Exchange flaws could be much worse than thought: Six hacking groups suspected of using the zero days pre-patch
- Reference: 1615811410
- News link: https://www.theregister.co.uk/2021/03/15/in_brief_security/
- Source link:
An [2]analysis by Slovak security shop ESET claims that six advanced criminal hacking groups, thought to have some level of state sponsorship, used the zero days to attack government and industry sites before the flaws were patched. At the time, Microsoft claimed that only one Chinese-based hacking group, dubbed Hafnium, had illicitly exploited the dodgy code. You can see the timeline below.
[3]
[4]
How it all went bad. Source: ESET. Click to enlarge
It appears five other groups – Tick, followed by LuckyMouse, Calypso, Websiic, and the Winnti Group – got in on the game before patches were released, although the latter (in the scenario outlined by ESET) used it just hours before the Microsoft announcement. And the timeline for this opens up some interesting possibilities, particularly in light of [5]reports that the flaws were leaked from a February 23 alert sent by Microsoft to key security partners worldwide.
[6]
DEVCORE hacker Orange Tsai [7]found the first Exchange bug on December 10, and had weaponized it to an admin-level RCE by New Year's Eve. After the January 5 notification to Microsoft he and the Redmond team finalised the draft report by February 18. It was sent on the 23rd, and five days later the second wave of attacks kicked off.
So pick your nightmare scenario. Either a state-sponsored team found and exploited the flaws – probably for a while before someone else found them – and then shared them out to similar groups. As a second possibility, DEVCORE or Microsoft's security team was penetrated (worrying in light of the targeting of ethical bug hunters), or finally, there's a possibility that one or more of Redmond's security partners is feeding information to the enemy.
The truth could also be a mishmash of all these options.
Could anything make this whole Exchange mess worse? Possibly: Sysadmins have taken to Reddit to [8]complain that Microsoft's MSERT malware protection tool is producing false positives for signs of the attacks on Exchange.
Former Apple materials lead accused of clumsily stealing secrets
Simon Lancaster, one of Apple's Advanced Materials Leads before he left the firm in November 2019, has been sued by his former employer for allegedly stealing company secrets for his own use, and for allegedly leaking to a member of the press.
In a lawsuit first [9]reported on Thursday, Apple has accused Lancaster of intellectual property theft, saying he used the purloined data as the basis for joining a startup. He is also accused of offering to feed Apple secrets to a journalist, who in return offered to write articles about said startup.
It's claimed he attended meetings he shouldn't have to get information on forthcoming Apple products, was passing information physically and digitally to the unnamed journalist, and established a relationship whereby the member of the media would dig into areas of Apple's business Lancaster wanted to know more about.
Lancaster is being sued for violation of Defense of Trade Secret Act, violation of California Uniform Trade Secret Act, and a breach of written contract.
More woes as recorded iPhone calls open to all
Not Apple's fault this one, but still very worrying.
For those iPhone users wanting to record their phone calls there's an app, unsurprisingly called Call Recorder, but it turns out those recordings could have been made available to all. Anand Prakash, founder of bug-hunters Pingsafe AI, spotted a glitch in the app that left a [10]reported 130,000 audio recordings, or around 300GB's of data, open for plundering.
"PingSafe AI decompiled the IPA file and figured out S3 buckets, host names and other sensitive details used by the application," [11]it said .
"The vulnerability allowed any malicious actor to listen to any user's call recording from the cloud storage bucket of the application and an unauthenticated API endpoint which leaked the cloud storage URL of the victim's data."
The app has now been fixed, thanks to responsible disclosure, but it might be worth deleting unwanted recordings.
Swiss police cuff member of Verkada bug finding team
Earlier this week bug hunters [12]found that admin credentials for video surveillance biz Verkada had been left exposed, leaving big-name customers like Cloudflare and Tesla having their in-facility surveillance potentially leaked. Now one of the team that found the issue has been cuffed, but not for that incident it seems.
Tillie Kottmann, the 21-year-old hacker who was mentioned in the original Verkada case, was [13]reportedly arrested by Swiss police on Friday. Not for the video incident, but for an earlier affair of criminal hacking. It's believed this is down to an investigation by the FBI in the Western District of Washington.
Time to get patching Git users
Git [14]has patched an RCE in the delayed checkout mechanism Git LFS uses, and it's a case of fix it now or cripple your systems.
Users need to upgrade to version 2.30.2 to avoid the error "where a specially crafted repository can execute code during a git clone on case-insensitive filesystems which support symbolic links by abusing certain types of clean/smudge filters, like those configured by Git LFS."
[15]
The only alternative is to disable support for symbolic links and process filters and avoid untrusted repositories. ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/
[2] https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YE@Sq1O6VWBJRXGr4Pym1QAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://regmedia.co.uk/2021/03/13/eset.jpg
[5] https://www.wsj.com/articles/microsoft-probing-whether-leak-played-role-in-suspected-chinese-hack-11615575793/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YE@Sq1O6VWBJRXGr4Pym1QAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://proxylogon.com/
[8] https://www.reddit.com/r/exchangeserver/comments/m2z7rj/msert_displays_files_infected_7_then_says_server/
[9] https://appleinsider.com/articles/21/03/11/apple-sues-former-employee-over-device-leaks-to-media
[10] https://techcrunch.com/2021/03/09/iphone-thousands-calls-exposed/
[11] https://www.pingsafe.ai/blog/how-we-could-have-listened-to-anyones-call-recordings
[12] https://www.theregister.com/2021/03/10/150k_cctv_cameras_verkada_breach/
[13] https://www.bloomberg.com/news/articles/2021-03-12/swiss-police-raid-apartment-of-verkada-hacker-seize-devices?sref=P6Q0mxvj
[14] https://github.blog/2021-03-09-git-clone-vulnerability-announced/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YE@Sq1O6VWBJRXGr4Pym1QAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
Re: We need to change the Internet
So, I have a question about this here Exchange Vuln....
The Co I used to work for had exchange, but INTERNAL only. Only active sync was exposed via a reverse proxy. Probably not that uncommon.
The question I need to ask is: Is it because they HAVE exposed their Exchange servers to the internet are they being hacked, in which case.... Imbeciles, or is there something a little more clever going on?
Re: We need to change the Internet
The exploit only works if you have OWA ETC exposed directly to the internet.
If you simply said "uh, no" and stuck the entire thing behind a VPN leaving nothing but ports 21/587 exposed then you remain impervious to this entire threat class.
The biggest surprise is that over fifty thousand exchange servers were compromised like this, and thus directly addressable on the internet.
Git update... bootnote... ish.
For those of us using an out of date Mac, homebrew refused to update git, citing a missing keg.
Yesterday, homebrew itself was updated and the latest version of git installs properly.
Get patching all High Sierra users!
The only alternative
. . is to stop using someone else's server to retrieve production code !
You bring the code in-house, you analyze it and test it, and when it is suitable, you compile it and put it on your production server.
Anything else is just asking for trouble.
We need to change the Internet
Easy access and performance have been the top priorities for years, security has always been just a "feature" - remember the old days when if you were driving around after an evening in the pub and it was never a problem unless you ran off the road a few times? Nowadays driving around is a security issue and doing it drunk is a crime, moving the driving world view into the Internet will not be easy but security needs to be a high priority - look at what's happening everywhere ... if it's connected to the Internet then it's at constant risk of getting hacked these days.
If we don't change the Internet then we'll keep getting hacked (see icon).