UNAUTHENTICATED RCE THAT BYPASSES 2FA — Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networks Organizations using Ivanti Connect Secure should take action at once.
Dan Goodin – Jan 10, 2024 10:18 pm UTC EnlargeGetty Images reader comments 7
Unknown threat actors are actively targeting two critical zero-day vulnerabilities that allow them to bypass two-factor authentication and execute malicious code inside networks that use a widely used virtual private network appliance sold by Ivanti, researchers said Wednesday.
Further ReadingMore US agencies potentially hacked, this time with Pulse Secure exploitsIvanti reported bare-bones details concerning the zero-days in posts published on Wednesday that urged customers to follow mitigation guidance immediately. Tracked as CVE-2023-846805 and CVE-2024-21887, they reside in Ivanti Connect Secure, a VPN appliance often abbreviated as ICS. Formerly known as Pulse Secure, the widely used VPN has harbored previous zero-days in recent years that came under widespread exploitation, in some cases to devastating effect. Exploiters: Start your engines
When combined, these two vulnerabilities make it trivial for attackers to run commands on the system, researchers from security firm Volexity wrote in a post summarizing their investigative findings of an attack that hit a customer last month. In this particular incident, the attacker leveraged these exploits to steal configuration data, modify existing files, download remote files, and reverse tunnel from the ICS VPN appliance. Researchers Matthew Meltzer, Robert Jan Mora, Sean Koessel, Steven Adair, and Thomas Lancaster went on to write:
Volexity observed the attacker modifying legitimate ICS components and making changes to the system to evade the ICS Integrity Checker Tool. Notably, Volexity observed the attacker backdooring a legitimate CGI file (compcheck.cgi) on the ICS VPN appliance to allow command execution. Further, the attacker also modified a JavaScript file used by the Web SSL VPN component of the device in order to keylog and exfiltrate credentials for users logging into it. The information and credentials collected by the attacker allowed them to pivot to a handful of systems internally, and ultimately gain unfettered access to systems on the network.
The researchers attributed the hacks to a threat actor tracked under the alias UTA0178, which they suspect is a Chinese nation-state-level threat actor. Advertisement
Like other VPNs, the ICS sits at the edge of a protected network and acts as the gatekeeper thats supposed to allow only authorized devices to connect remotely. That position and its always-on status make the appliance ideal for targeting when code-execution vulnerabilities in them are identified. So far, the zero-days appear to have been exploited in low numbers and only in highly targeted attacks, Volexity CEO Steven Adair said in an email. He went on to write:
However, there is a very good chance that could change. There will now be a potential race to compromise devices before mitigations are applied. It is also possible that the threat actor could share the exploit or that additional attackers will otherwise figure out the exploit. If you know the detailsthe exploit is quite trivial to pull off and it requires absolutely no authentication and can be done over the Internet. The entire purposes of these devices are to provide VPN access, so by nature they sit on the Internet and are accessible.
Further ReadingCasualties keep growing in this months mass exploitation of MOVEit 0-dayThe threat landscape of 2023 was dominated by the active mass exploitation of a handful of high-impact vulnerabilities tracked under the names Citrix Bleed or designations including CVE-2022-47966, CVE-2023-34362 and CVE-2023-49103, which resided in the Citrix NetScaler Application Delivery Controller and NetScaler Gateway, the MOVEit file-transfer service, and 24 wares sold by Zoho-owned ManageEngine and ownCloud, respectively. Unless affected organizations move more quickly than they did last year to patch their networks, the latest vulnerabilities in the Ivanti appliances may receive the same treatment.
Researcher Kevin Beaumont, who proposed Connect Around as a moniker for tracking the zero-days, posted results from a scan that showed there were roughly 15,000 affected Ivanti appliances around the world exposed to the Internet. Beaumont said that hackers backed by a nation-state appeared to be behind the attacks on the Ivanti-sold device. Enlarge / Map showing geographic location of ICS deployments, led by the US, Japan, Germany, France, and Canada.Shodan Page: 1 2 Next → reader comments 7 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars
GAINESVILLE, Fla. — DJ Lagway threw for a touchdown and set up another with a long completion in his return from a strained left hamstring, and Florida upset No. 21 LSU27-16 on Saturday to give the Gators their first series victory since 2018.
