop.

33:58 Presenter: So you can use this.

33:59 Presenter: Again, this is what it does, what I just explained.

34:03 Presenter: It also allows you to continuously iterate through those connections,

34:07 Presenter: those existing connections.

34:08 Presenter: So if you’d like to use one of them, you can do it.

34:11 Presenter: Now, of course, the idea behind this kind of project

34:17 Presenter: is just to give you the tools

34:19 Presenter: so you can show inside of your organization just how risky this thing is

34:24 Presenter: and try to measure whether your defenses will help you here.

34:28 Presenter: So this is a tool to help you calibrate your defenses

34:31 Presenter: and also kind of get the mind show that you need to invest in this space.

34:39 Presenter: All right.

34:39 Presenter: So in terms of our laundry list, remote execution, well, of course,

34:44 Presenter: arbitrary payloads, I can send whatever automation I’d like here.

34:47 Presenter: So this is everything that can be done with Power Automate, but trust me, it’s a pretty powerful platform.

34:54 Presenter: You can maintain access, of course.

34:57 Presenter: This is an HTTP endpoint.

34:58 Presenter: Avoid detection and attribution.

35:00 Presenter: We’ve talked about it.

35:01 Presenter: And logs, the main problem here is that once I delete the automation, the logs get deleted as well.

35:06 Presenter: So that leaves it at that.

35:10 Presenter: Okay.

35:10 Presenter: Okay, so we’ve seen how, and again, this went far and beyond what the APT group exactly did,

35:18 Presenter: but this was nothing sophisticated, right?

35:21 Presenter: Everything was kind of very basic.

35:23 Presenter: All right, so the last type of attacks I’d like to do, to show you today,

35:28 Presenter: is attacks that require nothing from the get-go,

35:31 Presenter: because everything I’ve shared up until now required some sort of initial access into an enterprise.

35:37 Presenter: Some account, could be a guest account, could be a low-privileged account,

35:40 Presenter: but it requires something.

35:41 Presenter: Now, what can I do with no access at all?

35:45 Presenter: So this is the world of kind of misconfiguration.

35:49 Presenter: And the number one thing you can think of,

35:52 Presenter: which I talked about at the beginning of this talk,

35:55 Presenter: was the OpenS3 bucket for AWS,

35:58 Presenter: which we’ve tried to solve for many years now.

36:00 Presenter: So AWS has actually this year produced some capabilities

36:04 Presenter: that are actually helping with this.

36:06 Presenter: But even if the default is fine,

36:10 Presenter: bucket with everybody, people can still make mistakes, right? So we’re going to see how this

36:15 Presenter: pops up again in low code. Let’s start with Microsoft. Microsoft has some, as an application,

36:21 Presenter: a type of application, a type of low code applications called PowerPorders or PowerPages.

36:26 Presenter: This is a low code application that is, that with the intention of being available to everybody on

36:33 Presenter: the internet. This is simply a website. And you use this, for example, for contractors that are

36:37 Presenter: arriving physically into your org, or people that are outside of your organization, they

36:43 Presenter: can register, they can view resources.

36:45 Presenter: Some resources in these websites are for administrators only, for example, but some of them are for

36:51 Presenter: everyone.

36:52 Presenter: So essentially, this is a website.

36:54 Presenter: It has a managed SQL server behind the scenes wrapped with an API.

36:58 Presenter: And so this, and one of the key features about, and this is how it looks like, it’s like a

37:03 Presenter: very rudimentary website.

37:05 Presenter: One of the key features that this type of application creates for you is an API endpoint.

37:11 Presenter: You can spot it here.

37:12 Presenter: Replace portal with your own portal name.

37:14 Presenter: This API endpoint is always created for your portals.

37:18 Presenter: And it allows you to use the basically REST API to query everything behind the application.

37:26 Presenter: Of course, you should need to be authenticated in order to use this API.

37:32 Presenter: API. However, there are cases

37:34 Presenter: where you want data to be available to

37:36 Presenter: anonymous users. So users have just

37:38 Presenter: entered their website for the first time.

37:40 Presenter: You need them to be able to, I don’t know,

37:42 Presenter: query images or something. So this

37:44 Presenter: needs to be a possibility, and so this

37:46 Presenter: endpoint is available to anonymous users

37:48 Presenter: as well. Alright.

