A Soft Hack

When is a hack not a hack?

We all get raises at the same time of year. The buzz is big around the time it happens… whispers of flat 2% or 1% across the board, rumors that “we’re all getting screwed”… you know, standard stuff. They are entered into our payroll software before they’re communicated to us, but we don’t have access, and there’s always a 7-10 day period between the decision and the communication. What, do we have to wait until we get the check to see what it’s going to be?

Well, in fact, no we don’t.

I found what I would like to call a “soft hack”… no injection or script-insertion, no session hijacking or privilege escalation. I didn’t even need a proxy to manipulate the parameters. I just poked around the site that stores our benefits information. See, the benefits information interfaces with the payroll information, which means the numbers I need are already in there. I know that because I’m a manager and I already saw my employees’ increases, but comp numbers are hidden from individuals. So mine is in there somewhere… somewhere.

I look at withholding - if I see how much they’re taking out of the check for taxes of social security, I’m home free. I can do that kind of math. No luck–that’s hidden too. Medical insurance? No luck–it’s a flat rate. Flex spending? Nope–another flat rate.

401(k) contributions? That would do it, right? If I’m withholding 6% and they print the dollar amount, the amount will represent 6% of the new number, right? Of course not–they just print the percentage.

Finally I look at our Life Insurance coverage amounts. My company is awesome–just for working here we get automatic life insurance, gratis, equal to TWO TIMES OUR ANNUAL SALARY.

So, the number listed there–I divide it in half, and there it is, my new salary. Thanks, boss!

Because I’m a software tester first and foremost, I want to verify my methodology: I’m able to look at my benefits “as of” arbitrary dates, so I set the date back a month or so, divided the life insurance in half, and boom… the old salary. We have a soft hack.

And that’s what worries me: even when they don’t give you the information, they give you the information. The thing about this hack, in light of my recent acquisition of the web app penetration testing unit, is that no tool, not AppScan or WebInspect, not burp suite or paros or httprint or nessus or nikto or IEWatch HTTPWatch. What is my AUT trying to tell the world, that I don’t want to tell them? Some little nugget sitting out there in plain site, waiting for the right person to come along and do some second-grade math?

It looks like the best security testing tool you possess is your own mad desire to get the data. Conjuring this motivation is difficult: I’m definitely more interested in my new paycheck numbers than I am in whether some theoretical user can escalate his permissions to perform admin tasks. It’s almost like I need to have a Stanislavski moment before I start this hack-testing: imagine I’m sitting in a dark room somewhere, logged into the target site using “rsmith/password”, and I’m not about to let rsmith’s meager permissions get in my way. I know that information is on that server, and they’ve opened up port 80 for me to get to it. There’s only a thin layer of imperfection sitting between me and the database. It’s only a matter of time.

Should I coin a new term? “Method testing”? Those words are all over these Internets, but they mean something quite different from what I’m spelling out here.

You heard it here first.

Tags: , , , , , ,

6 Comments for “A Soft Hack”

  1. Bill C. Says:

    This reminds me of the training I had as an MP in the Army. Basically everyone is trained to keep their mouth shut when in public. Even talking about where you are stationed is not allowed. The reason being is that letting even one small piece of information slip into the wrong hands can be used to determine the number of people stationed at that site, what their job is, even not talking about what your job is at the site is enough to clue the enemy into WHAT is going on at the site.

    And it doesn’t take much to get people/soldiers to talk. Just idle conversations over a beer at a bar. Talking to your girl friend about having to leave in the middle of the night, (she has friends that she’s going to tell why you couldn’t come to the party etc…).

    My point is none of these are “Interrogations” (in software we call them “Hacks”), but the information gained is just as worthy, and easier to attain. The only way to stop the leak is vigilance (and a few good testers:).

    Reply to Bill C.

  2. Jagad Guru Says:

    Wow , It is such a enlightening piece of information that I am really rejoiced over the fact that I now know something as cool as that. Thanks bro , you made everything quite clear , discussed every minor details. Nice sharing :)

    Reply to Jagad Guru

  3. thoan Says:

    hack b00m

    Reply to thoan

  4. Vibe.to Says:

    Hey buddy, do try that once u can hack in, are u able fiddle with the numbers.That would be like icing on the cake..nywaz thanks a lot for sharing thing..wonder if i could try sumthing similar!!

    Reply to Vibe.to

  5. Haady Says:

    Yeah, i agree with u.. Nice Post,

    Reply to Haady

  6. Cederash Says:

    Классная статья - спасибо!

    Reply to Cederash

Leave a Reply