SAP Patches Critical Flaws in MII, NetWeaver Products

SAP’s March 2021 Security Patch Day updates include 9 new security notes, including two for critical vulnerabilities affecting the company’s NetWeaver Application Server (AS) and Manufacturing Integration and Intelligence (MII) products.

This month’s set of patches also includes 4 updates to previously released Patch Day security notes, including updates for two notes rated Hot News (CVSS score 10), which address a missing authorization check in Solution Manager (CVE-2020-6207) and deliver the latest patches for the Chromium browser in Business Client.

The most severe of the newly released security notes addresses a code injection vulnerability in SAP MII. Tracked as CVE-2021-21480, the vulnerability features a CVSS score of 9.9.

Based on NetWeaver AS Java, SAP MII provides monitoring and data analysis capabilities, capturing data from production machinery and providing real-time information on performance and efficiency.

The critical vulnerability was identified in the Self-Service Composition Environment (SSCE) component, which allows the creation of dashboards (via drag-and-drop) that can be saved as JSP files. The flaw allows an attacker to inject malicious JSP code in a request to the server, which would then be executed when the infected dashboard is opened.

Exploitation of the bug would allow an attacker to access SAP databases and tamper with records, move laterally to other servers, inject malware, and modify network configurations to potentially compromise internal networks.

The second Hot News security note that SAP released on Tuesday addresses a missing authorization check in the Migration Service of NetWeaver AS Java (CVE-2021-21481, CVSS score 9.6).

Used internally to migrate applications between J2EE Engine releases, the service could be abused to gain administrative privileges and potentially fully compromise the vulnerable system. The fix for this vulnerability requires a system restart, Onapsis, a firm that specializes in securing SAP applications, explains.

This month, SAP released a single high-severity security note, to address a possible authentication bypass in HANA LDAP scenarios (CVE-2021-21484, CVSS score 7.7). Successful exploitation requires that the LDAP directory server enables unauthenticated bind and that SAP HANA has been configured to automatically create users and allow access based on LDAP authentication.

All of the remaining security notes included in the March 2021 Security Patch Day are rated medium severity. They address missing authorization checks, an insecure deserialization issue, a reverse TabNabbing vulnerability, improper input validation, and a server-side request forgery bug.

Related: Critical Vulnerability Patched in SAP Commerce Product

Related: Scanning Activity Detected After Release of Exploit for Critical SAP SolMan Flaw

Related: SAP Patches Serious Code Injection, DoS Vulnerabilities

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/F_swV98_auY/sap-patches-critical-flaws-mii-netweaver-products




Unpatched Flaws in Netgear Business Switches Expose Organizations to Attacks

Security researchers have identified multiple vulnerabilities in ProSAFE Plus JGS516PE and GS116Ev2 business switches from Netgear, the most severe of which could allow a remote, unauthenticated attacker to execute arbitrary code.

A total of 15 vulnerabilities affecting Netgear switches that use the ProSAFE Plus configuration utility were found to expose users to various risks, according to researchers with IT security firm NCC Group.

The most important of these bugs is CVE-2020-26919, an unauthenticated remote code execution flaw rated critical severity (CVSS score of 9.8).

Affecting firmware versions prior to 2.6.0.43, the bug is related to the internal management web application not implementing the correct access controls, which could allow attackers to bypass authentication and run code with the privileges of the administrator.

“Due to the ability of execute system commands through the ‘debug’ web sections, a successful exploitation of this vulnerability can lead to remote code execution on the affected device,” NCC Group notes.

The researchers also discovered that the Netgear Switch Discovery Protocol (NSDP), a network protocol functioning as a discovery method that also allows for switch management, fails to properly handle authentication packages, thus leading to authentication bypasses (CVE-2020-35231, CVSS score of 8.8).

An attacker able to exploit this vulnerability “could execute any management actions in the device, including wiping the configuration by executing a factory restoration,” the researchers say.

