Showing posts with label CyberX. Show all posts
Showing posts with label CyberX. Show all posts

Wednesday, December 18, 2019

New Industrial Espionage Campaign and a New Tool


Yesterday CyberX published a blog post about a new cyber espionage campaign that they explain targeted “hundreds of manufacturing and other industrial firms primarily located in South Korea.” They have named the campaign ‘Gangnam Industrial Style’ in a left-handed salute to the Korean targets.

Now this report is in the form of a blog post, so it does not have all of the technical details that we have come to expect from a new APT attack disclosure. Even so there are some interesting points that bear additional scrutiny.

Ganymede


Typically, when we see these reports of a new cyber-attack campaign it is initially based on information that the researchers obtained from their customers. Reports of anomalies, equipment problems, or compromised data causes the research firm to utilize their forensic capabilities to discover the core of the problem. When AV companies are involved, they can then look at the vast array of information provided by their (blissfully unaware in many instances) customers to track similar indications of compromise to determine the world-wide scope of the problem.

CyberX apparently has decided on a different track to finding attack indicators. They us a new tool, automated threat extraction platform called Ganymede. According to the blog-post:

“Ganymede continuously ingests large amounts of data from a range of open and closed sources. It uses specialized machine learning algorithms to identify documents with IoT/ICS-specific content as well as any malicious attachments, and to monitor domains of industrial companies that might be targeted.”

Apparently, in this case, Ganymede looked at emails to one or more of the reportedly affected companies to determine that they were phishing emails and contained a malicious .ZIP file containing the initial infection vector. I specifically asked if the emails referenced in the post were from CyberX customers and I was told by David Atch, VP of Research at CyberX:

“No, one of Section 52's [the name of the division of CyberX that conducted this research] abilities is to proactively uncover attacks using Ganymede. We work hard to find threats before they hit our customers.”

Commentary


I’m sorry, but that sounds suspiciously illegal; intercepting and reading corporate emails. I am sure that the attorneys for CyberX would disagree, but let’s leave that aside for a moment.

One of the things that we here from less tech-savvy commenters is the question, why can’t the government protect us from cyber-attacks, particularly nation-state level attacks on critical infrastructure. The standard answer is that it would require a DHS presence on the corporate networks to accomplish this and that is something that corporate America has been loath to accept.

Well, maybe a tool like Ganymede shows us a way around that. It would appear that monitoring communications into the network from the outside would allow a government agency like CISA to identify and flag dangerous communications before they actually infect the network. But, would companies want that type of external monitoring any more than they would a government presence on their network?

What would the government be monitoring for? Malware, of course. But, if the malware were not actually attached to the emails as CyberX is reporting in this case, looking for malware would be less than effective. So, to detect phishing emails with links to malware containing sites, the government would have to look at the content of the emails. Okay, maybe they would not be looking at all the words, diagrams, and pictures in the email; they would just have to look for links and then determine if those links led to phishing sites (or porn sites, or gambling sites, or questionable banking sites; but no they would just be looking for phishing sites, the government does not care about the other stuff).

But, what if a company does not want the government to ‘look’ at their emails; because how could you tell the difference between ‘looking’ and ‘reading’? Well, simple enough; you encrypt all of your email. Then, of course, the search for phishing emails would be stopped cold as well. You see the problem.

Side Note


How did I get started on this CyberX thing? Well, I got an email from a marketing firm asking if I would agree to an embargo on writing about the ‘Gangnam Industrial Style’ campaign until after the CyberX blog-post was published. In return I would get to see the blog post in advance. And apparently, I was not the only one (just do a Google® search for the attack name). I receive a number a couple of these every week. Usually I do not respond because I lack the technical skills to adequately evaluate all of the details involved. But something peaked my interest this time…..

Now, I am sure that CyberX will not be happy about this post, but I am not sorry about that. Readers of this blog are probably painfully aware that I speak my mind. That and the fact that I look at things from a slightly different perspective than most people writing in this field.

So, please keep those embargo offers coming. Just be aware that you will not get press release coverage in this blog.

Wednesday, May 1, 2019

Two Advisories Published – 04-30-19


Yesterday the DHS NCCIC-ICS published a control system security advisory for products from Rockwell and a medical device security advisory for products from Philips.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell CompactLogix 5370 programmable automation controllers. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks and George Lashenko of CyberX respectively. Rockwell has firmware updates to mitigate the vulnerabilities. There is no indication that either researcher was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Uncontrolled resource consumption - CVE-2019-10952; and
Stack-based buffer overflow - CVE-2019-10954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to render the web server unavailable and/or place the controller in a major non-recoverable faulted state (MNRF).

