Barracuda urges replacing, not patching, its email security gateways
krebsonsecurity.com
krebsonsecurity.com
> In a statement, Barracuda said it will be providing the replacement product to impacted customers at no cost
Obviously the time and effort to replace a device isn't free, but at least they're doing the right thing by acknowledging the issue and doing what they can to fix it definitively.
But correct - its the right thing to do regardless of the true, ultimate motivations...
But what I'd like to know is the impact of this? Like - how much corporate opportunity loss may have been created through information breaches which were unknown... That will never be known, unless we can assuredly say 'none' which is doubtful...
-
>Barracuda said the vulnerability existed in the Barracuda software component responsible for screening attachments for malware
Heh -- uhm... Isn't that like _THE_CORE_ component of the devices job?
Aside from ensuring filters on attachement egress blah blah...
--
>No other Barracuda product, including our SaaS email solutions, were impacted by this vulnerability
I'd like to hear them directly say that this specific ESG device line was NOT used in their Email SaaS offerings?
And to know exactly what ESG kit they are using?
Seems like a reasonable request if you're a large (or any) customer of theirs...
Unfortunately, add on that no customer makes a profit off their IT security org. Which disincentivizes excellence and incentivizes feature check-boxing at the lowest price point.
Which ultimately produces a highly privileged piece of software developed on budget salaries.
One reason MS security was a game changer (once the company got off its butt and admitted security was an existential threat to their OS sales) -- they could afford to burn great magnitudes of money to deliver.
(No offense intended to any of the amazingly brilliant non-MS Windows AV folks out there)
In my social circle, the kids Gaming PCs getting infected is very common.
Recently one of my boxes got hacked via a QBitTorrent exploit, and I didnt have Malware detection running, other than the built in W11 system.
I installed Malwarebytes and it detected and correctly removed the malware crypto miner.
FYI they exploited QBT via the web interface, which had default settings, but wasn't exposed via port forwarding to the web. It might have been via UPNP, which was enabled. No idea - but it's a common exploit used to DL a torrent then run a post DL script .bat file to DL and run a crypto miner.
I'd literally had QBT running on Windows for a couple of weeks, having switched from a dockerized setup on a Mac Mini. How Windows allows the running of a .bat file to DL an .exe that can run a crypto miner is just a bonkers lack of security!
Naturally I had to nuke the box from space anyway :-)
(you speak with a fluidity I did in my gaming heyday - but I am over the global heap at this point.)
Is it any different from Linux allowing the running of a .sh file to DL an ELF executable that can run a crypto miner?
Who or what triggers the execution of that script? If it is QBT, it almost sounds like malicious intent from the side of its developers.
> In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
It's either that or iOS-type walled garden, which one you prefer?
By the way, Windows even has the lock-down switch, it's just off by (a sane) default.
Also, blaming OS for not protecting from random app exploits isn't fair.
Chances are it's so core that some buggy LZMA or something implementation was offloaded to ASIC.
I’m used to companies taking the “deny, deny, deny” route and these articles are then written by their community saying the response is insufficient.
When is our industry going to agree on a standard where we go "no, that is too dumb, too far"? This "oh there was an issue but it's fixed now" doesn't begin to address the severity of the fuckup this is.
Do you have some other data to substantiate your ire or are you just piling on?
> The vulnerability stemmed from incomplete input validation of user supplied .tar files as it pertains to the names of the files contained within the archive. Consequently, a remote attacker could format file names in a particular manner that would result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product.
I would not be comfortable to continue using a product that contained such an egregious flaw.
Pulled the hard drive and loaded it up into VMmware ESX 2(?). It flew and there was one less server/appliance in my rack.
Barracuda was one of this early companies that made a very useful product out of free software. I idolized that and wanted to work there.
Then they were taken over by some outside company, started making all kinds of products that weren't in their core, support faltered...I'm kind of surprised they are still around.
What software? Is it just ClamAV in an appliance?
After a device is compromised, patching it won't help. Their software team (quite reasonably) says that after anyone else has got root on the system, their software patch system probably can't reliably be sure to get rid of the malware.
So, they are offering to replace any device in this position. The replacement is probably a refurbished one from another customer, but has gone back to the factory to be flashed by some debug port - and using that you can wipe all the flash memory and be pretty sure there is nothing evil left.
Edit: Typo.
https://www.bloomberg.com/news/features/2018-10-04/the-big-h...
Despite this, Bloomberg have refused to retract it or supply any credible sources, presumably because and continues to draw traffic.
Someone on one of these sides needs to provide evidence to support their claims. Clearly the authors of the original article have no intention or it would have been done already.
It’s trivial to debunk because the story was a hack job with no sources to begin with: the burden on proof is on the accuser in this case.
But I agree that you should filter all the relevant ports in all networks, just in case somebody screws up.
[0] https://www.theregister.com/AMP/2022/06/02/conti_rasomware_i...
