Boa 被遗忘的 Web 服务器对关键行业构成威胁

Microsoft analysts report that vulnerabilities in Boa’s Forgotten Web Servers, which were deprecated in 2005, are being used to hack organizations in the energy sector.

Back in 2021, Recorded Future discovered a Chinese hack group that was attacking power grids in India. In April 2022, the same researchers published a new report describing attacks launched by anothergovernment hackerfrom China against the Indian energy sector.

Then the attackers attacked several Indian power grid operators, compromised the national emergency response system, as well as a subsidiary of an unnamed logistics company.

Let me remind you that we also said that Chinese Government Hackers Successfully Spy on Organizations in Europe, Australia and Southeast Asia, 还有那个 China uses the Great Cannon again for DDoS attacks.

Recorded Future specialists did not report anything about the attack vector used by the hackers, but now Microsoft Security Threat Intelligence analysts write that the attackers used a vulnerable component of the Boa open-source web server. Its development was discontinued back in 2005, but Boa is still used by many IoT devices (from routers to smart cameras), as it is included in popular SDKs.

Since Boa is one of the components used to log in and access IoT device management, this greatly increases the risk of hacking critical infrastructure with vulnerable IoT devices running a vulnerable web server.

According to Microsoft, in just a week, more than 1 million Boa server components were discovered worldwide, accessible via the Internet.

Boa 被遗忘的 Web 服务器

Boa servers are affected by several known vulnerabilities, including arbitrary file access (CVE-2017-9833) and information disclosure (CVE-2021-33558). Microsoft continues to see how attackers try to exploit vulnerabilities in Boa <...>, meaning the web server is still an attack vector.the researchers write.

Essentially, an unauthenticated attacker could exploit these vulnerabilities to obtain user credentials and then use them to remotely execute code. For example, in one of the latest attacks using these vulnerabilities, Hive ransomware operators compromised Tata Power, India’s largest energy company.

The attack, detailed in the Recorded Future report, was one of several attempts to invade India’s critical infrastructure since 2020. 同时, the last attack was confirmed in October 2022. The popularity of the Boa web server is indicative of the potential risk that an insecure supply chain carries, even if best practices are applied to devices on the network.analysts write.

关于作者

卡琳娜·威尔逊

随着超过 10 多年在线和印刷媒体写作经验, 我是提供清晰且引人注目的文案的专家.

我曾为一家领先的 SEO 文案机构撰写文章,也为一些英国最知名的品牌撰写文章, 杂志和报纸.

发表评论