Philips Advisory


This advisory describes a cross-site scripting vulnerability in the Philips Tasy EMR workflow based information system. The vulnerability was reported by Rafael Honorato. Phillips has provided generic workarounds to mitigate the vulnerability. There in no indication that Honorato has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with site or VPN access could exploit the vulnerability to provide unexpected input into the application, execute arbitrary code, alter the intended control flow of the system, and access sensitive information.

Friday, August 17, 2018

ICS-CERT Publishes 3 Advisories


Yesterday the DHS ICS-CERT published two control system security advisories for products from Tridium and Emerson and a medical device security advisory for products from Philips. The Tridium advisory was previously published on the HSIN ICS-CERT library on July 10, 2018. For more on this HSIN resource see the final section below.

Tridium Advisory


This advisory describes two vulnerabilities in the Tridium Niagara controller. The vulnerabilities were reported by Johnathan Gains and Leet Cyber Security. Tridium has updates available that mitigate the vulnerability. There is no indication that that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2017-16744; and
Improper authentications - CVE-2017-16748

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to crash the device being accessed; a buffer overflow condition may allow remote code execution.

Emerson Advisory


This advisory describes four vulnerabilities in the Emerson DeltaV DCS Workstations. The vulnerabilities were reported by Younes Dragoni of Nozomi Networks, Ori Perez of CyberX. Emerson has a patch available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Uncontrolled search path element - CVE-2018-14797;
• Relative path traversal - CVE-2018-14795;
• Improper privilege management - CVE-2018-14791; and
• Stack-based buffer overflow - CVE-2018-14793

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, malware injection, or malware to spread to other workstations.

Philips Advisory


This advisory describes two vulnerabilities in the Philips PageWriter Cardiographs. Philips is self-reporting these vulnerabilities to ICS-CERT. Philips has produced generic workarounds and plans to issue updates to mitigate the vulnerabilities in the middle of next year.

The two reported vulnerabilities are:

• Improper input validation - CVE-2018-14799; and
• Use of hard-coded credentials - CVE-2018-14801

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow buffer overflows or allow an attacker to access and modify settings on the device.

HSIN Library


It has been a while since I mentioned the ICS-CERT library on the Homeland Security Information Network. This restricted access, on-line resource provides ICS-CERT a method of sharing information with the user community for vulnerabilities that may affect critical homeland resources. This restricted release is designed to allow owners a chance to implement mitigation measures before the vulnerability becomes public knowledge.

For more information about this program and to request access see this ICS-CERT page.

Thursday, July 19, 2018

ICS-CERT Publishes 4 Advisories


Today the DHS ICS-CERT published four control system security advisories for products from Moxa, Echelon, and AVEVA(2).

Moxa Advisory


This advisory describes a resource exhaustion vulnerability in the Moxa NPort serial network interface. The vulnerability was reported by Mikael Vingaard. The latest firmware mitigates the vulnerability. There is no indication that Vingaard has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability  to send TCP SYN packages, causing a resource exhaustion condition that would cause the device to become unavailable.

Echelon Advisory


This advisory describes four vulnerabilities in the Ecelon Smart Server and i.LON products. The vulnerabilities were reported by Daniel Crowley and IBM’s X-Force Red team. Echelon has a new version that mitigates three of the vulnerabilities and provides a workaround for the fourth. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-10627;
• Authentication bypass using an alternate path or channel - CVE-2018-8859;
• Unprotected credentials - CVE-2018-8851; and
Clear text transmission of critical information - CVE-2018-885

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for remote code execution on the device.

In Touch Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InTouch HMI. This vulnerability was reported by George Lashenko of CyberX. Aveva has updates available that mitigate the vulnerabilities. There is no indication that Lashenko has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to remotely execute code with the same privileges as those of the InTouch View process which could lead to a compromise of the InTouch HMI.

