TrustSink: How a Rogue External MFA Provider Steals Passwords

https://hackernoon.imgix.net/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-wv83bgg.webp

Meet TrustSink, a technique that turns a rogue external MFA provider into a persistent credential trap. See how it works, why password resets may not remove the risk, and how defenders can detect rogue providers.

Varonis Threat Labs identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow.

While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error.

In our test tenant, every sign-in completed normally while our server received passwords with timestamps and source IP addresses. Resetting a captured password did not remove the rogue...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more