SchoolsBroadband Posted April 25, 2020 Posted April 25, 2020 Morning all, I received the link below this morning via email. I highly suggest anyone with a Sophos XG firewall follows Sophos's advice. http://app.go.sophos.com/e/er?s=1777052651&lid=15561&elqTrackId=739249abcf3a4321852c8b6d925cab96&elq=410ad22f4f564d94b224e5c19fe64b8f&elqaid=12444&elqat=1 Dave 1
Arthur Posted April 25, 2020 Posted April 25, 2020 Link to KB article (minus the tracking): https://community.sophos.com/kb/en-us/135412 I received the same email from Sophos this morning saying the hotfix had already been applied. The automatic installation feature is definitely worth enabling. 👍
Jobos Posted April 26, 2020 Posted April 26, 2020 By time the hotfix was installed it was too late, the buggers has already ran the SQL injection and compromised the firewall meaning the passwords had to be changed.
Arthur Posted April 26, 2020 Posted April 26, 2020 (edited) By time the hotfix was installed it was too late, the buggers has already ran the SQL injection and compromised the firewall meaning the passwords had to be changed. Did you have the Admin and/or User Portal services enabled on the WAN interface? Sophos received a report on 22 April 2020, at 20:29 UTC regarding an XG Firewall with a suspicious field value visible in the management interface. Sophos commenced an investigation and the incident was determined to be an attack against physical and virtual XG Firewall units. The attack affected systems configured with either the administration (HTTPS service) or the User Portal exposed on the WAN zone. The attack used a previously unknown SQL injection vulnerability to gain access to exposed XG devices. It was designed to download payloads intended to exfiltrate XG Firewall-resident data. The data for any specific firewall depends upon the specific configuration and may include usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access. Passwords associated with external authentication systems such as AD or LDAP are unaffected. At this time, there is no indication that the attack accessed anything on the local networks behind any impacted XG Firewall. Although we have remediated this vulnerability, it is always a good idea to reduce attack surface wherever possible by disabling HTTPS Admin Services and User Portal access on the WAN interface. See https://community.sophos.com/kb/en-us/135414 See also: www.reddit.com/r/sysadmin/comments/g7ru9t/sophos_xg_firewall_sql_injection_and_rce Edited April 26, 2020 by Arthur
Wave9_Lee Posted April 27, 2020 Posted April 27, 2020 For info, all Wave 9 Managed Service customers have had the Hotfix applied and our engineers have worked over the weekend to perform the recommended remedial tasks for all appliances. All of our customers have been contacted (if we've missed anyone on here due to incorrect/out of date contact details, please email our support desk) The actions taken are precautionary, and there is no evidence that any customer data was accessed, or any firewall data exfiltrated. A detailed account of the attack is available here; https://news.sophos.com/en-us/2020/04/26/asnarok/ Thankfully Sophos identified the attack, developed a hotfix and applied to all auto-updating machines very quickly. If any Sophos users on here don't have the auto-update feature enabled on their XG, instructions are here; https://community.sophos.com/kb/en-us/135415 Any customers who need further advice or have any questions can contact us at [email protected] cheers 1
Jobos Posted November 30, 2020 Posted November 30, 2020 Bit late in the day but https://www.bleepingcomputer.com/news/security/hackers-tried-to-use-sophos-firewall-zero-day-to-deploy-ransomware did an interesting write up on the incident with a great flow chart on how it was put together.
synaesthesia Posted November 30, 2020 Posted November 30, 2020 Bit late in the day but https://www.bleepingcomputer.com/news/security/hackers-tried-to-use-sophos-firewall-zero-day-to-deploy-ransomware did an interesting write up on the incident with a great flow chart on how it was put together. Dead link?
Jobos Posted November 30, 2020 Posted November 30, 2020 Try this. https://www.bleepingcomputer.com/news/security/asnar-k-malware-exploits-firewall-zero-day-to-steal-credentials/ 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now