Jadan Baugh‘s 55-yard scoring scamper with 3:48 remaining essentially sealed it and put the Gators (5-5, 3-4 Southeastern Conference) on the verge of becoming bowl-eligible. Florida had dropped eight in a row against ranked opponents and was 1-10 under coach Billy Napier in rivalry games.
Former Florida coach Steve Spurrier suggested all week that fans should rush the field named after him if the Gators win. But it didn’t happen.
Florida’s defense, though, deserved to be celebrated. The unit sacked Garrett Nussmeier seven times — one more than LSU (6-4, 3-3) had allowed in its first nine games combined.
Lagway provided the big plays on offense for Florida. After sitting out most of the past two losses with the injury, he connected with Elijhah Badger for a 23-yard score in the first quarter. Lagway never scrambled but was mobile enough to create extra time by moving around the pocket.
He completed 13 of 26 passes for 226 yards. Badger caught six for 131 yards.
“Elite play,” Florida coach Billy Napier said of Lagway. “God blessed that young man.”
The game started to turn in Florida’s favor when T.J. Searcy sacked Nussmeier late in the third quarter. Nussmeier fumbled, one of his linemen scooped it out of the air then fumbled again. Caleb Banks recovered in what was one of several huge plays for the defensive tackle.
The Gators went backward from there despite the solid field position and ended up punting. But Jeremy Crawshaw pinned the Tigers inside the 10-yard line.
Florida then forced a punt and started another drive in LSU territory. This time, Lagway found Badger for a 36-yard gain that set up Ja’Kobi Jackson‘s 1-yard scoring run.
LSU dominated time of possession in the first half and doubled up Florida in plays. But Nussmeier struggled to find time in the second half. He completed 27 of 47 passes for 260 yards with a touchdown and the fumble, and the Gators’ defense frustrated him in bouncing back from a subpar effort the week before in a blowout loss at Texas.
“Last week was unacceptable, and they took ownership of that,” Napier said of his defense. “There was no moping around.”
Losing three in a row — to Texas A&M, Alabama and now Florida — makes it impossible for LSU coach Brian Kelly to continue his streak of 10-win seasons, which will end at seven. Kelly won double-digit games in each of his last five seasons at Notre Dame and extended it with consecutive 10-win campaigns in Baton Rouge.
“This is a simple exercise of do you want to fight or not?” Kelly said after the loss. “Do you want to fight and take responsibility as coaches and players that we’re not playing well and we’re struggling right now? … There’s a rough spot here that we have to fight through, and we have to do it together.”
As Napier left the field following handshakes and postgame interviews, he was cheered by the fans hovering at the team’s tunnel.
“You’ve got to be a tough guy, and you got to be up for the challenge,” Napier said. “This group has proven they’re up for that. It’s harder than ever in my opinion. These guys could have pointed fingers and splintered a long time ago. That’s what I’m most proud of.”
BOULDER, Colo. — Deion Sanders watched his Colorado offense put up 49 points on the top scoring defense in the Big 12 on Saturday, but he isn’t satisfied. The coach expects dominance in all three phases of the game.
The Buffaloes outplayed Utah in two out of three phases and eventually got rolling on offense in a 49-24 victory, extending their win streak to four games and ensuring they’ll remain in the Big 12 championship race the rest of the way. Afterward, Sanders delivered a critique that sounded a little more like a warning to others.
“We haven’t even put it all together yet,” Sanders said. “Like, we haven’t even played our best game. That should be, in itself, scary. Like, man, when I said we comin’, we still comin’. We never stopped comin’. We are comin’. And we ain’t nearly there yet.”
Colorado (8-2, 6-1) got a strong start from its defense, which held the Utes (4-6, 1-6) to 83 yards on 33 plays in the first half, and a 76-yard punt return touchdown from receiver LaJohntay Wester to help make up for a bumpy start on offense. Quarterback Shedeur Sanders was intercepted on his first pass and later fumbled a snap for another turnover.
It may not have been the Buffaloes’ finest performance of the season, but it was a 25-point win over the preseason Big 12 front-runner, snapping a seven-game losing streak against a program whose last win at Folsom Field came by a score of 63-21.
“I think that speaks a lot about the program and where we are,” Deion Sanders said. “We’ve got to tighten some things up and get some things together, but you see we’re trending in the right direction.
“We started off rough. That wasn’t indicative to who Shedeur is, and I thought he was kind of OK all game long. Then I look at the stats and he’s 30-for-41 for 340 [yards] and three [touchdowns]. Like, c’mon man. I guess I’m just a hard dad to please at times, as well as a hard head coach.”