37:49 Presenter: About a year and a half ago, the team

37:52 Presenter: at AppGuard discovered that the

37:53 Presenter: default setting for PowerPortal

37:56 Presenter: was for everything

37:57 Presenter: in the database to be available through this endpoint

38:00 Presenter: to anonymous users. Everything.

38:02 Presenter: Everything that is kind of administrative resources, everything.

38:05 Presenter: And this was the case for several years.

38:07 Presenter: By the way, I’m not sure that this is the case,

38:12 Presenter: but about six months later,

Defense Strategies and OWASP Low‑Code Guidance — Part 3

38:13 Presenter: Microsoft did a rebranding of Power Portals to Power Pages

38:17 Presenter: with a high push on security,

38:20 Presenter: and they actually have done some work pretty quickly

38:23 Presenter: to change the default here

38:24 Presenter: and to help customers identify misconfigurations.

38:27 Presenter: But still, of course, people make mistakes.

38:30 Presenter: so one of the things we wanted to see

38:33 Presenter: is how many of these mistakes can we find

38:36 Presenter: and so here’s our goal

38:38 Presenter: we’re going to try to find misconfigurations

38:41 Presenter: misconfigured portal that expose these endpoints

38:44 Presenter: and this is a real example of a request

38:47 Presenter: of the response that you get when you query this endpoint

38:50 Presenter: you can see that this is basically a list of tables that I can query

38:53 Presenter: default has nothing interesting

38:55 Presenter: entity forms that is just where form submissions are being saved

38:59 Presenter: Global variables is an interesting one, right?

39:02 Presenter: And this is a real example from a large financial services company in the U.S.

39:09 Presenter: Here’s what you get from global variables.

39:11 Presenter: You get authentication tokens, bearer tokens and authentication to Azure,

39:17 Presenter: API credentials to Azure.

39:19 Presenter: And, of course, this is, again, available to every organization.

39:21 Presenter: This was, of course, to everybody that queries the endpoint.

39:25 Presenter: This was, of course, disclosed and fixed.

39:29 Presenter: Now, the crucial, so we can see that there’s a misconfiguration here.

39:34 Presenter: The other thing we need to see is, I mean, how do you find these things?

39:38 Presenter: How do you find these misconfigured portals?

39:40 Presenter: The problem is that it’s very easy to find them

39:43 Presenter: because they are all in different subdomains in the same Microsoft domain.

39:48 Presenter: So just kind of a very basic subdomain enumeration,

39:52 Presenter: because this is Microsoft, I’m going to use Bing.

39:54 Presenter: Here’s a quick subdomain enumeration for you.

39:59 Presenter: there are that are hosted on this platform.

40:03 Presenter: So again, there’s an easy way for a hacker to iterate through all of those different

40:11 Presenter: portals and to scan them for this misconfiguration.

40:14 Presenter: It’s very rudimentary.

40:15 Presenter: And when we did something like that in order to find all of the different vulnerable applications

40:21 Presenter: and then disclose them to the vendors, we found a whole bunch of information.

40:25 Presenter: You can see some of the types of the data we found here.

40:29 Presenter: there’s more information in this link.

40:31 Presenter: Of course, we reached out to everybody that was infected.

40:36 Presenter: Okay.

40:40 Presenter: Let me show you one other example.

40:44 Presenter: So here’s an example with Zapier.

40:47 Presenter: Zapier has this, Zapier runs automations,

40:51 Presenter: but these automations are stateless in nature,

40:54 Presenter: so you don’t have any state that you can maintain.

40:56 Presenter: If you want state, if you need state inside of your automation, there’s a service they have called Storage by Zapier.

41:03 Presenter: It’s basically a key value storage.

41:05 Presenter: But the problem is that the secret behind it is a GUID.

41:11 Presenter: According to the documentation, it’s a GUID.

41:13 Presenter: It’s a GUID that the key that you need to provide for the storage is a random GUID.

41:19 Presenter: However, when we looked at the actual docs of the API, what you’ll see here is that in the examples,

41:26 Presenter: are definitely not good.

41:28 Presenter: They are definitely not random.

41:30 Presenter: They are definitely not strong enough.

41:32 Presenter: And so we figured that, well, what the heck, let’s try.

41:36 Presenter: Let’s try and see whether we can find keys

41:38 Presenter: that are not these random goods.

41:41 Presenter: And bear in mind, the only thing you need to do

41:43 Presenter: in order to query this API, again, is to have that key.

