British Airways: Suspect code that hacked fliers ‘found’
bbc.co.uk
bbc.co.uk
The BBC's technology reporting usually isn't that bad for a mainstream audience, but this is just egregious. On the one hand, perpetuating the myth that "anything I do on this page must be super safe because there's a green padlock", and on the other completely exaggerating the difficulty of going HTTPS now we have LetsEncrypt.
1. They genuinely didn't know about Let's Encrypt
2. Learning some new stuff to get a free cert didn't seem worth it because they're not paying anyway (at corps this is often because they have a bulk deal, or there will just be a Purchase Order so it's not their personal credit card bill, for crooks it's probably someone else's money anyway)
3. Some minor technical inconvenience made doing the ACME proof of control validations tricky. For example their DNS provider doesn't implement a sane API for changing TXT records.
There are other examples, the Nintendo Wii U, Internet Explorer on old enough XP (but really old XP can't grok modern TLS anyway and so you're screwed) but we're quickly talking about the minority of a minority.
I'm sure the perception was there though.
"Minority of a minority", maybe, but I still got around five tweets about it when it happened; more than most other changes I make.
https://www.reddit.com/r/pokemonshowdown/comments/7eix1o/pok...
The problem wasn't just because of the HTTPS cert, but also because it didn't support WebSocket on port 8000.
As usual in DNS this works fine in the Free implementation your OS vendor included, shame about all the expensive proprietary choices that get this wrong for every single new record type.
It's a pity it isn't just a TXT record.
Even if they are paying, the ROI on spending even a single day on learning new stuff is a long, long time if you're just buying a DV cert.
A security team reviewing that baways.com site would definitely make note of the fact that it was using letsencrypt.
Letsencrypt certs are widely used by malicious actors. Thus one not being used is noteworthy and why RiskIQ made note of it.
If someone who's downvoting me would like to show some examples of major websites from Fortune 100s or large international firms (like BA) using letsencrypt certs to collect payment info, then by all means, please do.
To a lay-person both those things ring very true, especially after Internet giants like Google have pushed https into everyone's throats.
I'm going to generously assume your experience with 4 weeks and two professionals charging you fees was for an Extended Validation certificate, which as the name suggests involves a bunch more paperwork that the ordinary DV cert the article is talking about. But even for EV you've had a bunch of your time wasted by people either being incompetent or deliberately inflating the costs. For an existing organisation in a jurisdiction like the UK or most US states, with online company databases and functioning infrastructure you ought to be talking hours rather than days and there's no reason it should involve accountants.
It probably wouldn't have tripped as "phishing" unless the crooks were dumb enough to host false BA branding on it, rather than just an API to accept the stolen credentials.
Because "BA" is so short and non-specific I'm doubtful that tools like Facebook's Certificate Transparency based "phishing warning" would have been useful here. And if you were an over-worked BA employee given 500 CT "phishing" warnings a day, what would you do? Visit the site in Chrome maybe? Then you see it has a generic holding page, no sign of phishing, you file it as a false positive, move on? How are you supposed to know it's being used by crooks?
Looks like the article got updated
Correct me if I'm wrong, but the file was hosted by BA within their CMS, yet the attackers were able to update this file to include their 22 lines of code.
Does this mean the attackers had access to the CMS for BA.com or is there a step I am missing or has been deliberately omitted?
The reason this report doesn't mention it, is that their analysis focuses on publicly facing changes, so they can find the change to the JS file but not the mechanism that was used to get it onto the server.
For that we'd need some statement from BA or some other intel. source that has more information on that aspect.
I've worked with CMS tools that allow you to add plain HTML blocks, even stuff inside <script></script>. If their CMS allows this, and some marketing person had "password123" as their CMS password, and they allow access from the web (instead of intranet/VPN + 2FA requirements)...
Instead this looks like a fairly well executed "traditional" attack on BAs CMS/Web server infrastructure.
It's a good example of why even front-end infrastructure components need good protection...
[0] https://cdn.riskiq.com/wp-content/uploads/2018/09/Webp.net-r...
The targeting of the attack and the fact that prior to that the file hadn't changed for 6 years make it unlikely that it was a downloaded copy that had been backdoored and then installed by BA.
https://www.riskiq.com/blog/labs/magecart-ticketmaster-breac...
I think the underlying problems are the same either way. In all these attacks the customer loads a page with dozens of scripts from at least a dozen servers and he or she has to trust them all.
Speaking as someone who frequently has to reload the checkout page five or more times while authorising successive waves of third party servers in Request Policy and NoScript - there is no way to tell. Any one could be the source of an attack or the destination for malicious exfiltration.
Should I do a geoip lookup on every sever on a page when shopping on-line? Baways.com looks like a perfectly plausible server for yet another piece of cruft, or analytics, or some baroque chain of payment services providers.
Since the customer has no way of telling we are depending on the suppliers noticing that the website they are serving has changed. Otherwise it's up to the banks to find the common thread in each new wave of fraudulent payments, oops.
The current sorry state of security online can only be fixed by the suppliers. I think that doing things properly will necessarily involve more respect for customers and less adtech/ spyware so that payment processes are better separated from everything else on the web </rant>
I would make that 'especially' instead of 'even', front-end infrastructure is arguably the safest way that an attacker has to try to compromise a system simply because by definition the system has to be somewhat open otherwise it could not do its job.
It would be nice if browsers implemented an <endscript> tag and refuse to parse anything below it as a script. It would raise the bar on injection attacks for very little additional complexity. Slightly troublesome in that all of your buttons and similar would have to just call already defined functions (no inline code), but that's a reasonable tradeoff I think.
Disclaimer: worked on ba.com in the ‘90’s
And there's more analysis at http://huagati.blogspot.com/2018/05/things-you-probably-dont...
And the fake BAWAYs server is still up - https://twitter.com/inventur_es/status/1039519364733497344
And the attackers knew how to use SSL as opposed to some 3DS/VBV "partners" I've seen in the wild
Excepted for the botched GDPR "agreement" box
English is my first language, but I'm really struggling to grok this headline.
> Quotation marks should be single:
> in headlines and cross-heads (eg: UK ‘to leave EU’); in promo text and for quotes within quotes (eg: Tom Bone said: “They say, ‘The Labour Party is finished’ before every election”) and inside quote boxes (eg: They sprayed ‘go home’ on our front door – Sandra Harris).
> In headlines where the attribution is clear, do not include unnecessary quote marks (eg Britain won’t hold referendum, says PM rather than Britain "won’t hold referendum", says PM).
> They should be double:
> outside the categories listed above - on the ticker, in regular text, summaries and picture captions. Also, at first use of phrases such as “mad cow disease” or “road rage”. (But quotation marks will be single if the phrase comes inside a direct quotation (eg: The minister said: “The spread of ‘mad cow disease’ had ruined thousands of lives.”) Either way, no punctuation is required after the first reference.
https://www.bbc.co.uk/academy/en/articles/art201307021121335...
By removing the phrase "that hacked fliers" you're left with "Suspect code 'found'". Which is the core of the statement. But that doesn't give enough context so the reference to the fliers was added.
I also think they wanted to lead with "British Airways" so a bit of contortion was necessary.
I think the answer is yes.
So I wonder why this issue was not reported earlier by some techie guy who's just booked a flight