The Story of the SolarWinds Hack
npr.org
npr.org
This is frustrating to read, since plenty of people did in fact warn that these kinds of systems were easy targets.
Support response:
"Regarding your second message about port 12345 on the Grafana Agent -- the HTTP server only exposes the Agent's internal metrics and provides an API for the Agent's status. The gRPC server is used for agents to communicate with one another, if the scraping service is used. It does not allow anyone to get access to their metrics.
That said there's we understand the concern and upon review will look at documenting that agents listen on 0.0.0.0 by default, and that you can change it by setting http_listen_address and grpc_listen_address in the Agent's server config to 127.0.0.1: (...)"
Also, sometimes I feel like I'm the only person in the world who is not comfortable in running tons of untrusted docker containers. If I put a link to a binary here and tell you to run it, I doubt any HN reader would. But 400MB of binaries? No worries, I have just the right tools to run them as root.
"But is there a vulnerability at the moment that can be exploited?" "None that we know of"
Containers also often get generous access rights and internet access, even assuming container solution being intact.
Security of the system inside is a whole big surface of attack that you have little control of (unless you meticulously analyze each docker full fucking system image every time you run them), and necessarily affects your systems because otherwise you would have no use for this container.
Certain data centers restrict access to outside network (i.e. Internet), with now popular public cloud. It's actually hard to place such restriction, because majority tooling, including official images are expecting to be connected outside.
It seems like SolarWinds should have known better themselves as well. There is no way that their upper management didn't know that they would be an amazing target for a hack. Supply chain attacks are not that new. Their lax security seems extremely negligent.
I've worked with people who don't operate this way, and who take continuous flack from CIOs for spending resources on verification for COTS IT management tools. But those teams are, in my experience, very rare --- and the SolarWinds hack provides further evidence of that view.
It's not a perfect predictor, but a reasonable rule of thumb: if you've never heard of a vendor's security team, chances are they barely have one. That's obviously true of... most vendors! So you should be careful when you select one for a role as sensitive as fleetwide agent-based monitoring, where a vulnerability or a software supply chain fuckup is going to create mass compromise. This seems so clear to me that it barely counts as insight.
IMHO most sane vendors who want you to install something on your machine make it open source and use existing tools as much as possible. Doing it this way also decreases chances of some "temporary fix" changes on even otherwise secure software. Companies optimize for money, management tries to align with company values and engineers often just have to follow it. It's inevitable what trade-offs will be made unless there's some direct negative impact. For everybody selling their time and not being heavily invested, ignoring black swans and basically "eating tons of sugar" is the natural move.
Presumes facts not in evidence.
From the nyt article https://www.nytimes.com/2021/02/23/opinion/solarwinds-hack.h... "The market loves to reward corporations for risk-taking when those risks are largely borne by other parties, like taxpayers."
See articles https://ciexinc.com/blog/solarwinds-articles/culture.html
Notice the report to SolarWinds: https://arcticsecurity.com/guides/2021/02/12/solarwinds-goin...
What does that tell you about their culture?
Yep, agreed. Its hard for me to believe that they didn't know they were rolling the dice on security, but just my intuition.
"A former security adviser at the IT monitoring and network management company SolarWinds Corp. said he warned management of cybersecurity risks and laid out a plan to improve it that was ultimately ignored.
In a 23-page PowerPoint presentation reviewed by Bloomberg News, Ian Thornton-Trump recommended to company executives in 2017 that SolarWinds appoint a senior director of cybersecurity, and said he told them that “the survival of the company depends on an internal commitment to security.”
The following month, he terminated his relationship with the company, saying he believed its leadership wasn’t interested in making changes that would have “meaningful impact.”"
Not even just for a nation state, it's the perfect target for anybody looking to gain reputation/large scale access to very interesting systems.
Hacking the keys to the kingdom from the people who are supposed to protect the kingdom from hacks.
In terms of "pwnage level" it can't get much "better" than that.
More important I think is that the months and months it takes to usher things through the process forces things to be out of date which in itself creates security problems.
An actual audit of the source code + running it in an instrumented live test environment to capture behavior is far better.
If you look at this case even briefly, you should come to the conclusion that the “security paperwork” is fairly useless.
An FTP server compromised because of a terrible password policy? No suspicious activity alerts of any kind? Executives who (based on their comments) are clearly ignorant of what makes software actually secure?
What is the paperwork able to prevent, if it can’t prevent such fundamental problems?
"Does this software touch literally every other system on the network?" should be a question that triggers a much more rigorous and deeply technical evaluation and review.
But the current processes don't work that way, they purely paperwork drills that often demonstrably make systems less safe.
Indeed, consider Figure 5 here [1]. A truly diabolical mastermind.
But seriously, the article looks like window dressing for common incompetence.
[1] https://www.microsoft.com/security/blog/2020/12/18/analyzing...
Nonetheless, there are some things that are kind of impressive. Inserting their own code into the build process without touching any file.
But the real level of skill, I think, is the operational discipline exercised by the attackers. For example, waiting two weeks before doing anything, erasing traces of what they did, and targeting very specific sites.
Why is this 'operational discipline' remarkable? I'd expect this to be common sense (including waiting for two weeks) , especially if I was a state actor and had spent a whole bunch of money on it? Or do you mean that the vast majority of hacking operations don't even bother to do this?
Yes, many operations make some kind of error that gives the whole thing away
1. Get the source-code of SolarWinds.Orion.Core.BusinessLayer.dll so they could know how to modify it
2. Get their modified source OR modified compiled DLL somehow into the build-pipeline at SolarWinds.
If SolarWinds could have prevented either of these two things from happening this attack would not have worked. Am I correct?
You're aware that this is exactly what solarwinds did, right?
This boils down to the question of should average companies be including the Russian intelligence services in their threat model? To paraphrase James Mickens great USENIX paper, if your threat model includes the SVR, you're going to be SVR'd upon.
Second, a company's threat model should include entities that want to attack them. Given that they are claiming the SVR wanted to and did attack them, it would be ridiculous to not include them since that would be empirical evidence that they are an actual threat actor. Even if we were to ignore empirical evidence any company like SolarWinds that sells to wide swaths of government agencies in critical capacities should absolutely be including foreign intelligence services in their threat models and should probably be required to demonstrate effectiveness against attacks funded to at least the $100M level since only at that level does it start to actually get problematic for state actors to run operations.
I have always argued that doing what I call "defense by presumed motive". The logic would have been "ok, UNC2452 wants to access DHS hacker's email. I'll go after SolarWinds". Better spend your energy on basic security principles.
It's a bit like arguing Bill Gates is a serious threat to any naval power because he can afford to buy a nuclear attack sub; there's more to it than that.
Like razor blades in peanut butter cups, says CrowdStrike.
The SolarWinds hack was a devastating attack on our sovereignty.
And so is the other.
Do you have any idea what America did in Russia in the immediate aftermath of the fall of the Soviet Union? The 1996 election in Russia which was majorly "interfered" with by Clinton: https://archive.is/R7i5u, not to mention the fact that most Russian hacking activities are done using NSA backdoors which were leaked?
I'm surprised and disappointed to see such flagrant ivory tower imperialism on HN.
I think it's a mistake to minimize Russian influence, when it suffices to compare the unmitigated disaster of U.S. actions - both government and private sector, and at enormous scale - in post-Soviet Russia.
But targeted ads are?
"They cleaned the crime scene so thoroughly investigators can't prove definitively who was behind it."
That's literally in the article but it doesn't stop them writing the whole thing as if it's utterly proven beyond doubt who was behind it.
Russia uses America as the core of their propaganda just the same as the DNC has been using Russia as their boogoieman since they needed a narrative to apply to Trump.
As someone who formerly worked for Crowdstrike and has performed the APT-29 demo countless times, I will say attribution is bullshit and people frankly have no real data to point fingers.
Major investigations were completed months ago.
There is no more evidence to suggest Russia was involved than there was that Dmitri himself was for political reasons. And Shawn Henry will fire you for saying this out loud.
Yea, wow, thanks NPR. Hard hitting stuff right there. Those are “very specific circumstances” that just happen to generally apply to a huge percentage of hacks.
I normally appreciate some stories on NPR, but you’re right. This is a narrative piece.
Plus, the article is written to condense technical information into something that's as layman-friendly as possible. The specific malicious update has to be downloaded, and also installed, and also running on a server which can reach out to anything on the internet. Their point is that there are only going to be so many servers that both use this software and meet those conditions, and that's in part why the backdoor took so long to identify. This is maybe a little obvious to people with infosec knowledge, but definitely not obvious to their target audience.
The article timing is interesting, but I don't think a coincidence is that unlikely. If you read the whole article, it covers enough that I could see it taking months to make.
I don't think coordination with the government is that unlikely, either, or perhaps just a pragmatic editorial decision ("everyone knows sanctions are likely going to be placed sometime in the next few months, and maybe we should wait until then so we can include those details in the story"). Both of those scenarios are more likely than a coincidence, probably - but, either way, I think your post seems overly cynical in general.
