Skip to content

How we won over hackers

At the beginning of October, our company faced a serious hacker attack.To ensure the operability of our services for all of our clients all around the world, we have several nodes – in different data centers across the globe. It was one of these nodes that was attacked and completely disabled.

How is this possible? All of our servers are well protected and accept management requests only from addresses known to us, and the authentication by username and password is generally prohibited, which makes it impossible to log on using brute force or a directory attack. However, this attack turned out to be successful. The reason is that the hackers were not trying to get access to our system, they got access to the hardware. They used vulnerabilities in the Supermicro software, a US manufacturer of server motherboards. It is a very large and well known manufacturer of server hardware with a good reputation. For the sake of convenience of remote server administration, the manufacturer has a hardware and software complex called “Supermicro IPMI”, which allows you to remotely connect to the I / O system of the motherboard and thus directly control the hardware. Naturally, it provides protection against unauthorized access. However, several critical vulnerabilities have been discovered in recent years. Access to this utility on all our servers is also restricted to addresses known to us. However, on one single server, due to uncoordinated actions of the technical support of the data center, no such restrictions were set. Due to this set of circumstances (lack of access restrictions and presence of vulnerabilities) intruders were able to get access to our equipment.

What were the consequences? As a result of malefactors’ actions all the information on one of the servers was destroyed. But it didn’t affect our clients in any way. The load of serving our customers was taken by neighboring nodes. No customer data was stolen (it was never there), no customer statistics or settings were lost, since they were copied on all other nodes. After a few days the situation was completely normalized: we examined the problem, restored the functionality of the node and ensured its further security.

But why were we attacked? Most likely, because we have some data to steal. Just like any other company, large or small, IT-related or not at all. Bear this in mind when you underestimate a hacker’s interest in your data.

In any case, the hackers did not manage to do any damage to our clients and no tangible damage to ourselves. However, it certainly added to our experience. Usually, everyone keeps a close eye on vulnerabilities in the OS, software code, libraries used, and so on. Rarely does anyone think about the fact that it is important to keep an eye on updating the motherboard firmware (BIOS) or its individual components (IPMI) for security in general. Especially since technically it is quite a complicated process. Hopefully, our story has reminded you to do both.

To prevent yourself & your company from similar cases, trust SafeDNS to provide you with DNS Security. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SafeDNS
SafeDNS breathes to make the internet safer for people all over the world with solutions ranging from AI & ML-powered web filtering, cybersecurity to threat intelligence. Moreover, we strive to create the next generation of safer and more affordable web filtering products. Endlessly working to improve our users’ online protection, SafeDNS has also launched an innovative system powered by continuous machine learning and user behavior analytics to detect botnets and malicious websites.

黑客組織 Lazarus 偽裝成 Amazon 信件入侵

國際資安大廠 ESET 於近期發現一波惡意文件攻擊行動,受害者為一名荷蘭航太公司員工及一名比利時政治記者,他們分別經由 LinkedIn 及電子郵件收到偽裝來自 Amazon 的信件開啟後中標。這波攻擊主要目的在於竊取資訊。經過分析後,判定是由曾駭入過 Sony 的黑客組織 Lazarus 所為。

ESET 研究人員表示,這波攻擊最值得注意的是,黑客開採了 Dell 一項重大風險韌體漏洞 CVE-2021-21551,這項漏洞是在去年(2021)被揭露,位於 Dell 驅動程式 DBUtil(dbutil_2_3.sys)之中,屬於存取控管不足漏洞,可讓具本機非管理員權限的攻擊者取得核心模式執行權限,以執行惡意程式碼,風險值 8.8。此漏洞可以透過 Dell 更新的程式發布給 Dell 消費及企業終端,包括電腦、平板等,估計可能數量達千萬甚至上億台。在去年公布時,這漏洞還沒有遭到開採的記錄,且 Dell 2 也在同年即修補了 CVE-2021-21551 漏洞。

ESET 研究人員指出,這是 CVE-2021-21551 有記錄以來首次被開採,經由這項漏洞,黑客在用戶電腦中下載了一款使用者模式(user-mode)模組,而得以讀寫 Windows 核心記憶體,然後再利用核心記憶體寫入的權利,關閉 Windows 7 用以監控惡意活動的機制,包括登錄編輯程式、檔案系統、行程建立、及事件追蹤(event tracing)等。

藉由關閉 Windows 的安全監控機制,Lazarus 得以在受害者電腦中植入多種惡意程式,包括 dropper、loader、HTTPS 後門程式、HTTPS 上傳器及下載器程式,其中包括 Blindingcan 遠端存取木馬(Remote Access Trojan,RAT)。

Blindingcan 多年前即被北韓黑客用以攻擊全球多國人士,具有竊取資訊、建立或終止新程序,或是搜尋、寫入、移動與刪除、變更檔案、變更時間戳記,刪除自己蹤跡等強大能力。

除了核心記憶體外,黑客可能也已成功存取多項 Windows 內前所少見或未見的區域,研究人員說這有待日後研究。

ESET 資安專家提醒儘速升級 Dell DBUtil 韌體外,企業用戶也應規範員工,不得在公司網絡內的電腦上從事私人事務,讓黑客有可趁之機。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

黑客組織 Lazarus 偽裝成 Amazon 信件入侵

國際資安大廠 ESET 於近期發現一波惡意文件攻擊行動,受害者為一名荷蘭航太公司員工及一名比利時政治記者,他們分別經由 LinkedIn 及電子郵件收到偽裝來自 Amazon 的信件開啟後中標。這波攻擊主要目的在於竊取資訊。經過分析後,判定是由曾駭入過 Sony 的黑客組織 Lazarus 所為。

