Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Ynglaur
Oct 9, 2013

The Malta Conference, anyone?
If this turns out to be something preventable with MFA vs, I dunno, a true zero day exploit chain...wow.

Adbot
ADBOT LOVES YOU

Revdomezehis
Jul 26, 2003
OMG a Moose!
Yeah I hope he's wrong cuz oof. "The attackers utilized state of the art techniques once inside of our system to use our product to spread malware to our clients and infiltrate their systems" Thanks for the info, but how did they get into your systems initially though? "Password was password ¯\_(ツ)_/¯ "

AlternateAccount
Apr 25, 2005
FYGM
Somewhere, in a galaxy far far away, Dark Helmet is laughing.

"Admin123" is the leading guess.

some kinda jackal
Feb 25, 2003

 
 
Please, they have SOME standards :rolleyes:

It was @dmin123!

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
I figured was Solar123

tagesschau
Sep 1, 2006

D&D: HASBARA SQUAD
THE SPEECH SUPPRESSOR


Remember: it's "antisemitic" to protest genocide as long as the targets are brown.

This aged poorly.

RFC2324
Jun 7, 2012

http 418

P@ssw0rd!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

tagesschau posted:

This aged poorly.

It really did, didn't it?

Yeah, I reached out to a bunch of my clients, outside of applying the Hotfix 1 and tomorrow's Hotfix 2, and resetting the credentials on the box or that have touched the box, unless you actually see the IOCs like the hash'ed DLL and the planted service DLL, just patch and monitor.

quote:

a. [SolarWinds.Orion.Core.BusinessLayer.dll] with a file hash of [b91ce2fa41029f6955bff20079468448]

b. [C:\WINDOWS\SysWOW64\netsetupsvc.dll]

https://cyber.dhs.gov/ed/21-01/

CommieGIR fucked around with this message at 20:44 on Dec 14, 2020

evil_bunnY
Apr 2, 2003

ghostinmyshell posted:

I might be your boss.

The little if any good news out of this is the InfoSec group hosed up by going right to "wipe our systems nooooooooooooooooooooooooooooooooow," and cc'd everyone before providing any actual evidence we were compromised. Someone was smart enough to call them out to ask for reports from the 2-3 security appliances we pay a fuckton for asking if there was any actual suspicious activity and what's up with them if we are so hosed we need to wipe our systems.
your infosec group is a bunch of morons

tagesschau posted:

This aged poorly.
It really hasn't. for each solarwind there's dozens of random dweebs getting popped because of low hanging fruit.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

evil_bunnY posted:

It really hasn't. for each solarwind there's dozens of random dweebs getting popped because of low hanging fruit.

True, but it was posted in context to the Fireeye Breach which turns out to be directly related to the Solarwinds backdoor, and in that way it has.

Target wise: Gov affected is up to Treasury, Commerce, DHS, and Booze Allen Hamilton got hit too.

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Maybe the government shouldn't trust the security of its software to the lowest bidder.

Wiggly Wayne DDS
Sep 11, 2010



CommieGIR posted:

True, but it was posted in context to the Fireeye Breach which turns out to be directly related to the Solarwinds backdoor, and in that way it has.

Target wise: Gov affected is up to Treasury, Commerce, DHS, and Booze Allen Hamilton got hit too.
you don't have to be sophisticated to put a backdoor into low hanging fruit

CLAM DOWN
Feb 13, 2007




my domain is contoso.com and the shared enterprise admin account is ntP@ssw0rd!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Wiggly Wayne DDS posted:

you don't have to be sophisticated to put a backdoor into low hanging fruit

You do to actually need some level of sophistication to stay hidden while its being deployed, which is why Supply Side attacks are rare. Its a pretty good feat to stay hidden inside the build environment for 6 months.

Farking Bastage
Sep 22, 2007

Who dey think gonna beat dem Bengos!
There are reports now of several SolarWinds execs dumping their stock options right before this blew up. They loving knew.

quote:

Now comes news that SolarWinds Co. Director Aurora Co-Invest L.P. Slp sold 2,079,823 shares of the business’s stock in a transaction last Monday, December 7th.

Farking Bastage fucked around with this message at 21:53 on Dec 14, 2020

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Farking Bastage posted:

There are reports now of several SolarWinds execs dumping their stock options right before this blew up. They loving knew.

The Execs are always the first to know, of course.

Defenestrategy
Oct 24, 2010

CLAM DOWN posted:

my domain is contoso.com and the shared enterprise admin account is ntP@ssw0rd!

Thats my domain too!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Defenestrategy posted:

Thats my domain too!

I thought I asked kindly for you to not steal my ideas :(

Farking Bastage
Sep 22, 2007

Who dey think gonna beat dem Bengos!

CommieGIR posted:

The Execs are always the first to know, of course.

It means they sat on it long enough to get their golden parachutes

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
This fucks with other rich people, so they might actually get a slap on the wrist for that one.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
SANS live webcast re:Solarwinds

https://www.youtube.com/watch?v=4tmlZCk2gCg

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Farking Bastage posted:

There are reports now of several SolarWinds execs dumping their stock options right before this blew up. They loving knew.

If you’re a director of a public company you’re almost certainly trading under a 10b5-1 plan, and had to schedule that trade (or its parameters based on public info) 6+ months ago.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Subjunctive posted:

If you’re a director of a public company you’re almost certainly trading under a 10b5-1 plan, and had to schedule that trade (or its parameters based on public info) 6+ months ago.

Like they'd face any real punishment for not doing so.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

CommieGIR posted:

Like they'd face any real punishment for not doing so.

You don’t have to, it’s just that a 10b5-1 plan is an affirmative defence against charges of trading while possessing material non-public information. That is hard to avoid as a director, to the extent that trades outside a plan almost certainly fall afoul of it, and directors are the ones with personal liability at the end of the day (D&O insurance won’t cover you). But the trading disclosures have information about when the relevant plan was filed, so it’s easy to check Edgar if you want to.

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


https://savebreach.com/solarwinds-credentials-exposure-led-to-us-government-fireye-breach/

Interesting, I don't think I saw this here but maybe I did.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
SANS livestream finished, led by @MalwareJake:

Attributing to Russia
No obfuscation in the code
May be more affected Solarwinds products, but we have no proof either way yet.
Nobody is sure what happened past June 2020 yet, waiting more details

IOCs were provided, included the domain names they were reaching out to:


Subjunctive
Sep 12, 2006

✨sparkle and shine✨

they probably spent a pretty penny on those domains!

Farking Bastage
Sep 22, 2007

Who dey think gonna beat dem Bengos!

Subjunctive posted:

You don’t have to, it’s just that a 10b5-1 plan is an affirmative defence against charges of trading while possessing material non-public information. That is hard to avoid as a director, to the extent that trades outside a plan almost certainly fall afoul of it, and directors are the ones with personal liability at the end of the day (D&O insurance won’t cover you). But the trading disclosures have information about when the relevant plan was filed, so it’s easy to check Edgar if you want to.

https://www.sec.gov/cgi-bin/own-disp?action=getissuer&CIK=0001739942
They got themselves and their buddies out before the hack went public.

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

25 posts ago

Otis Reddit
Nov 14, 2006
How did they spoof the SAML tokens?

Butter Activities
May 4, 2018

klosterdev posted:

Maybe the government shouldn't trust the security of its software to the lowest bidder.

Oh buddy I’m a nurse at a government hospital and let me tell you about our equipment

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Martytoof posted:

Please, they have SOME standards :rolleyes:

It was @dmin123!

Just make sure to post it to the public

Maneki Neko
Oct 27, 2000

Man I understand that CISA is conservative and will likely narrow their definitions to match everyone elses at some point, but CISA saying "all of Solarwinds 2019.4" is a much broader scope than just the "2019.4 hotfix 5 and later" that everyone else is saying and really causing a lot of confusion to folks. Questions about that seemed to be most of the ones on various calls I was on yesterday.

Hopefully they also reconcile the "patch/don't patch" instructions soon too because right now there's just a lot of confusion if you do any work with government.

Sickening
Jul 16, 2007

Black summer was the best summer.

Maneki Neko posted:

Man I understand that CISA is conservative and will likely narrow their definitions to match everyone elses at some point, but CISA saying "all of Solarwinds 2019.4" is a much broader scope than just the "2019.4 hotfix 5 and later" that everyone else is saying and really causing a lot of confusion to folks. Questions about that seemed to be most of the ones on various calls I was on yesterday.

Hopefully they also reconcile the "patch/don't patch" instructions soon too because right now there's just a lot of confusion if you do any work with government.

This mess with solar winds isn't getting enough attention to be honest. Its one of the biggest security blunders in infosec history.

Defenestrategy
Oct 24, 2010

Sickening posted:

This mess with solar winds isn't getting enough attention to be honest. Its one of the biggest security blunders in infosec history.

even bigger than when a bunch of CIA tools got leaked like two years ago?

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Defenestrategy posted:

even bigger than when a bunch of CIA tools got leaked like two years ago?

Considering Solarwinds is heavily used in nearly every US Government facility: Yes.

The only saving grace here is that they pulled that stunt with Fireeye, which alerted them to the operation, and Fireeye in turn blew the cover off it.

Otis Reddit
Nov 14, 2006
Yeah. This seems like The Big One

Farking Bastage
Sep 22, 2007

Who dey think gonna beat dem Bengos!
Ours are shut down until further notice.

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Sickening posted:

This mess with solar winds isn't getting enough attention to be honest. Its one of the biggest security blunders in infosec history.

Agreed if it turns out that random dude on twitter who claims creds were public isn't full of poo poo.

Adbot
ADBOT LOVES YOU

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
More info on how the Solarwinds trojan evaded detection:

https://twitter.com/cybercdh/status/1338975171093336067?s=20

And the IOC URLs were pretty big money....

https://twitter.com/blackorbird/status/1338695429496553472

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply