Author: Clear Infosec

  • Recent Ransomware attacks 2022

    Recent Ransomware attacks 2022

    Ransomware attacks have become very high in recent days. The ongoing attacks cause losses to lots of organizations. Knowledge of Ransomware and its anatomy is very important to mitigate these attacks. Some simple Protection and Response plans available can be useful in understanding the basics of the mitigation process. Let’s see some of the attacks by Ransomware groups on famous industries.

    In January 2022, the ransomware attack on Bernalillo country in New Mexico can be considered the starting point of this year’s cyber-attack on a large scale. This attack causes many educational institutes and government institutes. The officials, however, said that they didn’t pay any ransom.

    The famous sports manufacturer Puma had a data breach on their employee information. Almost 6000 employees’ personal information has been stolen. But the officials announced the customer’s data were not damaged.

    Similarly, in Portuguese Media, Impresa was attacked by the Lapsus$ gang. This happened during the New year holidays blocking the organization’s websites and online services.

    A multinational defense contractor, Hensoldt, which provides sensor solutions for the defense and security software for many US dense organizations, was under a Ransomware attack. Authorities didn’t reveal the details of the attack, but the ransomware group Lorenz which claimed responsibility for the attack, said they received the ransom. Whether the ransom was paid or not can be a debate.

    The LockBit ransomware gang attacked Bridgestone organization, one of the largest manufacturers of tires, in Feb 2022. The organization tried its best to mitigate the attack, but still, the company was forced to halt its productions for nearly a week. The LockBit gang later threatened the company to pay the ransom before 15th march, or they would leak the stolen information. There was no official information on whether the organization paid ransom or not. Still, it is reported that the company was able to perform a comprehensive security check and reconnect to its network. 

    Near the end of February, one of the largest microchip makers in the USA, Nvidia, was attacked by the Lapsus$ gang, the same one that attacked Impresa. It was confirmed that the group had stolen the data of employees and proprietary company data. Because of this breach, the company went offline for two days. It was rumored that Nvidia tried to hack the attackers to retrieve the data. But Nvidia authorities announced that they are in the process of analyzing the data loss and have not commented on the hacking part.

    In March 2022, Okta, the identity and access management company, confirmed that there was an unsuccessful attempt on their data. Lapsus$ group announced in their Telegram group that they had breached the company’s security and accessed their data. It was later confirmed that Sitel, an Okta sub-processor that provides Okta with contract workers for our Customer Support organization, was breached, and nearly 300 customers were compromised.

    The same organization publicly announced that they had claimed an account in Microsoft and gained limited access. Microsoft announced they received an alert and started the mitigating process, and when the attacker announced in public, the company intervened and stopped the attacker. The company also assured “no customer code or data was involved in the observed activities.”


    Known ransomware attacks in April 2022 by country

    From the pie chart provided by Malwarebytes, it is clear that ransomware attacks are very high worldwide. These charts were only for April, which shows the alarming number of attacks.

    The new gang, Black Besta, came out of nowhere and conducted nearly eleven successful breaches of organizations. Experts in the field believed it might be some old gang re-established themselves in the new name. Some of the organizations attacked are American Dental Association and Deutsche Windtechnik.

    Austin Peay State University also confirmed it had been a victim of a Ransomware attack. The university asked the professors and students to immediately disconnect their systems from the university network. These actions were taken by posting the alert in their official tweet.

    It can be very clear that many attacks were happening worldwide in all industries. Even the top giants also become victims of these attacks. It shows that good knowledge and a well-equipped cybersecurity team are highly important. Moreover, due RaaS model, carrying out ransomware attacks becomes simplified. To know more about the latest trends in cybersecurity services and ransomware, you can check the clearinfosec site.

  • ToddyCat APT unveiled

    ToddyCat APT unveiled

    Multiple threats detected from December 2020 against high-profile entities in Europe and Asia are finally traced to be responsible by a new Advanced Persistent Threat (APT) actor. Not much information about this is not yet gathered but its noticeable signs are the use of 2 previously unknown tools named “Samurai Backdoor” and “Ninja Trojan”.

