nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
February 2023
- 45 participants
- 195 messages
Re: [nexa] [HYDEPARK] Well, I never: AI is very proficient at designing nerve agents
by vincenzo.ciancia
Davvero scary e al contempo non vedo alcun modo di fermare la cosa. L'unica cosa che posso suggerire è la lettura di ghiaccio nove di Vonneghut e aspettare la fine. Inviato dal mio Galaxy
-------- Messaggio originale --------Da: "Diego.Latella" <diego.latella(a)isti.cnr.it> Data: 11/02/23 17:55 (GMT+01:00) A: Discussioni varie ISTI <hydepark(a)isti.cnr.it>, nexa(a)server-nexa.polito.it, associati(a)uspid.org Oggetto: [HYDEPARK] Well, I never: AI is very proficient at designing nerve agents
Buona letturayJ. NaughtonWell, I never: AI is very proficient at designing nerve agents
The Guardian
https://www.theguardian.com/commentisfree/2023/feb/11/ai-drug-discover-nerv…
--
Dott. Diego Latella - Senior Researcher CNR/ISTI, Via Moruzzi 1, 56124 Pisa, Italy (http:www.isti.cnr.it)FM&&T Lab. (http://fmt.isti.cnr.it)
CNR/GI-STS (http://gists.pi.cnr.it)https://www.isti.cnr.it/People/D.Latella - ph: +390506212982, fax: +390506212040===================The quest for a war-free world has a basic purpose: survival. But if in the process we learn how to achieve it by love rather than by fear, by kindness rather than compulsion; if in the process we learn how to combine the essential with the enjoyable, the expedient with the benevolent, the practical with the beautiful, this will be an extra incentive to embark on this great task.Above all, remember your humanity.-- Sir Joseph RotblatI don't quite know whether it is especially computer science or its subdiscipline Artificial Intelligence that has such an enormous affection for euphemism. We speak so spectacularly and so readily of computer systems that understand, that see, decide, make judgments, and so on, without ourselves recognizing our own superficiality and immeasurable naivete with respect to these concepts. And, in the process of so speaking, we anesthetise our ability to evaluate the quality of our work and, what is more important, to identify and become conscious of its end use. […] One can't escape this state without asking, again and again: "What do I actually do? What is the final application and use of the products of my work?" and ultimately, "am I content or ashamed to have contributed to this use?"-- Prof. Joseph Weizenbaum ["Not without us", ACM SIGCAS 16(2-3) 2--7 - Aug. 1986]
Feb. 11, 2023
Well, I never: AI is very proficient at designing nerve agents
by Diego.Latella
Buona letturay
J. Naughton
Well, I never: AI is very proficient at designing nerve agents
The Guardian
https://www.theguardian.com/commentisfree/2023/feb/11/ai-drug-discover-nerv…
--
Dott. Diego Latella - Senior Researcher CNR/ISTI, Via Moruzzi 1, 56124
Pisa, Italy (http:www.isti.cnr.it [1])
FM&&T Lab. (http://fmt.isti.cnr.it)
CNR/GI-STS (http://gists.pi.cnr.it)
https://www.isti.cnr.it/People/D.Latella - ph: +390506212982, fax:
+390506212040
===================
The quest for a war-free world has a basic purpose: survival. But if in
the process we learn how to achieve it by love rather than by fear, by
kindness rather than compulsion; if in the process we learn how to
combine the essential with the enjoyable, the expedient with the
benevolent, the practical with the beautiful, this will be an extra
incentive to embark on this great task.
Above all, remember your humanity.
-- Sir Joseph Rotblat
I don't quite know whether it is especially computer science or its
subdiscipline Artificial Intelligence that has such an enormous
affection for euphemism. We speak so spectacularly and so readily of
computer systems that understand, that see, decide, make judgments, and
so on, without ourselves recognizing our own superficiality and
immeasurable naivete with respect to these concepts. And, in the process
of so speaking, we anesthetise our ability to evaluate the quality of
our work and, what is more important, to identify and become conscious
of its end use. […] One can't escape this state without asking, again
and again: "What do I actually do? What is the final application and use
of the products of my work?" and ultimately, "am I content or ashamed to
have contributed to this use?"
-- Prof. Joseph Weizenbaum ["Not without us", ACM SIGCAS 16(2-3) 2--7 -
Aug. 1986]
Links:
------
[1] http://www.isti.cnr.it
Feb. 11, 2023
Re: [nexa] ChatGPT: five priorities for research
by Antonio
...
> "Amazingly, ChatGPT gets hired at L3 when interviewed for a coding
> position,” says the document. And while level three is considered an
> entry-level position on the engineering team at Google, average total
> compensation for the job is about $183,000
>
> https://www.pcmag.com/news/chatgpt-passes-google-coding-interview-for-level…
>
E' la /moda/ del momento, mettere alla prova ChatGPT nel superamento di
esami scolastici, di abilitazione, test per la selezione del personale,
ecc.:
ChatGPT can (almost) pass the US Medical Licensing Exam [1]
e, ovviamente, la /reazione/ degli esperti.
Expert reaction to study on ChatGPT almost passing the US Medical
Licensing Exam [2]
A.
[1] https://www.eurekalert.org/news-releases/978878
[2]
https://www.sciencemediacentre.org/expert-reaction-to-study-on-chatgpt-almo…
Feb. 11, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by Antonio
...
> Credo che ci sia una e una sola "ransom note" per server fisico (bare
> metal) con VMware ESXi compromesso... le macchine virtuali potrebbero
> essere anche centinaia per ciascun nodo fisico
... e ad ogni macchina virtuale potrebbero puntare decine di siti
(Name-Based Virtual Host).
Un modo, tutto sommato semplice, di controllare se in quei server è
/ospitato/ qualche
sito web potrebbe essere il /reverse IP lookup/.
Lo farei io ma in questo momento mi trovo sprovvisto dell'elenco dei 350
milioni di domini
attualmente registrati [1] ;)
A.
https://www.verisign.com/assets/domain-name-report-Q32022.pdf
Feb. 9, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by Antonio
...
> Chi non fosse del settore potrebbe pensare che in OVH siano degli
> sprovveduti, senza sapere che OVH - come altri, tipo Hetzner, dove ci
> sono altri server compromessi - affitta server fisici (bare metal) sui
> quali i clienti possono decidere di installare il sistema operativo che
> preferiscono [2], VMware ESXi compreso.
E le responsabilità ricadono sul cliente, come espressamente indicato nelle
Condizioni Particolari di Servizio [1]:
"Per quanto riguarda le installazioni ESXi su risorse Cliente dedicate
(Server Host), OVHcloud informa il
Cliente come indicato sopra. Il Cliente è interamente responsabile degli
aggiornamenti minori (patch) di ESXi
e li gestisce direttamente. A questo proposito, OVHcloud incoraggia il
Cliente a verificare regolarmente gli
aggiornamenti disponibili presso l'editor VMware. A questo scopo, il
Cliente può utilizzare il VUM (Virtual
Update Manager) di VMware. OVHcloud declina qualsiasi responsabilità in
caso di malfunzionamento del
Servizio a seguito degli aggiornamenti dell'Hypervisor installati dal
Cliente. Allo stesso modo, il Cliente si
assume la piena responsabilità della mancata applicazione degli
aggiornamenti dell'Hypervisor.
A.
[1]
https://storage.gra.cloud.ovh.net/v1/AUTH_325716a587c64897acbef9a4a4726e38/…
(pag. 6)
Feb. 9, 2023
In Italia (eh?!?) si sa sempre pochissimo degli attacchi informatici
by 380°
Buongiorno,
oltre agli attuasi casi di cronaca, ricordate il polverone sul
ransomware in Regione Lazio del 30 Luglio 2021?
La situazione al 25 Ottobre 2022 è ancora questa:
https://www.insicurezzadigitale.com/ransomware-in-regione-lazio-la-situazio…
«Ransomware in Regione Lazio, la situazione ancora sotto indagine»
--8<---------------cut here---------------start------------->8---
[...] Si fa notare inoltre che in questo contesto inSicurezzaDigitale ha
già inoltrato una richiesta di accesso ai dati (FOIA), che però al
momento non può essere espletata proprio a causa delle indagini ancora
in corso, sia da parte delle autorità che dal Garante per la Protezione
dei Dati Personali.
“In tale prospettiva il materiale di cui si chiederebbe l’ostensione è
sottoposto al segreto istruttorio“, si legge nella nostra istanza.
[...] Abbiamo visto cosa succede in Irlanda con l’attacco informatico al
sistema sanitario degli ospedali, resi fuori uso per del tempo, che ha
presentato gravi conseguenze in pazienti (donne incinta e bambini senza
visite necessarie).
--8<---------------cut here---------------end--------------->8---
Quindi non sappiamo nulla perché "le indagini sono ancora in corso",
dopo un anno e mezzo suonati.
Questo articolo del 12 Maggio 2022 tratta il problema in termini più
generali:
https://www.ilpost.it/2022/05/12/trasparenza-attacchi-informatici/
«In Italia si sa sempre pochissimo degli attacchi informatici»
--8<---------------cut here---------------start------------->8---
Le istituzioni decidono spesso di non comunicare nulla o di negare, con
il rischio che le conseguenze vengano ingigantite o sminuite
[...] La mancanza di informazioni e, come in questo caso, la negazione
fanno parte di una strategia comunicativa che negli ultimi mesi è stata
seguita anche da altre organizzazioni, ministeri e grandi aziende
interessate da attacchi informatici. Gestire le crisi in questo modo
però è una scelta che comporta diversi rischi non solo nel breve
periodo, ma anche sulla percezione generale che le persone hanno degli
attacchi informatici.
[...] Uno dei problemi più diffusi in Italia, sostiene Carola Frediani,
fondatrice della newsletter e del sito Guerre di Rete, è che vengano
date indicazioni poco chiare in merito alla natura dell’incidente. «La
semplice definizione “attacco informatico” spiega poco e si presta a
diverse possibili interpretazioni», dice. «La precisione consente di
capire meglio cosa stia accadendo e avere una maggiore percezione del
rischio. Invece spesso, a causa della scarsa trasparenza, vengono
ingigantiti attacchi in realtà banali e limitati. Ma c’è anche il
rischio opposto, cioè di percepire gli incidenti come tutti uguali,
anche quando in realtà mostrano problemi di sicurezza e vulnerabilità».
Un altro errore abbastanza comune è dichiarare fin da subito un
responsabile dell’attacco che non sempre è attribuibile con certezza: le
rivendicazioni andrebbero verificate con attenzione. Negli ultimi mesi
ci sono stati diversi casi in cui attacchi puramente criminali,
organizzati con l’obiettivo di estorcere denaro alle organizzazioni
colpite, siano stati attribuiti a gruppi di hacker russi schierati con
il governo di Vladimir Putin. Era successo, per esempio, dopo l’attacco
contro Trenitalia, di cui in seguito sono state smentite le motivazioni
politiche. «Ci sono gruppi criminali russi che sembrano avere
collegamenti con l’intelligence e quindi può esserci un allineamento
degli obiettivi», spiega Frediani. «Ma sono informazioni molto difficili
da verificare e che in ogni caso vanno contestualizzate».
[...] bisogna distinguere tra due livelli di comunicazione: da una parte
vanno protette le informazioni relative alle indagini delle autorità che
si occupano di sicurezza informatica, dall’altra è indispensabile essere
preparati alla gestione comunicativa di un attacco, soprattutto quando
le conseguenze coinvolgono le persone. «L’atteggiamento migliore è
mantenere un contatto costante con gli utenti, le persone», dice
Giustozzi. «Invece spesso si decide di nascondere tutto, negare, non
dire niente per non fare brutta figura, per non creare allarmismo. Ma le
informazioni filtrano e finiscono per generare molti sospetti».
--8<---------------cut here---------------end--------------->8---
Quindi sebbene faccia /molto/ comodo usare i problemi di scurezza
informatica come arma propagandistica per sostenere che "ha stato
Voldemort", la cosa non fa altro che indebolire _ulteriormente_ la già
asfittica cultura informatica che a stento sta cercando uno spiraglio
per /fiorire/, finalmente. Serve /aria/ (trasperenza), tanta aria
fresca!
saluti, 380°
P.S.: di nuovo, titoli come "In Italia si sa sempre pochissimo degli
attacchi informatici" servono solo a fare clickbait (perché la patria
commiserazione paga tantissimo, in Italia) ma basta leggere il testo
dell'articolo per capire /banalmente/ come tutto il mondo è paese:
trovatemi un solo rapporto serio di un incidente analogo al ransomware
di Regione Lazio in qualsiasi altro /paradiso IT/.
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
Feb. 9, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by 380°
Buongionro,
un piccolo passo indietro e /di lato/
380° <g380(a)biscuolo.net> writes:
[...]
> NetBlocks lo quantifica, perdita del 74% della connettività italiana:
>
> https://twitter.com/netblocks/status/1622227650386214913?s=20
>
> --8<---------------cut here---------------start------------->8---
>
> Confirmed: #Italy is in the midst of a major internet outage with high
> impact to leading operator Telecom Italia; real-time network data show
> national connectivity at 26% of ordinary levels; incident ongoing 📉
> #TIMDown
>
> --8<---------------cut here---------------end--------------->8---
quindi il 5 Febbraio c'è stata quella perdita di connettività, in
contemporanea agli attacchi ransomware a VMware, ma è solo una
coincidenza: giusto?
