Skip to contentExploitQuest

Lesson 1 of 1 in Lateral Movement

One Laptop, The Whole Organisation

The reason a single infected machine is a company-wide crisis: attackers move sideways. Reused local passwords, stolen credentials and flat networks let a foothold on one unremarkable computer become control of everything it can reach.

3 min read

Not yet reviewed

Wrenlearner

If they land on one reception laptop, that is contained, isn't it? It is just the one machine.

Magpieadversary

It is never just the one machine. From that laptop I can see the others. If the local administrator password is the same everywhere — and it so often is — then one is all of them. I do not re-break in. I walk.

Rookmentor

That walk is the difference between an incident and a catastrophe. And the thing that stops the walk is a wall the attacker cannot see through or a credential that does not fit the next lock.

Why sideways is so easy

Lateral movement thrives on sameness and trust. Networks are often flat — once you are inside, everything can talk to everything — and credentials are often shared, so the key that opened one machine opens the next. The attacker rarely needs a new exploit to move; they need a reused password and a path that was never blocked.

Reused local admin password   one password, every machine, one fall
Stolen credentials reused      the key from box A fits box B
Flat network                   inside is inside; nothing stops east-west
Trust relationships            this server is allowed to reach that one
  1. Line 1The classic. Image every laptop from the same template with the same local administrator password, and compromising one hands over all of them.
  2. Line 3A flat network treats "inside the perimeter" as "trusted". The perimeter is one phished click thick, and then there are no more walls.

In 2017 the NotPetya malware turned a single foothold into worldwide damage in hours, crippling shipping, logistics and manufacturing companies. It used a known exploit and stolen credentials to spread from machine to machine automatically. What made it so devastating was not how it got in — so what was it?

Building internal walls

The defences all make the inside less uniform and less trusting: segment the network so a machine can only reach what it genuinely needs, give every machine a unique local administrator password so one fall is not all of them, require a second factor on internal services and not just the perimeter, and watch east-west traffic — machine talking to machine — for the patterns that only an intruder makes.

Flat and uniform

Same local admin password everywhere.
Inside the perimeter is fully trusted.
Any machine can reach any other.

Segmented and unique

A different local password per machine.
Internal services still ask for proof.
Machines reach only what their job needs.

The left column is one bad click away from total loss; the right turns the same click into a contained mess. The attacker's walk only works while the floor is flat.

One thing you can do this week: at home, put the devices you trust least — the smart TV, the random gadgets — on your router's guest network, away from your computers and phones. It is network segmentation at the smallest scale, and it is the same idea that stops a walk becoming a catastrophe.