Sanders praised Utah’s defense and the problems it presented throughout the contest and said he was thankful for the challenge. It took complementary football to overcome the two first-half turnovers, with Colorado’s defense holding Utah to field goals after both takeaways. The Buffaloes didn’t surrender a touchdown until midway through the third quarter.
“Those type of things can’t happen,” Shedeur Sanders said, “and I’m going to have a talk with the whole offense and apologize for my performance out there at the very beginning, because I can’t put the team in that type of situation. I’m thankful for the defense. I may have to take them out to dinner this week for saving me and saving the team.”
Sanders responded after the fumble by guiding an 85-yard touchdown drive that featured another highlight-reel moment for Travis Hunter. Sanders threw deep to Colorado’s two-way star on a fourth-and-8, and Hunter made a leaping grab over two Utah defenders for a 25-yard gain. Sanders hit Will Sheppard for an 8-yard score on his next throw to extend Colorado’s lead to 21-6.
Hunter added to his Heisman Trophy résumé Saturday with 55 receiving yards on five catches, a 5-yard rushing touchdown on a reverse and his third interception of the season while playing 132 snaps.
When asked if he had a message for undecided Heisman voters, Deion Sanders did not hold back.
“If they can’t see, they can’t see,” Sanders said. “It is what it is. I mean, Travis is who he is. It’s supposed to go to the best college football player. I think that’s been a wrap since, what, Week 2? So we ain’t petitioning for nobody. We ain’t doing that. We’ve got a wonderful display of cameras here and I think we’re on national television every week. If they can’t see it, there’s a problem.
“Don’t allow their hatred for me to interfere with our kids’ success. They gotta stop that. Y’all gotta stop. Some of y’all are like that. Y’all gotta stop that, man. Give the kids what they deserve, man. I had my turn. I played 14 years. You had 14 years to hate me. Now let it go.”
Hunter was the Heisman front-runner in ESPN BET odds entering Week 12 at +125, ahead of Oregon quarterback Dillon Gabriel, Boise State running back Ashton Jeanty and Miami quarterback Cam Ward.
Colorado’s defense was able to constantly pressure freshman quarterback Isaac Wilson, forcing four sacks and three interceptions, and Utah finished with a mere 31 rushing yards, their fewest in a game since 2011. The preseason No. 12 Utes were considered the Big 12 favorites entering their first season in the conference but are now in danger of their first losing campaign since 2013.
“I’m in the twilight zone,” Utah coach Kyle Whittingham said. “… It’s the most difficult year of my coaching career, hands down, not even close.”
Colorado continues to control its destiny in chasing a Big 12 championship game bid, as the lone team in the 16-member conference that has lost just one conference game entering Saturday. The Buffaloes’ four-game win streak since a 31-28 home loss to Kansas State on Oct. 12 is the longest of Sanders’ two-year tenure.
After a 4-8 debut season, he has this once struggling program right where he planned to be for Year 2. In a league known for dramatic games decided by one-score margins, Sanders isn’t just trying to survive and advance to Arlington, Texas. He says he’s aiming for “flawless.”
“We expect to be here,” Sanders said. “A lot of y’all didn’t expect us to be here, and don’t think we don’t know that. But we expected to be where we are. Matter of fact, we expected to be a little better.”
Mark Webber’s role as Pulp’s fan club manager started simply enough, writing newsletters and posting out small bits of memorabilia such as postcards, stickers and badges. But, just like the band he loved, he wanted to do things a little differently.
A balloon launch to drum up publicity in their hometown of Sheffield didn’t attract too many people, he recalls, but one did make it all the way to Slovenia. The following year, he cut up a pair of Jarvis Cocker‘s trousers into 500 pieces, “all put in individually numbered envelopes and sent out to fans”.
It was 1993, a decade on from the release of Pulp‘s debut album, but still two years before they were to achieve huge mainstream success. A few years later, they decided to offer Cocker’s old Hillman Imp car, no longer roadworthy, as a competition prize. “It was crushed, compacted into a cube, someone won it, and we delivered it in a truck to their garden.”
It was genius silliness, indicative of the time. Nowadays, if you’re a young fan who loves a band or an artist, you assemble on social media – but back in the 1990s, it was all about signing up to the official fan club.
