Tactic in which an attacker compromises a website legitimately visited by their target to infect it without its knowledge, rather than attacking the victim directly.
The expression watering hole borrows the image of a predator waiting for prey around a watering hole, an obligatory passage point. Appearing in security literature around 2012, it describes an indirect compromise technique that is particularly effective against heavily defended direct targets, such as government agencies, defense contractors or research institutes, whose employees nonetheless frequent less secure sector websites: professional forums, industry associations, standards-body sites. The attacker selects and compromises these intermediary sites, injects malicious code, a drive-by download or a browser exploit, and waits for the target to come to them. The technique is attributed notably to the APT1 and Elderwood groups, which targeted US defense contractors via sub-contractor sites. It is difficult to detect because the infected employee performed a perfectly normal action, visiting a legitimate professional site, and the infection may exploit a zero-day vulnerability that triggers no alert. For insurers, watering-hole attacks illustrate the limits of the defensive perimeter concept: the compromise chain begins outside the insured's network, raising questions about coverage for losses initiated by third parties not party to the policy.
In 2013, Apple, Facebook, Microsoft and Twitter were compromised via a developer forum for iOS developers regularly visited by their engineers. The site had been booby-trapped with a Java zero-day exploit. No phishing attempt targeting employees directly had been necessary.
watering hole, point d'eau, attaque par compromission de site tiers, strategic web compromise