Jump to content

Recommended Posts

Posted
By time the hotfix was installed it was too late, the buggers has already ran the SQL injection and compromised the firewall meaning the passwords had to be changed.
Posted (edited)
By time the hotfix was installed it was too late, the buggers has already ran the SQL injection and compromised the firewall meaning the passwords had to be changed.

Did you have the Admin and/or User Portal services enabled on the WAN interface?

 

Sophos received a report on 22 April 2020, at 20:29 UTC regarding an XG Firewall with a suspicious field value visible in the management interface. Sophos commenced an investigation and the incident was determined to be an attack against physical and virtual XG Firewall units. The attack affected systems configured with either the administration (HTTPS service) or the User Portal exposed on the WAN zone.

 

The attack used a previously unknown SQL injection vulnerability to gain access to exposed XG devices. It was designed to download payloads intended to exfiltrate XG Firewall-resident data. The data for any specific firewall depends upon the specific configuration and may include usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access. Passwords associated with external authentication systems such as AD or LDAP are unaffected. At this time, there is no indication that the attack accessed anything on the local networks behind any impacted XG Firewall.

 

Although we have remediated this vulnerability, it is always a good idea to reduce attack surface wherever possible by disabling HTTPS Admin Services and User Portal access on the WAN interface. See https://community.sophos.com/kb/en-us/135414

 

2020-04-24%2019_48_14-Photos.png

 

See also: www.reddit.com/r/sysadmin/comments/g7ru9t/sophos_xg_firewall_sql_injection_and_rce

Edited by Arthur
Posted

For info, all Wave 9 Managed Service customers have had the Hotfix applied and our engineers have worked over the weekend to perform the recommended remedial tasks for all appliances. All of our customers have been contacted (if we've missed anyone on here due to incorrect/out of date contact details, please email our support desk) The actions taken are precautionary, and there is no evidence that any customer data was accessed, or any firewall data exfiltrated. A detailed account of the attack is available here; https://news.sophos.com/en-us/2020/04/26/asnarok/

 

Thankfully Sophos identified the attack, developed a hotfix and applied to all auto-updating machines very quickly. If any Sophos users on here don't have the auto-update feature enabled on their XG, instructions are here; https://community.sophos.com/kb/en-us/135415

 

Any customers who need further advice or have any questions can contact us at [email protected]

 

cheers

  • Thanks 1
  • 7 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...