Aug. 17, 2026

Backup Security Best Practices: Lessons From a Real Red Team Breach

Backup Security Best Practices: Lessons From a Real Red Team Breach

Backup security best practices start with one uncomfortable truth: if you haven't checked your backup server for a default password, someone else might check it for you. In this episode, Prasanna and Mike Saylor join me to dig into how backup systems become the easiest way into your network — and the easiest way out for stolen data. We walk through the real story of a red teamer who used a backup server's weak credentials to restore a domain controller straight outside the company's firewall, then had the run of the place.

From there we get into the stuff that actually gets skipped: service accounts nobody's watching because they're "always on" and mostly invisible, default passwords baked into backup hardware that never get changed, and why the backup admin — usually the newest, most junior person on the team — ends up holding the keys without the security training to know what they're holding. We talk about how to find every service account you've got, how to figure out which ones actually need the privileges they've been handed, and why "it's always been that way" is exactly how breaches happen.

We close out on authentication: multi-factor authentication versus passkeys, why email one-time codes aren't the security win companies think they are, and why an authenticator app with its own PIN beats "remember this device" every time. Mike also shares a story about catching failed admin logins that turned out to be something a lot more human than a hacker — and why monitoring for those anomalies matters either way.

If you manage backup infrastructure, run a security team, or just got handed the backup admin job because nobody else wanted it, this episode is your checklist. Backup security best practices aren't complicated — they're just consistently ignored, and that's exactly what attackers count on.

Chapters:

00:00 – Cold open: the hacker on your backup server

01:34 – Welcome and episode setup

04:17 – The Duane Lafleur red team story

06:41 – Backup servers as an exfiltration risk

08:19 – Service accounts: the invisible attack surface

28:40 – Locking down the admin account

30:08 – MFA vs. passkeys for backup security

Speaker:

There could be a hacker working their way into your backup server right

Speaker:

now, not because your firewall failed, but because nobody ever even bothered

Speaker:

to change the password on the box.

Speaker:

Today, Prasanna and I sit down with Mike Saylor, uh, to talk about backup

Speaker:

security best practices, the stuff that most teams skip, mainly because

Speaker:

backups are invisible until they're not.

Speaker:

Uh, we're talking about things like default passwords on backup hardware,

Speaker:

service accounts that nobody's looking at, uh, admin logins at 2:00 in the

Speaker:

morning, and why passkeys beat MFA.

Speaker:

There's a real story in here about a red teamer who broke into a company through

Speaker:

their backup system and walked out the front door with the domain controller.

Speaker:

If this is your first time watching or listening to me, I'm

Speaker:

W. Curtis Preston, aka Mr. Backup.

Speaker:

I've been obsessing about backup, recovery, and now cyber

Speaker:

recovery for over 30 years.

Speaker:

If that's your bag, then I'm your guy.

Speaker:

You're not gonna find anyone that cares about this topic more than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups of

Speaker:

the database that we had just lost.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap Up.

Speaker:

Hey, welcome to the Backup Wrap Up.

Speaker:

I'm your host, Debbie Curtis Preston, and today I have my two besties with me.

Speaker:

We've got Prasanna, getting more gray hair every day, and Mike,

Speaker:

my fellow gray-haired enthusiast.

Speaker:

How's it going, Mike?

Speaker:

It's going great.

Speaker:

Thanks for having me, and good to catch up with you guys

Speaker:

Yeah,

Speaker:

have a question, Curtis

Speaker:

What's that?

Speaker:

Is it better to have natural gray or is it better to dye your hair?

Speaker:

That's always been, like, the constant debate, and I think men typically

Speaker:

don't dye versus women, right?

Speaker:

I'm just going.

Speaker:

All

Speaker:

That's probably generalization

Speaker:

Prasanna.

Speaker:

Two little stories on, to answer that question.

Speaker:

clearly I've gone with natural, clearly.

Speaker:

and there was a minute there where I tried, some, like the kind that

Speaker:

is just supposed to subtly dye your hair, before I went completely gray.

Speaker:

And I did it, and my wife didn't even notice.

Speaker:

So I was like, then, what's even the point?" And then the other thing was

Speaker:

I was talking to her one day and I was like, my wife is Filipino for those

Speaker:

that don't know, and I said, one good thing about Filipino, you guys, like

Speaker:

your hair like stays black forever."

Speaker:

And she looked at me and she goes, know we dye it, right?"

Speaker:

It's like, "No, I had no idea."

Speaker:

Oh, Curtis.

Speaker:

typical dude.

Speaker:

Anyway.

Speaker:

All right.

Speaker:

So we are back to our, series, of, g- basically working through our new book,

Speaker:

that, Mike and I came out with, which is Learning Ransomware Response and Recovery.

Speaker:

For those of you watching on YouTube, you can see a giant version

Speaker:

of that over my shoulder there.

Speaker:

And, if you're not checking us out on YouTube, you should

Speaker:

definitely check out our channel.

Speaker:

And of course, we also have the shorts version.