41:46 Presenter: You don’t need to be authenticated.

41:50 Presenter: Okay, so let’s just try, for example, 1, 2, 3, 4, 5.

41:53 Presenter: We tried it, and of course it worked.

41:56 Presenter: So what we had there is, so you can see, I have an example, so I’ll show them.

42:02 Presenter: Here’s the message where the secret is incorrect.

42:08 Presenter: So you get the secret must be a valid UUID4, okay?

42:12 Presenter: Here’s the message when it’s correct, just a bunch of data.

42:15 Presenter: So we’ve got a bunch of information there, again, authentication tokens, API keys, emails.

42:21 Presenter: We simply use an enumeration attack, right?

42:23 Presenter: We just went through lists of common passwords and iterated through them.

42:26 Presenter: And actually when we went to Zapier with this and talked to them about it, what actually happened was that they initially didn’t have any verification that the secret is actually a UUID4.

42:39 Presenter: Instead, they just told the user, hey, it’s your responsibility.

42:44 Presenter: Please enter a good password.

42:48 Presenter: And so people used 1, 2, 3, 4, 5 like the docs say.

42:52 Presenter: Or they used password, password or whatever they used.

42:57 Presenter: And this was the case for several years.

42:59 Presenter: Until someone found it, they told Zapier about it.

43:03 Presenter: And Zapier’s solution was to deal with every new secret out there.

43:10 Presenter: So today, if you use this platform, this feature, you have to use UID4.

43:15 Presenter: Well, but what about old passwords?

43:18 Presenter: These are still there.

43:19 Presenter: And by the way, they are still there today.

43:23 Presenter: So in some cases, people have stopped using them.

43:26 Presenter: kind of just a cleanup that is difficult to actually accomplish, and so this is still an

43:31 Presenter: active problem. All right. Here’s a summary of what we’ve seen so far, and I have just one other

43:42 Presenter: thing to share with you today. And so we’ve seen that low code is a big thing, and it’s a big thing

43:48 Presenter: in every organization, and I strongly encourage you, don’t go into the place where you think it

43:56 Presenter: problem because you’ll end up exactly where we ended up with bringing your own devices,

44:00 Presenter: solving it a few years too late. It’s vastly underrated by security teams, and we actually

44:06 Presenter: don’t have the right tools in our tool set to deal with this because we don’t have the

44:11 Presenter: monitoring capabilities. There’s no STLC. There’s no way to do this manually. Business

44:16 Presenter: users are not security savvy, nor should they. There’s a huge challenge for us to address

44:21 Presenter: here, and we need to be proactive about it. Attackers are already taking advantage of

44:26 Presenter: bunch of examples of living off the land attacks.

44:29 Presenter: Because these platforms operate as credential,

44:32 Presenter: like credential sharing as a service,

44:34 Presenter: they are basically the perfect place for a hacker to be at.

44:38 Presenter: And the permissions you need in order to gain access

44:40 Presenter: to these types of platforms in organizations are pretty low.

44:44 Presenter: You’ve seen hiding inside of those platforms,

44:48 Presenter: persistency mechanisms.

44:49 Presenter: Again, APTs have already used this.

44:51 Presenter: You’ve seen predictable misconfiguration.

44:53 Presenter: This is nothing new.

44:54 Presenter: We’ve seen this again and again with every important platform.

44:57 Presenter: This is just another one.

44:58 Presenter: And note that this is always about the platform saying that the choices are up to the user,

45:05 Presenter: that the platform has created a secure platform, but the user has to choose a good password.

Defense Strategies and OWASP Low‑Code Guidance — Part 4

45:10 Presenter: The user has to choose the right permissions for their APIs.

45:14 Presenter: Of course, when it’s easy to make mistakes, we make mistakes.

45:19 Presenter: And you’ve seen a couple of tools that I’ve shared here today.

45:22 Presenter: The very one is ZappGreds that allows you to identify these overshared credentials in Zapier.

45:26 Presenter: The other one is installing the backdoor in Microsoft 365 that you can play around with.

45:31 Presenter: I also encourage you, if you’re interested, check out Google for no-code malware.

45:36 Presenter: You’ll find a tool that allows you to use RPA basically as a malware for Windows 11.

45:44 Presenter: And now the last thing I’m going to finish with is actually defense.