ESET 研究人員表示,這波攻擊最值得注意的是,黑客開採了 Dell 一項重大風險韌體漏洞 CVE-2021-21551,這項漏洞是在去年(2021)被揭露,位於 Dell 驅動程式 DBUtil(dbutil_2_3.sys)之中,屬於存取控管不足漏洞,可讓具本機非管理員權限的攻擊者取得核心模式執行權限,以執行惡意程式碼,風險值 8.8。此漏洞可以透過 Dell 更新的程式發布給 Dell 消費及企業終端,包括電腦、平板等,估計可能數量達千萬甚至上億台。在去年公布時,這漏洞還沒有遭到開採的記錄,且 Dell 2 也在同年即修補了 CVE-2021-21551 漏洞。

ESET 研究人員指出,這是 CVE-2021-21551 有記錄以來首次被開採,經由這項漏洞,黑客在用戶電腦中下載了一款使用者模式(user-mode)模組,而得以讀寫 Windows 核心記憶體,然後再利用核心記憶體寫入的權利,關閉 Windows 7 用以監控惡意活動的機制,包括登錄編輯程式、檔案系統、行程建立、及事件追蹤(event tracing)等。

藉由關閉 Windows 的安全監控機制,Lazarus 得以在受害者電腦中植入多種惡意程式,包括 dropper、loader、HTTPS 後門程式、HTTPS 上傳器及下載器程式,其中包括 Blindingcan 遠端存取木馬(Remote Access Trojan,RAT)。

Blindingcan 多年前即被北韓黑客用以攻擊全球多國人士,具有竊取資訊、建立或終止新程序,或是搜尋、寫入、移動與刪除、變更檔案、變更時間戳記,刪除自己蹤跡等強大能力。

除了核心記憶體外,黑客可能也已成功存取多項 Windows 內前所少見或未見的區域,研究人員說這有待日後研究。

ESET 資安專家提醒儘速升級 Dell DBUtil 韌體外,企業用戶也應規範員工,不得在公司網絡內的電腦上從事私人事務,讓黑客有可趁之機。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

OpenSSL Vulnerability – What It Means For Your OT Network

The cyber security community was deeply engrossed this week in the news that OpenSSL, the organization responsible for the software package that encrypts and secures communications across much of the internet, was about to release a patch for a newly discovered “Critical” vulnerability.

The original announcement on October 25th was met with a cyclone of reaction and commentary from security experts. However, after a few tense days of speculation, OpenSSL downgraded the vulnerability rating to “High” before publicly releasing details of the security flaw and the patch on November 1, 2022. Despite the lowered rating, and while the issue is turning out not to be the crisis that many experts had feared, this is still considered a potentially major security issue and it is important to understand it and take remedial action where necessary.

This blog will explain what OpenSSL is used for, the commotion caused by the announcement this week, what it means for your OT network’s cyber security, and offer SCADAfence’s analysts advice for protecting your network from the vulnerabilities.

Continue reading

ESET releases new SMB research, finds businesses lose hundreds of thousands of euros in data security breaches

BRATISLAVA, Nov. 10, 2022 ESET, a global leader in cybersecurity, today released its 2022 SMB Digital Security Sentiment Report, which surveyed over 1,200 cybersecurity decision-makers from small to medium-sized businesses (SMBs) in Europe and North America. The report explores cybersecurity sentiments within the broader context of recent security developments and world events shaping SMBs’ perceptions of security.

According to the new data, over two thirds of SMBs have experienced a data security incident in the past 12 months, incurring an average estimated cost of nearly €220,000. Yet the top concern over the business implications of a cyberattack named by SMBs was loss of data (29%). While these decision-makers are concerned about the possible implications of an attack, 70% of businesses surveyed admitted that their investment in cybersecurity has not kept pace with recent changes to their operational models (e.g., hybrid working).

The latest ESET Threat Report data shows a 20% year-to-date increase in 2022 in threat detections compared to last year. As many as 83% of the polled businesses believe that “cyber-warfare is a very real threat that can impact everyone,” suggesting that the ever-growing threats are significantly affecting SMB sentiment. Also, 74% of SMBs in North America and Europe believe that they are more vulnerable to cyberattacks than enterprises.

Respondents identified the following top cybersecurity concerns for the next 12 months:

  • Malware (70% in total, statistically significant difference recorded in Sweden 50%)
  • Web attacks (67% in total, statistically significant difference recorded in Spain 87%)
  • Ransomware (65% in total, statistically significant difference recorded in Denmark 80%)
  • Third-party security issues (64%)
  • Distributed denial-of-service attacks (60%)
  • Remote Desktop Protocol attacks (60% in total, statistically significant difference recorded in Spain 79%


It is no surprise, therefore, that SMBs’ overall confidence in cyber-resilience for the next 12 months remains low, with only 48% of the respondents claiming to be moderately or very confident in their cyber-resilience. It is worth noting here that the confidence among the respondents from Scandinavia (32%) was significantly lower than the rest of Europe and North America (both at 49%).

Despite major global developments such as the war in Ukraine and continuing remote work arrangements post-COVID-19, SMBs identified the number one factor significantly increasing the risk of cyberattacks as the lack of cyber-awareness among their employees (43%). Other major factors include nation-state attacks (37%), vulnerabilities in the partner/supplier ecosystem (34%), continued hybrid working (32%), and use of Remote Desktop Protocol (31%).

ESET partnered with the independent UK-based research company Insight Avenue to conduct the survey for the ESET 2022 SMB Digital Security Sentiment Report by targeting 1,212 IT security decision-makers in the UK, the US, Canada, France, Germany, Spain, Italy, Poland, Sweden, the Czech Republic, the Netherlands, Denmark, Norway, and Finland. The respondents represent businesses ranging in size from 25 to 500 employees and with varying IT security maturity and budgets.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×