Speaker:

we do 30 second to a minute and a half short clips, which are doing really well.

Speaker:

and we get a lot of, get a lot of, commentary on them.

Speaker:

sometimes, not good, but sometimes people have no problem with, expressing

Speaker:

their opinion, to a random stranger on the internet because they're generally

Speaker:

people that don't, know who we are.

Speaker:

And, so they're just, they just see me making a random claim and, and then

Speaker:

they wanna argue with me, which is fine.

Speaker:

You want discussion?

Speaker:

Yeah

Speaker:

yeah, more interaction, And, any comment, even if the comment is, "You're a

Speaker:

freaking idiot," it builds engagement.

Speaker:

So comments are good.

Speaker:

but today,

Speaker:

co-host has amazing hair

Speaker:

yeah.

Speaker:

Yeah, I-- we did

Speaker:

You talking about me?

Speaker:

Yeah.

Speaker:

sorry

Speaker:

We did get a, we did get a comment about your hair is gorgeous.

Speaker:

and I knew he was talking about you.

Speaker:

but, speaking of the book, there is a, there's a quote in there from one of our

Speaker:

podcast guests, which was Duane Lafleur.

Speaker:

Duane is a, he's a red team person, right?

Speaker:

he hacks companies on purpose for, as requested by the companies.

Speaker:

I once again will mention the movie Sneakers.

Speaker:

If you haven't seen it, go watch it.

Speaker:

it's not, obviously it- it's movies, but it does a pretty good job

Speaker:

of showing what, red teaming is.

Speaker:

And, and there's a few late great actors in there, specifically, Robert Redford.

Speaker:

y-

Speaker:

IP

Speaker:

great just, yeah.

Speaker:

but, it, Duane's, Duane talked about how he loved backups, except

Speaker:

not for the reason I love backups.

Speaker:

And that was he loved them because, one of the things that we talk about a lot

Speaker:

is that backups, because of what they are, where, you're either invisible

Speaker:

or you're in trouble, because of what they are, they often go, ignored from

Speaker:

a cybersecurity perspective, right?

Speaker:

For a couple of reasons.

Speaker:

One is nobody wants to, get their hands in there because once you

Speaker:

start sticking around in the backups, somebody might ask you actually

Speaker:

to be the backup person, right?

Speaker:

And so there's that, and then because of that, it's often the junior person.

Speaker:

So you have the junior person running backups, and the junior person is the one

Speaker:

who knows the least about cybersecurity.

Speaker:

And today we're gonna talk about things that you need to be doing to

Speaker:

your backup system, and specifically we're gonna talk about accounts

Speaker:

today that are around all the time.

Speaker:

We're gonna talk about service accounts, we're gonna talk about passwords.

Speaker:

And he talked about, where he was able to penetrate a system, a company via their

Speaker:

backup system because what he did was he used some lackadaisical security to, take

Speaker:

control of the backup system and then used that control to restore, the backup

Speaker:

server to a, com- the storage completely outside of the company's, firewall.

Speaker:

It was a backup of the domain controller that he restored to outside of this,

Speaker:

their world where he then had complete control over that server and he was able

Speaker:

to extract all kinds of information.

Speaker:

And this is the kind of thing that we talk about a lot in the book where

Speaker:

it's like your backup server, only does it need to be protected because

Speaker:

you need it for recovery when you get hit from, a ransomware, but also

Speaker:

because it is an exfiltration Source, a potential exfiltration source.

Speaker:

And so there are unfortunately a lot of default passwords.

Speaker:

This is one of the things we're gonna talk about.

Speaker:

There's a lot of default passwords that are in, especially I'm

Speaker:

gonna say backup hardware.

Speaker:

there are some default passwords in some of the backup software, but

Speaker:

I think it's less of a, a problem.

Speaker:

But, so that's what we're gonna talk about in this episode.

Speaker:

Prasanna, it sounded like you, you had

Speaker:

I had a question.

Speaker:

Yeah.

Speaker:

I know you were just talking about default passwords, but I don't think

Speaker:

it applies only for the backup space.

Speaker:

I don't know if you've seen all the issues people have had with network

Speaker:

routers being compromised, being used as botnets for attacks in other places

Speaker:

or as resident, residential proxies.

Speaker:

But all of this stems from, people not changing the default password

Speaker:

when they buy a router, right?

Speaker:

You go buy a wireless access point and you are like, "Oh, I'll just

Speaker:

leave the defaults as it is."

Speaker:

Yeah, agreed

Speaker:

Everything that we're gonna say in this episode would also apply to any other

Speaker:

network or storage infrastructure, except that this podcast isn't called

Speaker:

The Network Schnetwork, it's called The Backup Wrap-Up, and so we're

Speaker:

gonna focus on the backup systems.

Speaker:

But yeah, Prasanna, you're completely, correct that, that there are a lot of,

Speaker:

default passwords out there, especially on network equipment that, the good news

Speaker:

is, at least with network equipment, there are people that actually want to

Speaker:

be network admins, and so they actually study it, and they tend to be, they often

Speaker:

tend to be cybersecurity leaning, and so they tend to be a little better at

Speaker:

doing this, although clearly not perfect.