NCC Group says that Netgear has informed them that the NSDP has reached end of life (EOL) and that none of the issues identified in it will be addressed. Users are advised to disable the remote management feature.

“Netgear reported that most of the vulnerabilities affecting the NSDP protocol were known due to end-of-life years ago and it is still enabled for legacy reasons, for customers who preferred to use Prosafe Plus. Furthermore, we were informed that, due to hardware limitations, it is not possible to implement many of the standard encryption protocols, such as those needed to implement HTTPS,” NCC Group notes.

The researchers also found issues with the firmware update mechanism on the vulnerable switches. One of them, CVE-2020-35220 (CVSS score of 8.3), could allow attackers to upload custom firmware files without administrative rights.

The second issue (CVE-2020-35232, CVSS score of 8.1) resides in the improper implementation of internal checks, which could allow attackers to craft firmware files that could “overwrite the entire memory with custom code.”

Other high-severity vulnerabilities in Netgear’s switches could lead to denial of service (CVE-2020-35224, CVSS score 8.1), or could allow an attacker to generate valid passwords (CVE-2020-35221, CVSS score 7.5) or perform requests using a single authenticated packet (CVE-2020-35229, CVSS score 7.5).

A stored XSS issue in language settings (CVE-2020-35228, CVSS score 7.2) could be abused to inject JavaScript code that would be executed on all webpages, while a buffer overflow (CVE-2020-35227, CVSS score 7.2) could be abused to cause a system reboot, among others.

Another vulnerability in the NSDP protocol, the researchers discovered, could be abused to retrieve the DHCP status without authentication, thus allowing remote users to configure the service, likely leading to denial of service (CVE-2020-35226, CVSS score 7.1).

The security researchers also identified a series of medium-severity flaws, such as unauthenticated access to switch configuration parameters (CVE-2020-35222), TFTP unexpected behavior (CVE-2020-35233), integer overflow instances (CVE-2020-35230), write command buffer overflows (CVE-2020-35225), and ineffective cross-site request forgery protections (CVE-2020-35223).

In December 2020, Netgear released firmware version 2.6.0.48, which includes patches for CVE-2020-35220, CVE-2020-35232, CVE-2020-35233, and other issues. The remaining issues won’t receive patches, the researchers say.

Related: NETGEAR Router, WD NAS Device Hacked on First Day of Pwn2Own Tokyo 2020

Related: Netgear Starts Patching Serious Vulnerabilities Affecting Tens of Products

Related: Senator Urges Vendors to Secure Networking Devices Amid COVID-19 Outbreak

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/LzZrWK1srh8/unpatched-flaws-netgear-business-switches-expose-organizations-attacks




Critical 0-day that targeted security researchers gets a patch from Microsoft

Shadowy figures stand beneath a Microsoft logo on a faux wood wall.

Microsoft has patched a critical zero-day vulnerability that North Korean hackers were using to target security researchers with malware.

The in-the-wild attacks came to light in January in posts from Google and Microsoft. Hackers backed by the North Korean government, both posts said, spent weeks developing working relationships with security researchers. To win the researchers’ trust, the hackers created a research blog and Twitter personas who contacted researchers to ask if they wanted to collaborate on a project.

Eventually, the fake Twitter profiles asked the researchers to use Internet Explorer to open a webpage. Those who took the bait would find that their fully patched Windows 10 machine installed a malicious service and an in-memory backdoor that contacted a hacker-controlled server.

Microsoft on Tuesday patched the vulnerability. CVE-2021-26411, as the security flaw is tracked, is rated critical and requires only low-complexity attack code to exploit.

From rags to riches

Google said only that the people who reached out to the researchers worked for the North Korean government. Microsoft said they were part of Zinc, Microsoft’s name for a threat group that is better known as Lazarus. Over the past decade, Lazarus has transformed from a ragtag group of hackers to what can often be a formidable threat actor.

