News: 1669230010

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks

(2022/11/23)


Microsoft is warning that systems using the long-discontinued Boa web server could be at risk of attacks after a series of intrusion attempts of power grid operations in India likely included exploiting security flaws in the technology.

Those affected may be unaware that their devices run services using the discontinued Boa web server, and that firmware updates and downstream patches do not address its known vulnerabilities

Researchers with Microsoft's Security Threat Intelligence unit examined an April [1]report from cybersecurity company Recorded Future about the intrusion efforts into India's power grid dating back to 2020 and, more recently, into a national emergency response system and a global logistics company's Indian subsidiary.

Recorded Future [2]attributed the [3]attacks on the power grid to a Chinese threat group called RedEcho using the ShadowPad backdoor malware to compromise IoT devices.

The Microsoft researchers, digging into the report, detected a vulnerable component – the Boa web server – on the IP addresses listed as indicators of compromise (IOC). They wrote in their own [4]analysis this week that they "found evidence of a supply chain risk that may affect millions of organizations and devices."

Boa is an open-source web server designed for embedded applications and used to access settings, management consoles, and sign-in screens in devices. It was discontinued in 2005 but is still being used by vendors in a range of IoT devices and popular SDKs, they wrote.

You might not even know it's happening

"Without developers managing the Boa web server, its known vulnerabilities could allow attackers to silently gain access to networks by collecting information from files," the researchers wrote. "Moreover, those affected may be unaware that their devices run services using the discontinued Boa web server, and that firmware updates and downstream patches do not address its known vulnerabilities."

In this case, Microsoft reviewed the IP addresses Recorded Future included in the list of IOCs and linked many back to IoT devices like routers that included unpatched vulnerabilities. All the published IP addresses were compromised by various attackers using different tactics that included downloading a variant of the [5]Mirai IoT botnet malware, attempts to use default credentials for brute-force attacks, and efforts to run shell commands.

[6]

"Microsoft continues to see attackers attempting to exploit Boa vulnerabilities beyond the timeframe of the released report, indicating that it is still targeted as an attack vector," the analysts wrote.

[7]WASP malware stings Python developers

[8]Eggheads show how network flaw could lead to NASA crew pod loss. Key word: Could

[9]Shocker: EV charging infrastructure is seriously insecure

[10]SolarWinds reaches $26m settlement with shareholders, expects SEC action

Boa is still widely used, with Microsoft detecting more than 1 million internet-exposed Boa server components around the world. It's particularly common in IoT devices like routers and cameras.

A reason could be that Boa is used in SDKs, which are not always patched even when the IoT device's firmware is updated. It's also difficult to tell whether device components can be or have been updated. An example is RealTek's SDKs, which include Boa and are used in SoCs by companies that make gateway devices like routers, access points, and repeaters.

[11]

[12]

Attackers over the past few years have targeted devices that use [13]RealTek's SDKs .

Among the known Boa web server vulnerabilities are [14]CVE-2017-9833 and [15]CVE-2021-33558 , which could enable attackers to remotely run code after gaining access to the device by reading its "passwd" file or stealing user credentials after access sensitive URIs in the web server. These flaws can be exploited without needing user authentication.

[16]

Being able to collect data from critical infrastructure networks without being detected can lead to attacks that are highly disruptive, costing millions of dollars and impacting millions of people and companies.

"The popularity of the Boa web server displays the potential exposure risk of an insecure supply chain, even when security best practices are applied to devices in the network," the researchers wrote. "Updating the firmware of IoT devices does not always patch SDKs or specific [SoC] components and there is limited visibility into components and whether they can be updated."

Vulnerabilities in the software supply chain have been highlighted in recent years by breaches at SolarWinds and Kaseya and amplified by the [17]Log4j vulnerability. In its annual data breach [18]report , Verizon noted that 62 percent of attacks that involve device or system intrusions began with cybercriminals exploiting flaws in partners' systems. ®

Get our [19]Tech Resources



[1] https://www.recordedfuture.com/continued-targeting-of-indian-power-grid-assets?__hstc=156209188.65c2d309abc7befc704e210a65154bf8.1666196607997.1666196607997.1666196607997.1&__hssc=156209188.1.1666196607998&__hsfp=2445685111

[2] https://www.theregister.com/2022/04/08/china_sponsored_attacks_india_ukraine/

[3] https://www.theregister.com/2021/03/01/statesponsored_chinese_group_attacked_india/

[4] https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/

[5] https://www.theregister.com/2021/08/25/mirai_botnet_critical_vuln_realtek_radware/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y36mC06u61rxgOHbPiMOggAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://www.theregister.com/2022/11/16/wasp_python_malware_checkmarx/

[8] https://www.theregister.com/2022/11/15/pcspoof_tte_flaw/

[9] https://www.theregister.com/2022/11/15/ev_charging_infrastructure_sandia/

[10] https://www.theregister.com/2022/11/04/solarwinds_settlement_sec_enforcement/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y36mC06u61rxgOHbPiMOggAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y36mC06u61rxgOHbPiMOggAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2021/08/16/realtek_wifi_sdk_vulnerabilities/

[14] https://nvd.nist.gov/vuln/detail/CVE-2017-9833

[15] https://nvd.nist.gov/vuln/detail/CVE-2021-33558

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y36mC06u61rxgOHbPiMOggAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2022/11/16/iranian_cyberspies_log4j/

[18] https://www.verizon.com/business/en-gb/resources/reports/dbir/

[19] https://whitepapers.theregister.com/



Not even SSL...

Jou (Mxyzptlk)

Boa, how con someone use this thing on the net today?

Re: Not even SSL...

DoContra

Leaving aside the debate of Encrypt all the things or not, the last update was in... [1]2005 ! (And if there ever was a svn/cvs repo in SourceForge, it hasn't survived the conversion to git...). If for whatever reason you need a brutally small HTTP server, there's always [2]OpenWRT's uhttpd , which supports SSL and even supports CGI (or at least something close enough). Otherwise, nginx can be slimmed down quite a bit (~2MB + deps install size for the nginx-light debian package, which has some room to be slimmed down).

[1] http://www.boa.org/

[2] https://git.openwrt.org/project/uhttpd.git

If you ever want to have a lot of fun, I recommend that you go off and program
an imbedded system. The salient characteristic of an imbedded system is that
it cannot be allowed to get into a state from which only direct intervention
will suffice to remove it. An imbedded system can't permanently trust
anything it hears from the outside world. It must sniff around, adapt,
consider, sniff around, and adapt again. I'm not talking about ordinary
modular programming carefulness here. No. Programming an imbedded system
calls for undiluted raging maniacal paranoia. For example, our ethernet front
ends need to know what network number they are on so that they can address and
route PUPs properly. How do you find out what your network number is? Easy,
you ask a gateway. Gateways are required by definition to know their correct
network numbers. Once you've got your network number, you start using it and
before you can blink you've got it wired into fifteen different sockets spread
all over creation. Now what happens when the panic-stricken operator realizes
he was running the wrong version of the gateway which was giving out the wrong
network number? Never supposed to happen. Tough. Supposing that your
software discovers that the gateway is now giving out a different network
number than before, what's it supposed to do about it? This is not discussed
in the protocol document. Never supposed to happen. Tough. I think you get
my drift.