11 ms·
Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
- pizza 5y agoIf I'm understanding this correctly, the DOJ authorized the FBI to exploit the exploit to remove the exploit from exploited servers? This proactivity is something I remember hearing recently that the NSA wished they could have
- tiahura 5y agoNot quite. A federal judge authorized the FBI to act. Not my area of practice, but seems odd - maybe akin to an ex parte tro?
- mrstubbs 5y agoThe statement says they were authorized to send commands to vulnerable servers through the exploited services/webshells which removed said webshells from the system.
- paxys 5y agoMore like – FBI wanted to patch affected servers remotely without getting every owner's consent but weren't sure of legality so they asked a judge to sign off on it.
- elliekelly 5y agoWhoa. Has this ever been done before?
- vmception 5y agoAsking a judge for a really broad constructive warrant and pretending that the founding fathers anticipated this use case in their aggregate infinite wisdom is very common
- tony101 5y agoThe warrant is actually quite specific, down to the exact URL paths of the shells to be searched and removed. See pages 20 and 21 of https://www.justice.gov/opa/press-release/file/1386631/download https://www.justice.gov/opa/press-release/file/1386631/downl...
- atat7024 5y agoHow many IPs are they allowed to break into to find the webserver behind those domains?
- not2b 5y agoIt's bizarre to think that we should be bound forever more to only do the things that people in 1789 thought appropriate. But it seems to me that they followed the procedure outlined in the 4th amendment; they went to court and got a specific warrant to remove a specific bit of malware from a specified set of servers. Madison deliberately left many provisions in the Constitution and Bill of Rights open-ended because he wasn't an idiot and knew that the founders could not anticipate everything. Had the FBI acted on its own it would be overreach. They went to court, got a warrant, and did pretty much the minimum required to eliminate the threat.
- jamiek88 5y agoGood job those aristocrats from 1790's were omnipotent then.
- IHLayman 5y agoActually, according to the brief they actually didn’t patch the servers, but only removed the web shell: “This operation was successful in copying and removing those web shells. However, it did not patch any Microsoft Exchange Server zero-day vulnerabilities or search for or remove any additional malware or hacking tools that hacking groups may have placed on victim networks by exploiting the web shells.”
- mjn 5y agoI think this is the relevant court record: https://www.justice.gov/opa/press-release/file/1386631/download https://www.justice.gov/opa/press-release/file/1386631/downl... The mechanism seems to be a search warrant. The FBI applied for a warrant to "search" all compromised Exchange servers in the United States, and to "seize" the illicit malware on those servers by executing a specified series of commands. A few excerpts from the above link: "FBI personnel now seek authorization to search the compromised Microsoft Exchange Servers and uninstall the web shells on those servers". (6th page of the PDF) "This warrant authorizes the United States to seize and copy from Microsoft Exchange Servers located in the United States the web shells identified in Attachment A, and to delete the web shells from those servers." (11th page)
- deleted 5y ago[deleted]
- iudqnolq 5y agoHere's the authorities they cite > a magistrate judge ... has authority to issue a warrant to use remote access to search electronic storage media and to seize or copy electronically stored information located within or outside that district if ... the media are protected computers that have been damaged without authorization and are located in five or more districts. > A warrant may be issued for any of the following: (1) evidence of a crime; (2) contraband, fruits of crime, or other items illegally possessed; (3) property designed for use, intended for use, or used in committing a crime; or (4) a person to be arrested or a person who is unlawfully restrained. https://www.law.cornell.edu/rules/frcrmp/rule_41 https://www.law.cornell.edu/rules/frcrmp/rule_41
- mjn 5y agoInteresting, I had missed that. The language allowing remote searches when computers "have been damaged without authorization and are located in five or more districts" seems to be recent, added by Congress in a 2016 amendment: https://www.justice.gov/archives/opa/blog/rule-41-changes-ensure-judge-may-consider-warrants-certain-remote-searches https://www.justice.gov/archives/opa/blog/rule-41-changes-en...
- alfiedotwtf 5y agoWhat if servers that got “fixed” weren’t American? Would that mean the FBI went outside its jurisdiction and could be seen as an illegal act across international borders?
- brown9-2 5y agoWhat harm could the owner claim and who would prosecute that? I think an act of shutting down exploited servers is being overthought here.
- yjftsjthsd-h 5y agoWell the most obvious thought is if it doesn't go perfectly - server is compromised but works, feds patch it, patch breaks it in some unforseen way.
- Geezus_42 5y agoA previous comment quoted officials stating that no patch was applied. They only removed the specific malware in the warrant and left the servers as they were. Which means they could simply be exploited again.
- salawat 5y agoA Government overstep is never a topic where overthinking is a hazard. This type of thing sets precedents that case law keeps alive into perpetuity.
- 7952 5y agoWhat troubles me is such broad use of a warrant. Is this really search and seizure?
- nojito 5y agoNo chance of this happening because the IPs are required to be disclosed before getting the sign off to do it.
- OGWhales 5y agoThat was a fun way to phrase that.
- varenc 5y agoPresumably the FBI limited this operation to "U.S. Networks". I wonder how they determined that? Based on domain registration? IP block ownership? What about a non-US company with servers outside of the US that has a Point-of-Presence IP inside the US? Seems like there's no perfect way to determine programmatically.
- iudqnolq 5y agoHere's what the warrant says > The presumptively U.S.-based Microsoft Exchange Servers, corresponding to the approximately [redacted] web shells in Attachment A appear to be located in five or more judicial districts, according to publicly available Whois records and IP address geolocation
- varenc 5y agoThanks! I couldn't find the warrant before but that string was enough to locate it: https://www.justice.gov/opa/press-release/file/1386631/download https://www.justice.gov/opa/press-release/file/1386631/downl...
- rektide 5y agoThe DoJ's Advanced SysOps Team strikes again! We upgrade what no one else will!!
- edoceo 5y agoLike the SeaBees but for tech-infrastructure.
- Forge36 5y agoInteresting precedent. Will they bill Microsoft? If not, I'm curious if this could mark the start of externalizing security and cleanup responsibilities to the federal government.
- ianhawes 5y agoThe FBI is notorious for billing banks after responding to bank robberies. /s
- sneak 5y agoHow is this legal? Has the judiciary simply accepted the fact that the CFAA doesn't apply to FBI agents?
- newleaf 5y agoSomeone can provide a better explanation, but this is similar to how breaking and entering is illegal, but the same action with a warrant isn’t.
- chris_wot 5y agoI think the following comment has the part of the law that allows them to close the web shells: https://news.ycombinator.com/item?id=26802130 https://news.ycombinator.com/item?id=26802130
- deleted 5y ago[deleted]
- sneak 5y agoThere is a constitutional basis for a warrant being permitted, upon probable cause, to execute specifically and exclusively a search. This isn't a search, it isn't a warrant, and there's no constitutional amendment that outlines the situations in which the feds are allowed to break into my computers.
- jhugo 5y agoDid you read the article or just the headline? A judge issued a warrant. You can argue over where they should have issued one, but “it isn’t a warrant” is just wrong...
- nerdponx 5y agoGP's point is that this should not be considered a constitutionally valid warrant, even if a judge granted it.
- sneak 5y ago> This operation was successful in copying and removing those web shells. However, it did not patch any Microsoft Exchange Server zero-day vulnerabilities or search for or remove any additional malware or hacking tools that hacking groups may have placed on victim networks by exploiting the web shells. So they removed the IOC but left the hole wide open. This kind of "help" is going to be an incentive to stop doing business with US hosting companies.
- neolog 5y agoThis is a pretty interesting take. Can someone who disagrees respond?
- nojito 5y agoWhy would you want an external actor to go around patching systems? This is about damage mitigation and removing the shells is an excellent way of achieving it.
- sneak 5y agoYou have misunderstood me: I don't want them patching systems; I don't want them touching systems that aren't theirs at all. It's illegal for a reason. They committed the same crime by removing the web shells as was committed by the person who placed them there. (Who can put them right back.)
- tony101 5y agoIt is not a crime because they had a search warrant signed by a judge. https://www.justice.gov/opa/press-release/file/1386631/download https://www.justice.gov/opa/press-release/file/1386631/downl...
- deleted 5y ago[deleted]
- crb002 5y agoWow. This is crazy unconstitutional. DOJ could seek civil injunction perhaps, but using criminal authority to break into servers without probable cause of any criminal action is crazy bad. Another good reason to stop using proprietary binaries and instead compile your own source - even if you use code under proprietary copyright. Imagine if France also decided to "help" and bricked your server on accident.
- joenathanone 5y agoSo if a criminal is running from the police and breaks into your home to hide, what your saying is that the police shouldn’t go in and remove the criminal from your house because that would mean the police are committing a crime by entering into your home?
- social_quotient 5y agoI think there is a balance here. State run anti virus and malware agency seems also the wrong solution. The issue with granting power in cases like this is that it’s really hard to unwind it. What happens when the FBI wants to remote to your personal laptop to remove an exploit? How do you balance all this?
- IHLayman 5y agoThe authorities actually have wide latitude... there was one case where a house was destroyed in pursuit of a fugitive, LegalEagle did a whole show on it: https://youtu.be/Dk8QO6jE5dA https://youtu.be/Dk8QO6jE5dA
- social_quotient 5y agoFascinating thx
- social_quotient 5y agoMy initial thoughts And what happens if they break something while patching the exploits? Just seems odd that somehow the FBI is the best server admin here? I feel like I’m missing the full view of the implementation specifics. Shouldn’t the disincentive for admins to run unpatched just be monetary damages once/if a damage occurs? Why are my tax dollars paying for lazing email hosts? Seems like a lot of other issues (unless I’m missing something)
- 0xcde4c3db 5y ago> And what happens if they break something while patching the exploits? Probably the same thing that happens when officers injure people or damage property in the course of executing a warrant (which is quite common). In short, either the victim is rich and/or outraged enough to venture a lawsuit against the relevant agency or they just file insurance claims and hope for the best. I wouldn't be surprised if part of the reasoning for signing off on this action was that the risk of damage was considerably lower than what is routinely understood to be part and parcel of executing search warrants.
- avz 5y ago> Just seems odd that somehow the FBI is the best server admin here? Without arguing for or against it, I can see this new role viewed as a "sysadmin of last resort" wherein an authorized institution steps in to ensure a minimum security level among neglected systems in their jurisdiction.
- ericbarrett 5y ago> Why are my tax dollars paying for lazing email hosts? I presume they're worried about industrial espionage and sabotage.
- mlyle 5y agoIf your front door breaks leaving your house unsecured such that it is noticed and reported to authorities... you'll find that many local police will secure your building for you in the most hamfisted way possible. It's still probably better than leaving it open.
- 5y ago
- codezero 5y agoThis reminds me of a time at Red Hat when a worm was going around and infecting Red Hat systems, one of the engineers reverse engineered the worm and wanted to release it in the wild to fix the bug, legal wouldn’t let them. I think legal was right (for a public company) but this kind of shows the actual right response, in my opinion. Keep in mind in like 1999, you didn’t expect upgrades via package managers online for most large customers so this was an appealing release vector.
- angled 5y agoWas that a BIND / named bug?
- codezero 5y agoWas too long ago to remember, but bind was one of my areas of focus back then so maybe?
- Cthulhu_ 5y agoSimilarly nowadays there's efforts to take over C&C servers and mechanisms with the intent to disable a virus / worm going around.
- nuisance-bear 5y agoIt also sounds like the time Max Butler exploited a buffer overflow in BIND to patch a bunch of DOD systems. As we later found out, he added some extra "functionality" to that patch. Who's to say FBI hasn't done that in some small fraction of cases? https://en.wikipedia.org/wiki/Kingpin_(book) https://en.wikipedia.org/wiki/Kingpin_(book)
- mschuster91 5y agoInteresting, looks like he's actually supposed to be released from prison today: > Butler is currently incarcerated at FCI Victorville Medium 2 in California, he expected to be released April 14, 2021.
- 5y ago
- fatiherikli 5y agoThis is too much texts for a security vulnerability. They can just create an hotfix for it.
- mmaunder 5y agoInteresting. They're violating their own CFAA law (accessing a computer without authorization or exceeding the access granted) to remove web shells. Legally, this is hacking. Which means that the FBI just hacked a bunch of Exchange servers to clean them. So the message here is, if you don't clean up your act and you're on a USA network, we'll do it for you without your permission. The beef is at the end of the article: This operation was successful in copying and removing those web shells. However, it did not patch any Microsoft Exchange Server zero-day vulnerabilities or search for or remove any additional malware or hacking tools that hacking groups may have placed on victim networks by exploiting the web shells. The Department strongly encourages network defenders to review Microsoft’s remediation guidance and the March 10 Joint Advisory for further guidance on detection and patching. The FBI is attempting to provide notice of the court-authorized operation to all owners or operators of the computers from which it removed the hacking group’s web shells. For those victims with publicly available contact information, the FBI will send an e-mail message from an official FBI e-mail account (@FBI.gov) notifying the victim of the search. For those victims whose contact information is not publicly available, the FBI will send an e-mail message from the same FBI e-mail account to providers (such as a victim’s ISP) who are believed to have that contact information and ask them to provide notice to the victim. If you believe you have a compromised computer running Microsoft Exchange Server, please contact your local FBI Field Office for assistance. The FBI continues to conduct a thorough and methodical investigation into this cyber incident.
- chris_wot 5y agoAre we sure? It appears the court gave them authority.
- tony101 5y agoIndeed, there is a search warrant signed by a judge: https://www.justice.gov/opa/press-release/file/1386631/download https://www.justice.gov/opa/press-release/file/1386631/downl... See pages 18 to 21.
- andrewmg 5y agoIt's no CFAA violation: "This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States." 18 U.S.C. § 1030(f). DOJ obtained authorization here, most likely under Fed. R. Crim. P. 41(b)(6)(B)--which, interestingly enough, cross-references the CFAA.
- slt2021 5y agothis action only removes already installed web shells, and does not patch, nor does it prevent from future take overs of these servers, right? if left unpatched, these same servers could be reinfected next day?
- deleted 5y ago[deleted]
- tatersolid 5y agoA Windows defender update is protecting against reinfection assuming there are no active admins.
- natural219 5y agoI'm interested in the moral hazard this creates if this practice becomes widespread. If your servers are "too big to fail", and the FBI/NSA can reliably zero-day into your servers to patch zero-day bugs, that seems like a pretty good deal for skimping on some of your security budget.
- slt2021 5y agoFBI/NSA doesn't give a damn about some unpatched servers in the wild. They are probably clearing web shells in order to bait hackers into reinfecting the same servers, and try to locate/attribute the original bad actor.
- hn_throwaway_99 5y agoI'm kind of annoyed by some of the general negative tone of some of the comments here: "Ha! The FBI is guilty of hacking", or "But they didn't patch the root cause!" In my understanding, the FBI: 1. Applied for and received a lawful court order 2. To make as minimally invasive as change as possible to help the targeted networks 3. While making a best effort to contact the network owners to tell them what they were doing and then 4. Widely publicizing what they did. Not everything is some big "gotcha" conspiracy. We can just say "thank you" and move on.
- alfiedotwtf 5y ago> We can just say “thank you“ and move on Tl;dr: I’m from the government, and I’m here to help
- zapdrive 5y agoNice try, FBI.
- andrewstuart2 5y agoI don't know that anybody is frustrated about what they did. It's that anybody else who could have benevolently done the same thing, much faster, but without all the process, would be in massively hot water. I think mostly it's just frustrating to want to do the right thing, know that you could, also know that you can't, and then see somebody get to do it officially so much later. Top that all off with the fact that it's really hard to trace who and what were involved, versus a more transparent process where legitimate experts could chime in and prevent any further harm. Instead we have to cross our fingers that they did it right and that the judge understood what he was agreeing to. And I mean it's not a unique problem to this circumstance. Just kinda how institutions tend to be.
- vulcan01 5y ago> It's that anybody else who could have benevolently done the same thing, much faster, but without all the process, would be in massively hot water. Isn't this how it is with a lot of things? The government can tax people. If I tried to tax people, that would be illegal coercion.
- exabrial 5y agoStop protecting Microsoft. Let them absorb the damage and die.
- sennight 5y agoWell, this is a totally awful development. In the 80s the idea of white worms being used to patch vulnerabilities was rejected for good reason, so I have to think this has little to do with security and much more to do with normalizing behavior that really shouldn't be tolerated. They didn't even patch the hole... Before anyone tries framing it as a service to the security of the majority - understand that this is the introduction of a new attack vector: state actors hamfistedly bumbling around your network while "doing you a favor". If the threat even approached a level justifying this kind of action, the far more effective and less damaging approach would be directing upstream networks to blackhole routes to the machines.
- waihtis 5y agoIn less than 18 months there will be a startup (likely from Israel) who will provide this kind of service for US Government, and it will normalize and move from state to commercial /prediction
- austinheap 5y agoIt’s not a development. Court-authorized public/private patching initiatives have long existed. They’re much higher profile and news worthy theses days, though.
- sennight 5y agoCare to provide an example of the USG leveraging a vulnerability to delete files on hundreds of domestic servers without the permission or knowledge of the owners? Because the closest thing I can think of involves the military targeting a foreign botnet. I know Microsoft went after a botnet with a forced Windows update mechanism, but Microsoft isn't the FBI and their update system is a known quantity.
- julia00001 5y agoIf you like xxx games, you need to see this game with me, I'm sure you will love it ACCESS GAME:https://picsporn.blogspot.com/p/porn-game.html https://picsporn.blogspot.com/p/porn-game.html
- nijave 5y agoImo seems reasonable. There are plenty of other government agencies with far more power in their respective industries. FDA, Public Health Departments, the myriad of banking regulators. In may of those, the respective regulators can shit the entire business down. Here, the FBI didn't even power the servers off and they got a warrant without going through a secret court Companies have had plenty of time to address the issue on their own, at this point
- technion 5y agoA substantive portion of these unpatched servers end up ransomed. And if not yet, they will be. A proportion of ransom victims show up expecting the FBI to help, even if they were extremely negligent in allowing the incident to occur. Another very high proportion just pays the ransom. The FBI here aren't just "protecting lazy admins", there are some further reaching consequences to failing to act. Note also people are talking about "applying patches" but the order more specifically talks about removing web shells. If my experience is indicative, there are more hosts that applied patches too late and didn't remove the web shells mass scanners deployed, than hosts that never patched. I expect a lot of this disruption is about deleting a one line .aspx file.
- shuntress 5y agoI would like to see this type of thing become more popular with general law enforcement. It is very frustrating to have essentially no recourse available to stop the constant vulnerability scans targeting my house. If random people constantly walk up to every house on the street looking for pick-able locks, the police are (Setting, for a moment, aside over/under policing and other issues) available to help stop them. But, for the digital equivalent, our collective response (especially among technical people) is typically "[shrug] Make sure your locks are unpickable and your windows unbreakable. And if you cant handle that, then just move in to the Facebook highrise"
- gnu8 5y agoThis is not a thing that a court can authorize.