Speaker:

Or have been doing it for a longer amount of time than the backup admins have been

Speaker:

Mike, the first thing I wanna talk about is this idea of service accounts.

Speaker:

and w- that they're invisible, that they're this thing that's

Speaker:

happening and it's a thing that you can then use to, to, attack things.

Speaker:

You wanna talk about what service accounts are?

Speaker:

About the service accounts Yeah the funny thing about service accounts a lot of

Speaker:

times when we red team an organization even the security services that you're

Speaker:

running are susceptible to compromise So a lot of times we take advantage of

Speaker:

like the antimalware service account or like a Qualys vulnerability scanner It's

Speaker:

a service account that's got privileges it's not protected they're assuming the

Speaker:

endpoint is protected And so when you compromise that account now you have

Speaker:

privilege across all of the endpoints where that agent or service is deployed

Speaker:

it is often overlooked and it's overlooked for a couple of reasons One typically

Speaker:

when you deploy a technology that requires a service account you give it privilege

Speaker:

cause you want it to work shortest path to getting things operational we don't have

Speaker:

to troubleshoot restricted access Just give it all the access and it'll work And

Speaker:

then we'll we'll pull the access back as needed but they forget that part or often

Speaker:

it's overlooked or we ran out of time or we ran out of budget or we've got this

Speaker:

other fire that came up we need to go put out and it just gets pushed off the plate

Speaker:

Mike,

Speaker:

and yeah it's very

Speaker:

and Mike, just real quickly, could you help y- listeners who may not

Speaker:

know, like what is a service account?

Speaker:

Because maybe not everyone is familiar with that aspect

Speaker:

they take a couple of different flavors The the probably the most common one

Speaker:

is just it's just a it's like another user account on the network So there's

Speaker:

mikecompanycom and then there's backupagentcompanycom so it's another

Speaker:

user account in the network and you just you have to know the credentials to log

Speaker:

into it and use it Sometimes that's just filed away somewhere in a password vault

Speaker:

or somebody's desk and you don't have to log into it because once it's running it

Speaker:

just runs until you need to make a change

Speaker:

and some of those accounts, Mike, some of those accounts, if they're created

Speaker:

by the backup software itself, they could indeed have like default passwords

Speaker:

that the backup software, put in there.

Speaker:

Certainly and that lead that leads it to the next type and that's more of an

Speaker:

agentbased software So you install a piece of software on the computer it has its own

Speaker:

credentials and you authenticate it back to a console like your backup console your

Speaker:

antivirus console and it just it runs on that that endpoint with those credentials

Speaker:

and often back to the initial comment often it's a privileged privileged account

Speaker:

Yeah, because if you think about backups, in order for backups to do their job,

Speaker:

they have to have superuser access.

Speaker:

They have to be able to access all files in order to both, first to be able to

Speaker:

res- to back them up, but also, just as importantly, to be able to restore them.

Speaker:

You have to have write-level access to all the accounts, and that does bring me back.

Speaker:

I'll pick on, what back in the day was my favorite product was NetBackup,

Speaker:

and, they had a tool called BPGP.

Speaker:

they did, I do, I did find out they definitely eventually, got rid of this

Speaker:

tool, but, it was originally called BPCP.

Speaker:

BP was the Backup Plus, the original name of the product.

Speaker:

And if you were on the backup server, you could use BPCP to read or write any

Speaker:

file transfer from any file from any client where that daemon, was running.

Speaker:

and so it ju- it just made it really easy.

Speaker:

even with the software, with most backup software products, you can use

Speaker:

the software to back up a file, then restore it locally, but BPCP made it

Speaker:

possible to just do it in one step.

Speaker:

and that just gives you an idea of the kind of thing that

Speaker:

you could do if you have this.

Speaker:

Certainly and if I could add two two comments real quick One since you brought

Speaker:

it up is it pronounced demon or daemon

Speaker:

I say demon,

Speaker:

I say Damon.

Speaker:

you do you're backup guy

Speaker:

Yeah

Speaker:

yeah, it is spelled daemon.

Speaker:

I don't know.

Speaker:

by the way, it's also pronounced L- Linux, based on the fact that it came from Linus

Speaker:

I will never pronounce it

Speaker:

I will never pronounce it that way either, but it is based on the name

Speaker:

of the guy who wrote it initially, whose name is pronounced Linus.

Speaker:

whatever.

Speaker:

Anyway,

Speaker:

the last thing I'll add the last thing I'll add on default passwords there

Speaker:

there's another problem or a a a variation of the default password situation and

Speaker:

that's coincidental password So maybe the password has been changed but

Speaker:

it's the same password that's used for a lot of other things So this admin

Speaker:

account password is the same as that admin password But then also when you

Speaker:

get to managed service providers so maybe you outsource IT management that

Speaker:

IT management company may be using the same backup password for your

Speaker:

environment that as the same password they're using at another company's

Speaker:

environment

Speaker:

my head to think of that

Speaker:

world very similarly bad guys are looking for the shortest path with the least

Speaker:

with the most value So if I'm gonna steal if I know to look for backups

Speaker:

and that's where all the data is gonna look at managed service providers cause

Speaker:

that's where all the passwords are

Speaker:

Yeah.

