'Drupalgeddon2' Touches Off Arms Race To Mass-Exploit Powerful Web Servers (arstechnica.com)
Researchers with Netlab 360 warn that attackers are mass-exploiting "Drupalgeddon2," the name of an extremely critical vulnerability Drupal maintainers patched in late March. The exploit allows them to take control of powerful website servers. Ars Technica reports: Formally indexed as CVE- 2018-7600, Drupalgeddon2 makes it easy for anyone on the Internet to take complete control of vulnerable servers simply by accessing a URL and injecting publicly available exploit code. Exploits allow attackers to run code of their choice without having to have an account of any type on a vulnerable website. The remote-code vulnerability harkens back to a 2014 Drupal vulnerability that also made it easy to commandeer vulnerable servers.
Drupalgeddon2 "is under active attack, and every Drupal site behind our network is being probed constantly from multiple IP addresses," Daniel Cid, CTO and founder of security firm Sucuri, told Ars. "Anyone that has not patched is hacked already at this point. Since the first public exploit was released, we are seeing this arms race between the criminals as they all try to hack as many sites as they can." China-based Netlab 360, meanwhile, said at least three competing attack groups are exploiting the vulnerability. The most active group, Netlab 360 researchers said in a blog post published Friday, is using it to install multiple malicious payloads, including cryptocurrency miners and software for performing distributed denial-of-service attacks on other domains. The group, dubbed Muhstik after a keyword that pops up in its code, relies on 11 separate command-and-control domains and IP addresses, presumably for redundancy in the event one gets taken down.
Drupalgeddon2 "is under active attack, and every Drupal site behind our network is being probed constantly from multiple IP addresses," Daniel Cid, CTO and founder of security firm Sucuri, told Ars. "Anyone that has not patched is hacked already at this point. Since the first public exploit was released, we are seeing this arms race between the criminals as they all try to hack as many sites as they can." China-based Netlab 360, meanwhile, said at least three competing attack groups are exploiting the vulnerability. The most active group, Netlab 360 researchers said in a blog post published Friday, is using it to install multiple malicious payloads, including cryptocurrency miners and software for performing distributed denial-of-service attacks on other domains. The group, dubbed Muhstik after a keyword that pops up in its code, relies on 11 separate command-and-control domains and IP addresses, presumably for redundancy in the event one gets taken down.
See subject & isn't that right, APK? Please give me a link to your awesome hosts file engine. You are a true genius and anyone who talks to you (especially ShanghaiBill and Zontar) repeatedly embarrasses themselves against you.
This story appeared two days ago on Ars Technica... How about you post breaking news instead of last week's news BeauHD? The rest of us security-types don't wait for you to get bored and start typing... as we have a dozen browser tabs on a dozen different sites so we are kept abreast of issues that impact us with a minimum of delay.
Best wishes to you though.
..because they needed to come up with a catchy name?
FIRST POST
captcha: organize
The exploit allows them to take control of powerful website servers
Powerful indeed, since you need huge resources to run Drupal decently.
Big part of the reason there are so many un-patched Drupal sites is the cost of Drupal consultants. Hourly rates in the $200+ range are a big risk vector to consider for small to medium sized sites.
Sensible people would briefly use the servers to install a lightweight, hard-to-find bitcoin miner that stayed out of the way until the victim's computer was doing nothing, but still had an internet connection. Don't get greedy. Don't thrash the hard drive or run the graphics card 'til it melts. Just take a little sip here and a little sip there, and rely on having a lot of places to go for that little sip.
I bet something like that could stay under the radar for a long, long time.
I've calculated my velocity with such exquisite precision that I have no idea where I am.
seriously, i enjoy rolling around in adult diapers with my piss and shit all coagulating - you might say I am HOSTing my own filth and I love it
Or does it matter. I would think Linux would be harder to breech.
I don't run Drupal but in a six hour period Saturday morning even my little website was hit on from 147 different IP addresses, each using 4 or 5 requests in rapid succession. Made my logs hard to read.
That's ok, Drupal's code of conduct specifically bans malicious hacking because it isn't nice. That, and any form of kink that doesn't have a parade and could be inconvenient for Dries's IPO.
God bless the Drupal CoC.
It's worse than Wordpress. That's saying something.
These garbage cms's that have an established base of "developers" with a lot of sunk costs becoming "experts" need to die. Maybe a good, easy to use cms will come along but it won't be Drupal or Wordpress.
Noice... TFA links back to the 2014 security advisory and completely misses a link to the current 2018 security advisory.
If it is so easy to inject code that can do fundamental things to those servers, why doesn't someone issue a patch via the exploit? Exploit'em back!
Why the fuck does anyone still use Drupal, it has proven time and time again to be a total clusterfuck when it comes to security and doesn't seem to be improving. It is like the turds MS churned out in the late 90's.
Hello everyone. I would like to apologize for begin the raging asshole that I am. You see I am now undergoing a treatment program in an attempt to resolve my many issues. In going through this self discovery process I have discovered that a lot of my problems, especially with my inadequacy, centers around the fact that I was repressing my homosexuality. I now know that homosexuality isn't bad it is just the repression of it and the problems that causes are bad. Most notably his repression caused me to act out at anyone who rightfully pointed out my failings. I realize now that so much of what I said was just wrong. I also realize that I have developed serious problems such as stalking, harassment, poor physical health, and feelings of inadequacy. To this end I would like to apologize to the entire slashdot community.
APK
P.S. => As part of my treatment I have been forced to read what I wrote and realize now that all the mockery and insults I received were fully justified... apk
Disclaimer: I've used and developed for both Drupal and WP professionally, for a living. A good living.
Like most PHP systems Drupal is built by monkeys on crack with zero clue about proper software architecture. Unlike WordPress though it doesn't have a 140 million+ installbase and an army of people messing around with it every day and patching holes as they pop up just about instantly. This is a problem. Add to that the fact that while both WP and Drupal are built by people who didn't know squat what they were doing when they started out, WP actually makes it somewhat easy to code around it's mess, just using a few utility functions from WP core to latch on to the DB and the user management and stearing clear of the rest of the mess, getting to doing real work roughly 10 minutes in to your first WP plugin.
Drupal OTOH is a mess through and through *and* forces you to follow along, making development much more difficult. Which is why the installbase is 'only' a few million which AFAICT isn't enough to compensate for crappy webapps built by n00bs in PHP. I expect Drupal holes like this one to be much more of a problem vis-a-vis WPs holes, simply because the userbase is orders of magnitude smaller than of WP.
My 2 cents.
We suffer more in our imagination than in reality. - Seneca
See Subject: APKoin is better than all other cyypto coin guarantee to not loose value
Get APKoin by spreading the word of "LORD of HOSTS" to all conrners of teh internet
Get APKoin by "Kick stomping heart" FAKE name slashdot l[users] who dare defy brilliant APK
Redeemable for ultra premium moose dik you can suck or take in ass
Premium rewards like suk my MEGA MAN PENIS or lick my gaint ballz
APK
P.S.=> The Soros and ROTHSCHILD backed jew bankers want to destroy CRYPTO COIN because it can derail their plans to enslave great american worker. Trump was the first major disruption to they plans APKoins is the next... apk
It's a Linux issue. Linux fucking sucks.