News: 1704374109

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Infostealer malware, weak password leaves Orange Spain RIPE for plucking

(2024/01/04)


Updated A weak password exposed by infostealer malware is being blamed after a massive outage at Orange Spain disrupted around half of its network's traffic.

The network provider is Spain's second most popular and on Wednesday evening confirmed its RIPE account had been breached by an attacker.

RIPE is the regional database that contains all IP addresses and their owners in Europe, the Middle East, and Central Asia.

[1]

The attack was claimed by an individual operating under the alias of "Snow," who published a series of screenshots explaining how they supposedly carried out the attack.

[2]

[3]

Researchers used the information in the shared images to determine that the RIPE account had been accessed after the attacker harvested admin credentials using [4]infostealer malware . The malware had infected the account of an Orange Spain employee.

The password was revealed to be "ripeadmin" – a simple and [5]easily guessable password for an important account.

[6]

Researchers at Hudson Rock described the password as "ridiculously weak" before confirming with "high certainty" this was the method used to breach the RIPE account.

"This attack again illustrates how a single infostealer infection could be detrimental to any company," the company [7]said in a post .

"It is important to routinely check your organizational exposure to infostealer infections which are the top initial attack vector for threat actors to access corporate and customer accounts."

[8]

Infosec specialist Kevin Beaumont also noted that RIPE does not mandate 2FA or MFA use, and it wasn't enabled at Orange Spain, whereas North America's equivalent database, [9]ARIN , has mandated it since February 2023.

"Also, there is no sane password policy at RIPE – you can use borisjohnson as your password, in other words, it is a powder keg," he [10]claimed .

[11]Copy that? Xerox confirms 'security incident' at subsidiary

[12]Google password resets not enough to stop these info-stealing malware strains

[13]Court hearings become ransomware concern after justice system breach

[14]Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials

"The account in question has been on an infostealer since August last year, with the details resold onwards."

Following the RIPE account breach, Snow then appears to have [15]hijacked the network provider's border gateway protocol (BGP) traffic, which led to the service outage experienced by customers.

The attacker modified the autonomous system (AS) number associated with Orange Spain's IP address and changed the route origin authorizations (ROAs) – cryptographically signed objects that help to securely verify that announced BGP routes are associated with the correct origin – in turn breaking the network's BGP routing.

"Orange Spain has had their /12 [ROA records] (and likely others) broken by (what appears to be) someone breaking into their RIPE account and making RPKI ROA's to somewhere else," [16]blogged Ben Cartwright-Cox, director at Port 179, the company behind network and monitoring and analytics tool BGP.Tools.

"Current reachability of impacted prefixes is pretty poor… the current ROA is pointing to AS49581 ("Ferdinand Zink trading as Tube-Hosting")."

"Snow" [17]documented the attack via a freshly minted X account, goading Orange Spain and encouraging it to reach out and request the new RIPE admin credentials after they were breached and changed.

Orange Spain [18]confirmed its RIPE account was breached via its X account, adding that service was restored shortly after acknowledging the outage.

There is no evidence to suggest any customer or client data was compromised during the incident, and the disruption was to its services only, Orange added.

Beaumont said he's seen credentials to thousands of different RIPE accounts on infostealer marketplaces, and expects a wave of similar attacks to take place now the incident at Orange Spain has been publicized. ®

Updated at 16.32 on Janusry 4, 2024, to add:

Orange has sent us a statement.

“The problem has been solved yesterday and the appropriate measures have been taken to prevent such an incident from happening again. As you know, Orange's account at the IP network coordination centre (RIPE) was improperly accessed, affecting the browsing of some of our customers. The service has been restored since yesterday.

“We confirm that in no case have our customers' data been compromised, only the browsing of some services has been affected.”

Get our [19]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZbkPVv6RYB9IAK2HkYi3QAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZbkPVv6RYB9IAK2HkYi3QAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZbkPVv6RYB9IAK2HkYi3QAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/AMP/2024/01/02/infostealer_google_account_exploit/

[5] https://www.theregister.com/2023/11/20/your_password_hygiene_is_still/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZbkPVv6RYB9IAK2HkYi3QAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.infostealers.com/article/infostealer-infection-of-an-orange-employee-results-in-bgp-disruptions/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZbkPVv6RYB9IAK2HkYi3QAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/02/22/afrinic_failure_warning_apnic_link/

[10] https://doublepulsar.com/how-50-of-telco-orange-spains-traffic-got-hijacked-a-weak-password-d7cde085b0c5

[11] https://www.theregister.com/2024/01/03/xerox_inks_confirmation_of_security/

[12] https://www.theregister.com/2024/01/02/infostealer_google_account_exploit/

[13] https://www.theregister.com/2024/01/02/victoria_court_system_breach/

[14] https://www.theregister.com/2023/12/20/hotel_cybercrime_research/

[15] https://www.theregister.com/2020/10/02/protonmail_telstra_bgp_hijack/

[16] https://benjojo.co.uk/u/benjojo/h/r1zj333N4L6cF7P1xv

[17] https://twitter.com/Ms_Snow_OwO/status/1742666456058470739

[18] https://twitter.com/orange_es/status/1742616775647265035

[19] https://whitepapers.theregister.com/



Not limited

Diogenes8080

So if "Snow" had chosen to redirect a whole collection of announcements for high-traffic Orange networks on to one specific customer, the effect would have been trivial?

Considering previous BGP whoopsies, I think not. In fact, is there a correlation between the MFA implementation date for ARIN and an apparently inadvertent attempt to route a large part of the US eastern seaboard through an obscure southern US steelworks or lumber yard?

sitta_europea

ripeadmin

I ask you.

HOW TO PROVE IT, PART 4

proof by personal communication:
'Eight-dimensional colored cycle stripping is NP-complete
[Karp, personal communication].'

proof by reduction to the wrong problem:
'To see that infinite-dimensional colored cycle stripping is
decidable, we reduce it to the halting problem.'

proof by reference to inaccessible literature:
The author cites a simple corollary of a theorem to be found
in a privately circulated memoir of the Slovenian
Philological Society, 1883.

proof by importance:
A large body of useful consequences all follow from the
proposition in question.