    Since its start in December 2020, this threat managed to compromise selected Exchange Servers in Taiwan and Vietnam with the use of an unknown exploit leading to the creation of the well-known China Chopper Web Shell, which in turn used to initiate a multi-stage infection chain. Numerous components including custom loaders were found to be used in the final execution stage of passive backdoor samurai. Only 3 organizations were targeted at first by the group behind ToddyCat APT. But the count raised with the group exploiting the ProxyLogon vulnerability to compromise multiple servers across Europe and Asia.

    It is suspected that the group started exploiting Exchange Servers in December 2020, but the information to confirm this is insufficient. The Samurai passive backdoor, a sophisticated backdoor that typically operates on ports 80 and 443, was used to hack Microsoft Exchange Servers, which were the only targets of the first wave of attacks.

    During the period of the second wave, researchers found a sudden surge in the attacks. It is at this time the backdoor exploited the ProxyLogon vulnerability.

     

    The attack surface in the third wave is noted the third wave increases the attack surface to include desktop systems, whereas the first two waves solely affected Microsoft Exchange Servers.

    Credits: Kaspersky

    Security researchers say that there is only a little information is available about this threat actor.

    As mentioned earlier in this blog, the APT leverages 2 passive backdoors in the Exchange server environment with malware called Samurai and Ninja and takes complete control of the victim’s hardware and network. The Samurai malware uses multiple modules that allow the attackers to take control of the remote systems and freely move inside the targeted network. In some cases, Samurai backdoor lays a path to launch another malicious program called Ninja.

    The affected governmental and military groups demonstrate that this group is focused on highly prominent targets and is likely employed to accomplish important objectives, most likely connected to geopolitical interests.

  • Ransomware As A Service

    Ransomware As A Service

    Ransomware as a service is a business model where the customers or the malicious party use the ransomware developed by the experienced hacker. They may pay a certain amount, or a certain percentage of the total ransom received using this tool or code. This may be an example of software as a service.

    And the best part of RaaS is the person who uses this service does not need to know anything about coding. In the past, any attacker needs to have a good amount of knowledge in coding to initiate the attacks. But with the model of Raas, the user is not required to know even the basics of coding and still can execute the attack.

    This increasing trend of Raas gives a huge disadvantage to cybersecurity experts. The number of ransom attacks has been on the increasing graph ever since the Raas model was started. Companies or organizations of all sizes are trying their best to increase their cybersecurity to reduce the victimization of Raas.

    Ransomware attacks are found to be always on the rise. According to the report jointly given by The Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the NSA, ransomware attacks in 2022 will only be on the rising side.

    The most dangerous thing about Raas is it’s very easy to find. It becomes like ordinary goods sold on a market. Some Raas kits even have 24/7 support; other offers, there are forums on this kind of service to provide user services. They follow the same kind of treatment as SaaS. This kind of Raas service is not much costly too. If they buy a kit for 40 to 50$, they can earn up to thousands of dollars if the attack is successful. The person who uses RaaS needs a few attacks to succeed in becoming a rich person.

    The way RaaS work

    • First, the skilled ransomware developer will create a new kind of ransomware that is unlikely to be discovered by the organization’s firewall or cybersecurity team. This itself will give a high chance of a successful attack.
    • The developed code is then advertised in the designated forum or in other ways. The code will be developed to be modified easily to meet the multi end-user infrastructures. The developers mostly use cloud concepts, so it will be easy for users to use. We can call the customer’s affiliates.
    • Next, the affiliates will spread the malware. It may be a targeted attack or send the malware on the internet and wait for the user to get phished. It should be noted that phishing attack may look simple but causes more damage.
    • If the attack were successful, the money would be distributed among the affiliates and developers, as discussed earlier. There are many methods for this distribution, which will be explained briefly on the following page. It should be noted that most of the ransom was asked in cryptocurrency nowadays. This is to make use of the advantage of blockchain technology.

    The model of RaaS

    Almost all the RaaS methods will come under this kind of model. This model is based on profit distribution profits between the developer and affiliates.

    • Monthly Subscription

    In this method, the users pay a monthly fee, like subscribing to a newspaper and earning some percentage of the successful ransom. The developer may use the money from the subscription to develop a code or consider it a pure profit if there are many subscribers.

