[ << ALL_FEED ]

X-user data filtering

More in General

📫 X-Filtering of User Data

In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we want to talk about how attackers exfiltrate useful data through X-headers of email messages.

In emails, in addition to mandatory headers such as From, Date, etc., there are headers with the X prefix. They carry additional information, for example, details about the operation of email security mechanisms, service identifiers, and various metadata about the sender.

Each service and organization can set their own X-headers without explicit restrictions, so their number can currently be counted in the thousands. Describing and understanding the content of each one is an incredibly difficult task. Attackers take advantage of this. They create their own X-headers and place encoded useful data in them that needs to be exfiltrated.

😠 For example, the headers of such an “unusual” email might look like this:


Received: from SB1P221MB1152.NAMP221.PROD.OUTLOOK.COM
 (3613:10b6:806:388::20) by BD0P221MB0288.NAMP221.PROD.OUTLOOK.COM with
 HTTPS; Thu, 20 Mar 2024 21:28:15 +0000
...
From: John Doe <jdoe@testsolutions.com>
To: John Goe <jgoe@prodsolutions.com>
Subject: New Test
Date: Thu, 20 Mar 2024 21:28:15 +0000
Accept-Language: en-US
Content-Language: en-US
X-Ms-Exchange-Organization-Authmechanism: 04
X-Ms-Exchange-Organization-Authsource: BD0P221MB0288.NAMP221.PROD.OUTLOOK.COM
X-Ms-Has-Attach: yes
...
X-Entity-ID: WABIHdrtPzUrGNbwVwoPTQ==
X-Trusted-Header: c2VjcmV0X2xvZ2luOnNlY3JldF9wYXNzd29yZA==
X-Ms-Exchange-Organization-Scl: -1

As you can see, X-headers contain many different types of information: numbers, strings, something like boolean values, encoded sequences, and so on.

Among them, it is difficult to find the header that clearly poses a threat. In this case, the “bad” header turned out to be X-Trusted-Header (it contains user credentials), which in terms of content is completely comparable to the legitimate X-Entity-ID.

😑 To avoid arousing suspicion from email security systems, attackers also supply the email with the most innocuous text possible, without adding suspicious components such as HTML parts or attachments.

Thus, this turns out to be an extremely convenient and covert method of data exfiltration for attackers. This technique is often used in corporate espionage, when an insider has legitimate access to email systems. They can embed useful data in headers, sending it under the guise of a regular business email.

It is worth noting that this method has one main limitation — it only transmits small amounts of data. That is, it is well suited for exfiltrating encryption keys, credentials, and the like.

However, if an attacker tries to transmit large blocks of data this way (for example, files), it will be very noticeable against the background of all email traffic.

😱 What to do:

1. Implement methods for analyzing the content of email headers. Best done using a DLP system.

2. Pay attention to unusual X-headers in outgoing emails. This can be done, for example, by calculating the statistics of mentions of such headers over a certain period, where the least mentioned ones are the most suspicious.

3. Monitor streams of emails with identical content sent to a single address.

#Detect #Tip
@ptescalator

More from global_author

More from global_author

More in General