As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others
- Reference: 1639611067
- News link: https://www.theregister.co.uk/2021/12/15/log4j_latest_cisa/
- Source link:
Up until now, it was largely accepted that mere private miscreants, criminal gangs, and security researchers were mostly scanning the internet for systems and services vulnerable to [1]CVE-2021-44228 in the open-source logging library widely used by Java applications. Network observers say they've seen tens of thousands of attempts per minute. Successful exploitation may result in the installation of ransomware and cryptocurrency miners, the theft of cloud credentials and other information, and so on.
On Tuesday, the Microsoft Threat Intelligence Center (MSTIC) [2]pointed the finger at specific countries, saying they are using the security bug to spread extortionware, test exploit code, and infiltrate networks:
MSTIC has also observed the CVE-2021-44228 vulnerability being used by multiple tracked nation-state activity groups originating from China, Iran, North Korea, and Turkey. This activity ranges from experimentation during development, integration of the vulnerability to in-the-wild payload deployment, and exploitation against targets to achieve the actor’s objectives.
For example, MSTIC has observed PHOSPHORUS, an Iranian actor that has been deploying ransomware, acquiring and making modifications of the Log4j exploit. We assess that PHOSPHORUS has operationalized these modifications.
In addition, HAFNIUM, a threat actor group operating out of China, has been observed utilizing the vulnerability to attack virtualization infrastructure to extend their typical targeting. In these attacks, HAFNIUM-associated systems were observed using a DNS service typically associated with testing activity to fingerprint systems.
Phosphorous is the Iranian group [3]accused of trying to infiltrate online accounts of those involved in the US presidential elections last year. Hafnium is the Chinese team said to have [4]exploited holes in Microsoft Exchange Server around the start of this year. Of course, Western agencies wouldn't dream of abusing this hole in the wild.
Earlier this week, Kaspersky Lab and Bitdefender said it had seen attempts to attack Log4j deployments coming from Russian IP addresses, though we note it's not terribly difficult to route connections through nodes in the land of President Putin. Mandiant also [5]said it has seen exploitation attempts from black-hat hackers linked to Beijing and Tehran.
[6]
Yes, attribution is hard and all that. But it's interesting this is coming to light as the US government's Cybersecurity and Infrastructure Security Agency [7]tells all federal civilian agencies to take care of CVE-2021-44228 by December 24, 2021. That's quite a tight deadline. Version 2.16 of Log4j 2.x is available that disables the vulnerable functionality by default and removes the insecure message lookup code completely.
[8]
[9]
The programming blunder has been added to CISA's [10]known exploited vulnerabilities catalog .
Log4j doesn't just blow a hole in your servers, it's reopening that can of worms: Is Big Biz exploiting open source? [11]READ MORE
This security flaw is one of the worst, if not the worst, in a decade or more: there are going to be long-term repercussions as systems thought to be free of the bug turn out to be vulnerable and are exploited months or years later.
Organizations need to not only locate installations of services and applications that deep down use Log4j and patch them, but also investigate whether or not they were compromised, what information was at risk if that happened, and perhaps even just assume they were compromised and work from there.
CISA has a bunch of useful resources [12]here on GitHub , including a big list of affected software and products and related advisories – from Amazon cloud services to VMware tools.
[13]
“CISA is working closely with our public and private sector partners to proactively address a critical vulnerability affecting products containing the log4j software library," CISA Director Jen Easterly [14]said over the weekend.
"This vulnerability, which is being widely exploited by a growing set of threat actors, presents an urgent challenge to network defenders given its broad use. End users will be reliant on their vendors, and the vendor community must immediately identify, mitigate, and patch the wide array of products using this software.
"Vendors should also be communicating with their customers to ensure end users know that their product contains this vulnerability and should prioritize software updates."
[15]
So far, CISA says it is not aware of any US federal government agencies suffering a security breach from Log4j. ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2021/12/14/apache_log4j_2_16_jndi_disabled/
[2] https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
[3] https://www.theregister.com/2020/09/11/microsoft_us_election_security_assessment/
[4] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/
[5] https://www.wsj.com/articles/hackers-backed-by-china-seen-exploiting-security-flaw-in-internet-software-11639574405?mod=djemalertNEWS
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbrH-WZ2zFpkonPxHQIWHwAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbrH-WZ2zFpkonPxHQIWHwAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbrH-WZ2zFpkonPxHQIWHwAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[11] https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/
[12] https://github.com/cisagov/log4j-affected-db
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbrH-WZ2zFpkonPxHQIWHwAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbrH-WZ2zFpkonPxHQIWHwAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
Shit show
Most of my webby stuff is behind HA Proxy. I put in a rule to block most naive jndi type GETs after normalisation - they go to a tarpit. I've seen a few requests per day. Perhaps if you look a bit crap and sad then you drop off the radar.
One was quite persistent and looked like a security research effort (I can't be arsed to follow up). Another is really sad and clearly has a bug or two in their code. The GET tries to create a URL with ${hostName} in it, so they've got their quoting etc screwed up. Another makes the same mistake as the last but the URL is repeated several times in a weird nesting bug.
The clever kids will no doubt be causing some harm in the near future but there are some comical efforts from the skiddies too.
"the US government's Cybersecurity and Infrastructure Security Agency tells all federal civilian agencies to take care of CVE-2021-44228 by December 24, 2021. That's quite a tight deadline."
Tight? Only by government standards. I think our deadline was today.
This certainly looks like the worst I've seen in my career. There is already so much said about it but the amount of time and money this is going to cost us is hard to imagine.