Roboto botnet-angrep Webmin sårbarhet på Linux-servere

Qihoo 360 Netlab-spesialister studerte Roboto botnet, som dukket opp i sommer. Botnet Roboto angriper Webmin-sårbarhet på Linux-servere.

Jegn August 2019, informasjonssikkerhetseksperter rapporterte at en bakdør ble oppdaget i Webmin, en populær systemadministrasjonsløsning for Unix-systemer (som Linux, FreeBSD, eller OpenBSD).

sårbarhet CVE-2019-15107 allowed an attacker to execute arbitrary code on the target system with superuser rights.

“Since exploiting the vulnerability was not difficult, just a few days after the disclosure of the bug information, vulnerable versions of Webmin were attacked”, – skrive experts from Qihoo 360 NetLab.

It should be noted that according to official developers, Webmin has Mer enn 1,000,000 installasjoner. Shodan discovers that more than 230,000 of them are accessible via the Internet, and according to BinaryEdge, Mer enn 470,000 installations are vulnerable and accessible via the Internet. Selvfølgelig, such a “tidbit” had to be noticed by hackers.

“The Roboto botnet was one of the first to exploit the vulnerability in Webmin. Introduced in August 2019, Roboto lately has been mainly involved in development, with evolution of not only a size of the botnet, but also of the complexity of its code”, – write researchers from Qihoo 360 NetLab.

Although the main purpose of the botnet is definitely to conduct DDoS attacks, experts have not yet noticed Roboto doing it. Researchers believe that while botnet operators are mostly busy increasing size of the botnet, they have not yet reached the actual attacks.

Les også: Den berømte infostealer “Agent Tesla” har en uvanlig dropper

Ifølge analytikere, the botnet is able to arrange DDoS using ICMP, HTTP, TCP and UDP. I tillegg, Roboto, installed on hacked Linux machines, can:

  • work as a reverse shell, which will allow an attacker to run shell commands on an infected host;
  • collect information about the system, processes and network of the infected server;
  • upload collected data to a remote server;
  • run system () kommandoer;
  • execute a file downloaded from a remote URL;
  • delete itself.

Another interesting feature of Roboto is the structure of its internal design. Bots here are organized in a P2P network and transmit commands that they receive from the management server to each other. Derfor, not every bot individually communicates with the management server. The fact is that P2P communications are not so common in DDoS botnets (you can recall Hajime Og Hide’N’Seek botnets as examples).

Som et resultat, most Roboto bots are simple “zombies” engaged in sending commands, while others work to support a P2P network or scan for other vulnerable Webmin installations to increase the size of the botnet.

Polina Lisovskaya

Jeg jobber som markedssjef i mange år nå og elsker å søke etter interessante emner for deg

Legg igjen et svar

Tilbake til toppen-knappen