ZeroHour
Security Affairspublished ()ingested @securityaffairs

ZoneAlarm forum site hack exposed data of thousands of users

criticalData breachimportance 60CVE-2019-16759

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-16759
Pre-Authentication Remote Code Execution in vBulletin 5.x

CVE-2019-16759 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in vBulletin 5.x through 5.5.4 (CWE-94, code injection) in the PHP widget rendering component. An attacker triggers it by sending a crafted request to the 'ajax/render/widget_php' routestring with a malicious PHP payload in the widgetConfig[code] parameter, requiring no credentials or user interaction. Successful exploitation yields remote command execution on the web server as the web application user, enabling full compromise of the forum, theft or modification of its user database, and a foothold for further network access. Any site running vBulletin 5.x through 5.5.4 is affected, and exploitation is confirmed in the wild: the flaw was attacked as a zero-day after public exploits appeared, with headline-reported compromises including the Comodo Forums breach affecting about 245,000 users and the ZoneAlarm forum hack, and botnets observed exploiting the flaw. It is listed in CISA KEV (added 2021-11-03) with a 99.7% EPSS score, indicating near-certain near-term exploitation probability.

Do: Upgrade vBulletin to a release newer than 5.5.4 (the patched 5.5.x version per vendor instructions), as required by the CISA KEV action. As an interim mitigation, block or filter requests to the 'ajax/render/widget_php' routestring (or strip the widgetConfig[code] parameter) at the web server or WAF. Because exploitation requires no authentication and public PoC exploits are widely available, assume compromise and check logs for requests to ajax/render/widget_php containing widgetConfig[code], and investigate any forum for signs of data theft or web shell implantation.

9.8100% KEV PoC ×9
  • vBulletin 5.x through 5.5.4
largetens of thousands of internet-exposed vBulletin 5.x forum installations (plausibly 10k–100k+ sites, translating to hundreds of thousands to millions of forum…

Indicators of compromiseAll →

TypeIndicatorContext
domainforums.zonealarm.comed members is not so great, the incident only impacted the “forums.zonealarm.com” domain, which has roughly 4,500 subscribers. “This is a se
Full article490 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 11, 2019

This is really an embarrassing incident, ZoneAlarm forum site has suffered a data breach exposing data of its discussion forum users.

ZonaAlarm, the popular security software firm owned by Check Point Technologies, has suffered a data breach. According to the post published by The Hacker News, the security breach exposed the data of ZonaAlarm discussion forum users.

The ZoneAlarm suite includes antivirus software and firewall solutions to and users and small organizations, it has nearly 100 million downloads.

“Though neither ZoneAlarm or its parent company Check Point has yet publicly disclosed the security incident, the company quietly sent an alert via email to all affected users over this weekend, The Hacker News learned.” reads the post published by The Hacker News.

The company sent a data breach notification mail to forum users urging them to change their forum account passwords. At the time it is unclear when the attackers compromised the ZoneAlarm forum. The message revealed that attackers gained unauthorized access to forum members data, including names, email addresses, hashed passwords, and date of births.

The good news is that the number of affected members is not so great, the incident only impacted the “forums.zonealarm.com” domain, which has roughly 4,500 subscribers.

“This is a separate website from any other website we have and used only by a small number of subscribers who registered to this specific forum,” reads the data breach notification message. “The website became inactive in order to fix the problem and will resume as soon as it is fixed. You will be requested to reset your password once joining the forum.”

The incident is embarrassing because was caused by the lack of patch management for the impacted forum. A company spokesperson told The Hacker News that attackers exploited the CVE-2019-16759 remote code execution vulnerability in the vBulletin forum software.

In September, an anonymous hacker disclosed technical details and proof-of-concept exploit code for a critical zero-day remote code execution flaw in vBulletin. The issue could be exploited remotely by an unauthenticated attacker. The PoC exploit published by the hacker works on vBulletin versions 5.0.0 till the latest 5.5.4, and the ZoneAlarm forum was running the 5.4.4 version.

The zero-day flaw in the forum software resides in the way an internal widget file of the forum software package accepts configurations via the URL parameters. The expert discovered that the package fails to validate the parameters, an attacker could exploit it to inject commands and remotely execute code on the vulnerable install.

Another security firm suffered a data breach due to the CVE-2019-16759 remote code execution vulnerability. In October, hackers breached the ITarian Forum, the Comodo discussion board and support forum, accessing login credentials of nearly 245,000 users registered with the Comodo Forums websites. 

ZoneAlarm immediately launched an investigation into the incident and took down the forum website.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/93711/data-breach/zonealarm-forum-site-hack.html