Nonetheless the article was correct the hack did not need bizarre or rare circumstances to take effect.
Docker's a decent way to address this, since you install the dependencies when building the image rather than when running the container, so you can build the image elsewhere or through CI and run the container on any server without having to allow access to package management repo servers.
You're ready for offline install!
That's a lot of words to say, we don't know who did it. I had a quick look but couldn't find anything, why are the fingers being pointed at Russia?
https://www.reuters.com/article/us-global-cyber-solarwinds/s...
Edit: Your link show Kaspersky labs making the claim that this was the FSB. Yet the West also claims Kaspersky is controlled by FSB! Well, you could say "they should know". Or maybe they want to humor the West so their ban will be lifted. Or maybe they aren't controlled by the FSB at all. But if the West can't figure that out, how do they expect to figure out the true origin of the hack.
"A riddle wrapped in mystery, inside an enigma"
Is there the rare case that we shouldn't update because the update could contain a malicious payload? If the update gets served over plaintext HTTP I would treat it as suspicious and may even block it from connecting at all. I run the risk of having outdated software, but that can be addressed by storing the software in a machine that's not connected to The Internet in any way, so it can't really do anything/talk to a C2 server (if someone does decide to execute an 0day with the software or inject malicious code via a rogue update).
If you have a machine that's air-gapped and its only IO is strictly humans (read: keyboard/screen, not USB or other electronic means) then your weak point is the human, so center your security around that. You can look at security of lottery machines to get a good idea how that's handled.
But if you're updating the machine with updates, then it doesn't really fit that criteria, soooo....
>And so we are fairly broadly deployed software and where we enjoy administrative privileges in customer environments.
There is a lot of talk about shoring up security practices by many of the people quoted here. But something that would be hard to admit is that maybe they should not have administrative privileges in customer environments. Maybe they should not install agents on your machine. They would never recommend you to do so with anyone else, except them of course, because you can trust them.
But, is it possible or practical to do network management without "agents" ?
I feel like this says "well, we are not really sure".
From the viewpoint of the public it would be important to know what made this attack possible, and how to defend against it, even if the actual attack was accomplished some other way.
I guess what I'm asking is, do they know how to repeat this attack?
Nice writing I guess, but, what allowed them to get into the build scripts?
https://itwire.com/security/solarwinds-speaks-out,-and-softw...
So it sounds like the VM host they were running builds upon was compromised - or maybe JetBrains was compromised?
JetBrains claims there is no evidence they were compromised https://blog.jetbrains.com/blog/2021/01/07/an-update-on-sola...
https://www.nytimes.com/2020/12/03/us/politics/vaccine-cyber...
That's from December. Still going on.
https://www.reuters.com/article/us-health-coronavirus-vaccin...
Wall Street Journal:
https://www.wsj.com/articles/SB1039184086357188113
Wikipedia:
1. http://en.wikipedia.org/wiki/Ptech
2. https://archive.org/details/GunsNButterIndiraSinghPtechAndTh...
3. http://masshightech.bizjournals.com/masshightech/stories/200...
5. http://web.archive.org/web/20080905224929/http://www.theamer...
6. http://web.archive.org/web/20080820045652/http://www.total91...
7. http://web.archive.org/web/20080515202659/http://www.judicia...
8. http://web.archive.org/web/20081015113454/http://911citizens...
9. http://web.archive.org/web/20080915185702/http://counterterr...
10. http://rememberingmichael.wordpress.com/2008/03/20/in-memory...
I assume that things available only as youtube video, unavailable in a text form are unimportant.
(not all things in text form are important, but it is a nice filter that basically always works)
something about leading a horse to water I suppose
The best backdoors are those, which are never found.
You want to leverage your access to perform actions because you got get revealed\blocked even not intentionally.
Once you act, let's deploy some ransom, wipe some data, shut down power plants, you will be shown.
Keeping a perfectly stealth backdoor for years as environments, software and personal change is extremely difficult.
In my home windows setup, only windows defender, firefox and chrome are allowed out going internet access in regular base. Everything else are blocked.
Windows update are only allowed when I in the mood for it (~once a year). Anyone can do this easily by control srvhost.exe 's internet access with windows firewall app.
Quis custodiet ipsos custodes? Who monitors the monitor?
What happens when it is compromised, loopholed through, gets its inputs tampered with, etc.? For a home setup and its threat model, this sounds a simple, workable plan. When you're dealing with attacks of the level of sophistication described in the OP, trusting trust [1] becomes complicated and difficult.
[1] http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thom...
https://blog.thinkst.com/p/if-nsa-has-been-hacking-everythin...
