ContentsThe library

Thinking Like an Attacker

Three Harmless Things in a Row

Last timeGoing Through It Systematically

Real incidents are rarely one dramatic failure. They are three or four findings nobody would have fixed, arranged in an order, each one making the next one possible.

Severity is not local

The list from the last lesson is full of findings that nobody would fix.

An endpoint that confirms whether an address is registered. A file upload

that keeps the name it was given. A page that reflects a parameter back

into the response. A worker that retries a failed job without checking

whether it already ran.

Taken one at a time each of those is a shrug. Nothing is disclosed,

nothing is lost, and a reasonable engineer asked to prioritise them would

put every one at the bottom.

That instinct is the subject of this lesson, because it is how most real

incidents happen. The question a finding should be asked is not what does

this lose, it is what does this enable, and that question cannot be

answered by looking at the finding.

FIG 1The same four findings, scored twice
severity alone, 0 to 3severity in the chain, 0how easy to fix, 0 to 3how alarming it sounds,
an endpoint confirms whe0311
an upload keeps the file0321
a page reflects a parame1322
a retry runs a job that 0230
The first column is nearly all zeros and the second is nearly all threes. The two marked cells are the same finding scored both ways, and the gap between them is the entire argument of this lesson. Note also that the easiest fix is in the row that sounds least alarming.

What a step hands over

The reframing that makes chains visible is to describe every finding by

the capability it grants rather than by the damage it does.

Almost nothing in a real chain causes damage. The steps hand over

knowledge of a valid name, or an identifier that turns out to be accepted

elsewhere, or one permission more than intended, or a place on disk where

a file can be left, or a way to make one operation slow enough to matter.

FIG 2One chain, drawn as what the attacker holds
Ten nodes alternating between a step and what the attacker now holds. Read only the odd nodes and it is a list of trivia. Read only the even ones and it is an escalation. Neither view alone shows the incident.
FIG 3The same chain, with what it cost and what it was worth
stepstepwhat it handed overcost to the attackerseverity if found alonewhat happened
1address confirmationa real staff nameten minutesnone, closed as working as intendedThis is the step that gets closed with a comment explaining that the behaviour is necessary for the sign-up flow, which is true.
2a reflected parametera link that looks internalan afternoonlow, needs user interactionNeeds user interaction is the phrase that buries this category, and the chain is precisely a description of how that interaction is obtained.
3any staff session reaches the consoleread access to every accountnothingnot on the list at allNot a finding. A design decision, made for a good reason, which is why no enumeration pass caught it and why the drawing from lesson two matters.
4an unattributed exportthe table, with no recordminuteslow, internal toolInternal tool is doing the same work that needs user interaction did two rows up, and it is wrong for the same reason.
5the whole chainthe outcome you actually care aboutone daythe worst thing in the registerOne day of work, four findings, none of which would have reached the top of anybodys list.
5 steps
Look down the last column, then at the last row. Four entries of none or low produce the worst outcome on the asset register, and the total cost to the attacker is a single day.

Building the chain

Chains are found backwards. This is the single most useful technique in

the lesson and it is counterintuitive, because the findings are in front

of you and the temptation is to start there.

Starting from a finding and asking what it could lead to produces a story.

There is always a sequence of events in which some trivial thing becomes

terrible, and the room enjoys inventing them, and the output is not

rankable because nobody can say whether any of it is likely.

Starting from an outcome and asking what would be required produces a

requirement. Take the worst line of the asset register. To read every

customer record, somebody needs console access. To get console access,

they need a staff session. To get a staff session, they need either a

password or a way to use one. Each answer is a question, and the questions

terminate either at something on your findings list, which closes a chain,

or at something genuinely hard, which is a defence you can name.

The lesson stops here

2 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Start With What You Would Hate to Lose
  2. 02The Drawing Is Where the Findings Areopening only
  3. 03Nobody Attacks You in Generalopening only
  4. 04A Checklist Beats Being Cleveropening only
  5. 05Three Harmless Things in a Rowyou are here
  6. 06Rank by Loss, Not by Frightopening only
  7. 07Most of the List Is Not Going to Be Fixedopening only
  8. 08Hook It to the Things That Changeopening only

Read alongside