News: 1621429331

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Miscreants started scanning for Exchange Hafnium vulns five minutes after Microsoft told world about zero-days

(2021/05/19)


Attackers began scanning for vulnerabilities just five minutes after Microsoft announced there were four zero-days in Exchange Server, according to Palo Alto Networks.

Malicious people seeking to exploit flaws in general were doing so within a quarter of an hour of details being released, the company's Cortex Xpanse research team said today.

Although research director Rob Rachwald did not elaborate when The Register asked for more detail on its findings, a released report reckoned "scans began within 15 minutes after Common Vulnerabilities and Exposures (CVE) announcements were released between January and March."

[1]

[2]

"Computing has become so inexpensive that a would-be attacker need only spend about $10 to rent cloud computing power to do an imprecise scan of the entire internet for vulnerable systems," said Palo Alto's latest attack surface threat report. Such technology can be used for good as well as bad; search engines such as Shodan and GrayHatWarfare are built on it.

Around a third of "overall security issues" noticed by Palo Alto related to poorly configured remote desktop protocol (RDP) setups, with cloud environments being responsible for 80 per cent of "critical" vulns spotted during what the company described as scans of "the public-facing internet attack surface of some of the world's largest businesses."

The finding about time-of-flight between vuln disclosure and malicious scan hunting for exploitable deployments chimes with previous research on the same topic: last summer [3]a SANS researcher noticed fresh honeypots were being probed for newly patched Citrix vulns – ironically he was hoping for attackers to try to exploit known vulns in F5 Networks gear at the time.

[4]

Inexplicably, some organisations drag their feet when it comes to patching even critical flaws. Last year's Netlogon vuln, which [5]allowed attackers to bypass logon authentication and gain domain admin-level privileges on vulnerable networks, was being actively exploited a month after Microsoft emitted patches amid top-grade warnings about the critical security risk that the flaw, CVE-2020-1472, posed.

Being slow to patch has consequences, as the EU Banking Authority found out a week after [6]patches were made available for the Hafnium Exchange vulns; the organisation [7]had to pull its email servers offline after being compromised , as did [8]the Norwegian Parliament . ®

Get our [9]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKU2GuT8WQlz7@X3lFZZVwAAAIM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKU2GuT8WQlz7@X3lFZZVwAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://www.theregister.com/2020/07/09/citrix_bugs_proof_of_concept_exploits/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKU2GuT8WQlz7@X3lFZZVwAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2020/09/24/microsoft_zerologon_in_wild/

[6] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[7] https://www.theregister.com/2021/03/09/eba_exchange_breach/

[8] https://www.theregister.com/2021/03/11/stortinget_attack/

[9] https://whitepapers.theregister.com/

Hobson's choice then!

KittenHuffer

Either patch fast and then have your systems go down cos the supplier has burped out a bad patch.

Or test the patches to make sure they don't bork your system .... only for the black hats to compromise your system before you're ready to apply that patch.

Re: Hobson's choice then!

UCAP

Or make sure that your systems are secured so that the black hats can't gain access to them from the Internet, or that any such systems that do require Internet access do not have any critical and/or sensitive data on them.

Note: Exchange would normally fall into the latter category.

Re: Hobson's choice then!

Neil Barnes

Y'know, if all those handy dandy click through and extension hiding and auto-executing things that MS have added over the years hadn't actually been added, life would be a lot simpler.

Re: Hobson's choice then!

Potemkine!

Note: Exchange would normally fall into the latter category.

Problem is, Exchange needs to be interfaced with an AD controller. I know many occurrences where both are on the same physical server.

Re: Hobson's choice then!

WolfFan

Hmm. We put the ADDS DC on one machine, stuff like DHCP, DNS, RRAS, on another, and Exchange, file services, database services, etc., on other machines. That’s other physical machines. There might be multiple file servers running in VMs, but on one or two or three (redundancy, y’know) different physical machines. None of which will be a DC.

Re: Hobson's choice then!

Roland6

There are a lot of (small) businesses that only use one physical server running in VM's: DC, RDS, & Exchange...

Re: Hobson's choice then!

Dippywood

...patch fast and then have your systems go down cos the supplier has burped out a bad patch.

Down == safe. Not the 'safe' you want, and possibly permanently 'safe.'

But safety first, recover what's left of the business later - it is the modern way.

You get what you pay for

Potemkine!

Many SME companies doesn't consider that paying a competent IT guy is required. Many big group prefer to externalize everything to the lowest bidder. Those companies get the service they pay for: a shitty one.

Re: You get what you pay for

Mike 137

" Many big group prefer to externalize everything to the lowest bidder "

Most SMBs in my experience outsource to any old guys someone suggested, or to an "all in" external IT service from their vendor with "support" thrown in.

You get the security you put the necessary and appropriate effort into. However, if you know nothing about infosec because you're an expert widget maker or art studio, how on earth are you expected to know the difference? Most of the available guidance is so superficial or general that it doesn't inform, and the rest is so technical that it only informs those who already know.

We need real public education on practical infosec that equips folks to evaluate and select support services properly.

Re: You get what you pay for

Version 1.0

Employ a competent IT security person, someone who leaves a USB stick in the office when they are interviewed and later in the day when someone picks the Rubber Ducky USB stick up and plugs it into their computer the entire network is compromised with a message on every computer, "You folks need to employ me to stop this happening again."

There's another way to survive. Mutual trust -- and help.
-- Kirk, "Day of the Dove", stardate unknown