Magento shopping cart attack targets critical vulnerability revealed in early 2022
- Reference: 1691749392
- News link: https://www.theregister.co.uk/2023/08/11/magento_shopping_cart_attack_targets/
- Source link:
Security researchers at Akamai say they have identified a server-side template injection campaign aimed at Magneto 2 shops that have yet to address [1]CVE-2022-24086 , an input validation flaw with a CVSS score of 9.8.
"Unfortunately, businesses find it difficult to properly identify all their assets and patch in a timely manner," said Maxim Zavodchik, director of threat research at Akamai, in an email to The Register .
Businesses find it difficult to properly identify all their assets and patch in a timely manner
"Although zero-days and newly disclosed CVEs present a large opportunity for attackers, older CVEs are still being exploited by threat actors to get initial access to sites and networks."
The campaign, as explained in a [2]blog post by Zavodchik and Akamai colleagues Ron Mankivsky, Dennis German, Chen Doytshman, and Tricia Howard, has been underway since at least January 2023.
[3]
"The attacker seems to be interested in payment stats from the orders in the victim's Magento store placed in the past 10 days," they said.
[4]
[5]
This isn't entirely unsurprising. At least seven threat groups have focused on attacking Magento shops since 2015, according to the security researchers. These groups, referred to collectively as Magecart due to their focus on Magento shopping carts, rely on various malware techniques like JavaScript data skimming, to intercept and steal transaction data from ecommerce websites.
The latest campaign, which Akamai has dubbed "Xurum" because that was the name of the attacker's command-and-control server until Akamai's post on the subject evidently prompted a name change.
[6]
Zavodchik said Akamai does not have insight into the number of affected or vulnerable Magento stores. "We are inspecting and blocking incoming attacks targeted at our customers, but our [Web Application Firewall] does not collect information about the customers' Magento version."
[7]Ecommerce platforms (cough, Magento) need patching before Black Friday, warns UK's National Cyber Security Centre
[8]Obscure internet boutique Amazon sues EU for calling it a Very Large Online Platform
[9]Amazon Prime too easy to join, too hard to quit, says FTC lawsuit
[10]Shopify sees $1.5B loss turn into $68M profit, celebrates by firing 20% of staff
The attackers attempted to serve two different payloads from four IP addresses, three associated with service provider Hetzner in Germany and one associated with Shock Hosting in the United States.
"The first variant executes the file_get_contents PHP function to send a request to the attacker’s C2 server xurum.com to determine whether the server is vulnerable to CVE-2022-24086 while the Base64 blob decodes to https://xurum.com/mo ," the researchers explain.
The second variant delivers malicious PHP code, obfuscated using Base64 encoding and executed using the shell_exec PHP function, from the xurum server.
The xurum server, when it was operating, was physically located in the Netherlands and operated by Russian hosting biz VDSina.ru. When Akamai checked the server via VirusTotal, it was not rated malicious.
[11]
The researchers observed that instead of running the web shell on an attacker-controlled server, the code fetches a web shell from GitHub and, rather than writing it to disk, runs it in memory when the newly created "registration.php" page is accessed.
"The CVE enables arbitrary code execution on the target server," explained Zavodchik. "Attackers use this to pull the web shell from Github and execute it on the victim. The attackers are making a request with the exploit to the vulnerable server, then the exploit is making a request to Github to fetch the web shell and execute it."
The attackers try to prevent unauthorized use of the web shell by requiring the presence of a specific "magemojo000" cookie in the web request as an execution condition. They also use CSS to hide the login page for the web shell off-screen.
To prevent the malicious component from being detected, the attacker code registers the web shell as a new Magento component called "GoogleShoppingAds."