InduSoft Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Aveva InduSoft Web Studio and InTouch Machine Edition HMIs. This vulnerability was reported by Tenable Research. Aveva has updates available that mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

Tuesday, December 5, 2017

ICS-CERT Publishes 1 Advisory and 1 Update

Today the DHS ICS-CERT published a control system security advisory for a product from Siemens. It also updated a previously issued advisory for products from Siemens.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens Industrial Products. The vulnerability was reported by George Lashenko of CyberX. Siemens has produced a firmware update that mitigates the vulnerability. There is no indication that Lashenko was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to conduct a denial-of-service (DoS) attack. The Siemens security advisory notes that the attacker requires network access to the affected devices.

Siemens Update


This update provides additional information for an advisory that was originally published on November 14th, 2017. The new information is updated affected version and mitigation information for:

• SCALANCE W-700 (IEEE 802.11n): All versions prior to V6.2.1

The associated Siemens updated security advisory also provides additional mitigating factors for:

• SCALANCE W-700 devices operated in Access Point;
• RUGGEDCOM RX1400 and RS9xxW;

KRACK Rant


The first vendor has now published a fix for the Key Reinstallation Attack – (KRACK) set of vulnerabilities that make control systems utilizing wireless systems using WPA2 security vulnerable to man-in-the-middle attacks; this is good news. Unfortunately, ICS-CERT still has not issued an alert outlining the extent of the vulnerability to the control system community. Nor have they even provided links to either the KRACK web site or the original paper describing the vulnerabilities. So much for ICS-CERT being interested in keeping the ICS community up to date on wide ranging vulnerabilities.

Friday, October 6, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Siemens and GE.

Siemens Advisory


This advisory describes an authentication bypass vulnerability in the Siemens 7KT PAC1200 data manager. The vulnerability was reported by Maxim Rupp. Siemens has produced new firmware that mitigates the vulnerability. There are not indications that Rupp has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to bypass authentication mechanisms and perform administrative functions. The Siemens security bulletin reports that the attacker must have network access to the device to exploit the vulnerability.

GE Advisory


This advisory describes a stack-based buffer overflow vulnerability in the GE CIMPLICITY software. The vulnerability was reported by David Atch of CyberX.  GE has released a new version that mitigates the vulnerability. There is no indication that Atch has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to crash; a buffer overflow condition may allow arbitrary remote code execution.

Tuesday, March 28, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from 3S – Smart Software Solutions and Siemens.

3S Advisory


This advisory describes two vulnerabilities in the 3S CODESYS Web Server which is used by an undisclosed variety of equipment manufacturers. The vulnerability was reported by David Atch of CyberX. 3S has provided a patch that mitigates the vulnerability. ICS-CERT reports that Atch has tested the patch and apparently verifies the efficacy of the fix.

The two vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2017-6027; and
• Stack-based buffer overflow - CVE-2017-6025

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerabilities to allow arbitrary files to be uploaded to the CODESYS Web Server without authorization. Additionally, an attacker may be able to crash the application or execute arbitrary code.

Siemens Advisory


This advisory describes multiple vulnerabilities in the Siemens RUGGEDCOM VPN endpoints and firewall devices. Maxim Rupp reported four of the five vulnerabilities. Siemens has developed a mitigation tool [.PDF download] for these vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The vulnerabilities are:

• Improper authorization - CVE-2017-2686 and CVE-2017-2689;
• Cross-site request forgery - CVE-2017-2688
• Cross-site scripting - CVE-2017-2687 and CVE-2017-6864;


ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to perform actions with administrative privileges. The Siemens Security Advisory notes that network access is required to exploit three of the vulnerabilities while the other two require a social engineering attack.

Tuesday, January 26, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two control system advisories. They were for systems from Rockwell Automation and MICROSYS.

Rockwell Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Allen-Bradley MicroLogix 1100 PLCs. The vulnerability was reported by David Atch of CyberX. Rockwell has produced a firmware update that mitigates the vulnerability, but there is no indication that Atch has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to run arbitrary code on the device.

MICROSYS Advisory

This advisory describes a memory corruption vulnerability in the MICROSYS PROMOTIC application. The vulnerability was reported by Praveen Darshanam of Versa Networks. MICROSYS has produced a new version which mitigates the vulnerability and Darshanam has verified the efficacy of the fix.

ICS-CERT reports that it would be relatively easy to craft a social engineering exploit of this vulnerability. This is the first time that I have seen ICS-CERT that crafting a specific social engineering exploit “would be simple”.


The PROMOTIC update note indicate that the vulnerability exists in the TrendsView ActiveX component.
 
/* Use this with templates/template-twocol.html */