A United Nations report from 2019 reportedly estimated Lazarus and associated groups have generated $2 billion for the country’s weapons of mass destruction programs. Lazarus has also been tied to the Wannacry worm that shut down computers around the world, fileless Mac malware, malware that targets ATMs, and malicious Google Play apps that targeted defectors.

Besides using the watering-hole attack that exploited IE, the Lazarus hackers who targeted the researchers also sent targets a Visual Studio Project purportedly containing source code for a proof-of-concept exploit. Stashed inside the project was custom malware that contacted the attackers’ control server.

While Microsoft describes CVE-2021-26411 as an “Internet Explorer Memory Corruption Vulnerability,” Monday’s advisory says the vulnerability also affects Edge, a browser Microsoft built from scratch that’s considerably more secure than IE. The vulnerability retains its critical rating for Edge, but there are no reports that exploits have actively targeted users of that browser.

The patch came as part of Microsoft’s Update Tuesday. In all, Microsoft issued 89 patches. Besides the IE vulnerability, a separate escalation privilege flaw in the Win32k component is also under active exploit. Patches will install automatically over the next day or two. Those who want the updates immediately should go to Start > settings (the gear icon) > Update & Security > Windows Update.

https://arstechnica.com/?p=1748406




Tens of thousands of US organizations hit in ongoing Microsoft Exchange hack

A stylized skull and crossbones made out of ones and zeroes.

Tens of thousands of US-based organizations are running Microsoft Exchange servers that have been backdoored by threat actors who are stealing administrator passwords and exploiting critical vulnerabilities in the email and calendaring application, it was widely reported. Microsoft issued emergency patches on Tuesday, but they do nothing to disinfect systems that are already compromised.

KrebsOnSecurity was the first to report the mass hack. Citing multiple unnamed people, reporter Brian Krebs put the number of compromised US organizations at at least 30,000. Worldwide, Krebs said there were at least 100,000 hacked organizations. Other news outlets, also citing unnamed sources, quickly followed with posts reporting the hack had hit tens of thousands of organizations in the US.

Assume compromise

“This is the real deal,” Chris Krebs, the former head of the Cybersecurity and Infrastructure Security Agency, said on Twitter, referring to the attacks on on-premisis Exchange, which is also known as Outlook Web Access. “If your organization runs an OWA server exposed to the internet, assume compromise between 02/26-03/03.” His comments accompanied a Tweet on Thursday from Jake Sullivan, the White House national security advisor to President Biden.

Hafnium has company

Microsoft on Tuesday said on-premises Exchange servers were being hacked in “limited targeted attacks” by a China-based hacking group the software maker is calling Hafnium. Following Friday’s post from Brian Krebs, Microsoft updated its post to say that it was seeing “increased use of these vulnerabilities in attacks targeting unpatched systems by multiple malicious actors beyond HAFNIUM.”

Katie Nickels, director of intelligence at security firm Red Canary, told Ars that her team has found Exchange servers that were compromised by hackers using tactics, techniques, and procedures that are distinctly different than those used by the Hafnium group Microsoft named. She said Red Canary has counted five “clusters that look differently from each other, [though] telling if the people behind those are different or not is really challenging and unclear right now.”

On Twitter, Red Canary said that some of the compromised Exchange servers the company has tracked ran malware that fellow security firm Carbon Black analyzed in 2019. The malware was part of an attack that installed cryptomining software called DLTminer. It’s unlikely Hafnium would install a payload like that.

Microsoft said that Hafnium is a skilled hacking group from China that focuses primarily on stealing data from US-based infectious disease researchers, law firms, higher-education institutions, defense contractors, policy think tanks, and nongovernmental organizations. The group, Microsoft said, was hacking servers by either exploiting the recently fixed zeroday vulnerabilities or by using compromised administrator credentials.

It’s not clear what percentage of infected servers are the work of Hafnium. Microsoft on Tuesday warned that the ease of exploiting the vulnerabilities made it likely other hack groups would soon join Hafnium. If ransomware groups aren’t yet among the clusters compromising servers, it’s almost inevitable that they soon will be.