    • Affiliate

    In this model, a certain number of profits will be given to the RaaS developer. Instead, a developer will provide efficient service and support till the attack is successful.

    • One-time access

    The customer will pay the amount upfront and buy the code in this model. What he does with that and the profits earned solely belong to the customer.

    • Profit sharing

    This model is similar to the affiliate model. The profits are divided between the developer and customer based on their predetermined conditions.

     By understanding how RaaS works and familiarizing yourself with their models, the cybersecurity team to develop their defense. As a cybersecurity expert, you need to be aware of attacks’ different methods and principles to develop a successful defense. It is best to understand more about ransomware, its anatomy, and prevention methods, even if you are not in cybersecurity. Knowing this knowledge may help you avoid becoming a victim of ransomware attacks.

  • Ransomware Blockchain

    Ransomware Blockchain

    This blog will see whether it is possible to use the blockchain concept to track ransomware attackers or prevent such attacks. I have explained Ransomware in my previous blogs, and you can look into it for more details.

    Everyone will be aware of cryptocurrency at this age. The arrival of cryptocurrency as a boon or curse is still a debate. Cryptocurrency uses blockchain technology for the transaction. With rising cryptocurrency trends and the advantage of blockchain technology, cybercriminals started to ask for cryptocurrencies as a ransom.

    Source: Chainalysis

    According to the data collected by chainalysis, more than 600 million USD are transacted as ransomware. They also mentioned that with continuous updates and the range of 2021 may increase further and might be higher than the year 2022.

    Blockchain is a decentralized and digital log of encrypted transactions in the form of blocks. Each transaction is verified by the majority of the participants of the system. The emergence of blockchain also caused a rapid increase in a ransomware attacks. It is mainly because the attackers can demand the ransom in cryptocurrency, and because of its technology, the anonymity of the attackers can be maintained.

    It becomes a game between security experts and attackers to use blockchain for good or harm.

    Blockchain logs are decentralized, so there won’t be a single copy of the confidential data. Also, according to blockchain technology, once the data is entered, it’s impossible to change it. Because of this, both the sender and receiver of the data can be sure that no data has been altered.

    Since the data is decentralized, the critical information ends up in many places. There may be different organizations may store data in the same decentralized storage. This also makes the attacker’s work difficult. If an attacker needs to take the data, they need to compromise multiple protocols in different places.

    Blockchain also uses the sequential hashing (SeqHash) technique; this helps secure the integrity of the data or blocks every 10 minutes. Each company will use its encryption for data too.

    But obviously, if there are any errors in decentralized architecture, the attackers can use them as entry points. If there is one thing that can be sure about security is there is not 100% safe. Cybercriminals will find a way to extract a loophole if security experts find a way to protect. It’s an endless cycle, and whoever is up to date and on top of their game will achieve victory for that moment.

  • Follina – ZeroDay hole in MS Office

    Follina – ZeroDay hole in MS Office

    Microsoft has confirmed a Remote Code Execution (RCE) vulnerability in Microsoft Support Diagnostic Tool (MSDT) which is expected to be exploited since April, at least.  It was on May 27th, 2022, reports came about malicious word documents that leverages remote templates in order to execute PowerShell via the ms-msdt Office URL scheme. This vulnerability is assigned with CVE-2022-30190.

    An attacker who successfully exploits this flaw can execute arbitrary code by calling application’s privileges. In the context allowed by the user’s permissions, the attacker can then install applications, read, alter, or remove data, and create new accounts.

    It all started with a security researcher finding a document on VirusTotal that was used to execute PowerShell code. The security researchers have been analysing the malicious file and discovered that it was actually exploiting a zero-day vulnerability in MSDT. With this file, the researchers found that it will take only opening the file to trigger the exploit.

    Analysis:

    Follina is an RCE vulnerability found in MSDT that impacts several versions of Microsoft Office, including the patched versions of Office 2019 and 2021. Though an attacker leveraging flaw is likely to be Remote, Microsoft list the attack vector as “local” because of the way it is exploited.

