Israeli Cyber Experts Uncover Attack on 85,000 MySQL Servers
srnnews.com
srnnews.com
“The attack starts with a password brute-force on the MySQL service. Once successful, the attacker runs a sequence of queries in the database, gathering data on existing tables and users,” said Ophir Harpaz and Omri Marom, researchers with Guardicore Labs, in a Thursday post. “By the end of execution, the victim’s data is gone – it’s archived in a zipped file which is sent to the attackers’ servers and then deleted from the database.”
Fair enough.
Here's a better link: https://threatpost.com/please_read_me-ransomware-mysql-serve...
I am unable to change the URL in the submission. Perhaps someone with appropriate privileges could do so?
https://www.guardicore.com/labs/please-read-me-opportunistic...
> That site’s history with HN [1] isn’t exactly confidence inspiring.
Unfortunately, guardicore.com's "reputation" [2] isn't much better!
Of all the articles on this topic linked in this thread, the one from ThreatPost [3] is probably the "most reputable" as far as I'm concerned.
--
[0]: https://news.ycombinator.com/item?id=25524954
[1]: https://news.ycombinator.com/from?site=srnnews.com
[2]: https://news.ycombinator.com/from?site=guardicore.com
[3]: https://threatpost.com/please_read_me-ransomware-mysql-serve...
https://blog.shodan.io/its-still-the-data-stupid/
You can search for Redis instances that have disabled authentication and have a "crackit" key stored in them which is created by one of those Redis malware bots:
https://beta.shodan.io/search?query=crackit
I'll add that the vendors have actually gotten much better! Redis and MongoDB both now have good, secure defaults. And I believe both will throw you a huge warning if you're listening on 0.0.0.0 w/out authentication.
Favicons can be a single image or multiple images.
Here is a good recent thread on it on HN. Will put the map there as well come to think of it.
https://beta.shodan.io/search?query=http.favicon.hash%3A7085...
It takes a bit more refining to get a good list of results; the general idea is to find websites that look like the real deal but are located somewhere on the Internet where you didn't expect to find them.
I keep meaning to sit down and do a bit of analysis on the source of the connections.
All of those prior submissions were from user 'dulo'. If you check their history, all 153 submissions of theirs are dead.
This includes submissions from such publications as the Washington Post, USA Today, Popular Science, Fortune, Slate, a whole bunch of newspapers from fairly major cities, and much more. Most of them seem to be reasonable submissions, too.
They were all within about a month or so of each other, starting right after the account was created, and mostly happened in large batches. It seems highly likely they tripped some anti-spam or anti-flooding detector and the user was perma-banned and all their submissions instantly killed.
Coupled with the current top comment[0], I’m inferring quite a bit about that site.
I do understand the need for network access but I'd never rely on the authentication frameworks (of any database server) to handle this. Limited network access or a front-end API (itself with limited access). Never expose your data source if you don't have to.
They say the victims are buying their data back to prevent it being sold to a third-party.
"Once they’re in the database, they steal the data, send it to their own servers and then delete it from the local machines," Harpaz continued. "The victim has to pay a ransom for the data to be returned."
Elsewhere in the article:
"Once hackers manage to steal the data, it is posted on a website and sold to the highest bidder unless the victim agrees to pay a ransom of roughly $500."
I conclude that we're both right :)
They delete "from the local machines" which I interpret to be the victim's server. If the victims had had data backups, as simple as a daily cron task that calls mysqldump, presumably they would be unconcerned about restoring their data. However, they would still worry about their data being sold.
Since there's zero guarantee that the thieves will take down the data for the $500 fee, it seems pointless to pay them. They could come back in a month and say "you owe us another $500". Or just go ahead and sell the data anyway.
Other than that you need to invest time and effort into an IDS that suits your environment.