Backdooring servers

Brian Krebs and others reported that tens of thousands of Exchange servers had been compromised with a webshell, which hackers install once they’ve gained access to a server. The software allows attackers to enter administrative commands through a terminal Window that’s accessed through a web browser.

Researchers have been careful to note that simply installing the patches Microsoft issued in Tuesday’s emergency release would do nothing to disinfect servers that have already been backdoored. The webshells and any other malicious software that have been installed will persist until it is actively removed, ideally by completely rebuilding the server.

People who administer Exchange servers in their networks should drop whatever they’re doing right now and carefully inspect their machines for signs of compromise. Microsoft has listed indicators of compromise here. Admins can also use this script from Microsoft to test if their environments are affected.

This week’s escalation of Exchange server hacks comes three months after security professionals uncovered the hack of at least nine federal agencies and about 100 companies. The primary vector for infections was through software updates from network tools maker SolarWinds. The mass hack was one of—if not the—the worst computer intrusions in US history. It’s possible the Exchange Server will soon claim that distinction.

There’s still much that remains unknown. For now, people would do well to follow Chris Krebs’ advice to assume on-premises servers are compromised and act accordingly.

https://arstechnica.com/?p=1747745




Microsoft Shares Additional Mitigations for Exchange Server Vulnerabilities Under Attack

Microsoft on Friday released alternative mitigation measures for organizations who have not been able to immediately apply emergency out-of-band patches released earlier this week that address vulnerabilities being exploited to siphon e-mail data from corporate Microsoft Exchange servers.

“These mitigations are not a remediation if your Exchange servers have already been compromised, nor are they full protection against attack,” Microsoft warned in a blog post. “We strongly recommend investigating your Exchange deployments using the hunting recommendations here to ensure that they have not been compromised. We recommend initiating an investigation in parallel with or after applying one of the following mitigation strategies.”

Microsoft also provided a nmap script to help customers discover vulnerable servers within their infrastructure.

Security researchers have warned that multiple cyber-espionage groups have been targeting vulnerable Exchange servers. Some reports suggest that 30,000 or more organizations may have been hacked via the Exchange security holes.

Analysts say that HAFNIUM, a state-sponsored hacking group operating out of China, has been on an an active hacking spree with a massive espionage campaign underway to siphon data from organizations globally.

“This is the real deal. If your organization runs an OWA server exposed to the internet, assume compromise between 02/26-03/03,” Ex-CISA Chief Chris Krebs tweeted. “Check for 8 character aspx files in C:\\inetpub\wwwroot\aspnet_client\system_web\. If you get a hit on that search, you’re now in incident response mode.”

The U.S. Cybersecurity and Infrastructure Security (CISA) also issued an alert Friday, urging organizations to upgrade their on-premises Microsoft Exchange servers to the latest supported version.

Cybersecurity firm Volexity, which was credited by Microsoft for reporting different parts of the attack chain, has published a blog post with technical details and a video demonstrating exploitation in action, along with known attacker IP addresses connected to the attacks. Volexity said it detected anomalous activity from two of its customers’ Microsoft Exchange servers in January 2021, which led to discovery of the attacks.

“This is an active threat,” White House press secretary Jennifer Psaki said in a press briefing Friday. “Everyone running these servers needs to act now to patch them. We are concerned that there are a large number of victims and are working with our partners to understand the scope of this.”
view counter

For more than 10 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Previous Columns by Mike Lennon:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/IihaWmU26H4/microsoft-shares-additional-mitigations-exchange-server-vulnerabilities-under-attack




Supermicro, Pulse Secure Respond to Trickbot’s Ability to Target Firmware

Server and storage technology giant Supermicro and secure access solutions provider Pulse Secure have issued advisories to inform users that some of their products are vulnerable to the Trickbot malware’s ability to target firmware.

