Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
justice.gov
justice.gov
Keep in mind in like 1999, you didn’t expect upgrades via package managers online for most large customers so this was an appealing release vector.
> Butler is currently incarcerated at FCI Victorville Medium 2 in California, he expected to be released April 14, 2021.
Microsoft and the DOJ have established a track record of getting judicial approval and so on. I'm sure now it is a much more known quantity / outcome legally for them than Red Hat back in 1999. I can imagine there is a good chance of a judge in 1999 think "You're who? and you want to wut wut the wut wut?"
See pages 20 and 21 of https://www.justice.gov/opa/press-release/file/1386631/downl...
Madison deliberately left many provisions in the Constitution and Bill of Rights open-ended because he wasn't an idiot and knew that the founders could not anticipate everything. Had the FBI acted on its own it would be overreach. They went to court, got a warrant, and did pretty much the minimum required to eliminate the threat.
The mechanism seems to be a search warrant. The FBI applied for a warrant to "search" all compromised Exchange servers in the United States, and to "seize" the illicit malware on those servers by executing a specified series of commands.
A few excerpts from the above link:
"FBI personnel now seek authorization to search the compromised Microsoft Exchange Servers and uninstall the web shells on those servers". (6th page of the PDF)
"This warrant authorizes the United States to seize and copy from Microsoft Exchange Servers located in the United States the web shells identified in Attachment A, and to delete the web shells from those servers." (11th page)
> a magistrate judge ... has authority to issue a warrant to use remote access to search electronic storage media and to seize or copy electronically stored information located within or outside that district if ... the media are protected computers that have been damaged without authorization and are located in five or more districts.
> A warrant may be issued for any of the following:
(1) evidence of a crime;
(2) contraband, fruits of crime, or other items illegally possessed;
(3) property designed for use, intended for use, or used in committing a crime; or
(4) a person to be arrested or a person who is unlawfully restrained.
Once it gets established as a legal thing, they'll keep pushing it...
Edit: to the iudqnolq's reply below - warrant doesn't have to explicitly permit it. My understanding [IANAL] is that, at least in the physical world, whatever gets in "plain view" of the officer during any authorized law enforcement activity also becomes a fair game. I.e. they were called for the noise and upon entering see a kilo of heroin laying on the table - the heroin comes into play even though they didn't have a search warrant for it. So i'd expect that the same principle would be applicable in the virtual world too.
If it isn’t passively visible, it is not, by definition, in plain view. If they have to do a search, however simple, beyond what is explicitly authorized in the warrant, to find the information or to find whatever would give them probable cause to believe it is contraband or evidence of crime, they can neither seize it nor get a search/seizure warrant based on their observation of it under the plain view doctrine.
This warrant does not authorize the seizure of any tangible property. Except as provided above, this warrant does not authorize the seizure or copying of any content from the electronic storage media identified in Attachment A or the alteration of the functionality of the electronic storage media identified in Attachment A."
https://www.justice.gov/opa/press-release/file/1386631/downl...
If this sort of thing is a good idea, there should really be legislation about it specifically.
Warrants are issued if there is an evidence of a crime. The existence of these shells is the evidence.
I think an act of shutting down exploited servers is being overthought here.
https://www.justice.gov/opa/press-release/file/1386631/downl...
No, just as US law enforcement doesn’t when they arrest people overseas, but also, just as in that case...
> an illegal act across international borders?
Yes.
In my understanding, the FBI:
1. Applied for and received a lawful court order
2. To make as minimally invasive as change as possible to help the targeted networks
3. While making a best effort to contact the network owners to tell them what they were doing and then
4. Widely publicizing what they did.
Not everything is some big "gotcha" conspiracy. We can just say "thank you" and move on.
Tl;dr: I’m from the government, and I’m here to help
Top that all off with the fact that it's really hard to trace who and what were involved, versus a more transparent process where legitimate experts could chime in and prevent any further harm. Instead we have to cross our fingers that they did it right and that the judge understood what he was agreeing to.
And I mean it's not a unique problem to this circumstance. Just kinda how institutions tend to be.
Isn't this how it is with a lot of things? The government can tax people. If I tried to tax people, that would be illegal coercion.
But the process is the whole point isn't it? If anyone was able to do this whenever they wanted and without oversight that would be a major concern. This is an example how this kind of thing can be done in a safer, legal way. Of course it won't be as fast as just letting anyone do this, but that's a price worth paying.
To me the FBI's behavior is the equivalent of "Since there have been several break-ins in our district and our local police dept. has determined that the internal door locks of business offices in our district are faulty, so we have broken into each business, and fixed the locks ourselves, we have attempted to trace you and notify you if you have publicly available contact info". Noble, yet still chilling.
The problem with a hack is that it can be done within hours on properties everywhere, so just dropping a note won't be fast enough for most. Where there is an equivalent in real-world (i.e. immediate threat of a break-in), police can and will act to secure that property.
So I don't see the chilling effect, it's something that (at least in Europe) is common part of preventive policing.
Exactly, in this case they got the equivalent of a court order to enter every house and check the locks.
Which no judge would be likely to approve if it were actual physical houses. But servers...
The weird thing is the warrant authorizing entry into pretty much any computer anywhere. Could they get a warrant to enter any computer anywhere to look for child porn? Or "terrorism" or whatever? Probably not, that's not the way warrants work, except now are they going to?
... which is not what happened.
And - "open door" metaphors do not work well for cybersecurity due to an entirely different threat model. These vulnerable machines are globally available for anyone to break into with almost no effort.
How would you show the source was the original hackers and not the FBI?
If, for example, part of the mechanism that allowed them to do this involved a search warrant for "all computers in the US"...that's a precedent that has obvious, chilling, future implications.
Perhaps that wasn't the mechanism, but it's such a broad action that I'm worried something like that is involved.
So the message here is, if you don't clean up your act and you're on a USA network, we'll do it for you without your permission.
The beef is at the end of the article:
This operation was successful in copying and removing those web shells. However, it did not patch any Microsoft Exchange Server zero-day vulnerabilities or search for or remove any additional malware or hacking tools that hacking groups may have placed on victim networks by exploiting the web shells. The Department strongly encourages network defenders to review Microsoft’s remediation guidance and the March 10 Joint Advisory for further guidance on detection and patching.
The FBI is attempting to provide notice of the court-authorized operation to all owners or operators of the computers from which it removed the hacking group’s web shells. For those victims with publicly available contact information, the FBI will send an e-mail message from an official FBI e-mail account (@FBI.gov) notifying the victim of the search. For those victims whose contact information is not publicly available, the FBI will send an e-mail message from the same FBI e-mail account to providers (such as a victim’s ISP) who are believed to have that contact information and ask them to provide notice to the victim.
If you believe you have a compromised computer running Microsoft Exchange Server, please contact your local FBI Field Office for assistance. The FBI continues to conduct a thorough and methodical investigation into this cyber incident.
"This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States."
18 U.S.C. § 1030(f).
DOJ obtained authorization here, most likely under Fed. R. Crim. P. 41(b)(6)(B)--which, interestingly enough, cross-references the CFAA.
Edit: After re-reading my post above, I guess I did suggest they violated the CFAA in law. Not my intent to say that. I'll leave it as is.
By default, we expect moral people to conform to the laws of their jurisdiction. Not because the laws are necessarily morally positive; most laws are morally kind of neutral, but because the predictability itself is a good virtue.
Of course, that default presumption can be overcome with a relatively low burden of proof.
Slavery was once legal, and this kind of thinking is what made people want to continue it
Most things that are legal aren't outlined in the law anyway, they're omitted.
So for slavery, you would expect the laws to eg deal with run-away slaves etc, not so much with slavery itself.
> I think it is reasonable to conclude they were referring to the bulk of the law that is administrative/procedural/etc. There are 53 titles of US code, and one of those (title 18) is about criminal code. The rest are predominately not matters of morality.
Yes, exactly. And I am presuming here, that there is a presumption in morality that all-else-being equal, it's more moral to stick to these neutral laws, just because it makes living in a society with other people more bearable.
Eg in a moral sense it doesn't matter whether people drive on the left side of the road or the right side. But if there's a law about driving on the books, you better follow it.
(No clue whether this is strictly speaking something about morals or more about ethics?)
...
> I'm using CFAA as a moral definition of hacking, not legal.
Please don't move goalposts; it degrades the conversation. Better to own the error to let the conversation proceed normally, allowing everyone to learn together. (I doubt most of us knew about the LE carve out, for instance)
Warrants that enable search and seizure on domestic individuals and corporations are...the main expected use of warrants in the US system.
As endpoints of a slippery slope argument go, that's...kind of thr opposite of what you’d usually target.
Warrants have always allowed the bypass of physical security devices, why would digital ones be any different?
