ZeroHour
Security Affairspublished ()ingested @securityaffairs

Backdoored Webmin versions were available for download for over a year

highMalwareimportance 47CVE-2019-15107

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-15107
Unauthenticated Command Injection RCE in Webmin <= 1.920

CVE-2019-15107 is a critical (CVSS 9.8) unauthenticated command injection (CWE-78) in Webmin versions 1.920 and earlier, located in the 'old' parameter of password_change.cgi. An attacker can trigger it by sending a crafted, unauthenticated request to password_change.cgi with shell metacharacters in that parameter, causing arbitrary commands to execute on the server. Because Webmin typically runs with elevated privileges, successful exploitation yields full control of the host, and the flaw has seen real-world use including ransomware operations. Any system running Webmin 1.920 or older is affected, and related reporting indicates backdoored Webmin versions were available for download for over a year, so compromised installs may not be obvious. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-25) with known ransomware use, EPSS puts the 30-day exploitation probability at 99.8%, multiple public PoCs exist, and the Roboto P2P botnet has been reported targeting Linux Webmin servers.

Do: Upgrade Webmin to a version later than 1.920 per vendor instructions, which is CISA's required action for KEV listings. Because backdoored Webmin versions were reportedly distributed for over a year, also hunt for signs of compromise (unexpected processes, outbound connections, or a modified password_change.cgi) rather than only patching. Until updated, restrict access to the Webmin interface (default TCP port 10000) to trusted networks or place it behind a VPN.

9.8100% KEV ransomware PoC ×5
  • Webmin <= 1.920
masson the order of 100,000+ internet-exposed Webmin servers
Full article415 words · extracted from securityaffairs.com · click to collapse

Webmin, the popular open-source web-based interface for Unix admin contained a remote code execution vulnerability for more than a year.

Webmin is an open-source web-based interface for system administration for Linux and Unix. It allows users using web browsers to set up user accounts, Apache, DNS, file sharing and much more.

News of the day is that Webmin contained a remote code execution vulnerability, tracked as CVE-2019-15107, for more than a year. The worst aspect of the story is that the flaw appears to be an intentional backdoor.

Install Webmin 2

The flaw affects the procedure for changing expired passwords, the backdoor could be exploited by a remote attacker to execute malicious commands with root privileges on the machine running vulnerable Webmin.

The expert decided to not report the flaw to the Webmin development team.

The issue was first discovered by security researcher Özkan Mustafa Akkuş that publicly disclosed it at the DEF CON 27 hackers conference earlier in August.

https://twitter.com/ehakkus/status/1160394550323453953

The backdoor affects Webmin 1.882 through 1.921, but experts observed that default configuration are not vulnerable because the affected feature is not enabled by default. Only version 1.890 is affected also in the default configuration.

Webmin 1.930 and Usermin version 1.780 have addressed the flaw.

“I’ve rolled out Webmin version 1.930 and Usermin version 1.780 for all repositories. This release includes several security fixes, including one potentially serious one caused by malicious code inserted into Webmin and Usermin at some point on our build infrastructure.” Webmin developers explained.

“To exploit the malicious code, your Webmin installation must have Webmin -> Webmin Configuration -> Authentication -> Password expiry policy set to Prompt users with expired passwords to enter a new one. This option is not set by default, but if it is set, it allows remote code execution,”

Developers are still investigating how and when the backdoor was inserted, but they pointed out that the exploitable code has never existed in official github repositories, so they have rebuilt from git source on new infrastructure.

It seems that only offical downloads have been compromised with a backdoor along with the SourceForge repository.

Likely the backdoor was planted by threat actors that compromised build infrastructure.

Searching with Shodan for internet-exposed Webmin installs, it is possible to find over 217,000 instances, most of them located in the United States, France and Germany. Only 1,400 are Webmin version 1.890, which is vulnerable in the default configuration.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Webmin, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/90109/hacking/backdoored-webmin.html