search

A router higiéniájának javítása a szibériai állami támadások elleni védelemhez

person Szerző CISA
source Forrás: All CISA Advisories
calendar_today
schedule 3 perc olvasás

A Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors. Summary: The FSB Center 16 continues to exploit poorly configured and vulnerable networking devices worldwide. This advisory builds on the FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement, by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to better understand and counter the threat. The following agencies authored and co-sealed this advisory: United States National Security Agency (NSA), United States Cybersecurity and Infrastructure Security Agency (CISA), United States Federal Bureau of Investigation (FBI), United States Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), United Kingdom National Cyber Security Centre (NCSC-UK), Czech Republic National Cyber and Information Security Agency (NÚKIB), Danish Defence Intelligence Service (DDIS), Estonian Foreign Intelligence Service (EFIS), Estonian Information System Authority (RIA), Finnish Defence Intelligence (FDI), Finnish Security and Intelligence Service (SUPO), French National Cybersecurity Agency (ANSSI), Italian External Intelligence and Security Agency (AISE), Italian Internal Intelligence and Security Agency (AISI), The Military Counterintelligence Service of Poland (SKW), Sweden National Cyber Security Centre (NCSC-SE). The authoring agencies highly recommend network defenders implement mitigations to harden networks against this exploitation: Disable Cisco Smart Install, Use SNMPv3 with strong authentication, Disable SNMPv1 and SNMPv2, Monitor for unusual credentials, Use a Management Information Base (MIB) allow list, Reference the vendor-specific MIB for the network devices and monitor OIDs for indications of reconnaissance or misconfiguration, Restrict management protocols, Use ACLs to only allow management protocols from management devices, Disable TFTP, TCP port 4786 (SMI), UDP ports 161 and 162 (SNMP), TCP/UDP ports 10161 and 10162 (SNMPv3), Update network device software and firmware images, Use an attack surface management service to identify and secure Internet-facing systems with weak configurations and known vulnerabilities, U.S.-based federal, state, local, tribal, and territorial governments and U.S. critical infrastructure organiztions should consider signing up for CISA’s no-cost Cyber Hygiene services. U.S. Defense Industrial Base organizations should consider signing up for NSA’s DIB Cybersecurity Services. The primary methods used by the actors are scanning to identify poorly configured networking devices, primarily routers, for exploitation. The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication. These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to copy its configuration to a file, often called “config.bkp” or “output.txt”. The actors also exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices. Mitigation actions include disabling Cisco Smart Install, using SNMPv3 with strong authentication, disabling SNMPv1 and SNMPv2, monitoring for unusual credentials, using a Management Information Base (MIB) allow list, referencing the vendor-specific MIB, restricting management protocols, using ACLs, and disabling TFTP, TCP port 4786 (SMI), UDP ports 161 and 162 (SNMP), and TCP/UDP ports 10161 and 10162 (SNMPv3).

Kapcsolódó cikkek

cybersecurity

Új dél-korei kampány hamis programozási interjúkat használ a fejlesztők adatai ellopásához

Koreai-ligához tartozó hackerek a SVG zászló képeken rejtették el a rosszindulatú szoftvert, hogy a fejlesztővizsgálatok során a programozási feladatokat is megvizsgálhassák. Egyetlen antivírus-szolgáltató sem talált rá.

cybersecurity

Az Abbott két számítógépes incidenset vizsgál meg, miután kártételezési vádak merültek fel.

Az Abbott Laboratories két különálló számítógépes biztonsági incidenset vizsgál, miután megerősítette, hogy a Cancer Diagnostics üzletágában található belső Exact Sciences rendszerekhez történt jogosulatlan hozzáférést. Emellett egy másik vádot is vizsgál, amely szerint támadók megsebeztek a LabCentral portált, és vállalatadatokat elloptak.

cybersecurity

A HollowByte-nak talált DDoS-es hibát az OpenSSL szerveren, 11 bájtos payloadokkal.

Egy biztonsági rést, melyet HollowByte-nak neveztek, segítségével hitelesítés nélküli támadók az OpenSSL szervereken elindíthatnak egy szolgáltatási elutasítás (DoS) állapotot, csak 11 bájtnyi kártékony terheléssel.