In early December, security researchers at Advanced Intelligence (AdvIntel) and enterprise device security firm Eclypsium revealed that Trickbot not only survived a takedown attempt, but also gained the ability to scan UEFI/BIOS firmware for vulnerabilities that would allow making modifications.

Referred to as Trickboot, the ability would enable TrickBot operators to use firmware implants and backdoors in their attacks, control the boot operations to fully control systems, or even start bricking devices, the researchers warned at the time.

“TrickBoot is a new functionality within the TrickBot malware toolset capable of discovering vulnerabilities and enabling attackers to read/write/erase the device’s BIOS,” Supermicro notes in an advisory published this week.

The malware can check if the BIOS control register is unlocked and if modifications could be made to the BIOS region contents, and then implant malicious code that would survive OS reinstalls.

Supermicro said the vulnerability affects a subset of the X10 UP motherboards and that a mitigation will be provided. However, only products that have not reached end of life (EOL) will automatically receive the BIOS update. Patches for EOL products will be provided at request.

“A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device,” Pulse Secure notes in its advisory.

The company says that only two of its device models are affected, namely PSA-5000 and PSA-7000. Patches are available for Pulse Connect Secure / Pulse Policy Secure and are pending release for Pulse One (the on-prem appliance only).

Related: NSA Publishes Guidance on UEFI Secure Boot Customization

Related: TrickBot Gets Updated to Survive Takedown Attempts

Related: New Dell Utility Alerts Security Teams of BIOS Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/dVRnmu8xB50/supermicro-pulse-secure-respond-trickbots-ability-target-firmware




Several Cisco Products Exposed to DoS Attacks Due to Snort Vulnerability

Cisco informed customers on Wednesday that several of its products are exposed to denial-of-service (DoS) attacks due to a vulnerability in the Snort detection engine.

The flaw, tracked as CVE-2021-1285 and rated high severity, can be exploited by an unauthenticated, adjacent attacker — the attacker is on the same layer 2 domain as the victim — to cause a device to enter a DoS condition by sending it specially crafted Ethernet frames.

Cisco says the vulnerability is in the Ethernet Frame Decoder component of Snort. The issue impacts all versions of the popular open source intrusion prevention and intrusion detection system (IPS/IDS) prior to 2.9.17, which contains a patch.

CVE-2021-1285 has been found to impact Integrated Service Router (ISR), Catalyst Edge software and platform, and 1000v series Cloud Services Router products. These devices are affected if they are running a vulnerable version of Cisco UTD Snort IPS engine software for IOS XE or Cisco UTD Engine for IOS XE SD-WAN, and they are configured to pass Ethernet frames to Snort.

Cisco says the vulnerability is related to a Firepower Threat Defense (FTD) issue patched in October 2020.

The vulnerability was found during the resolution of a support case and there is no evidence that it has been exploited in malicious attacks.

Cisco on Wednesday also published advisories for a dozen other vulnerabilities, which have been assigned a medium severity rating. These impact Webex, SD-WAN, ASR, Network Services Orchestrator, IP phones, and Email Security Appliance products, and they can lead to information disclosure, path traversal, authorization bypass, DoS attacks, privilege escalation, and SQL injection.

Related: Recent Sudo Vulnerability Affects Apple, Cisco Products

Related: Cisco Patches Critical Vulnerabilities in SD-WAN, DNA Center, SSMS Products

Related: Cisco Investigating Report of Vulnerability Found in Counterfeit Switches

Related: Over 70 Vulnerabilities Will Remain Unpatched in EOL Cisco Routers

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/8UDxQwtE38U/several-cisco-products-exposed-dos-attacks-due-snort-vulnerability




Multiple Cyberspy Groups Target Microsoft Exchange Servers via Zero-Day Flaws

Security researchers warn that multiple cyber-espionage groups are targeting the recently addressed zero-day vulnerabilities in Microsoft Exchange Server and say that more than 300 web shells have been identified on the compromised servers.

