'Drupalgeddon2' Touches Off Arms Race To Mass-Exploit Powerful Web Servers (arstechnica.com)
Researchers with Netlab 360 warn that attackers are mass-exploiting "Drupalgeddon2," the name of an extremely critical vulnerability Drupal maintainers patched in late March. The exploit allows them to take control of powerful website servers. Ars Technica reports: Formally indexed as CVE- 2018-7600, Drupalgeddon2 makes it easy for anyone on the Internet to take complete control of vulnerable servers simply by accessing a URL and injecting publicly available exploit code. Exploits allow attackers to run code of their choice without having to have an account of any type on a vulnerable website. The remote-code vulnerability harkens back to a 2014 Drupal vulnerability that also made it easy to commandeer vulnerable servers.
Drupalgeddon2 "is under active attack, and every Drupal site behind our network is being probed constantly from multiple IP addresses," Daniel Cid, CTO and founder of security firm Sucuri, told Ars. "Anyone that has not patched is hacked already at this point. Since the first public exploit was released, we are seeing this arms race between the criminals as they all try to hack as many sites as they can." China-based Netlab 360, meanwhile, said at least three competing attack groups are exploiting the vulnerability. The most active group, Netlab 360 researchers said in a blog post published Friday, is using it to install multiple malicious payloads, including cryptocurrency miners and software for performing distributed denial-of-service attacks on other domains. The group, dubbed Muhstik after a keyword that pops up in its code, relies on 11 separate command-and-control domains and IP addresses, presumably for redundancy in the event one gets taken down.
Drupalgeddon2 "is under active attack, and every Drupal site behind our network is being probed constantly from multiple IP addresses," Daniel Cid, CTO and founder of security firm Sucuri, told Ars. "Anyone that has not patched is hacked already at this point. Since the first public exploit was released, we are seeing this arms race between the criminals as they all try to hack as many sites as they can." China-based Netlab 360, meanwhile, said at least three competing attack groups are exploiting the vulnerability. The most active group, Netlab 360 researchers said in a blog post published Friday, is using it to install multiple malicious payloads, including cryptocurrency miners and software for performing distributed denial-of-service attacks on other domains. The group, dubbed Muhstik after a keyword that pops up in its code, relies on 11 separate command-and-control domains and IP addresses, presumably for redundancy in the event one gets taken down.
..because they needed to come up with a catchy name?
FIRST POST
captcha: organize
The exploit allows them to take control of powerful website servers
Powerful indeed, since you need huge resources to run Drupal decently.
Wow Chris: your boss at your government IT job for three-letter agencies is happy tonight! Oh wait, that boss is Trump, right?
Hosts files are Jewish plot to steal your precious bodily fluids, perpetrated by (((APK))).
Big part of the reason there are so many un-patched Drupal sites is the cost of Drupal consultants. Hourly rates in the $200+ range are a big risk vector to consider for small to medium sized sites.
Sensible people would briefly use the servers to install a lightweight, hard-to-find bitcoin miner that stayed out of the way until the victim's computer was doing nothing, but still had an internet connection. Don't get greedy. Don't thrash the hard drive or run the graphics card 'til it melts. Just take a little sip here and a little sip there, and rely on having a lot of places to go for that little sip.
I bet something like that could stay under the radar for a long, long time.
I've calculated my velocity with such exquisite precision that I have no idea where I am.
You got a problem with that, noob?
Or does it matter. I would think Linux would be harder to breech.
I don't run Drupal but in a six hour period Saturday morning even my little website was hit on from 147 different IP addresses, each using 4 or 5 requests in rapid succession. Made my logs hard to read.
That's ok, Drupal's code of conduct specifically bans malicious hacking because it isn't nice. That, and any form of kink that doesn't have a parade and could be inconvenient for Dries's IPO.
God bless the Drupal CoC.
ty for confirming that the infosec team does nothing but surf the Internet for stories they can send around. This proves what Iâ(TM)ve been telling our CIO for months
It's worse than Wordpress. That's saying something.
These garbage cms's that have an established base of "developers" with a lot of sunk costs becoming "experts" need to die. Maybe a good, easy to use cms will come along but it won't be Drupal or Wordpress.
I for one welcome our new I.T. closet cleaner overlord from the FBI.
Noice... TFA links back to the 2014 security advisory and completely misses a link to the current 2018 security advisory.
If it is so easy to inject code that can do fundamental things to those servers, why doesn't someone issue a patch via the exploit? Exploit'em back!
Why the fuck does anyone still use Drupal, it has proven time and time again to be a total clusterfuck when it comes to security and doesn't seem to be improving. It is like the turds MS churned out in the late 90's.
Hello everyone. I would like to apologize for begin the raging asshole that I am. You see I am now undergoing a treatment program in an attempt to resolve my many issues. In going through this self discovery process I have discovered that a lot of my problems, especially with my inadequacy, centers around the fact that I was repressing my homosexuality. I now know that homosexuality isn't bad it is just the repression of it and the problems that causes are bad. Most notably his repression caused me to act out at anyone who rightfully pointed out my failings. I realize now that so much of what I said was just wrong. I also realize that I have developed serious problems such as stalking, harassment, poor physical health, and feelings of inadequacy. To this end I would like to apologize to the entire slashdot community.
APK
P.S. => As part of my treatment I have been forced to read what I wrote and realize now that all the mockery and insults I received were fully justified... apk
Disclaimer: I've used and developed for both Drupal and WP professionally, for a living. A good living.
Like most PHP systems Drupal is built by monkeys on crack with zero clue about proper software architecture. Unlike WordPress though it doesn't have a 140 million+ installbase and an army of people messing around with it every day and patching holes as they pop up just about instantly. This is a problem. Add to that the fact that while both WP and Drupal are built by people who didn't know squat what they were doing when they started out, WP actually makes it somewhat easy to code around it's mess, just using a few utility functions from WP core to latch on to the DB and the user management and stearing clear of the rest of the mess, getting to doing real work roughly 10 minutes in to your first WP plugin.
Drupal OTOH is a mess through and through *and* forces you to follow along, making development much more difficult. Which is why the installbase is 'only' a few million which AFAICT isn't enough to compensate for crappy webapps built by n00bs in PHP. I expect Drupal holes like this one to be much more of a problem vis-a-vis WPs holes, simply because the userbase is orders of magnitude smaller than of WP.
My 2 cents.
We suffer more in our imagination than in reality. - Seneca
creimer, this is the only clicks you are getting to get from now on since youtube barred your stupid click-bot.
MODDOWN! ; creimer youtube spam post again!
creimer wants you to click on his youtube channel, then click on his stupid amazon affiliate link spam on Youtube. There is nothing of value on creimer youtube channel. Only creimer click-bot goes there.
Last week of April! Get your Goat C on and let's get a 1,000+ views on this video!! Go, Slashdot, go!
See Subject: APKoin is better than all other cyypto coin guarantee to not loose value
Get APKoin by spreading the word of "LORD of HOSTS" to all conrners of teh internet
Get APKoin by "Kick stomping heart" FAKE name slashdot l[users] who dare defy brilliant APK
Redeemable for ultra premium moose dik you can suck or take in ass
Premium rewards like suk my MEGA MAN PENIS or lick my gaint ballz
APK
P.S.=> The Soros and ROTHSCHILD backed jew bankers want to destroy CRYPTO COIN because it can derail their plans to enslave great american worker. Trump was the first major disruption to they plans APKoins is the next... apk
It's a Linux issue. Linux fucking sucks.