5 ms·
https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e the Reddit comments from Huntress Labs
by terom 5y ago
https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e the Reddit comments from Huntress Labs contain more concrete interim technical details from their investigations.
* `/dl.asp` authentication bypass
* `/KUpload.dll` file upload, likely using authenticated session
* `/userFilterTableRpt.asp` command execution on previously uploaded file
- bithavoc 5y agoFrom Update 12: > The userFilterTableRpt.asp file contains a significant amount of potential SQL injection vulnerabilities, which would offer an attack vector for code execution and the ability to compromise the VSA server. It's been 19 years[0] since Kaseya added this task to their BugZilla: "Migrate from Active Server Pages to ASP.NET". [0]https://en.wikipedia.org/wiki/Active_Server_Pages https://en.wikipedia.org/wiki/Active_Server_Pages
- terom 5y agoIt's also interesting to note that their initial on-prem VSA fix/updates will include disabling some functionality: https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689-Important-Notice-July-7th-2021 https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689-... > We will be releasing VSA with staged functionality to bring services back online sooner. The first release will prevent access to functionality used by a very small fraction of our user base, including: > * Classic Ticketing > * Classic Remote Control (not LiveConnect). > * User Portal Without knowing anything about Kaseya, it sounds to me like the exploited endpoints were related to some kind of legacy features with a higher level of technical debt, and fixing all of the identified vulnerabilities in those components will take time.
- terom 5y agoAnd apparently one of the vulnerabilities exploited in this attack had been discovered and reported to Kaseya by independent researchers back in April: https://news.ycombinator.com/item?id=27763202 https://news.ycombinator.com/item?id=27763202
- cartoonworld 5y agoKaseya doesn't have a CISO from what I can see. CEO Fred Voccola retreived from https://blog.malwarebytes.com/ransomware/2021/07/kaseya-ceo-the-impact-of-this-incredibly-sophisticated-attack-is-very-minimal/ https://blog.malwarebytes.com/ransomware/2021/07/kaseya-ceo-... We weren’t quite sure exactly what it was, but as third parties, the community, our own monitoring customers, we started noticing some strange behaviors,” Voccola recounted in the video. “Within an hour, we immediately shut down VSA.” [...] “When something happens, it’s how prepared the organization was, how quickly the organization is to admit something happened,” Voccola said. “Seek help from people and try to get focus on the customers and get information out there.” That makes sense though, their leadership is laser-focused on successful outcomes and a commitment to their customers. It was their incompetent acquisition culture who cut corners on all the boring stuff, like validation, testing, assurance, quality, engagement with for-free security researchers. Their plan was to stumble into the dashboard and trip over the off switch, after someone else told them they'd been wrecked. This is absurd, incompetent, immorally negligent and contrary to industry SOPs (use bug bounties, have a CISO).