    An attacker would create a malicious document, usually in Microsoft Word, and email it to their victim. An attacker can leverage this vulnerability to run commands with the permissions of the application that opened the infected document. Microsoft says that the attacker will be able to install programs, view, change, or delete data, or create new accounts.” The PowerShell was found to be used in the attacks observed in April. A broad range of attacks are expected with this vulnerability in the near future.  

    Proof of Concept:

    A detailed technical breakdown of this vulnerability is provided by Huntress Labs and you can also find other PoC in GitHub.

    Remediations:

    An effective patch is not yet released at the time of writing, you can find mitigation steps to limit attack surface. Microsoft has released mitigation guidance for this vulnerability and this vulnerability was revealed by a member of the Shadow Chaser Group, according to Microsoft’s alert.

    The mitigation guidance says that in Microsoft Defender, activate “Block all office apps from creating child processes” in Block Mode in order to prevent this vulnerability from being exploited. It is still not unclear what the impact would be for this mitigating effort.

  • WINDOWS LSA Spoofing Vulnerability

    WINDOWS LSA Spoofing Vulnerability

    Microsoft released a patch for Windows Local Security Authority (LSA) spoofing recently. This was one among the 74 security flaws reported to be fixed with the new patch, including 7 critical, 66 deemed important and 1 low severity.

    Windows LSA spoofing vulnerability (CVE-2022-26925) is being wildly exploited. As per Microsoft an unauthorised bad actor will be able to “coerce the domain controller to authenticate to the attacker using NTLM.” A bad-actor, via man-in-the-middle attack can easily exploit this vulnerability. They inject themselves into the logical network path between the target and the resource requested. The bug individually has a 8.3 CVSS severity score but when combined with NTLM relay attacks, the combined severity score is would be 9.8, according to Microsoft.

    Cybersecurity and Infrastructure Security Agency (CISA) have added this vulnerability in their “Must-Patch” list because federal agencies are advised to patch the vulnerabilities within a specified timeframe. Microsoft is giving further mitigation instructions for this vulnerability, as well as a default configuration for Windows servers with specified roles enabled, which permits exploitation of the vulnerability.

    “The story behind CVE-2022-26925 is no advanced reverse engineering, but a lucky accident. During my pentests in January and March, I saw that PetitPotam worked against the [domain controllers],” said Raphael John from Bertelsmann Printing Group, who has been credited by Microsoft for reporting CVE-2022-26925 on Twitter.

    Microsoft has addressed this vulnerability with the May patches release and warned at the time that the vulnerability has been publicly disclosed and exploited in attacks. The May 10 upgrade should not cause issues on client devices or non-domain controller servers, according to CISA, and users should continue to install it on these devices.

    Base Score Metrics explained

    1. Attack Vector

    It describes the context by which the vulnerability exploitation is possible. In this case, it is the Network. The vulnerable component is bound to the network stack and the set of possible attackers extends beyond the other options listed, up to and including the entire Internet. 

    1. Attack Complexity

    It describes the conditions beyond the attacker’s control that must exist in order to exploit the vulnerability. In this case, it is High. requires the attacker to invest in some measurable amount of effort in preparation or execution against the vulnerable component before a successful attack can be expected.

    1. Privileges required

    It describes the level of privileges the attacker must have in order to exploit the vulnerability. In this case, it is None. The attacker is unauthorized and requires no access to settings or files to perform an attack. 

    1. User Interaction

    It describes the requirement for a user other than the attacker to perform a successful attack. It is None in this case. The vulnerable system can be exploited without any user interaction.

    1. Scope

    It shows the if components other than the vulnerable component are affected with the attack when the vulnerability is exploited. Base score increases if so. It is Unchanged in this case as this vulnerability, when exploited, can affect only the resources managed by same security authority.

    1. Confidentiality

    It measures the impact to the confidentiality of information resources managed by a software component due to a successful exploitation. In this case, it is High as there is a total loss of confidentiality.

    1. Integrity

    It measures the impact to the integrity of a successful exploitation. It is High in this case as there is a total loss of integrity.