There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated response back thanking him for his help and saying the problem had been fixed.
When NPR asked SolarWinds' vice president of security, Brown, about this, he said that the password "had nothing to do with this event at all, it was a password to a FTP site." An FTP site is what you use to transfer files over the Internet. He said the password was shared by an intern and it was "not an account that was linked to our active directory."
The attack implanted malicious code into their code, learning the tooling, process and responsibilities of the personal.
They then reversed engineered the protocol and used it in their backdoor to look basically the same as regular communications.
The issue is that we blindly trust 3rd party software that is used by hundreds of companies. this makes SolarWinds a prime target, one that is worth the efforts taken in this case.
This kind of attack needs an entry point, and an exposed FTP server provides the potential for one. Whether it actually was the entry point is a separate matter, willfully ignoring one unlocked door means there's likely to be others.
you can't cover all entry points, it's a matter of time for someone to make a mistake. the fact that the adversary showed these extreme levels of proficiency and dedication tells me that the vast majority of companies would have fallen for that. In fact, the backdoor was running for months on targets like Microsoft, gov agencies, security companies like Malwarebytes.
These companies know a thing or two about security.
Today we work with "assume breach" mentality that assumes you are already compromised.
Leaking the extremely weak login credentials to your updateserver, trough a public Github repo, is not exactly a glowing endorsement of how serious security seems to have been taken at Solwarwinds.
With stuff like that being a thing, who knows where else they cut corners/got lazy.
> this makes SolarWinds a prime target, one that is worth the efforts taken in this case.
A prime target, yet apparently could still not be bothered to put in some minimum effort to protect themselves.
What would have been the minimum effort that would have protected them?
That said, foothold for this stuff more often than note comes from keys on public GitHub repos (or things like that: simple misses that are enough to throw the door open).
I hear things like “intern” and “totally unrelated” and it’s the dog whistles of policy/policy enforcement failures of these sorts of initial ways in.
So many sexy hacks start from admin123 passwords unfortunately
I think both the intern that posted the file and the person making that statement both did not realize that someone had given the user write access.. which in my opinion was the actual mistake, not the ftp or the password.
You should always verify the data you get, be careful with complex supply chains, and avoid binaries you didn't build yourself. Don't skip these things just because "that's the way it's always been done." 10 years ago very little internet traffic was encrypted, security still means progress not the status quo.
Afaik that was the updatesever and the password originally came from a public Github repo where is was stored in plaintext since at least June 2018 [0]
[0] https://www.theregister.com/2020/12/16/solarwinds_github_pas...
I don't know if it the damage was greater than NotPetya but you definitely can have something more destructive without it being immediately apparent. If you lose credit card numbers and PII from your customers you HAVE to report it to the public but there are different rules for the loss of incredibly valuable intellectual property.
First, to correct a common misconception, NotPetya definitely wasn't ransomware run amok - it was designed to look like the previously popular Petya ransomware, but the actual ransom and decryption key processing mechanism was removed as that wasn't its purpose. It was masquerading as ransomware, but it wasn't ransomware, it just destroys data by encrypting it with a non-recoverable key.
Just as Solarwinds, NotPetya also was a targeted supply chain attack - it was deployed through updates from a previously hacked accounting/tax software company "Intellect Service" to all their customers in Ukraine, which also included many multinational companies which had their finance depts file tax reports in Ukraine; and just as Solarwinds, NotPetya is attributed to Russian government.
The main difference is that, as you say, it seems that Solarwinds was (at least at the stage it was detected) used only for espionage, while NotPetya was designed for pure destruction.
NP, as Maersk and co experienced was definitely rware (a variant, sure) run amok however. It’s industry consensus that the attacker either a) didn’t think of the possible Global blast radius or b) thought of the blast radius but didn’t plan for how bad it would get.
In a sense, SW might reflect a more mature approach: consider the network spread, use a different exploit and intent - spyware for espionage vs rware variant for destruction.
That said, very different exploits and intents were used.
https://www.theverge.com/2021/4/15/22385371/russia-sanctions...
(Which is itself a bit odd. The US has argued in other contexts for "cyber norms" which would allow pure espionage operations, but put more restrictions on attacks. And so far as anyone can tell so far, SolarWinds was a pure espionage operation -- using tools that could be repurposed to do something else, but you could say that about a lot of operations in this sphere, including US operations that our government wants everyone else to shrug off. Yet here are the sanctions. I expect the "norms" push, to the extent that the current administration still wants to pursue it, will take some kind of a hit...)
I'm a sense it's only not a nightmare if you aren't paying attention.