skip to content

Poisoned Destinations

Nobody sends anything: the operator waits where a target group already goes and picks the site as a filter for its readers. Interviewers ask because the reflex is to call it the site owner's problem.

on this pageshow

explore

questions

4

In a watering-hole attack, how does the attacker target a specific group without sending anything?

level: juniorimportance: must knowfreq 66%

answer

  1. nobody is sent anything
  2. the readership does the selecting
  3. the domain is genuinely theirs
  4. targeting by place, not by person
  5. collateral visitors are the cost

basics

~20 s

A watering hole works by poisoning a site only the target group reads, so the readership performs the selection. No message is sent, no recipient is ever chosen, and no mail path exists anywhere on the route.

solid answer

~40 s

The attacker picks a destination instead of a person. If an industry-association page is read almost exclusively by one sector's platform engineers, poisoning that page reaches those engineers without anyone selecting them: the site's readership is the filter, and it does the targeting for free. Nothing is sent, so there is no recipient list, no sender to impersonate, and no mail path on the route at all. The visitor arrives by habit, at a domain that is genuinely old and genuinely theirs, which is why the usual `is this the real site?` instinct never triggers. The trade is precision for reach: the operator gets everyone who visits, including people they did not want, and must either accept that or add server-side filtering on the poisoned page so only matching visitors are served.

go deeper

for a junior

Be ready to define the technique in one sentence and say plainly that the site's readership does the targeting, so no recipient is ever chosen and nothing is sent.

for a middle

Explain the mechanics: how the poisoned page can filter by source network, geography or user agent so only matching visitors are served, and why the third party's genuine reputation is doing so much of the work.

for a senior

Show you can classify correctly under pressure - delivery rather than payload, a human-chosen destination rather than an automated build path - and reason about which of your people sit in that readership.

for a principal

Own the fact that the poisoned asset belongs to someone else. Be ready to argue what your organisation does about a dependency on a third-party resource it cannot fix, and who pays for the alternative.

## The idea Most social engineering starts with a message: someone picks recipients, writes a lure, and pushes it at them. A **watering hole** inverts that. The attacker picks a *place* the intended people already go, poisons it, and waits. The name comes from a predator sitting at the pool rather than chasing individual animals across the plain. ## Why the readership is the mechanism The selection work is done by whoever reads the site. Suppose there is an industry-association page that publishes the specification updates and conformance notes for one narrow sector, and in practice its weekly readers are the platform engineers of the two dozen firms in that sector. An operator who gets content onto that page has reached exactly those engineers, and has done so **without ever knowing a single name, address or phone number**. That is the whole trick, and it is why the technique is described as targeted even though the operator never targeted anybody. Three consequences follow, and interviewers probe all three: 1. **There is no message, so there is no message-shaped defence on the path.** Nothing was mailed, so nothing was evaluated for sender authenticity, nothing was rewritten, and there is no recipient list to reason about afterwards. Reasoning that starts with `how did it get past mail?` has already gone wrong. 2. **The reputation involved is real.** The domain was registered years ago, it belongs to the organisation whose name is on it, it is bookmarked, and the visitor arrived by habit rather than by clicking a link somebody sent. Every heuristic a person is taught for spotting a lure - check the sender, hover the link, look at the domain - is aimed at a message that does not exist here. 3. **Precision is bounded by readership, not by intent.** If the site is read by the sector *and* by students, journalists and search-engine crawlers, all of them are in scope. Collateral reach is the default cost of the technique. ## How operators narrow it anyway Because collateral reach is a cost, the poisoned page is often not served to everyone. Server-side filtering can gate on the source address range or the network the visitor comes from, on geography, on browser language or user agent, on the referring page, or on whether a cookie from an earlier visit is present. Non-matching visitors are handed the ordinary page and never see anything unusual. This is a *narrowing* move: it shrinks the pool to something closer to the intended readership, at the price of missing intended visitors who look wrong. ## What class of thing this is - and what it is not Getting the classification right matters more than the label: - It is a **delivery** technique. It answers `how does the content reach the person`, not `what does the content do`. - The poisoned thing is a **destination a human chose to visit**. If the poisoned thing sits inside an automated build path - a package namespace, a mirror, an installer pulled by a pipeline - that is a different family with different economics, because no human is choosing anything and the reach is every consumer of that artefact rather than every reader of a page. - It does not by itself imply a flaw was used. A watering hole can serve an exploit, or it can serve a panel that asks the visitor to download something. Those are different mechanisms with different answers, and assuming the first is the most common mistake here. ## The economics, from the other side A watering hole is not cheap. The operator must first obtain write access to a third party's site, or find a component that site includes and poison that instead. What they buy with that effort is reach into a group they could not have enumerated, arriving with the third party's credibility attached. That is why the technique is associated with operators who care about a *category* of victim - a sector, a community, a country's engineers - rather than with anyone hunting one named organisation, who would find a direct route cheaper. ## What removes it The thing the technique cannot substitute is a person's browser fetching content from a destination the person chose. You cannot patch a site you do not own, so the levers that actually bite are further down: controlling what may run on the endpoint after the fetch, and removing the dependency on the third-party resource so your people are no longer part of that readership.

  • How does an operator narrow a watering hole further than the readership already does?
    With server-side filtering on the poisoned page: the source address range or network the visitor arrives from, geography, browser language or user agent, the referring page, or a cookie set on an earlier visit. Non-matching visitors are handed the ordinary content. It trades reach for precision - intended visitors who look wrong are missed too.
  • Why is a long-established third-party site more valuable to the operator than a convincing lookalike domain?
    Because it is not a lookalike. The domain really belongs to that organisation, has years of history, is bookmarked, and is reached by habit rather than by following a link somebody sent. There is no sender to scrutinise and no domain string to compare, so the checks people are trained to run have nothing to bite on.
  • What does a watering hole cost the operator that a mass mail campaign does not?
    Write access to somebody else's site, or to a component that site includes. That is real work and it may be needed again if the third party cleans up. In exchange the operator gets reach into a group they could never have enumerated, delivered with the third party's credibility attached and with no lure text to be judged.

A predator that waits at the only water hole does not need to know which animals live nearby. The location has already narrowed the guest list.

saying these in an interview costs you the question

  • Says a watering hole targets one named individual
  • Assumes a message was sent and got through
  • Claims the site must be a lookalike domain
  • Thinks every visitor is always served the same content
  • Assumes an exploit is always involved

context

open as a page

Why does patching a browser do nothing against a fake 'update required' download prompt?

level: middleimportance: must knowfreq 58%

basics

~20 s

Patching removes software flaws, and a fake update prompt uses none. The page persuades a person to download and run an installer, so execution is granted by consent. Browser version, sandbox and patch level are all irrelevant to that.

open as a page

A sponsored search result served an installer, but the same link now shows the vendor's real page - why?

level: seniorimportance: should knowfreq 35%

basics

~20 s

The advertisement's click-through URL points at a redirector the operator controls. It inspects the visitor - address, geography, user agent, referrer, whether they have been seen before - and hands non-matching visitors the genuine page. One URL, two destinations.

open as a page

An industry site your engineers read weekly is poisoned by a publicity-seeking crew and you do not own it - what do you decide?

level: principalimportance: nice to knowfreq 20%

basics

~20 s

You cannot fix a site you do not own, so the choices are telling its operator, telling the sector, or removing your people's need to visit it. Each has a different owner and a different cost.

open as a page