Speaker:

So if I compromise one managed service provider I likely have

Speaker:

access to many client environments

Speaker:

a thing, this was several years ago, but there was a dentist

Speaker:

Post office, yeah

Speaker:

that they hacked the MSP, and as a result they were able to hack,

Speaker:

hundreds of dentists around the country

Speaker:

That's right

Speaker:

So for the service account, Mike's, because when it gets deployed to

Speaker:

your environment, you're going to have multiple agents deployed across

Speaker:

all of these systems in order to be able to back up and restore them.

Speaker:

Are each of these service accounts across all of the individual machines

Speaker:

uniquely protect- or do they have unique passwords, or is it typically

Speaker:

a single service account which might be local to a particular machine might

Speaker:

share a common password with another service account on a different machine?

Speaker:

Typically and I would say typically putting that in the 90 percentile range

Speaker:

the passwords are the same I think there are some highly regulated and

Speaker:

possibly highly more secure environments where you could assign unique passwords

Speaker:

but that's definitely the exception

Speaker:

more management, more complexity, all the rest of that

Speaker:

For sure

Speaker:

For

Speaker:

so it's bad enough if we, are able to compromise a single account.

Speaker:

what then, let's talk about privilege escalation, Mike.

Speaker:

what is privilege escalation and what could someone do, once they achieve that?

Speaker:

So privilege escalation is taking whatever access you you're able to gain

Speaker:

at whatever level normal user guest super user admin global admin and get to that

Speaker:

next level and sometimes we talk about privilege escalation but sometimes you can

Speaker:

actually justify demotion for a particular objective so maybe I wanna pretend I'm

Speaker:

Curtis So I'm global admin I have that ability I can now give myself access to

Speaker:

a a demoted account like Curtis normal user in order to use Curtis's identity

Speaker:

to achieve whatever but the promotion part or the escalation part is I am

Speaker:

Curtis and I wanna be an admin so I'm using Curtis's local permissions on his

Speaker:

computer or his network permissions to find and recon is always the first phase

Speaker:

Find those service accounts find those accounts that have default passwords

Speaker:

and then escalate to that and that whether that's straight to admin or an

Speaker:

administrative privileged account or some series of stepping stones to get there

Speaker:

the thing from a backup perspective that I want people to understand is that almost

Speaker:

every backup software product that I worked with has the idea of a pre and a

Speaker:

post script, So if you can put a script in the appropriate place, the backup

Speaker:

software will run that script as the privileged account that backup runs at.

Speaker:

So if you basically create a script, it creates a user that gives you the

Speaker:

permission that you want, the backup, and put it in the right place, backup will

Speaker:

then use that, will run that script for you, and then you can put in the script

Speaker:

to clean up, behind yourself, right?

Speaker:

So this is just something you need to be aware of.

Speaker:

You should be looking for these scripts, that you should be checking if there

Speaker:

aren't any of these scripts, you should be looking to make sure that

Speaker:

they don't magically appear, right?

Speaker:

and then also if you are using these scripts, you should make sure that

Speaker:

the, that they don't, change on you

Speaker:

Do you know, Curtis or Mike, if any of these backup systems actually look

Speaker:

to see if a script has been changed, like outside… I'm just imagining

Speaker:

a case that someone goes, like a script is defined, a pre-script.

Speaker:

They go behind the scenes to the file system.

Speaker:

They change the script.

Speaker:

They haven't changed the name of it, right?

Speaker:

But is there any backup software that actually does like a verification

Speaker:

to ensure that like a script has not changed between when the admin

Speaker:

actually configured it versus now?

Speaker:

Yeah.

Speaker:

I, I don't, I certainly don't know of any that do that.

Speaker:

But I tell you what, we've got a lot of listeners, and a lot

Speaker:

of them are vendor, people.

Speaker:

So I… If you're aware of a product that does do that, that checks the

Speaker:

scripts that, you know, that… It would be… What would be really nice

Speaker:

is to make sure that the first time a new script is run, it, we send up

Speaker:

some authentication and say, "Hey, is this what you intended to do?" and you

Speaker:

do four eyes, authentication, which is where you have to have two people,

Speaker:

to authenticate That would be nice.

Speaker:

It would also be nice to do what you're suggesting, which is, checking

Speaker:

to make sure that the script that we're running is the same as this.

Speaker:

You could do that by fingerprinting and all that kind of stuff.

Speaker:

But, so this is just something to look into.

Speaker:

and then, let's talk about… What?

Speaker:

Go ahead.

Speaker:

real real quick on that I yeah I'm not familiar with a backup solution that does

Speaker:

that but there are thirdparty tools that do file integrity monitoring so they'll

Speaker:

look for changes in the hash changes in the configuration Tripwire used to do that

Speaker:

I don't know what they're called today But then a lot of security monitoring

Speaker:

tools you can point at an object whether that's a file or a folder or metadata and

Speaker:

it'll alert you when something changes

Speaker:

because all those, the, the ones that I'm aware of, the, would put the script

Speaker:

in a particular predictable place.

Speaker:

and, and so you could monitor for that.

Speaker:

So let's talk about something that I talk a lot about, Mike, and that

Speaker:

is this idea that the backup system should not share any, credentials with

Speaker:

the production environment, right?

Speaker:

that we don't put it in the, Active Directory domain, for example.

Speaker:

why is that the case?

Speaker:

Well which it just it goes back to that idea or the concept of putting as many

Speaker:

layers of security and obfuscation and really just extra effort as you can to

Speaker:

not only deter and potentially hinder but also give you time to identify when

Speaker:

weird things are happening So for example if you've got your backup your backup

Speaker:

system on a separate network like a like a management network so all your servers

Speaker:

you'd have two two network interfaces one for production and one for backup and

Speaker:

management all day long your production network interface is just super busy

Speaker:

and it's dynamic there's just tons of activity and you that's needle in a hayst

Speaker:

needle in a haystack looking for bad actors But on your management interface

Speaker:

that's like you can baseline that You know exactly what's going on there when to

Speaker:

expect backups what bandwidth looks like connections and all those things So much

Speaker:

less dynamic traffic on that interface and much easier to identify when weird things

Speaker:

are happening So there's that then on the Active Directory side let's just take the

Speaker:

example that you brought up where a bad guy was able to to get a copy of a domain

Speaker:

controller then the domain controller has all the privileged accounts and some of

Speaker:

those are you just have to have like your global admin and Office 365 exchange admin

Speaker:

All those things are in your normal Active Directory and they need to be but some of

Speaker:

these others like your backup admin maybe your your cybersecurity tools some of

Speaker:

those other things recovery accounts So if someone does compromise your

Speaker:

domain you've got this other interface with separate credentials that you

Speaker:

might be able to re reacquire some of those servers or part of your network

Speaker:

Yeah, I li- I like that separate network.

Speaker:

I've always been a fan of the separate network, for backup traffic, more

Speaker:

so back when that really meant that the backup system could get

Speaker:

a predictable amount of bandwidth.

Speaker:

But now, And what's really nice about it now is that we can do this, this is

Speaker:

part of infrastructure as code, right?

Speaker:

That you can just literally, as you're creating your VMs, in the cloud, you

Speaker:

can create them this way, and you say, "All backup traffic goes through

Speaker:

this, port, and production traffic goes through that port." Prasanna,

Speaker:

actually see that in production today, Mike?

Speaker:

oh,

Speaker:

I wonder if a lot of this like sort of… 'Cause I know like ideally,

Speaker:

it is best practice to have like separate management network, backup

Speaker:

network, and production network.

Speaker:

But that's also like time-consuming to set up and manage over time and everything

Speaker:

else, And also in the world of virtual machines where it could be easier,

Speaker:

but it's also still a bit of a pain.

Speaker:

And so are you actually seeing people continue to have these like

Speaker:

isolated networks that they use?

Speaker:

I haven't seen any new ones A lot of the ones that are out there have been there

Speaker:

for a while mostly in telecom And y your backup strategy your management strategy's

Speaker:

gonna drive that architecture in the environments where I've seen the separate

Speaker:

interface their backup jobs were huge and even having the separate interface

Speaker:

and better bandwidth they still struggled with backup jobs completing before the

Speaker:

next business day so that was primarily the driver for the strategy for those

Speaker:

organizations is how do we make our backup strategy effective instead of thinking we

Speaker:

need a new strategy and then probably more recently today they're all mostly VLANs

Speaker:

instead of physical network interfaces

Speaker:

Yeah, that's a good point.

Speaker:

do you wanna, just cover what a VLAN is real quick for those

Speaker:

that are not familiar with that?

Speaker:

Yeah So a a VLAN is j it's a virtual network but it's run off of one appliance

Speaker:

And so if you think about a a switch with let's just 32 16 32 ports that you

Speaker:

would plug in your network cables to when you log into that that switch the

Speaker:

interface for that allows you to assign or create these virtual networks so that

Speaker:

network jack Ethernet jack one through six is VLAN one now you can create access

Speaker:

lists and restrictions whether it's computer in VLAN one cannot talk to any

Speaker:

other computers and vice versa so it's isolated but you can also restrict the

Speaker:

type of traffic we don't allow people in VLAN one to receive internet traffic we

Speaker:

restrict that both normal HTML and the encrypted 443 ports and those protocols

Speaker:

You can do a lot with VLANs from a a another layer of network management

Speaker:

and security And then a computer a a server again if you had two network

Speaker:

interfaces or even a virtual network interface now that we're talking about

Speaker:

virtual machines you can connect that one computer to one to many virtual networks

Speaker:

through through that VLaning switch

Speaker:

is a way we can segregate the traffic even though we only have one actual interface.

Speaker:

Right

Speaker:

about most consumer Wi-Fi devices or routers these days, right?

Speaker:

You have a guest network and you have your normal, right?

Speaker:

And that is a form of s- network segregation.

Speaker:

I'm sure they're using VLANs or something under the covers as well.

Speaker:

All right.

Speaker:

So let's just talk about, let's review, the basically the things that people

Speaker:

can do, to help with this problem.

Speaker:

and the first one I'm gonna talk about is the easy one, which is go look for and

Speaker:

change all the default passwords, right?

Speaker:

think about all of these backup, especially backup service accounts.

Speaker:

Prasanna, you mentioned network infrastructure.

Speaker:

I'd say storage infrastructure.

Speaker:

servers don't tend to have, 'cause unless it's a, an appliance

Speaker:

server that you bought, they don't tend to have default passwords.

Speaker:

Although I suppose like a, particular distribution might have that.

Speaker:

any other default passwords, Mike, that you can think of that people

Speaker:

should go be look, looking to change?

Speaker:

Just about anything comes with a default password whether it's blank or password

Speaker:

admin or the name of the product and there there may also be a support account so if

Speaker:

you need help you're gonna call a number or get on a website and they're gonna

Speaker:

be able to remote connect in using their support account My recommendation to all

Speaker:

of those support situations turn it off until you need help Don't just leave it

Speaker:

on cause those are just like home security systems you A contractor now it's not

Speaker:

even the company that installs it now they hire contractors that come out and

Speaker:

install your home security system and the default you know key or password is 1111

Speaker:

or what have you And you can put in your new code 1234 But unless you delete or

Speaker:

disable the original code it's still there

Speaker:

Yeah,

Speaker:

But it… One, one thing though.

Speaker:

So I have a sprawling enterprise network, right?

Speaker:

With a whole bunch of devices.

Speaker:

How am I supposed to figure out, what has default passwords and what doesn't?

Speaker:

is there a tool out there that can ki- that can look across my entire

Speaker:

network and they say, "Hey, this is the type of device you have.

Speaker:

Okay, let me try its default"?

Speaker:

A vulnerability scanner like like Nessus You can you can You There's an open source

Speaker:

version of Nessus it doesn't have all the bells and whistles but it's good enough

Speaker:

Yep.

Speaker:

Spell that, Mike

Speaker:

make sure you read the NESSUS Nessus make sure you read the manual or watch

Speaker:

some some YouTube videos before you run it cause it can it can be disruptive if

Speaker:

you don't configure it well But there are plugins for or switches to turn

Speaker:

on to test for default passwords and there's other So those are traditional

Speaker:

network devices like switches routers servers some software and then for OT

Speaker:

operational technology related hardware like SCADA devices and thermostats and

Speaker:

printers and smart boards there are other tools that are more current on

Speaker:

configurations and passwords for those

Speaker:

Yeah.

Speaker:

to go back to your support account, I can, give a shout-out to Rubrik here.

Speaker:

One of the things I know, and maybe there's other products that do this,

Speaker:

but I just know in, in the case of Rubrik, they're not able to connect

Speaker:

from the outside to the support account.

Speaker:

They require you to do an SSH tunnel.

Speaker:

the, the server is set up or the, the appliance is set up in such a way that

Speaker:

you can't connect to the outside on that account, and it would be… If

Speaker:

it's possible for you to do that, And by the way, if you guys are aware of

Speaker:

other backup software or backup hardware products that, that do that same

Speaker:

concept, I like that as well, that the account is set up in such a way that you

Speaker:

cannot connect to it from the outside.

Speaker:

the, I like that a lot.

Speaker:

another thing… Go ahead.

Speaker:

What's that?

Speaker:

that thought and enhancing my previous comment about turning stuff off when you

Speaker:

don't need it that includes publicfacing services so if a vendor does need to SSH

Speaker:

or VPN in to address help you address a problem those services should only be

Speaker:

enabled and turned on when they're needed

Speaker:

Agreed.

Speaker:

not just all

Speaker:

Agreed.

Speaker:

Especially my favorite service, RDP, the, the

Speaker:

Ransomware Deployment Protocol.

Speaker:

Two two other things I'd like to add

Speaker:

sure

Speaker:

is one of the other situations that we run into a lot is backup admin is running

Speaker:

daytoday operations as backup admin So he's checking his email he's surfing the

Speaker:

internet and that's the admin account And so good best practice is Bob backup admin

Speaker:

has a b a normal Bob account that's not an admin and that's what he's doing daytoday

Speaker:

stuff in and then he's gotta log into Bob the backup admin to do backup admin stuff

Speaker:

Like

Speaker:

That's painful, Mike.

Speaker:

And then the last thing I'll mention because if this happened your your

Speaker:

red team example earlier would have been more difficult if not preventable

Speaker:

encrypt your backups and have different credentials for the decryption part

Speaker:

Yeah.

