Not a drill: VMware vuln with 9.8 severity rating is under attack
arstechnica.com
arstechnica.com
If you don't see dysfunction, you're not looking closely enough. That's not to say all organizations are equivalently dysfunctional or that we shouldn't strive for better. I'm just saying that "dysfunctional" isn't a damning accusation.
I like the scores - just ask them - what's the score.
Any further references to this? I’d love to have something I can send around internally. The people running Tenable tend to treat these numbers as gospel.
We also do this with pen test reports which suffer the same kinds of issues.
Usually find that sometimes a medium is a critical for us and some times a high is a low for us - based on performing this kind of assessment.
Totally agree, and I do that - check the vulnerability description, see if we’re using that part of the library, etc… it usually works out that we’re not actually affected by whatever the alert is.
So its a serious vuln, but not as serious as say if it was in a component that was always exposed to the internet in the core part of vmware. I guess vulns can always be worse.
How bad it is depends on how you use vmware. I mean regardless, clearly everyone affected should patch.
CVSS is generally used on the sysadmin side to figure out what to patch first. Successful attackers generally go after shit that's unpatched. This often means that the most exploited bugs are the ones with the lowest CVSS scores, so new tools and techniques tend to grow around issues that sysadmins consider to not be a big deal.
People eventually catch on that the "no big deal" bugs are getting exploited en-masse, and try to tweak the scoring process, which is why we're on CVSSv3 now with CVSSv4 in the works, and it's just as useless as it's always been.
Namely, you should be taking the base CVSS score and including the temporal and environment metrics to actually determine your organizational risk. A base 9.x could easily be driven to low based on the access, exploitability, and CIA requirements for the system at hand.
P.s. I use yandex to find CVE POC, google is almost useless for that kind of search and yandex almost always deliver working code !
I use those POC to help the infosec team at work when the bosses postpone patching. There is nothing like a demo to persuade them we must patch now.
I'm hopefully preaching to the choir here but please beware that high-visibility flaws often attract fake PoCs. Malicious in the sense "might [also] attack the user" (you!).
Often these will surf on work done by valid PoCs to look credible. GitHub was stuffed with them for the Hafnium Exchange bug, before Microsoft brought down the ban hammer. (At the time there was lots of mewing about "Microsoft protecting their own" and "Microsoft killing free speech" but I wonder if they weren't also interested in stopping the pwnage from these fake exploits, too).
I'm not saying this repo is malicious. This github user looks legitimate and doesn't look like the obviously-created-by-a-bot profiles I've previously seen. Even so I wouldn't necessarily trust ~5000 vendored class files. Play carefully.
And have to stay away from pirated games.
A compiled executable from a trustworthy vendor gets a score of 1/65 on virustotal? Well, I guess you are running in a sandbox..
A legit library has enormous number of lines? Well I’m rolling my own (except for crypto, noone should roll their own)
I just cannot take the risk anymore.
That said, I understand that this vulnerability basically gives root to anyone with VPN access. In our case, pretty much anyone who has VPN access to the cluster already has root on it anyway.
It's not that hard, and anyone ignorant enough to expose a vCenter to the Internet deserves being shut down. This is unacceptably incompetent.
If your business depends on employees that are working remotely, and you have critical services behind a VPN, your VPN solution is now a critical service too, and should be built and managed accordingly.
Just throwing an OpenVPN host up isn’t enough. If you’re going down that road, you need multiple OpenVPN hosts, each one “hardened” (since they’re internet facing), and a mechanism to deploy the VPN clients (and certificates) to the users. You then need to do this a second time too for an entirely different VPN solution (OpenConnect? WireGuard? StrongSWAN?), in case the first one suffers a vulnerability that you can’t immediately mitigate and instead just needs to be shutdown.
Like most technology solutions, this is only trivial to resolve if you’re operating at a really small scale, all your users are tech savvy, and you don’t treat it as a business critical service.
The moment your business depends on it, it either ceases to be trivial, or becomes a large source of operational risk.
There is simply no excuse at all for having it directly wired to the Internet. None.
But yes, exposing highly sensitive tools to a wide, untrackable, and frequently hostile audience is not good practice.
And if you expose it to your customers, you either have to force them to use a VPN (and support it for even their dumbest users), or you expose it on the Internet.
Not great security wise, but the economics do push you into that direction.
What’s the .2 represent?
Down at the "Scope" section there's "changed" and "unchanged". If you click on "changed", it goes from 9.8 to 10.0.
Thinking of: “I will slaughter you”, where Daniel explains how he gets death threats from clueless sysadmins that see that they have been hacked by someone that used curl.
https://daniel.haxx.se/blog/2021/02/19/i-will-slaughter-you/
Edit: I have e-mailed the author, but someone that use Twitter may want to try and reach the author on @dangoodin001. Thank you.
If an insecure website can be hacked using only dev tools in the browser, does anyone blame browser vendor?
If they're trying to get across to a non-technical audience how easy it is, then why mention cURL? They're not going to know what cURL is, as evidenced by the explainer following immediately. Why not just say, "5 HTTP requests sent by the command line"?
This is an arstechnica article, their target demographic is more technically literate than the lowest common denominator.
Why would that be? Curl can perform incredibly complicated requests to the point where they're barely legible on the command line.
I still think it's strange to mention cURL specifically in the way they did and agree with the GP. Here's another terrible analogy for the HN archives, but it's kind of like saying, "the smash-and-grab on the jewel store can committed with a Stanley™ 16 oz Curved Claw Fiberglass Hammer" when of course any heavy, handheld object will do.
It might to you and people in your circle, but that's not the entire audience of the article. I wouldn't assume everyone knows what a Dremel is either.
I mean, the normal way to use curl for this kind of thing is to define the request you want to send in a file and tell curl to read the file. There's no requirement -- or implication -- of simplicity in an attack that "you can execute from the command line"; that description refers to every possible attack. It's meaningless. There's nothing you can do that you can't do from the command line.
If you have to censor your content to account for the stupid and the mentally ill (slaughter guy sounds schizophrenic complete with delusions of grandeur and persecution syndrome), you will have to stop posting completely.
What I find very distasteful is your attempt to incite people to harass the author over social media.
We had a company mailing list that people used to email jokes back and forth all the time.
One rather ignorant programmer put a rule on his email where he would get an alert whenever anybody emailed him with a particular word in the subject line. That word happened to get into a rather popular email thread, and in the middle of the thread we started getting complaints from him asking us to change the subject line because his pager was beeping off the hook.
Career limiting move! He took a lot of heat for making poor assumptions.