"This campaign serves as a practical example of how older vulnerabilities continue to be exploited years after disclosure, as businesses struggle to keep up with patches and security measures," the researchers conclude. ®
Get our [12]Tech Resources
[1] https://helpx.adobe.com/security/products/magento/apsb22-12.html
[2] https://www.akamai.com/blog/security-research/new-sophisticated-magento-campaign-xurum-webshell
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNZbJtPBNF@b4leqd6TOVwAAAYM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJtPBNF@b4leqd6TOVwAAAYM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNZbJtPBNF@b4leqd6TOVwAAAYM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJtPBNF@b4leqd6TOVwAAAYM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/11/22/ncsc_magento_updates_black_friday_reminder/
[8] https://www.theregister.com/2023/07/11/amazon_sues_eu_dsa/
[9] https://www.theregister.com/2023/06/21/amazon_prime_ftc_lawsuit/
[10] https://www.theregister.com/2023/05/04/shopify_layoffs_profit/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNZbJtPBNF@b4leqd6TOVwAAAYM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
GoogleShoppingAds
They'd be out of luck with me. I'd block that based on the name alone.
It happened to me too
Last month we took on a new client with an old Magento site. It had been infected with something very similar, instead of "xurum.com" it referenced another compromised site. Because credit cards had been exposed and fraudulent payments were reported by CC companies there had to be a PCI-DSS audit to make sure every last trace of infection was scrubbed. The problem was every time we cleaned up the offending card skimmer it would come back, sometimes right away, sometimes after several hours.
It took a lot of debugging to figure out there were two things going on; First the infection was in a database trigger so that each time an admin user logged in it was recorded in a specific database table, that triggered the trigger, that would re-inject the card skimmer. It was bloody hard to find because the database copy we took for analysis only had the plain data, not the triggers or functions. Let that be a lesson for you all!
Second the hackers would periodically return to the site, attempt to place an order as if they were a normal customer and if the expected javascript was missing they would log in with one of the four bogus admin accounts that had been set up, and add the same skimmer again but this time manually. I captured all this in logs and it was clearly practiced, the whole interaction took just 6 minutes. It's a very professional outfit and I suspect they likely contracted this step to a lesser hacking group. Modern hackers are not loners in hoodies with a taste for chaos but regular looking office workers in suits who work a 9-5.
The site was just waiting to get compromised. Not only was it using older versions of software, but it also did not add vulnerable functions like "system" and "exec" and "shell_exec" to PHP's "disable_function" setting. This setting is annoyingly left empty by the PHP Group when they should make it most secure by default. They do disable "allow_url_include" initially which is the sensible decision. Magento could also check for stuff like this on installation and put it in their .htaccess file if necessary, but they never bothered. Popular management software like cPanel do set this to protect newbies.
Re: It happened to me too
I think half the problem with Magento is that it's just so tricky to get to run stably in the first place, many don't bother updating it. The attitude seems to be, if it's working for $deitys sake don't touch it!
From personal experience, dealing with Magento is a bit like defusing a bomb. It doesn't matter how careful you are, the whole thing can still blow up in your face with the slightest misstep. It feels like sometimes it doesn't even require a misstep, it just depends what mood Magento is in on that particular day.
What also doesn't help is that many theme and plugin vendors require very specific Magento versions, many of which are woefully outdated and insecure. I had a client who purchased a Magento theme / custom plugin set from a vendor and bought the installation package from them. I had setup a completely stock, fully updated Magento installation for them to use, only to find they had wiped that and put a very old and insecure version in its place (we're talking 4 or 5 years old). I tried to re-update it and the whole site exploded. On checking with the vendor, they said they only support one specific version and we'd have to pay again for them to downgrade to that version. Needless to say, I got them to refund my client's money.
Re: It happened to me too
Thank you, your debug notes are extremely helpful!
“This isn't entirely unsurprising.”
Please don’t do this. So convoluted I’m not even sure if the intention was to convey lack of surprise (seems to fit the context better).
"... businesses find it difficult to properly identify all their assets ..."
Let me try to help with that.
This is the one that takes the money from the customer.
Mutants
Read this headline as a supermarket assault by The Brotherhood of Evil Mutants.