Speaker:

Agreed.

Speaker:

Agreed.

Speaker:

Now, in the case of this particular red team, he was able to actually take control

Speaker:

of the backup server, and so encryption doesn't help at that point, right?

Speaker:

he didn't steal backups, he stole the back- he stole the backup server, right?

Speaker:

and I think that's a mi a a common misconception for people that

Speaker:

think my data's encrypted it's only encrypted when you're not using it

Speaker:

Right

Speaker:

you can't work on encrypted data We're not that smart

Speaker:

yeah, by the

Speaker:

when you log in or authenticate to a system that's encrypted it becomes

Speaker:

unencrypted so that you can use it

Speaker:

By the way, along the same lines as, admin also, if your account, if

Speaker:

your admin account doesn't need to be named admin, change that, right?

Speaker:

Again, don't make it the default username and the default password, right?

Speaker:

admin?

Speaker:

yeah, admin, yeah, exactly.

Speaker:

and then we can also just talk about just hardening everything, but

Speaker:

especially the management plane and especially backup stuff, and that is

Speaker:

if you're not using either MFA or, pass keys on your, security infrastructure

Speaker:

and your backup infrastructure, it's time to do that, right?

Speaker:

Prasanna, you wanna remind us what MFA is and why we care?

Speaker:

Yeah.

Speaker:

MFA is multi-factor authentication.

Speaker:

So you see this everywhere, right?

Speaker:

It's like you log in using your password and it's "Please

Speaker:

touch your keypad," right?

Speaker:

The biometric sensor in order to know it's you or look at the face

Speaker:

ID so it knows it's you, and so this way you have multiple ways to

Speaker:

authenticate that it's just you.

Speaker:

It's not just the password you know, but it's also, who you are.

Speaker:

And so that's multi-factor authentication.

Speaker:

Passkey is, I don't know what I would call it.

Speaker:

It's like passwords on steroids because you don't really need to

Speaker:

know the password anymore, right?

Speaker:

It's the ability to tie a particular device to a particular website such that

Speaker:

you no longer necessarily need to use a password whenever you are accessing that.

Speaker:

It's tied… And once again, it uses sort of MFA or, biometrics

Speaker:

in order to do the initial establishing of the authentication.

Speaker:

But after that, it's automatic.

Speaker:

Yeah, so you

Speaker:

How'd I do?

Speaker:

yourself to the device and the device authe- authenticates itself.

Speaker:

Mike, just curious, one thing I've noticed lately has been random

Speaker:

companies that I interface with and they've done away with passwords,

Speaker:

but they've replaced it with, "We're going to email you a one-time code."

Speaker:

And I'm like, "This isn't better." w- your thoughts on that?

Speaker:

No I agree given enough reconnaissance and time bad guys are gonna figure that

Speaker:

out for that organization And if it also depends on whether are you emailing it to

Speaker:

my personal account Are you emailing it to my work account are you requiring me to

Speaker:

go set up a new account like that I don't use for anything else there's ways of

Speaker:

doing that and each one of them have pros and cons but long story short MFA really

Speaker:

needs to be a wwhat would be considered outofbounds communication so not normal so

Speaker:

like a an authenticator app on your phone is probably the better So you've gotta

Speaker:

Yeah

Speaker:

and set it up with layers also So my authenticator app requires a PIN to get

Speaker:

into the authenticator app in order to get the code to use as MFA to get into

Speaker:

whatever site But preempting all of that making sure that policy does not allow

Speaker:

me to bypass MFA because I now trust this device or remember me or any of those

Speaker:

other things that would then store an MFA token in a browser or on this computer to

Speaker:

be trusted again in the future MFA has to happen every time in order to be effective

Speaker:

again, Mike, I, I so often learn random stuff from you that, and this is the one

Speaker:

today, and that is I didn't know the, my, my particular authenticator app does not

Speaker:

require a pin, and I like that idea a lot.

Speaker:

I'm gonna go check to see if it supports it, and then perhaps

Speaker:

I just haven't turned it on.

Speaker:

Similar to back in the day when you talked about having a separate browser

Speaker:

for, or a separate browser session, and the way I did it was I take my accounts

Speaker:

that matter, and I run it on a completely different browser, and then I t- I use

Speaker:

Chrome as my, regular browser, and then I use a different browser for that stuff.

Speaker:

And I actually installed a Chrome plugin that if I go to any of those accounts that

Speaker:

matter, it says, "Hey, you're not supposed to be over here. You're supposed to be

Speaker:

over there in the other place," right?

Speaker:

So I love it when I… I've been

Speaker:

Learn tidbits.

Speaker:

it when I learn st- stuff new.

Speaker:

th- this particular old dog, new tricks.

Speaker:

What was that, Mike?

Speaker:

similar to your plugin, on the company network, if you've-- if

Speaker:

you're diligent about making sure that your admins are using the admin

Speaker:

account only when they're doing admin stuff, you can monitor, like alert.

Speaker:

Every time an admin logs in, someone should know.