I am not sure on any prior case law on this, but there's examples in the real world if you leave a dangerous attractive nuisance out in the public space, where it could potentially be harmful to people or animals. Local law enforcement or civic-minded citizens will remove it. It could be argued that leaving exposed outlook web access rooted systems out there for anyone to use on the public internet is not too dissimilar.
On a federal level? If you leave an abandoned ship leaking toxic chemicals anchored somewhere in a bay, don't be surprised if the USCG, a federal law enforcement agency, comes and seizes it...
See pages 18 to 21.
There you go.
Microsoft and the DOJ have several times gone to a judge to get permission to take over botnets. The reason being that to do so they take over the botnet and the result is of course that if they control the botnet they then have control of those computers. But you can't completely disassemble some botnets without taking it over.
And what happens if they break something while patching the exploits? Just seems odd that somehow the FBI is the best server admin here?
I feel like I’m missing the full view of the implementation specifics.
Shouldn’t the disincentive for admins to run unpatched just be monetary damages once/if a damage occurs?
Why are my tax dollars paying for lazing email hosts? Seems like a lot of other issues (unless I’m missing something)
Probably the same thing that happens when officers injure people or damage property in the course of executing a warrant (which is quite common). In short, either the victim is rich and/or outraged enough to venture a lawsuit against the relevant agency or they just file insurance claims and hope for the best.
I wouldn't be surprised if part of the reasoning for signing off on this action was that the risk of damage was considerably lower than what is routinely understood to be part and parcel of executing search warrants.
Without arguing for or against it, I can see this new role viewed as a "sysadmin of last resort" wherein an authorized institution steps in to ensure a minimum security level among neglected systems in their jurisdiction.
I presume they're worried about industrial espionage and sabotage.
> The presumptively U.S.-based Microsoft Exchange Servers, corresponding to the approximately [redacted] web shells in Attachment A appear to be located in five or more judicial districts, according to publicly available Whois records and IP address geolocation
The FBI here aren't just "protecting lazy admins", there are some further reaching consequences to failing to act.
Note also people are talking about "applying patches" but the order more specifically talks about removing web shells. If my experience is indicative, there are more hosts that applied patches too late and didn't remove the web shells mass scanners deployed, than hosts that never patched. I expect a lot of this disruption is about deleting a one line .aspx file.
if left unpatched, these same servers could be reinfected next day?
In may of those, the respective regulators can shit the entire business down. Here, the FBI didn't even power the servers off and they got a warrant without going through a secret court
Companies have had plenty of time to address the issue on their own, at this point
Before anyone tries framing it as a service to the security of the majority - understand that this is the introduction of a new attack vector: state actors hamfistedly bumbling around your network while "doing you a favor". If the threat even approached a level justifying this kind of action, the far more effective and less damaging approach would be directing upstream networks to blackhole routes to the machines.
/prediction
It is very frustrating to have essentially no recourse available to stop the constant vulnerability scans targeting my house.
If random people constantly walk up to every house on the street looking for pick-able locks, the police are (Setting, for a moment, aside over/under policing and other issues) available to help stop them.
But, for the digital equivalent, our collective response (especially among technical people) is typically "[shrug] Make sure your locks are unpickable and your windows unbreakable. And if you cant handle that, then just move in to the Facebook highrise"
So they removed the IOC but left the hole wide open.
This kind of "help" is going to be an incentive to stop doing business with US hosting companies.
This is about damage mitigation and removing the shells is an excellent way of achieving it.
It's illegal for a reason. They committed the same crime by removing the web shells as was committed by the person who placed them there. (Who can put them right back.)
/s
This isn't a search, it isn't a warrant, and there's no constitutional amendment that outlines the situations in which the feds are allowed to break into my computers.
Also, the typical remedy for a defective warrant is suppression of seized evidence, not criminal prosecution.
The word warrant does not appear on that webpage.
See pages 18 to 21.
See pages 18 to 21.
This is a search. Specifically, the web shells are (1) evidence of a crime, (2) contraband, fruits of crime, or other items illegally possessed, and (3) property designed for use, intended for use, or used in committing a crime. Any one of these three would be a valid basis for a search warrant.
I hope that in the future there will be some fine for Server Neglect (leaving internet facing server unpatched and hosting web shells for 5 days after patch publication by vendor) and you will lose your server and all your data for such misdemeanor.
I can see it now: "Government stole decades of family photos and videos because my Linux/Plex server was available online."
Another good reason to stop using proprietary binaries and instead compile your own source - even if you use code under proprietary copyright. Imagine if France also decided to "help" and bricked your server on accident.