The issues (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065), which Microsoft addressed this week, were being abused as part of an attack chain that allowed for the execution of arbitrary code, remotely.

Microsoft said that state-sponsored Chinese hacking group HAFNIUM has been exploiting the vulnerabilities “in limited targeted attacks,” but new details shared by various security firms suggest broader targeting.

“ESET telemetry shows that (at least) CVE-2021-26855 is actively exploited in the wild by several cyber-espionage groups. Among them, we identified LuckyMouse, Tick, Calypso and a few additional yet-unclassified clusters,” ESET said on Twitter.

The company also revealed that, while most of the targets are located in the United States, attacks against servers in Europe, Asia and the Middle East have been identified as well. The assaults were aimed at government organizations, law firms, medical facilities, and private companies.

Organizations can determine whether they might have been compromised by looking in C:\inetpub\wwwroot\aspnet_client\system_web\ for aspx files with names such as shell, supp0rt, aspnet, aspnet_client, and others, or for random filenames in the system_web subdirectory.

Managed detection and response (MDR) solutions provider Huntress says it has already observed more than 200 compromised Exchange Servers that received payloads within the “C:\inetpub\wwwroot\aspnet_client\system_web” directory, and claims to have identified more than 350 web shells to date.

An analysis of approximately 2,000 Exchange servers has revealed that roughly 400 of them were vulnerable, with an additional 100 potentially vulnerable, Huntress reveals.

The targeted organizations, the security firm says, include “small hotels, an ice cream company, a kitchen appliance manufacture, multiple senior citizen communities and other ‘less than sexy’ mid-market businesses. We’ve also witnessed many city and county government victims, healthcare providers, banks/financial institutions, and several residential electricity providers.”

The large number of identified web shells, Huntress points out, suggests that multiple uncoordinated actors might have been involved in exploitation, or that automated deployment tools were used. The attacks were also able to bypass installed antivirus and EDR solutions.

“These attacks are grave due to the fact that every organization simply has to have email, and Microsoft Exchange is so widely used. These servers are typically publicly accessible on the open internet and they can be exploited remotely. These vulnerabilities can be leveraged to gain remote code execution and fully compromise the target,” Huntress also notes.

Given the critical nature of these vulnerabilities, organizations are advised to apply the available patches as soon as possible.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert on these vulnerabilities, and the Department of Homeland Security (DHS) has issued an emergency directive requiring agencies to look for indicators of compromise (IOCs) and either perform forensic investigations where compromise has been identified or apply the available patches where no IOCs were found.

Related: Microsoft Patches Critical SharePoint, Exchange Security Holes

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/CfA0hcKpAII/multiple-cyberspy-groups-target-microsoft-exchange-servers-zero-day-flaws




Qualys Confirms Unauthorized Access to Data via Accellion Hack

Hours after the Clop ransomware gang published data allegedly stolen from information security and compliance solutions provider Qualys, the company has confirmed being impacted by the recent cyberattack involving Accellion’s FTA product.

Founded in 1999, the California-based firm serves more than 10,000 customers in over 130 countries around the world, including many of the Forbes Global 100 companies.

Data allegedly stolen from the company, including scan results and financial documents, was published on the “CL0P^_- LEAKS” Tor website this week. Maintained by the operators of the Clop ransomware, the portal is used to publish data stolen from victims unwilling to give in to their ransom demands.

Initially, the website would list data exfiltrated during ransomware attacks, but as of late it has been flooded with data stolen from various organizations that were relying on the Accellion FTA file transfer software.

The data was compromised during a December 2020 cyber-attack that Accellion confirmed earlier this year. A total of four zero-day vulnerabilities were identified in the attack, all of which have already been patched.

In a report published a couple of weeks ago, FireEye’s Mandiant researchers linked the attack to the FIN11 cybercrime group, a TA505 spin-off.

“The exploited vulnerabilities were of critical severity because they were subject to exploitation via unauthenticated remote code execution,” Accellion noted in a report detailing Mandiant’s investigation into the incident.

The company also said the attackers likely reverse engineered the file transfer software, which provided them with “a high level of sophistication and deep familiarity with the inner workings of the Accellion FTA software.”

Following the publishing of its data on Clop’s leaks website, Qualys confirmed impact from the Accellion FTA incident, saying that it resulted in “unauthorized access to files hosted on the Accellion FTA server.”

The company also notes that the unauthorized access was limited to the FTA server and that the incident had no “impact on the Qualys production environments, codebase or customer data hosted on the Qualys Cloud Platform.”

The Accellion FTA server, the company explains, was deployed in a segregated DMZ environment, separated from the production customer data environment. Furthermore, Qualys says it applied the released hotfix immediately after receiving it and completely isolated the FTA server after receiving an integrity alert a few days later.

“We immediately notified the limited number of customers impacted by this unauthorized access,” Qualys says, without providing additional information on the compromised data or the number of affected customers.

Related: Hackers Leak Data Stolen From Jet Maker Bombardier

Related: Cybercriminals Leak Files Allegedly Stolen From Law Firm Jones Day

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/XzvwjVogRbM/qualys-confirms-unauthorized-access-data-accellion-hack




Microsoft Pays $50,000 Bounty for Account Takeover Vulnerability

A security researcher says Microsoft has awarded him a $50,000 bounty reward for reporting a vulnerability that could have potentially allowed for the takeover of any Microsoft account.

The issue, India-based independent security researcher Laxman Muthiyah reveals, could have been abused to reset the password of any account on Microsoft’s online services, but wasn’t that easy to exploit.

The attack, the researcher explains, targets the password recovery process that Microsoft has in place, which typically requires the user to enter their email or phone number to receive a security code, and then enter that code.

Typically, a 7-digit security code is received, meaning that the user is provided with one of 10 million possible codes.

An attacker who wants to gain access to the targeted user’s account would need to correctly guess the code or be able to try as many of these codes as possible, until they enter the correct one.

Microsoft has a series of mechanisms in place to prevent attacks, including limiting the number of attempts to prevent automated brute forcing and blacklisting an IP address if multiple consecutive attempts are made from it.

What Muthiyah discovered, however, was not only a technique to automate the sending of requests, but also the fact that the system would no longer block the requests if they reached the server simultaneously (even the slightest delay would trigger the defense mechanism).

“I sent around 1000 seven digit codes including the right one and was able to get the next step to change the password,” the researcher says.

The attack is valid for accounts without two-factor authentication (2FA) enabled, but even the second authentication step could be bypassed, using the same type of attack, Muthiyah says. Specifically, the user is first prompted to provide a 6-digit code that their authenticator app has generated, and then the 7-digit code received via email or phone.

“Putting all together, an attacker has to send all the possibilities of 6 and 7 digit security codes that would be around 11 million request attempts and it has to be sent concurrently to change the password of any Microsoft account (including those with 2FA enabled),” the researcher says.

The issue was reported to Microsoft last year and a patch was rolled out in November. Microsoft awarded the researcher a $50,000 bug bounty reward as part of its Identity Bounty Program, assessing the vulnerability with a severity rating of important and considering it an “Elevation of Privilege (Involving Multi-factor Authentication Bypass)” — this type of issue has the highest security impact in Microsoft’s Identity Bounty Program.

The only reason the vulnerability was not rated critical severity, the researcher notes, was the complexity of the attack. To process and send large numbers of concurrent requests, an attacker would need a good deal of computing power, along with the ability to spoof thousands of IP addresses.

Related: Instagram Account Takeover Vulnerability Earns Hacker $30,000

Related: Microsoft Paid Out Over $374,000 for Azure Sphere Vulnerabilities

Related: Microsoft Paid Out Nearly $14 Million via Bug Bounty Programs in Past Year

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/OhRnJek1DxI/microsoft-pays-50000-bounty-account-takeover-vulnerability