Speaker:

It gets logged, and then over time, you've got a baseline.

Speaker:

Like admins, 99% of the time, they're only logging into the admin account

Speaker:

Monday through Friday, eight to five, maybe Saturday to do some work.

Speaker:

But so if you can baseline that activity along with having

Speaker:

visibility into it, again, you can start to look for anomalies.

Speaker:

Someone, admin logged in at 2:00 a.m., we should call the admin

Speaker:

and see if that's really them.

Speaker:

And that's, if it's a one-off thing, then that's, that's easy to manage.

Speaker:

then on the audit or even incident response side, if you're looking

Speaker:

backwards about, in, in time for activity about an, an admin account, you

Speaker:

should be able to tie admin logged in.

Speaker:

is there a ticket associated with that?

Speaker:

was there a, a change in the backup system?

Speaker:

Was there a break fix, a new install, a new config?

Speaker:

Is there a ticket for that?

Speaker:

So that goes back to general controls and are we actually doing, these good,

Speaker:

am I following the change management or patch management policy or what have you?

Speaker:

so from an audit perspective, there's that.

Speaker:

then incident response also, if it's an admin and we're logging those activities,

Speaker:

that's gonna help us build the picture for how this happened and when it happened and

Speaker:

Yeah,

Speaker:

all that

Speaker:

and you can also, a very common thing to do is to prevent the ability to log in

Speaker:

directly as the, the admin account, right?

Speaker:

you can say, you can establish that.

Speaker:

You have to es- you have to start with establishing that as a policy, right?

Speaker:

And then there are technological things that you can do to simply

Speaker:

prevent a person from logging in, directly to the admin account.

Speaker:

They have to log in as themselves and then become the admin account.

Speaker:

and that even if you can't prevent it, you can, again,

Speaker:

like you said, monitor for that.

Speaker:

So if they, if somebody, if anybody does directly monitor into the admin

Speaker:

account, that's an event, right?

Speaker:

That you need to go research, which…

Speaker:

And maybe it's just your employee, it's 2:00 in the morning and they're half

Speaker:

asleep and they don't know what they're doing, but, maybe it's a, bad guy.

Speaker:

I had the opposite, situation go where we were seeing failed login attempts to

Speaker:

an admin account every Thursday morning.

Speaker:

And, we would escalate that to the client.

Speaker:

They would go look at it, they'd close the ticket, and, but

Speaker:

we wouldn't get any feedback.

Speaker:

But every Thursday morning, there were these failed admin account logins,

Speaker:

and it was because their admin was going through a tough patch and would

Speaker:

go get drunk every Wednesday night and come in Thursday morning and have

Speaker:

trouble remembering his password.

Speaker:

So eventually we heard the whole story, but, that's

Speaker:

Yeah, b- Curtis, one of the things you write, you talked about MFA

Speaker:

and passkeys at the beginning.

Speaker:

Yeah

Speaker:

Do you know of any backup systems that use passkeys?

Speaker:

I know that there are some that support it, yeah.

Speaker:

yeah.

Speaker:

and I think most… what some of them do is they outsource it to,

Speaker:

if you're gonna use an OTP, right?

Speaker:

You're gonna, you're gonna use something like Okta, right?

Speaker:

They're gonna use some sort of SSO, right?

Speaker:

Single sign-on package, and then they outsource it to that.

Speaker:

but I am aware of a handful that, that directly support passkeys, and this

Speaker:

is the thing, like if you're not, if you're not looking into passkeys now,

Speaker:

it's the best thing that's available, from a security perspective, from

Speaker:

a login pers- security perspective.

Speaker:

It's better than MFA.

Speaker:

if you're using MFA, we're actually gonna be doing, the, an upcoming

Speaker:

episode on we're gonna be talking about phishing-resistant MFA why that's a thing

Speaker:

and why you need it and, and what to do.

Speaker:

But again, you could just skip it and go straight to passkeys.

Speaker:

and that's a good thing.

Speaker:

right.

Speaker:

any final thoughts, Mike?

Speaker:

Be diligent, read the manual, change your passwords

Speaker:

There you go.

Speaker:

Prasanna

Speaker:

I got nothing, but I do miss our, podcast recordings, so looking

Speaker:

forward to the upcoming ones

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

It was, we took a little break there.

Speaker:

and, so hopefully the people are enjoying the, or did enjoy the, the

Speaker:

encore episodes that we put out.

Speaker:

There were some really good episodes in there, so I hope they enjoyed those.

Speaker:

and I'm glad that we're now, recording again.

Speaker:

all right, folks, thanks for listening.

Speaker:

You are why we do this.

Speaker:

That is a wrap

Speaker:

The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston.

Speaker:

If you need backup or DR consulting, content generation, or expert witness

Speaker:

work, check out backupcentral.com.

Speaker:

You can also find links for my O'Reilly books on the same website.

Speaker:

Remember, this is an independent podcast, and any opinions that

Speaker:

you hear are those of the speaker and not necessarily an employer.

Speaker:

Thanks for listening