45:48 Presenter: So what is the best way for us to approach it?

45:54 Presenter: The number one

45:56 Presenter: Okay, so there are a bunch of recommendations here

45:58 Presenter: But let me kind of narrow it down for you

46:00 Presenter: One thing that is pretty obvious

46:02 Presenter: Is that if you don’t know what you need to protect

46:05 Presenter: You won’t be able to protect it

46:06 Presenter: So I know it’s a difficult thing to say

46:11 Presenter: But we need to inventory those applications

46:14 Presenter: We need to know who builds them

46:15 Presenter: We need to be able to have logs

46:17 Presenter: When something happens

46:18 Presenter: We need to be able to actually investigate it

46:22 Presenter: requires work. We need to work

46:24 Presenter: with the teams that are building those platforms,

46:26 Presenter: managing those platforms, search

46:28 Presenter: for them within your organizations, you’ll find

46:30 Presenter: them. We need to be part

46:32 Presenter: of the conversation for low-code.

46:34 Presenter: And one other thing to say about that

46:36 Presenter: is that these people, they are,

46:38 Presenter: I mean, at least the people that are managing those

46:40 Presenter: platforms, they are aware of the risks, and

46:42 Presenter: they are afraid. They are afraid because they’re alone

46:44 Presenter: and they don’t have the security teams

46:46 Presenter: with them to guide them in that process.

46:48 Presenter: So be there to help them

46:49 Presenter: build it in a secure way,

46:51 Presenter: and they will appreciate it

46:52 Presenter: because they will be able to use the platform

46:54 Presenter: kind of more robustly.

46:57 Presenter: Review those configurations inside of those platforms.

46:59 Presenter: These platforms are creating HTTP endpoint on your behalf.

47:02 Presenter: They are exposing business data.

47:04 Presenter: You need to be able to control this.

47:07 Presenter: There are two specific configurations

47:08 Presenter: that I’ve shared in this talk

47:10 Presenter: that I strongly encourage you to look at.

47:12 Presenter: One is about connector uses,

47:14 Presenter: just kind of, and those open,

47:19 Presenter: endpoint, all data and storage.

47:21 Presenter: And the other is a bypass consent flow for Microsoft. Check out this one. It’s really

47:25 Presenter: important. The number one resource that would help

47:29 Presenter: you if you want to be the champion of low-code security within

47:33 Presenter: your organization is the OWASP Top 10. This is a project that is

47:37 Presenter: dedicated to low-code, no-code apps and the types of problems that happen when

47:41 Presenter: business users are building those apps. This is different from the

47:46 Presenter: traditional

47:46 Presenter: OWASP top 10. It’s focused on business logic.

47:49 Presenter: What these applications are actually doing.

47:51 Presenter: And it will give you concrete examples

47:53 Presenter: that were found across the

47:55 Presenter: industry of problems that

47:57 Presenter: were found. And also a language

47:59 Presenter: you can share with your business users

48:01 Presenter: and with your leaders to push this

48:03 Presenter: forward.

48:06 Presenter: That’s

48:07 Presenter: everything I had. Thank you very much.

48:09 Presenter: Thank you.

48:18 Presenter: Yes?

48:19 Presenter: You have a question.

48:20 Presenter: Yeah?

48:20 Presenter: You mentioned that when you delete that automation flow,

48:24 Presenter: it leaves the logs.

48:26 Presenter: So there’s no location where those logs would be stored?

48:28 Presenter: In the back, there’s no permanent location?

48:30 Presenter: So there’s no way to retrieve those?

48:31 Presenter: You can route those logs to a storage account that is separate,

48:35 Presenter: and then if the automation gets deleted,

48:37 Presenter: the logs won’t get deleted,

48:39 Presenter: but it requires an action from your side,

48:41 Presenter: an administrative action.

48:43 Presenter: it doesn’t come with the vanilla configuration

48:48 Presenter: yes

48:48 Presenter: only if you use a connector that is underlying

48:56 Presenter: under the surface using the graph API and then the new

48:59 Presenter: graph API login capabilities might help you

49:02 Presenter: but no, all of the power platform API that are being used

49:06 Presenter: here, they are not logged, again not by default

49:09 Presenter: yes

49:20 Presenter: again not by default if you want this to be part of your own kind of configuration of your

49:25 Presenter: if you want your SOC to be able to monitor this you need to be active to be proactive