Four ways in through the front door, in one fortnight

· · Security Infrastructure

Somewhere in your office, or in a data centre you pay for, there is a box that faces the internet. It might be the firewall, the router, the thing staff connect to when they work from home, or the filter your email passes through. Most of the time nobody thinks about it. It was installed, it works, and it sits there.

It is also the first thing an attacker can reach. In the last fortnight, four different makes of that box were found to be under attack. In three of the four cases, the attacks started before a fix was available.

You do not need to follow the technical detail. You do need to know whether you own one, and who is looking after it.

The four

Citrix NetScaler. NetScaler ADC and Gateway are widely used to give staff remote access to office systems. Citrix published fixes for eight flaws on 27 September. Two of them let an attacker run commands on the device without logging in, and both were already being used. The National Cyber Security Centre issued its own advisory. Google researchers say one of the campaigns had been running "since at least early September", and The Register reports that victims include legal and professional services firms in Europe. Versions 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23 are affected.

Fortinet FortiMail. FortiMail is an email security appliance. Fortinet has warned that a flaw in its web interface is being exploited, letting an attacker write files to the device without logging in. For several versions the fix is still listed as "upcoming". Until it arrives, the advice is a workaround: switch off a feature called Identity Based Encryption if you do not use it, or make sure the management interface cannot be reached from the internet.

Check Point firewalls. Check Point has confirmed attacks on a flaw in the VPN feature of its Security Gateway. It says a wave of attempts against Spark customers began on 12 September. Spark is its range for small businesses. A second flaw in the same advisory had been exploited since 23 July. Fixes are available for both.

MikroTik routers. MikroTik routers are common in small offices and with smaller internet providers. Poland's national response team found that two flaws could be chained to take full control of a router with no password, as long as its remote administration service (SSH) was reachable from the internet. Attack logs date from 2 September, the day before MikroTik released fixes in RouterOS 6.49.21, 7.23.4, and 7.24.2.

How worried to be

Not every one of these is your problem, and the scary numbers attached to them do not tell you which is.

Three things matter more than the severity score:

  • Do you have one? Many small businesses have none of these four. Many others have one and do not know its name, because the IT provider chose it.
  • Is it being attacked now? All four are. That moves them ahead of anything that is merely theoretical.
  • Is the vulnerable part exposed? The FortiMail and MikroTik attacks need an administration service to be reachable from the internet. If yours is not, you have time. The NetScaler flaws are harder to avoid: one of them affects a setting that is on by default for remote access.

Patching does not undo a break-in

This is the part that gets missed. If the attacks started before the fix existed, then installing the fix closes the door. It does not tell you whether somebody came through it first.

The NCSC's advice on NetScaler is to check for signs of compromise, and where possible to replace an affected system with a clean, fully updated one. Charles Carmakal of Mandiant put it plainly: customers should examine their systems "before upgrading/patching", because "patching alone may not eradicate the threat actor". The reports describe attackers leaving behind hidden accounts and files that survive an update. On MikroTik routers, the sign is a new administrator account called "ops".

Fortinet makes the same point about its workaround. It stops new attacks. It removes nothing that was already planted.

What to do

  • Find out what you have. Ask whoever manages your network for the make, model, and software version of everything that faces the internet: firewall, router, remote access gateway, email filter. It should take them minutes. If it takes days, you have learned something.
  • If it is one of these four, ask two questions. Has it been updated or had the workaround applied, and on what date? And was it checked for signs of compromise first, using the manufacturer's published indicators?
  • Take administration off the internet. The login page for managing the device should not be reachable from outside. This one change would have blocked two of the four attacks.
  • Ask who watches for these warnings. Somebody needs to be reading the manufacturer's security notices for each device. If it is your IT provider, it should say so in the contract. "We patch monthly" is not fast enough when attacks begin before the fix.
  • Sign up to Early Warning. The NCSC's free Early Warning service tells UK organisations when it sees signs of trouble on their network addresses.
  • If you think you have been compromised, report it. The NCSC asks UK organisations to do so, and you may have duties to the Information Commissioner's Office and your insurer as well.

How Steelwise can help

Working out what faces the internet at your business, whose job it is to patch it, and whether the contract actually says so is a short piece of security advisory work. Get in touch if you would like a second opinion.

Further reading

← All filings