Pentester Perspective: Breaking Bad Backups

Source: The Adversary Co.

Author: By: Matt Millen

URL: https://adversaryco.com/blog/breaking-bad-backups.html

https://adversaryco.com/blog/breaking-bad-backups.html

ONE SENTENCE SUMMARY:

Real pentests show misconfigured backup infrastructure, especially domain-joined Veeam, enables credential theft, backup destruction, and full domain compromise.

MAIN POINTS:

  1. Ransomware increasingly targets backup repositories to block recovery and force ransom payments.
  2. Veeam’s report shows backups were targeted in 89% of ransomware victim organizations.
  3. Joining backup servers to production AD creates bidirectional compromise pathways between domain and backups.
  4. Weak segmentation often exposes consoles and repositories to general workstation networks.
  5. Legacy name-resolution and broadcast protocols enable credential interception and relay during AiTM positions.
  6. HTTP WSUS configurations allow network attackers to deliver malicious updates and gain SYSTEM execution.
  7. Local admin control of Veeam enables DPAPI decryption of stored credentials from configuration databases.
  8. Rogue vSphere endpoints can capture Veeam service credentials in plaintext during SOAP authentication.
  9. Unencrypted backup files on permissive SMB shares allow offline extraction of NTDS.dit and hashes.
  10. Hardening requires isolation, least privilege, restricted console access, encryption, immutability, logging, and rapid patching.

TAKEAWAYS:

  1. Separate backup infrastructure from production AD using a workgroup or isolated management forest.
  2. Enforce dedicated VLANs, strict firewalling, and admin via jump hosts or privileged workstations only.
  3. Replace Domain Admin backup accounts with tightly-scoped service accounts and MFA-protected administration.
  4. Turn on per-job AES-256 encryption and immutable repositories to prevent theft and backup sabotage.
  5. Treat backups like tier-zero assets: monitor access, audit configuration changes, and patch urgently.