当前位置:首页 > 报告详情

Tom Lancaster - 自上次边缘设备安全事件以来已经是零日Zero Days.pdf

上传人: 芦苇 编号:185936 2024-11-02 37页 2.29MB

1、 Volexity Inc.|Proprietary&ConfidentialIt Has Been 0 Days Since the Last Edge-Device Security Incident1Tom LancasterCyberThreat|December 2024TLP:WHITE Volexity Inc.|Proprietary&ConfidentialWhat are we talking about?Edge-Devices In the case of this talk those intended to help protect networks What do

2、 these attacks look like?What might you do to identify or stop these attacks on your network?2 Volexity Inc.|Proprietary&Confidential3Case 1:Ivanti Connect Secure Dec 23 Volexity Inc.|Proprietary&ConfidentialHow it started Signature designed to detect webshells on Exchange4 Volexity Inc.|Proprietary

3、&ConfidentialWebshell Discovery5 Volexity Inc.|Proprietary&ConfidentialThe Investigation Begins6 We acquire memory(RAM)and key files from the webserver Logons to the Exchange Server came from 192.168.x.x-ICS VPN device starting on December 6,2023 Volexity Inc.|Proprietary&ConfidentialAll roads lead

4、to.the ICS VPN Device7 Volexity Inc.|Proprietary&ConfidentialIvanti Connect Secure VPN Check the ICS version?Its up to date.We log into its admin interface to grab device logs and user VPN access logs What did we find?No logs Logging appears to be disabled completely8 Volexity Inc.|Proprietary&Confi

5、dentialNetwork Connections We then notice looking at historic network traffic and see:Outbound cURL request to ip- using the default Linux cURL UA.Outbound connection to external Cyberoam devices on TCP 443 afterwards.Inbound RDP(TCP 3389)and SMB(TCP 445)to machines on customer network.Authenticatio

6、ns to systems from the Pulse Secure system show a non-standard computer name(attacker system)9 Volexity Inc.|Proprietary&ConfidentialWhats going on the ICS VPN?10 Recent patch description for CVE-2023-41719 doesnt add up.Discovered by Synacktiv.Not used ITW Only affects admin panel(not web-facing).I

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文详细记录了两起针对边缘设备的网络安全事件,强调了这类设备在网络保护中的重要性。第一起事件涉及Ivanti Connect Secure VPN,攻击者在2023年12月6日通过ICS VPN设备开始攻击,利用了已知漏洞CVE-2023-41719。尽管Ivanti VPN设备具有内置的完整性检查工具,但该工具似乎被破坏,攻击者能够修改其功能并逃避检测。事件在2024年2月被揭露,随后进行了内存取证分析,确认了设备被 compromise。第二起事件发生在2024年4月,涉及Palo Alto Networks设备,攻击者使用YARA规则检测到的Python脚本进行攻击。两起事件中,攻击者都留下了痕迹,使得取证分析成为可能。文章最后强调了边缘设备作为网络安全的前沿阵地,需要特别关注和保护。
如何识别和防范攻击?" 边缘设备的安全挑战与解决方案" "从实际案例中学到的边缘设备安全教训有哪些?"
客服
商务合作
小程序
服务号
折叠