Would you still switch to a non barracuda device ?
I mean, I hear you, it sucks that being honest about the issue is leading to punishment, but rationally this is just how people are going to end up responding. If they really want to avoid this, don't give it to them for free, pay them for it.
As I understood it, the calculus was 'do nothing and keep the current barracuda stuff for a while longer or find another vendor and replace the barracuda stuff?' Now the former option is gone, and the calculus is 'replace current barracuda stuff with barracuda or another vendor?' So if you were already considering switching vendors, now is an opportune time to do so. You're going to be paying the eng/ops cost now anyhow, and as many in this thread have pointed out, one or two fairly off-the-shelf hw appliances are not exactly a big spend.
No you’re not. The people in this thread saying that have never actually managed technology because a vendor change that also requires a hardware swap is significantly more expensive than the drop in hardware swap.
The only exception to this is if you were already in the middle of the transition and were planning to phase it out shortly anyway.
Even adequately researching alternatives, let alone doing some trial testing, will take far more time than a swap.
Compared to migrating to a new vendor?
There is often a counter "but I still get some spam with exchange online/google workspace", to which I would counter that you will still get spam with a barracuda.
He’s been on his personal holy war on firmware for years now, I’m not joking, I’m curious to read his opinions on this issue.
Maybe barracuda could use some kind of standalone 2u oxide server instead of supermicro servers? ;)
And further, is it even possible to get Oxide equipment yet? Is there even a timeline? Or is it still vaporware?
Secure hardware can attest that its firmware is what it should be and doesn't have any persistent implants in it.
1. We aren't making standalone servers: the Oxide compute sled comes in the Oxide rack. So are not (and do not intend to be) a drop in replacement for extant rack mounted servers.
2. We have taken a fundamentally different approach to firmware, with a true root of trust that can attest to the service processor -- which can turn attest to the system software. This prompts a lot of questions (e.g., who attests to the root of trust?), and there is a LOT to say about this; look for us to talk a lot more about this
3. In stark contrast (sadly) to nearly everyone else in the server space, the firmware we are developing is entirely open source. More details on that can be found in Cliff Biffle's 2021 OSFC talk and the Hubris and Humility repos.[0][1][2]
4. Definitely not vaporware! We are in the process of shipping to our first customers; you can follow our progress in our Oxide and Friends podcast.[3]
[0] https://www.osfc.io/2021/talks/on-hubris-and-humility-develo...
[1] https://github.com/oxidecomputer/hubris
> The pivot from patch to total replacement of affected devices is fairly
> stunning and implies the malware the threat actors deployed somehow achieves
> persistence at a low enough level that even wiping the device wouldn’t
> eradicate attacker access.
Very interesting. I'd like to think it's probably some technical limitations in the recovery options rather than some weird magickery to persist beyond drive reset. Because, if it's not, everyone is screwed.There ought to be 3 physically-separate flash devices: bootloader (never changed), OS (managed by bootloader - updates deleted unless signed correctly), and data (wipeable by a physical reset button).
If you don't do this, then you're inviting implants a priori.
I mean it's obviously an interest to national security.
They could do that while maintaining the backdoors they want to keep so they can have an edge on cyber warfare.
The NSA does not protect the public's computers, they attack them.
The NSA has kept plenty of vulnerabilities under wraps, the tool leaks were a pretty rare occurrence of the KGB/GRU trying to burn NSA ops without directly involving themselves.
But:
"somehow achieves persistence at a low enough level that even wiping the device wouldn’t eradicate attacker access"
It started. Barrakuda at least is nice to replaces hw but soon vendors will be bored by replacing shit they themselve making and customers will be left with voulnerable systems. Simple x86/PC ecosystem is shit, intentionally crafted or not. And, very, very sadly on whole globe only EU is capable of enforcing something to be better. But chances are minuscule...
I don't think it's a proxy; it's an ordinary SMTP server, isn't it? All SMTP servers can be configured as relays.
I imagine people buy these Barracuda appliances for CYA reasons, and because there's a support contract.
Also, Barracuda cheaps out on these massively especially at the low end. I've seen, in the modern Core i years, Barracuda 1U appliances powered by Pentium III processors. I suppose they are powerful enough for the job Barracuda is asking of them, but it's worth a chuckle to see how many years old the chipset they're shipping is.
The hardware is absolutely the cheapest part of the stack for them.
China?
https://news.ycombinator.com/item?id=36061772
https://news.ycombinator.com/item?id=36136705
https://news.ycombinator.com/item?id=36143926
https://news.ycombinator.com/item?id=36156908
https://news.ycombinator.com/item?id=36233472
https://news.ycombinator.com/item?id=36238822
https://news.ycombinator.com/item?id=36248328
https://news.ycombinator.com/item?id=36255901
https://news.ycombinator.com/item?id=36261519
You're of course right that there were lots of submissions but on HN reposts are fine until a story gets significant attention, and the current thread is the first one to do that.