    1. Availability

    It measures the impact to the availability of the impacted component resulting from a successfully exploited vulnerability.

    This vulnerability is actively under exploitation, and we recommend updating the new Windows May patch. With Clear Infosec Threat Intelligence Bulletin, stay update of the new threats and stay fortified.

  • Do you know about Denonia?

    Do you know about Denonia?

    Malware that targets AWS Lambda Environments

    A first-of-its-kind malware that is specifically designed to execute in an AWS Lambda environment has been discovered by Cado labs. Even serverless environments are no longer safe. While the malware’s distribution is limited, the discovery of such malware is evidence of bad actors’ advanced technical skills and their interest in cryptocurrency.

    What is AWS Lambda

    AWS Lambda is serverless, event-driven compute service that runs code for any application or service without managing a server. It runs the code in response to events and can be triggered from over 200 AWS services and SaaS applications.

    A serverless environment doesn’t mean there isn’t any server lying behind, but the user doesn’t have to manually manage the virtual machine or infrastructure behind it. AWS Lambda automatically manages the underlying computing resources, unlike AWS EC2 (Elastic Compute Cloud).

    Why a malware inside a serverless environment can be a big deal?

    It is the cloud provider who manages and secures the underlying server, operating system, etc. reducing the attack surface. Under AWS shared responsibility model, AWS manages and secures the Lambda environment while the users secure the functions. Another feature to be mentioned is its ephemerality. AWS Lambda is short-lived, which means its runtime duration is very short. Security features of AWS lambda allow it to act only when the right resources or services with the right permissions try to invoke it.

    But we need to note that nothing could stop DENONIA. Denonia can be a great example that attackers are gaining advanced cloud-specific knowledge to exploit even the complex cloud infrastructure. It is still a mystery exactly how the bad actors were able to deploy Denonia in the AWS Lambda environment. This single malware shows that there might be more attacks to come.

    Denonia Malware

    Denonia malware is 64-bit executable targeting x86-64-bit architecture that is written in Go language. It is named after the domain it communicates with (gw.denonia.xyz).

    Denonia malware executes a customized version of XMRig in the lambda environment. XMRig is a software that is intended to mine Monero cryptocurrency. The malware uses several 3rd party libraries including the one that enables execution inside the AWS lambda environment. The security researchers were able to execute the malware on AWS Linux boxes used by the Lambda environment.

    How Denonia works

    Denonia communicates with Command and Control (C&C) servers using a GO library that supports DNS over HTTPS (DoH). The DNS queries are encrypted, and the requests go out as regular HTTPS traffic to DoH resolvers like Cloudflare, Google, etc.

    This technique provides some benefits which we must note. AWS cannot see the DNS lookups for the malicious Denonia domain, which helps to avoid detection from cloud workload protection tools. Since DNS requests appear as HTTPS traffic, it bypasses VPC level DNS controls.

    When DNS resolvers send an IP address back to malware, it simply writes it to XMRig, and the malware then starts XMRig from memory and communicates with the hacker mining pool to get the mining job started.

    The future implications

    Even though the malware seems to be causing harm to anybody now, the techniques used behind might open doors to more harmful attacks in the coming days. This single malware proved that even the serverless environments are not fundamentally secure as we thought they were.

    The need to build new security tools to deal with malware detection and prevention within the serverless environment is on the rise.

    Protect yourself from Denonia

    How Denonia gets deployed in the Lambda environment is still unknown. But it is important to take all possible security measures to bring more security to avoid it.

    1. Keep your AWS credentials secured and do not share them with anyone
    2. User accounts should be carefully set up with the least privileges
    3. Enable MFA for every account
    4. SSL/TLS protocol should be used to communicate with AWS resources
    5. Enable API and user log in with AWS CloudTrail
    6. Monitor activity logs regularly

    Found the article interesting? Follow us on LinkedIn, Facebook & Twitter for more updates on the new vulnerabilities and what is happening in the InfoSec community.

