Hacking victim Bit9 blames SQL injection flaw
Security vendor's breach came after it failed to install its own security software
IDG News Service - Bit9 said a common Web application vulnerability was responsible for allowing hackers to ironically use the security vendor's systems as a launch pad for attacks on other organizations.
Based in Waltham, Massachusetts, the company sells a security platform that is designed in part to stop hackers from installing their own malicious software. In an embarrassing admission, Bit9 said earlier this month that it neglected to install its own software on a part of its network, which lead to the compromise.
In a more detailed explanation on its blog on Monday, Bit9 said attackers gained access by exploiting a SQL injection flaw in one of its Internet-facing Web servers. A SQL injection flaw can allow a hacker to enter commands into a web-based form and get the backend database to respond.
The compromise happened around July 2012, wrote Bit9's CTO Harry Sverdlove. Once inside Bit9, the hackers accessed a virtual machine used to digitally sign code for Bit9, a security measure that verifies the company's code is legitimate.
The compromised server was shut down for about six months, but was brought back online in January. Bit9 then discovered the problem. "We took immediate containment and remediation steps, revoked the certificate in question and reached out to our entire customer base," Sverdlove wrote.
The hackers used Bit9's certificate to sign 32 of their own malicious files and scripts. Sverdlove described some of the malware as backdoors with the names "HiKit" and "HomeUNIX."
With Bit9's certificate, the malware would look legitimate to other security software. As its investigation unfolded, Bit9 found that the hackers planted the malware on other websites, constructing what is known as a drive-by-download attack.
That attack would exploit users running outdated versions of Oracle's Java software, which had been found to contain numerous vulnerabilities in recent months.
"We believe the attackers inserted a malicious Java applet onto those sites that used a vulnerability in Java to deliver additional malicious files, including files signed by the compromised certificate," Sverdlove wrote.
All told, three Bit9 customers were attacked, but Sverdlove did not reveal their names. More than 1,000 companies use Bit9's software, including Fortune 500 companies in banking, energy, aerospace and defense and U.S. federal government agencies.
Sverdlove wrote that the attacks appeared to be designed to "infiltrate select US organizations in a very narrow market space." Utilities, banks and government entities were not affected, he wrote.
Once the malware was installed, it communicated with servers on IP ranges belonging to network providers including New Century InfoComm Tech Co., Ltd. of Taiwan, the Asia Pacific Network Information Centre in South Brisbane, Australia, and Sparkstation in Singapore.
Bit9 said its product code was not affected, but it is reviewing its entire code base. The company also is undergoing a security audit and "addressed the errors that led to the compromise," Sverdlove wrote.
"While we believe Bit9 is the most effective protection you can have on your endpoints, I've always said there is no silver bullet to security," he wrote. "This incident has only fortified what we already knew...the enemy is persistent, sophisticated and motivated.
Send news tips and comments to email@example.com. Follow me on Twitter: @jeremy_kirk
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts