Confluence Zero Day, Tushar Richabadas – Barracuda Networks
Tushar Richabadas with Barracuda Networks discusses the Atlassian Conflunce zero-day vulnerability (CVE-2022-26134) announced on 6/2/22. Since its disclosure, Barracuda researchers have analyzed data from honeypot installations worldwide and discovered a large number of attempts to exploit this vulnerability.
Transcript
This is texturing TV. I have the great pleasure being joined by Tasha rashadabas who is senior product marketing manager with Barracuda. Welcome to shark.
Image good to be here great to have you tell us a little bit about yourself. Tell us a little bit about what you do at barcode. So I am the senior product marketing manager for application security and Cloud security at Barracuda networks among the things.
I do also select the port where along with other researchers. I look at new vulnerabilities the kind of attacks that are being launched against them from our honey pots and other systems and then we also work on directly search we publish the research for people to understand what the actual threats are and so on. Very good.
Very good. Well we're going to talk about a zero data was announced I think back in the beginning of June having to do with Confluence now have you I've used Confluence maybe a little longer but almost as long as I've known about Barracuda networks is the both have been around for a while very mature companies and products in atlassian. And I don't know what the marketing number that last thing would say the number of instances are installations, but it's got to be massive.
That's a very you well used application. So tell us about the zero day. I know it wasn't when you necessarily found but you did for the research and are seeing kind of what the attack vectors and attack traffic looking like Yep, so atlassian Confluence at least.
It's used widely for the most popular use is as a Wiki. Hey, we use it multiple organizations use it. So on June 2nd, which thankfully was a Thursday for all the Defenders.
Well actually did a coordinated release along with atlassian stating that we have this massive an authenticated root command execution while the ability Please start batching or look out for these attacks. I think the patch came a couple of days later, but atlassian had immediately published a blog post talking about the actual. Impacted versions.
They gave a bath rules which stays in the old back. But basically I said look you're going to be hit. I think will actually even said that it was already under active exploitation in some cases.
So it was a fairly serious thing that had to be patched or protected against immediately. As they say the security team the software teams. It wasn't a good day for them.
Those things right wasn't I mean as I said it. Yeah happening on a Thursday was always a good thing because log for sale for instance came out late on a Friday and little in the fair few weekends. So thanks for very long.
Yeah. So how do you look at this from the Barracuda perspective? Obviously, it's not your app.
You're you're but you certainly with the number of appliances and cloud services and all the things you are gonna see, you know, something like Confluence, you know, it's it's been around for a while. So it's gonna have a lot of I assume on Prem installations as well as Cloud versus something you in the last five years. You know, how do you look at this from a research perspective and what the information you gain about it?
Right. So for starters, we had some vulnerable applications up in Honey pots. And we also had our graph as a service which protects against all of you attack.
So when we started looking at the logs initially we saw a fair few. You know spray and play back on reconnaissance attacks. If you looked at it, I think the as soon as the POC came out on GitHub people were just grabbing the script and learning it really and then it's slowly started becoming that more CVS groups were trying to exploit the vulnerability.
We started seeing more serious payloads starting from Kind of basic attempts to dump the ETC password file or just find out if there is a vulnerable application at the back or then it we started seeing people trying to build the Mirai botnet and variations of Mirai being thrown in the payloads. Then we saw coin minus and a lot of coin minus especially since log for Shell we've been seeing pretty much any vulnerability that that is disclosed. You see a lot of money have a coin miners coming out.
Um, and yeah, so these we identified almost immediately then we started digging deeper. We found some Cobalt strike payloads, which is originally started Life as a pen testing tool, but now it's been co-opted by attackers and that was interesting and While we we have two more blog posts on this threat Spotlight coming out one of them takes a deeper look into fairly complicated script that sets up Manilow minor goes around moving other miners before it sets up and so on. Hmm interesting so you actually set up your own honey pots and do your own kind of examination what that's how you're part of how you're looking at.
Yeah, either such team. That's it. Yeah.
You also use any Anonymous anonymized data coming out of your products and services that help you kind of analyze and see what traffic flows and attacks are happening that way as well. Yes, we do. Look at anonymized data and that is part of the statue Spotlight.
So for instance when we talk about attacks coming in from specific geographic region that comes in from part of anonymized data, very good. So is this particular zero day with Confluence? Is it following a similar pattern that you see with other zero day or other other vulnerabilities or there's some unique characteristics of this particular one.
Um, I would say it is fairly similar to other vulnerabilities. So you have that initial. Thing of people just doing a spray and they attack and then slowly the more serious actors come in.
I forget who it was who published a research, but recently they talked about how Attackers aren't looking for new vulnerabilities are doing the research to identify new vulnerabilities as much as waiting for. A vulnerability to drop and then going after systems that are not patched or protected properly so you and that is fairly similar to what we saw here. In fact while the disclosure happened on the second.
At least in our systems the spikes these saw started on June 13th, which coincidentally is a Monday. So it almost seems like attackers spent that time building their tools doing their research and then launching full-scale attacks. You know when they came into the office after a nice relaxing weekend.
Now I'm gonna make an assumption you tell me if this is right my experience using a lot more. Let's say cloud-based ask me Services as opposed to running my own instance of Confluence or whatever my zapier, whatever the tool might be. I one of the things I really like about it is I'm not upgrading software all the time.
I mean it really it's taken that that burden because that's how you know, you get caught I stuff like that is Confluence. Yeah, we'll get to it in nine months later a couple months later. You kind of get around Apache it mean why you compromise to some vulnerability has come out.
Do you see do you see that kind of pattern where sass-based Services tend to have a much shorter window of where they're vulnerable because they are fast and they're getting upgraded as opposed to applications that are running either in the cloud or on-prem by organizations themselves. Is that a fair characterization? I don't know if we're there yet, but that would probably be the ideal state.
Right because even in a SAS application you have to deploy the patch. It's going to break someone's you know deployment because you may have an SLA in place for patching it or you may have a big customer who says that you can't hold this out without talking to us first, right? I don't think a class in this fairly large so they won't have had that problem.
This vulnerability is fairly serious. So I'm sure they're SAS Services were passed very quickly, but in general I Don't think we're there yet. Personally.
I don't think they're there yet. I think that is the ideal best case scenario. Maybe the other thing but this as we move absolutely more and more containerized microservice based applications that you upgrade much smaller pieces now not like my weight on the road because we're actually have a large base of software that isn't that way in theory, but also help I don't know if he's doing and doing text frying TV when that happens or you know breathing fresh here at that point.
But anyway, we know that we're on a path towards that well, are there any any kind of Lessons Learned you've seen either with this Confluence zero day or gone through this process any advice that you give your customers or you might typically put in your reports. Yeah, I mean hatching these are pretty obvious one right? Make sure you're yeah do I mean The biggest advice always with this is as soon as the packs is available, please match.
As soon as it is possible for you to patch patch patch early. Yes. It is difficult.
It does result in weekends going away. Change requests and all that have to be done. But patching is probably the best thing you can do and having multiple layers of security with defense in depth putting on my vendor hat here, of course defense in depth A term that has been used in abused for the while is also important.
Right? So you may need a couple of days to patch having a firewall where you can look at iocs and configure them will give you some piece of mind and hopefully prevent you from being compromised give you that, you know air cover. But yeah, like you said patching as soon as it is out as soon as you can test it and put it out.
It's probably the best way to secure your deployment. Very good. Well, you know the other thing I want to ask you about you talked about minors and Bitcoin miners.
Is that primarily people just taking over systems to be able to use it to their own Bitcoin mining or they doing more than that when they're 11 when they're exploiting these vulnerabilities? So the ones that do you seen by merely Bitcoin minus trying to do their best to maximize resources on the in the user system. So basically they will have scripts that try to look for other miners landing on the system.
They move them start their own mining operation, you know fairly thought out pieces of software that do a lot of things to ensure the best possible outcome for their own mining setup It's not the most efficient thing the more resources you have the more. Coins you can mind. So no they're trying to do the best they can.
You reminders we're gonna check out other miners, right? This is my job. I need this system.
I'm gonna explain it. Yeah, you know resources not to get noticed right? Just right radar.
Well really interesting job, really appreciate you coming and talking with us about the confidence zero days some of the lessons learned from that and all the way up to what's happening in the bit minor Bitcoin miner world. So you mentioned that you do research and Report, you know, there's some things that you can provide folks resources, like on the website, they can go get the latest information of the kind of research that you Yep. The Barracuda blog is a great resource for looking at the latest threats that we see we cover everything from email to data protection to network security to application security to Cloud security.
So there is a constant flow of valuable information that we put out. For instance yesterday. We published a new test Spotlight on the email side about malicious HTML attachments that are coming through an email and how attackers I basically embedding These HTML attachments in emails disguising them as weekly reports and then trying to trick users into doing the click the fishing link.
So we definitely are looking at much more than application security and trying to cover everything that Vector that an organization faces these days. com that correct. com, and it's all right there excellent, which is our have really appreciate you being with us today.
Please come back and got some more interesting research to show you. Hope everybody will check out the blog and feels like a great source to keep up what's going on, too. Thanks again back soon.
Thank you for having me. Thank you. Bye.