  • Microsoft Autopatch

    Microsoft Autopatch

    Everyone might have already known that Microsoft announced a feature Windows Autopatch, which will be released in July 2022. This blog is about this new feature that Microsoft is planning to release.
    Windows Autopatch is a service mainly designed to update the windows and office automatically. This feature will be available for free for those users who have a subscription to
    • Windows E3 or above
    • Microsoft Intune
    • Windows 10/11
    • Azure AD premium.
    And it does not apply to Windows Server OS and Windows 365 for Business.
    “This service will automatically keep Windows and Office software on enrolled endpoints up-to-date at no additional cost. The second Tuesday of every month will be ‘just another Tuesday’,” promised Lior Bela, a Sr. Product Marketing Manager at Microsoft.
    It was mentioned that the patch was mainly released to focus on updating the patch timely to reduce the security threats that may arise because of lag in an update. This update also focused on tackling the complexity involved in software updating in an entire IT organization.
    As we know, cybercrime is getting more and more advanced. Their knack for catching the loophole is also high reading all the attacks. So, we can guess they are hoping this update may reduce the attackers to catch this simple entry into the network or system, which may arise due to lag in time to update.


    Source: Windows

    According to the description given by Microsoft, the windows autopatch feature automatically creates four testing rings. Each of the testing rings represents all the diversity in an enterprise.
    The updates are initially tested on a small set of devices. If the update and installation create no further problems, the installation will be extended to larger sets of devices.
    The “test ring” will contain a minimum number of devices in the organization.
    “First ring” is around 1% of all the devices and software needed to keep up to date as soon as possible.
    “Fast ring” contains around 9% of the devices, and “broad ring” is around 90% of the rest of the devices.
    The population dividend if these rings are managed automatically. But the organization’s IT admins are given privileges to move specific devices from one ring to another ring


    Source: Windows

    And administrators can also stop, pause or roll back the update if they find any problems during the update or need an older version for their unique requirement.
    For more details about the requirements, eligibility, and other information about this feature, you can search in Windows Autopatch FAQ. Lior Bela publishes them.

  • What is Spring4Shell?

    What is Spring4Shell?

    Spring framework is found to have a Remote Code Execution (RCE) flaw. This vulnerability, if exploited successfully, will let the attacker take control of the targeted system. Fortunately, the team behind the framework was successfully able to release a patch to address the flaw.

    What makes Spring4Shell vulnerability (CVE-2022-22965) very dangerous is the leverage it gives to an unauthorized user. It is named Spring4shell due to its resemblance to the old threat log4shell. Many researchers believe this could have been worse than log4shell. This vulnerability impacts the spring framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and other older versions. The patch is available in versions 5.3.18 or later and 5.2.20.

    What is Spring framework?

    Spring is a popular application development framework for Java, used by millions of developers across the world. What adds the most value to it is that it is an open-source platform.

    Spring can be used to build websites and applications and there exist millions of sites on the internet that runs on the spring framework which potentially increases the attack surface.

    CVE 2022-22965

    You should not get confused this vulnerability with another vulnerability (CVE-2022-22963) that was disclosed at almost the same time in a component called the spring cloud function allowing code injection through Spring Expression language. This vulnerability, found in the Spring Cloud Function versions 3.1.6, 3.2.2, and below, does not impact the Spring core, but Spring4Shell does. But both the vulnerabilities can be used for remote code execution.

    Spring4shell vulnerability, affecting the Spring core, allows attackers to send a custom-built HTTP request to bypass the security measures in the HTTP request parser and leads to remote code execution. The bug exists in the getCachedIntrospectionResults method to gain unauthorized access. When special object classes are used, it creates a risk of data leakage and remote code execution.

    This vulnerability is easy for the bad actors to exploit if they can find vulnerable versions in the production environment.

    Check whether you are vulnerable or not:

    You are vulnerable if:

    1. You are using Spring framework versions 5.3.17 and below, 5.2.19, and below.
    2. Your app runs on Java 9+
    3. You have Apache Tomcat for serving the application
    4. You built applications as WAR files
    5. You use form binding with name=value pairs and not using Spring’s more popular message conversion of JSON/XML
    6. You don’t use an allowlist or you don’t have a denylist that blocks fields like “class”, “module”, “classLoader”

    It is a toiling process for the development team to manually check the entire source code. Using a Software Composition Analysis (SCA) tool. An SCA tool enables you to analyze and manage the open-source elements of your applications.

    It scans your source code repositories and figures out all the open-source components that are used to build your application. So, when a new vulnerability comes up, you can immediately verify whether you are using the vulnerable component.

    How to mitigate the issue:

    There are many PoCs available for the Spring4Shell vulnerability. As this is a new vulnerability and more exploits can be expected in the coming days and the one thing that you need to do to keep your application secured is to stay updated and patch.

    How Clear Infosec can help:

    Talk to our industry-leading security experts in order to keep your applications protected. Review your source codes and much more offerings and integrate security into every layer of your application development cycle.

  • Dirty Pipe – Privilege Escalation Vulnerability in Linux

    Dirty Pipe – Privilege Escalation Vulnerability in Linux

    Linux is found to have yet another severe privilege escalation vulnerability (CVE 2022-0847) in kernel version 5.8 and above. This vulnerability is allowed bad actors to execute malicious code that can act as a host to destructive actions like installing backdoors into the system, injecting code into scripts, and even creating unauthorized user profiles.

    This vulnerability was discovered by Max Kellermann in early March 2022 and is similar to the old Dirty Cow vulnerability (CVE 2016-5195). You must also note that the Dirty pipe vulnerability has been fixed in Linux Kernel versions 5.16.11, 5.15.25, and 5.10.102. If you are using Linux devices, ensure that it is updated to these versions or above.

    Let us look at the way the Linux kernel manages memory before we dive into the vulnerability.

    Working of Linux Kernel

    The kernel is a core program of an operating system. It is in fact the first program loaded when the system starts. The basic unit of memory is the PAGE. It is still unknown how large a page can get, but typically, it is considered as 4Kib. Page cache manages the page and pages are mainly used when a read or write operation is performed on the files on the disk. This reading and writing are performed with the use of PIPES. Piping is an old mechanism that sends the output of one command/process/program into another.  

    Before getting into this vulnerability, you should also know about “splice()”. This function speeds up the process of pushing the contents of a file into a pipe. In other words, it points the pipe at a page that is already loaded into the memory where a section of a read-only file is already opened.

    Dirty Pipe in Linux                                            

    Dirty Pipe vulnerability makes use of the pipeline mechanism to allow local users to gain root access to any system. What makes this vulnerability dangerous is that this vulnerability can be easily exploited with publicly available exploits.

    There are several ways to exploit this vulnerability for privilege escalation. This vulnerability makes the bad actors gain root access and write to read-only files possible. If the bad actor gets to the /etc/passwd file containing the list of users and their privileges, they can append to the file a new user with root privileges.

    How the exploit works

    Let us start by creating a pipe. You will then be copying arbitrary data into that pipe just to ensure that the pipe buff flag (can merge flag) is set in all instances. Then you will be draining the pipe leaving that flag set in all the pipe buffers. This is where the bug occurs.

    That flag is supposed to get reset. You will then splice data from a target read-only file into the pipe just before where the target is. Normally when you splice data into a pipe, you cannot write more data to that page. But this pipe buffer has the “can merge flag”.

    This results in a mergeable pipe buffer that also has a reference to data in it. Now starts the real exploit. You can now simply write arbitrary data to that pipe buffer and then overwrite what was being referenced.  

    The real problem

    The write permissions are working fine but the real problem is, the write permissions aren’t checked in pipes. It is because when you are at the pipe level, the kernel believes the permissions are already verified and accepted.

    This can make an unauthorized user gain root permissions and even inject arbitrary ssh keys to gain remote access to a system. This raises a big issue, making this vulnerability notable in the InfoSec community.

    Remediations

    Updating the kernel is the remedy here. Patch for this vulnerability was released very soon knowing the impact this will cause. The Linux kernel versions 5.16.11, 5.15.25, 5.10.102 are released with the patch included.

    If you are using Linux systems, ensure that you are using at least these versions or above.

    Stay secure with Clear Infosec

    To keep you informed of all the new vulnerabilities and fixes, sign up for our Threat Intelligence newsletter (TIB). Stay informed and stay secure.