For Webber, who started out as a Pulp fan himself, it was a dream job which eventually led to him becoming the band’s tour manager – and then, just before they hit the height of their fame, joining as guitarist.
Following the group’s second and long hoped-for reunion in 2023, he is now telling his story – from super fan to joining the band – in I’m With Pulp, Are You?.
It’s not an autobiography as such, but a scrapbook of moments told mainly through ephemera collected over the last five decades, from photographs and flyers to set lists and press clippings, as well as other notes and scribblings kept through the years.
Webber went through his hoard during the pandemic lockdown. “It was in disarray at the time,” he says. “I hadn’t looked at it for so long I was finding things I couldn’t even remember what they were.”
‘We were in a bubble – suddenly the world caught up’
Advertisement
His story with Pulp starts in 1985, when he was an “obsessive” teenage music fan hanging out at a small independent record store in Chesterfield “where all the weird kids would go”. Back then, the band’s fan base was small, he says, and they were “amused” by the “daft, psychedelic kids” who followed them. They got to know them.
Webber eventually started helping out with stages sets before taking on the fan club duties. Then his role morphed again as he was called on to play guitar and keyboards at live shows, and began to contribute to songwriting.
He became an official member in 1995 – just before they became one of the biggest bands in the UK with their fifth album, Different Class, thanks to songs such as Disco 2000, Sorted For E’s and Whizz, and signature track Common People.
“Do you think it’s a coincidence that happened just as I joined?” Webber asks, laughing. “There was this trajectory. There was such a momentum building that it just became clear that, like, every next thing the group did was going to be more successful.”
It was a strange feeling, he says. “Because we were in the bubble at the time, just doing our thing, and suddenly the world had caught up and kind of realised how great Pulp was.”
I’m With Pulp documents some of the milestone moments in the band’s history, such as the 1995 Glastonbury headline set, before the release of Different Class, which came about at short notice after The Stone Roses were forced to pull out. Webber recalls how the band spent the night camping backstage.
“That was horrible because I hate camping,” he says. “And the concert, at the time it didn’t feel like such a great show. But everyone seemed to love it.”
Headlining Glastonbury – but camping in tents
Looking back at the roster of recent Glastonbury headliners – Elton John, Paul McCartney, Adele, Dua Lipa, The Killers – it’s hard to imagine any of them pitching a tent in the mud before performing to 100,000 people.
“Well, I’ve never spent the night in a tent since then,” says Webber. “So it changed my life.”
A more infamous incident in Pulp’s history was Cocker rushing the stage during Michael Jackson’s performance of Earth Song at the Brits the following year.
At the time, it didn’t feel as significant a moment as it has become in popular culture, Webber says. “There was disbelief in the moment, that he actually dared to do it. And that it was so easy to do. That’s the thing none of us could really understand, that there was no security or anything stopping anyone getting on the stage that easily.”
The aftermath was more concerning. “Like, ‘is Jarvis going to go to prison?’ Because we were starting a tour the next day.”
Ultimately, says Webber, most awards ceremonies and industry events are “boring – you have to do something to amuse yourself”.
After splitting in 2002, Pulp reunited for the first time in 2011, and then again for shows last year.
The response was “kind of amazing”, Webber says. It’s “quite likely we will play in England before we disappear again”, he hints. “There’s nothing confirmed yet but we expect there’ll be more concerts next year.”
‘I probably should have enjoyed it more’
The book documents Webber’s story. The item he was most happy to rediscover, he says, was the briefcase he used during his time as tour manager, adorned with a vintage ‘I’m With Pulp, Are You?’ sticker, which provided inspiration for the title.
“I knew I had it somewhere, but what I didn’t expect when I opened it up was that it still contained some contracts, to do lists, itineraries, a Bic biro, a packet of Setlers, and the business cards of various guest houses,” he says. “I used to carry this around everywhere, and in the days before we all had mobile phones, it had to contain everything we’d need for a concert or tour.”
After taking the time to look back, is there anything he would change?
“Well, I mean, I probably should have enjoyed it more.” Webber laughs. “I’m always like the slightly glass half-full, grass is always greener type outlook… I did maintain quite a normal life, I didn’t have an address book full of celebrities that I’d go and hang out with – not that that’s something to aspire to, but, you know, maybe I should have been a bit more wild at the time when I had the chance.”
I’m With Pulp, Are You, published by Hat & Beard, is out now, with a launch night at the ICA in London on 27 November