ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Rudimentary attacks pose the greatest risk to midsized organizations

highRansomwareimportance 60CVE-2014-6271

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-6271
Arbitrary Code Execution in GNU Bash (Shellshock)

GNU Bash through version 4.3 improperly processes trailing strings that follow function definitions inside environment variable values, allowing injected commands to run (CWE-78, OS command injection); this flaw is widely known as 'Shellshock'. An attacker triggers it by supplying a crafted environment variable to any service that invokes Bash, most notably CGI web handlers but also SSH, DHCP clients, and other software that sets variables and spawns the shell. Successful exploitation yields arbitrary code execution with the privileges of the Bash process on the target host. Any Linux, Unix, or similar system running an unpatched Bash through 4.3 is affected, including web servers, appliances, and embedded devices that ship the shell. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2022-01-28) with a required action to apply vendor updates, and EPSS assigns it a 100% probability of exploitation within 30 days, so patching is urgent.

Do: Apply Bash updates per your OS vendor's instructions, as required by the CISA KEV listing, ensuring the installed shell is a patched build newer than the unpatched 4.3-era code. Prioritize internet-exposed systems that pass environment variables to Bash, especially CGI-based web servers, and audit embedded appliances and other Linux/Unix hosts that may have been missed by standard patching.

100% KEV
  • GNU Bourne-Again Shell (Bash) all versions through 4.3 (unpatched builds)
masshundreds of millions of installations, with hundreds of thousands to 1M+ internet-exposed systems
Full article394 words · extracted from helpnetsecurity.com · click to collapse

Rudimentary attacks, such as intrusion attempts, information gathering, and policy violations pose the greatest risk to midsized organizations, according to eSentire.

rudimentary attacks

Attacks per type heat map

“In 2016, the eSentire SOC detected almost 5 million attacks across hundreds of primarily small to medium organizations, spanning multiple industries,” said Viktors Engelbrehts, director of threat intelligence at eSentire. “Cybercriminals are attracted to easy targets because they are low risk, high reward, and require little effort to execute. However, available evidence suggests that the majority of opportunistic cyber-attacks against mid-sized businesses can be prevented by applying basic best practice security principles.”

Rudimentary attacks pose the greatest risk – cybercriminals are moving away from sophisticated malicious code attacks, with the majority of attackers preferring inexpensive and automated methods of intrusions, exploiting ‘low hanging fruit’ (representing almost 30% of all observed events). This trend is expected to continue so long as these techniques are successful.

Key findings

  • March to April and September to October were the most intense periods of threat events throughout the year, with March being the most active month, and June to July being the least active.
  • The most often observed threat categories were Intrusion Attempts, Information Gathering, and Policy Violations, representing 63% of all observed attacks.
  • Intrusions Attempts (primarily web attacks) was the top-ranking threat category, representing almost 30% of all observed events.
  • The top attack methods in the Intrusion Attempts category involve exploiting a Shellshock vulnerability (CVE-2014-6271), representing approximately 60% of all intrusion attempts.
  • OpenVAS remains the most prominent tool used for information gathering purposes, with 62% of all events attributed to this category. Attacks against the SSH protocol remain the second highest threat in this category, with 21% of all events attributed to attempts to guess or brute force passwords.
  • Web-based attacks and network scanning continue to increase as widely adapted automated tools allow a hands-off approach by threat actors.

Every organization is a target – with easier access than ever before to simple and automated tools, cybercriminals can stage attacks against every business. Attacks, such as ransomware, can reap financial gains without the painstaking effort required to identify and extract high value information from an organization’s network.

Detecting and disrupting the common methods and tools used will make attacks less effective, directly impacting cybercriminal rationale when choosing attack targets. This includes steps to minimize the attack surface and tailoring of security controls.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/05/08/rudimentary-attacks/