{"id":7287,"date":"2015-08-05T07:03:15","date_gmt":"2015-08-04T23:03:15","guid":{"rendered":"http:\/\/staging.bankvaultonline.com\/?p=1135"},"modified":"2015-08-05T07:03:15","modified_gmt":"2015-08-04T23:03:15","slug":"definition-of-the-day-watering-hole-attacks","status":"publish","type":"post","link":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/","title":{"rendered":"Definition of the Day: Watering Hole Attacks"},"content":{"rendered":"

Watering hole attacks were in the news earlier this year (2015) after a Chinese cyber espionage group successfully compromised several major US financial services and defense industry companies. The attack sprang from malicious code injected into www.forbes.com\u2019s \u2018Thought of the Day\u2019 widget, which is a flash pop-up users see upon visiting the Forbes.com home page. <\/p>\n

The group exploited two zero-day vulnerabilities, one in Microsoft’s Internet Explorer and the other in Adobe’s Flash Player \u2013 both have since been fixed by Microsoft and Adobe. <\/p>\n

The forbes.com example is a classic, \u2018watering hole\u2019 drive-by attack. The premise of the watering hole attack is simple: identify a place \u2013 online or in the real world \u2013 where members of a community gather and then poison that place. Once the place is \u2018poisoned\u2019 the hackers are then able to exploit vulnerabilities by injecting malware into those visiting that place. <\/p>\n

In the physical world, a watering hole attack might be something like setting up a fake, free wifi service at a coffee shop where employees of a target company often go. <\/p>\n

In the Forbes attack, the watering hole was their flash \u2018thought of the day\u2019 widget that many people in the financial services and defense industry see because they are so apt to visit www.forbes.com. <\/p>\n

Simple, classic and dangerous. <\/p>\n","protected":false},"excerpt":{"rendered":"

Watering hole attacks were in the news earlier this year (2015) after a Chinese cyber espionage group successfully compromised several major US financial services and defense industry companies. The attack sprang from malicious code injected into www.forbes.com\u2019s \u2018Thought of the Day\u2019 widget, which is a flash pop-up users see upon visiting the Forbes.com home page. […]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[346,349],"tags":[350,107,263,351,352,353,341],"class_list":["post-7287","post","type-post","status-publish","format-standard","hentry","category-definition-of-the-day","category-faqs","tag-chinese-cyber-espionage","tag-chinese-hackers","tag-definition-of-the-day","tag-forbes-com","tag-watering-hole","tag-watering-hole-attack","tag-zero-day-vulnerability"],"yoast_head":"\nDefinition of the Day: Watering Hole Attacks - BankVault<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Definition of the Day: Watering Hole Attacks - BankVault\" \/>\n<meta property=\"og:description\" content=\"Watering hole attacks were in the news earlier this year (2015) after a Chinese cyber espionage group successfully compromised several major US financial services and defense industry companies. The attack sprang from malicious code injected into www.forbes.com\u2019s \u2018Thought of the Day\u2019 widget, which is a flash pop-up users see upon visiting the Forbes.com home page. […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"BankVault\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/BankVaultOnline\/\" \/>\n<meta property=\"article:published_time\" content=\"2015-08-04T23:03:15+00:00\" \/>\n<meta name=\"author\" content=\"A. Yost\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:site\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"A. Yost\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Definition of the Day: Watering Hole Attacks - BankVault","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Definition of the Day: Watering Hole Attacks - BankVault","og_description":"Watering hole attacks were in the news earlier this year (2015) after a Chinese cyber espionage group successfully compromised several major US financial services and defense industry companies. The attack sprang from malicious code injected into www.forbes.com\u2019s \u2018Thought of the Day\u2019 widget, which is a flash pop-up users see upon visiting the Forbes.com home page. […]","og_url":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/","og_site_name":"BankVault","article_publisher":"https:\/\/www.facebook.com\/BankVaultOnline\/","article_published_time":"2015-08-04T23:03:15+00:00","author":"A. Yost","twitter_card":"summary_large_image","twitter_creator":"@bankvaultonline","twitter_site":"@bankvaultonline","twitter_misc":{"Written by":"A. Yost","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/#article","isPartOf":{"@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/"},"author":{"name":"A. Yost","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/3cdb9c0092164dfe039b20c2972e655a"},"headline":"Definition of the Day: Watering Hole Attacks","datePublished":"2015-08-04T23:03:15+00:00","dateModified":"2015-08-04T23:03:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/"},"wordCount":226,"commentCount":0,"publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"keywords":["Chinese cyber espionage","Chinese hackers","definition of the day","forbes.com","watering hole","watering hole attack","zero day vulnerability"],"articleSection":["Definition of the Day","FAQs"],"inLanguage":"en-AU","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/","url":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/","name":"Definition of the Day: Watering Hole Attacks - BankVault","isPartOf":{"@id":"https:\/\/www.bankvault.com\/#website"},"datePublished":"2015-08-04T23:03:15+00:00","dateModified":"2015-08-04T23:03:15+00:00","breadcrumb":{"@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/#breadcrumb"},"inLanguage":"en-AU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.bankvault.com\/definition-of-the-day-watering-hole-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.bankvault.com\/"},{"@type":"ListItem","position":2,"name":"Definition of the Day: Watering Hole Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.bankvault.com\/#website","url":"https:\/\/www.bankvault.com\/","name":"BankVault","description":"cybersecurity","publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bankvault.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-AU"},{"@type":"Organization","@id":"https:\/\/www.bankvault.com\/#organization","name":"BankVault","url":"https:\/\/www.bankvault.com\/","logo":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","contentUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","width":1212,"height":275,"caption":"BankVault"},"image":{"@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/BankVaultOnline\/","https:\/\/x.com\/bankvaultonline"]},{"@type":"Person","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/3cdb9c0092164dfe039b20c2972e655a","name":"A. Yost","image":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/11403c3c24c2d02aecc26fa833deb0ca?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/11403c3c24c2d02aecc26fa833deb0ca?s=96&d=mm&r=g","caption":"A. Yost"},"url":"https:\/\/www.bankvault.com\/author\/blogger\/"}]}},"_links":{"self":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/7287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/comments?post=7287"}],"version-history":[{"count":0,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/7287\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/media?parent=7287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/categories?post=7287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/tags?post=7287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}