Friday, January 27, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

Microsoft Warns of Boa Web Server Risks After Hackers Target It in Power Grid Attacks

Researcher by Researcher
November 25, 2022
in Cybersecurity
0
High-Severity Flaw in Argo CD is Information Leak Risk
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Microsoft is warning organizations about the risks associated with the discontinued Boa web server after vulnerabilities affecting the software were apparently exploited by threat actors in an operation aimed at the energy sector.

In 2021, threat intelligence company Recorded Future reported seeing a Chinese threat group targeting operational assets within India’s power grid. In April 2022, the cybersecurity firm published a new report describing attacks launched by a different Chinese state-sponsored threat actor against organizations in India’s power sector.

Targets included several State Load Despatch Centres (SLDCs) responsible for carrying out grid control and electricity dispatch operations. These SLDCs maintain grid frequency and stability through access to supervisory control and data acquisition (SCADA) systems.

When it released its report in April, Recorded Future shared some indicators of compromise (IoCs) to help organizations detect potential intrusions.

Microsoft has analyzed the IP addresses included in those IoCs and determined that they hosted Boa, an open source web server designed for embedded applications. The problem is that Boa has been discontinued since 2005, but it’s still present in many IoT devices.

“Microsoft assesses that Boa servers were running on the IP addresses on the list of IOCs published by Recorded Future at the time of the report’s release and that the electrical grid attack targeted exposed IoT devices running Boa,” Microsoft said in a blog post published on Tuesday.

An analysis conducted by the tech giant showed that some of the IP addresses were associated with vulnerable IoT devices, such as routers, housed by organizations in critical industries.

A Shodan search reveals hundreds of thousands of internet-exposed Boa web servers, including many in South Korea, Taiwan and the United States.

While Boa is no longer maintained, vulnerabilities are still being found in the web server, such as CVE-2017-9833, which allows arbitrary file access, and CVE-2021-33558, which can lead to information disclosure.

According to Microsoft, an unauthenticated attacker could exploit these vulnerabilities to obtain user credentials and leverage them for remote code execution.

One major issue related to Boa is that its presence in a product may not even be known as it’s often included in popular SDKs. For instance, a Realtek SDK provided to companies that make routers, access points and other gateway devices includes the Boa web server. It’s worth noting that Realtek SDK vulnerabilities have been known to be exploited in attacks.

“The popularity of the Boa web server displays the potential exposure risk of an insecure supply chain, even when security best practices are applied to devices in the network,” Microsoft said. “Updating the firmware of IoT devices does not always patch SDKs or specific SOC components and there is limited visibility into components and whether they can be updated.”

“The known CVEs impacting such components can allow an attacker to collect information about network assets before initiating attacks, and to gain access to a network undetected by obtaining valid credentials. In critical infrastructure networks, being able to collect information undetected prior to the attack allows the attackers to have much greater impact once the attack is initiated, potentially disrupting operations that can cost millions of dollars and affect millions of people,” it added.

Microsoft said it continues to see attacks targeting Boa vulnerabilities.

Recorded Future said that while it had not seen any evidence of industrial control system (ICS) networks being compromised in the attacks aimed at India’s energy sector, it could not rule it out. Now, Microsoft has also warned that the use of vulnerable components, such as Boa, could pose risks to IoT, as well as OT environments.

Related: Realtek SDK Vulnerability Exposes Routers From Many Vendors to Remote Attacks

Related: Security Camera Feeds Exposed Due to Flaw in SDK Used by Many Vendors

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:





Source link

Related articles

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

January 27, 2023
Learn cutting-edge ethical hacking techniques for just $39.99

Learn cutting-edge ethical hacking techniques for just $39.99

January 27, 2023
Tags: AttacksBoaGridHackersMicrosoftpowerrisksServertargetwarnsweb
Share76Tweet47

Related Posts

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

January 27, 2023
0

Authorities in the United States and Europe have announced the results of a major law enforcement operation targeting the Hive...

Learn cutting-edge ethical hacking techniques for just $39.99

Learn cutting-edge ethical hacking techniques for just $39.99

January 27, 2023
0

The 2023 Masters in Cyber Security Certification Bundle includes full online training prep for key cybersecurity exams. Image: StackCommerce For...

U.S. Takes Down Hive Ransomware Infrastructure

U.S. Takes Down Hive Ransomware Infrastructure

January 27, 2023
0

The FBI, Europol, and law enforcement authorities from several European countries have disrupted the Hive ransomware group’s operations, seizing two...

US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’

US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’

January 26, 2023
0

The FBI has at least temporarily dismantled the network of a prolific ransomware gang it infiltrated last year, saving victims...

Cybersecurity budgets aren’t matching cybersecurity challenges

Cybersecurity budgets aren’t matching cybersecurity challenges

January 26, 2023
0

A new study finds that due to the growing threat surface from hybrid work and third-party vendors, only half of...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Multicast Domain Name System (mDNS) – Still Flooding?

Multicast Domain Name System (mDNS) – Still Flooding?

January 27, 2023
Industry Reactions to Hive Ransomware Takedown: Feedback Friday

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

January 27, 2023
Why your data is more valuable than you may realize

Why your data is more valuable than you may realize

January 27, 2023
Learn cutting-edge ethical hacking techniques for just $39.99

Learn cutting-edge ethical hacking techniques for just $39.99

January 27, 2023

Recent Posts

Multicast Domain Name System (mDNS) – Still Flooding?

Multicast Domain Name System (mDNS) – Still Flooding?

January 27, 2023
Industry Reactions to Hive Ransomware Takedown: Feedback Friday

Industry Reactions to Hive Ransomware Takedown: Feedback Friday

January 27, 2023
Why your data is more valuable than you may realize

Why your data is more valuable than you may realize

January 27, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Finds Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved