AT&T said it's investigating and has "taken steps to mitigate" a botnet that infected more than 5,700 VoIP servers located inside its network, a spokesperson has told The Record earlier today.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-6079 | The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006. NVD description · AI analysis pending | 9.8 | 47% | PoC |
| — |
Full article298 words · extracted from therecord.media · click to collapse
AT&T said it's investigating and has "taken steps to mitigate" a botnet that infected more than 5,700 VoIP servers located inside its network, a spokesperson has told The Record earlier today. All the infected devices were EdgeMarc Enterprise Session Border Controllers, a type of Voice-over-IP server designed to balance and reroute internet telephony traffic from smaller enterprise customers to upstream mobile providers. According to Netlab, a network security division of Chinese tech giant Qihoo 360, a threat actor used an old exploit (CVE-2017-6079) to hack into unpatched EdgeMarc servers and install a modular malware strain named EwDoor. "[W]e confirmed that the attacked devices were EdgeMarc Enterprise Session Border Controller, belonging to the telecom company AT&T, and that all 5.7k active victims that we saw [...] were all geographically located in the US." The Chinese security firm said it's been tracking the EwDoor botnet and its attacks since late October 2021, during which time the malware went through at least three versions. An analysis of the malware revealed extensive backdoor and DDoS capabilities, which Netlab researchers suggested could be used to access devices to gather and steal sensitive information, such as VoIP call logs. But AT&T says it has not seen any evidence to sustain Netlab's assessment. "We have no evidence that customer data was accessed," the company said in an email earlier today. Netlab said that the 5,700 estimate it provided today was gathered following a brief window of visibility into the botnet's operations on November 8. Internet-wide scans suggest that more than 100,000 devices are using the same SSL certificate used on EdgeMarc VoIP servers, but it's unclear how many of these are vulnerable to CVE-2017-6079 and exposed to attacks.AT&T says it saw no evidence of data theft
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/att-takes-action-against-ddos-botnet-that-hijacked-voip-servers