Ecommerce platforms (cough, Magento) need patching before Black Friday, warns UK's National Cyber Security Centre
(2021/11/22)
- Reference: 1637601251
- News link: https://www.theregister.co.uk/2021/11/22/ncsc_magento_updates_black_friday_reminder/
- Source link:
If you run a small online business powered by the Magento ecommerce platform, Britain's National Cyber Security Centre (NCSC) is begging you to make sure it's fully patched ahead of Black Friday.
"Retailers are urged to ensure that Magento – and any other software they use – is up to date," said the GCHQ offshoot in a statement today, adding it had notified 4,151 online stores that their Magento installations were vulnerable to compromise by criminals.
"The majority of the online shops used for skimming identified by the NCSC had been compromised via a known vulnerability in Magento, a popular e-commerce platform," said the cybersecurity agency.
[1]
Magento is one of the more widely used open source e-commerce platforms. Although the company was bought out by Adobe a few years ago and a paid, managed version is available, many SMEs are skipping that to cut costs.
[2]
[3]
Compromising Magento to steal customers' credit card details is a problem that has lingered for years – and the barrier to entry for this kind of digital crime isn't very high, as Dutch infosec firm Sansec noted last year after [4]spotting a video offering Magento hacking tips for just $5,000 .
Willem de Groot, MD of Sansec, told The Register that card-skimming is a real headache around this time of year.
[5]
"Every year," he lamented, "Sansec observes an uptick in online skimming incidents in the week before Black Friday. Since 2015, we have discovered more than 60,000 online stores with an injected payment skimmer."
He recommended double-checking that Magento installations are fully up to date (the latest open source version is 2.4.3-p1) and enabling multi-factor authentication on staff accounts – and also encouraged consumers to use so-called "one-time" credit card numbers, which are available through some banks.
NCSC deputy director for economy and society Sarah Lyons said in a canned statement: "We want small and medium-sized online retailers to know how to prevent their sites being exploited by opportunistic cyber criminals over the peak shopping period."
[6]
Generic IT advice, including stuff aimed at non-techies, is available on the NCSC website.
Attacks on Magento installations are so popular in the criminal underworld that they spawned an entire industry of card thieves loosely known as Magecart. Magecart gangs mostly target ecommerce platforms, no longer limiting themselves to the Adobe-owned software that proved so lucrative for them.
[7]Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000
[8]Badmins: Magento shops brute-forced to scrape card deets and install cryptominers
[9]Magecart malware merrily sipped card details, evaded security scans on UK e-tailer Páramo for almost 8 months
Infosec firm RiskIQ, one of many vendors tracking Magecart's various Hydra-like incarnations, [10]noted in 2019: "Web skimming goes well beyond Magento. Skimming groups target almost any web environment, including dozens of other online shopping platforms used by stores around the world."
Magecart groups were behind the infamous compromises [11]of British Airways and [12]Ticketmaster .
There's one more thing that everyone can do to protect themselves against card fraud during this weekend's US-inspired Black Friday/Cyber Monday shopping frenzy.
"Monitor your card statements, especially in the holiday season," warned Sansec's de Groot. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2020/09/15/magento_1_exploit_sold_online/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2020/09/15/magento_1_exploit_sold_online/
[8] https://www.theregister.com/2018/04/03/magento_brute_force_attack/
[9] https://www.theregister.com/2020/05/19/paramo_hack_magecart/
[10] https://www.riskiq.com/blog/labs/magecart-beyond-magento/
[11] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/
[12] https://www.theregister.com/2020/11/13/ticketmaster_fined_1_25m_magecart_breach/
[13] https://whitepapers.theregister.com/
"Retailers are urged to ensure that Magento – and any other software they use – is up to date," said the GCHQ offshoot in a statement today, adding it had notified 4,151 online stores that their Magento installations were vulnerable to compromise by criminals.
"The majority of the online shops used for skimming identified by the NCSC had been compromised via a known vulnerability in Magento, a popular e-commerce platform," said the cybersecurity agency.
[1]
Magento is one of the more widely used open source e-commerce platforms. Although the company was bought out by Adobe a few years ago and a paid, managed version is available, many SMEs are skipping that to cut costs.
[2]
[3]
Compromising Magento to steal customers' credit card details is a problem that has lingered for years – and the barrier to entry for this kind of digital crime isn't very high, as Dutch infosec firm Sansec noted last year after [4]spotting a video offering Magento hacking tips for just $5,000 .
Willem de Groot, MD of Sansec, told The Register that card-skimming is a real headache around this time of year.
[5]
"Every year," he lamented, "Sansec observes an uptick in online skimming incidents in the week before Black Friday. Since 2015, we have discovered more than 60,000 online stores with an injected payment skimmer."
He recommended double-checking that Magento installations are fully up to date (the latest open source version is 2.4.3-p1) and enabling multi-factor authentication on staff accounts – and also encouraged consumers to use so-called "one-time" credit card numbers, which are available through some banks.
NCSC deputy director for economy and society Sarah Lyons said in a canned statement: "We want small and medium-sized online retailers to know how to prevent their sites being exploited by opportunistic cyber criminals over the peak shopping period."
[6]
Generic IT advice, including stuff aimed at non-techies, is available on the NCSC website.
Attacks on Magento installations are so popular in the criminal underworld that they spawned an entire industry of card thieves loosely known as Magecart. Magecart gangs mostly target ecommerce platforms, no longer limiting themselves to the Adobe-owned software that proved so lucrative for them.
[7]Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000
[8]Badmins: Magento shops brute-forced to scrape card deets and install cryptominers
[9]Magecart malware merrily sipped card details, evaded security scans on UK e-tailer Páramo for almost 8 months
Infosec firm RiskIQ, one of many vendors tracking Magecart's various Hydra-like incarnations, [10]noted in 2019: "Web skimming goes well beyond Magento. Skimming groups target almost any web environment, including dozens of other online shopping platforms used by stores around the world."
Magecart groups were behind the infamous compromises [11]of British Airways and [12]Ticketmaster .
There's one more thing that everyone can do to protect themselves against card fraud during this weekend's US-inspired Black Friday/Cyber Monday shopping frenzy.
"Monitor your card statements, especially in the holiday season," warned Sansec's de Groot. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2020/09/15/magento_1_exploit_sold_online/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZwhKY-GiQV4BPQbzZX-FwAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2020/09/15/magento_1_exploit_sold_online/
[8] https://www.theregister.com/2018/04/03/magento_brute_force_attack/
[9] https://www.theregister.com/2020/05/19/paramo_hack_magecart/
[10] https://www.riskiq.com/blog/labs/magecart-beyond-magento/
[11] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/
[12] https://www.theregister.com/2020/11/13/ticketmaster_fined_1_25m_magecart_breach/
[13] https://whitepapers.theregister.com/
Magento updates are a mess
One of the big reasons people don't update Magento as much as they should is that the update process is a complete trash fire. Since Adobe took over the updates have been of the quality we expect from the people who brought us Flash. For example, a recent security patch in the 2.3 release train cut out compatibility with PHP 7.2, and if you have critical third-party modules that don't like PHP 7.3 or 7.4 yet then tough luck. For complex sites it can take several weeks or months of re-development work to fix this, and to have it dumped on you without any notification is just sloppy.