Matteo G. Flora dice:
https://twitter.com/lastknight/status/1622283570013241344?s=20
--8<---------------cut here---------------start------------->8---
[...] non è il problema segnalato con ESXi, semplicemente è stato
palesemente un problema di un carrier, legato alla connettività BGP che
infatti dava una pletora di errori.
Questi errori, come abbiamo imparato dal down di Facebook, non sono
quasi mai creati da attacchi, ma da configurazioni errate. Oltretutto
c'entra nulla con VmWare (sarebbe come dire, ho un problema di iOs, è
impazzita una mietitrebbia: c'entra una minchia).
--8<---------------cut here---------------end--------------->8---
Esiste un report ufficiale che dica che quel problema è dipeso da una
errata configurazione BGP?!? Io non lo trovo.
@TonyAlligatour risponde a Flora:
(https://twitter.com/TonyAlligatour/status/1622524731202105345?s=20)
--8<---------------cut here---------------start------------->8---
i router BGP non altro che dei dispositivi è come tali possono essere
virtualizzati anche su ESXi, se qualcuno ha sfruttato la vulnerabilità
di ESXi. potrebbe aver preso il controllo di questi dispositivi è
configurarli al suo piacimento
[...]
sembra incredibile, ma è unico modo per collegare un bug di sicurezza su
ESXi con problemi di traffico intercontinentale
--8<---------------cut here---------------end--------------->8---
Quindi domando di nuovo: HA stata una sfortuita coincidenza?
Perché non esiste un "CSIRT", un ente cyberquaicos, che fornisca report
chiari ed esaustivi su incidenti come questo BGP hijacking?!?
Sarà mica una cosa seria, questa: la connettività italiana è calata del
74% per diverse ore di Domenica 5 e siamo qui a /speculare/ su cosa è
successo?!?
[...]
saluti, 380°
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
Feb. 9, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by 380°
(...segue)
ma torniamo "a bomba" a un paio di passaggi nell'articolo:
380° <g380(a)biscuolo.net> writes:
[...]
> https://censys.io/esxwhy-a-look-at-esxiargs-ransomware/
>
> «ESXWhy: A Look at ESXiArgs Ransomware»
--8<---------------cut here---------------start------------->8---
[...] Per the VMWare advisory, to execute such an attack, the actor must
have access to a system that resides within the same network segment as
ESXi and have access to port 427. This raises the question: how was that
initial access gained if local network access is needed to exploit?
--8<---------------cut here---------------end--------------->8---
Interessantissima (quanto tecnica) domanda, perché i dettagli contano
molto; in questo caso la riposta potrebbe essere: e se avessero
compromesso una delle VM ospitate e usato quella per fare "tunneling"
verso l'host? [1]. Mi pare comunque strano perché sull'host come minimo
dovrebbe esserci un Firewall che impedisce traffico dalle VM
--8<---------------cut here---------------start------------->8---
Oddly enough, not every compromised server was running the SLP service,
although some were. Below are two screenshots showing the output of
snmpnetstat against two separate compromised servers, which display
processes listening on the network. One shows an SLP service running,
the other does not.
--8<---------------cut here---------------end--------------->8---
(l'articolo poi riporta due screenshots coi risultati dello scan)
Effettivamente /pare/ che uno degli host compromessi non avesse il
servizio SLP (quello bacato, responsabile del heap-overflow che consente
il successo dell'attacco) attivo, almeno non sulla porta di default del
servizio... o almeno non nel momento in cui è stato eseguito il comando
SNMP, magari il sysadmin ha spento il demone prima dello scan (ma dopo i
ransomware) :-)
Comunque /pare/ ci siano alcuni "segnali" che ancora non consentono di
stabilire con certezza quale sia stato esattamente il vettore di attacco
utilizzato. Mah?!?
Ultima nota: spiace un po' leggere
--8<---------------cut here---------------start------------->8---
Perhaps not surprisingly, we observed that French cloud hosting provider
OVH is by far the most affected autonomous system, with just over 1,700
infected hosts during the 6-day time period we studied.
--8<---------------cut here---------------end--------------->8---
Chi non fosse del settore potrebbe pensare che in OVH siano degli
sprovveduti, senza sapere che OVH - come altri, tipo Hetzner, dove ci
sono altri server compromessi - affitta server fisici (bare metal) sui
quali i clienti possono decidere di installare il sistema operativo che
preferiscono [2], VMware ESXi compreso.
Saluti, 380°
[...]
[1] https://www.reddit.com/r/sysadmin/comments/10tbmve/comment/j77g7rc/?utm_sou…
[2] https://www.ovhcloud.com/it/bare-metal/os/
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
Feb. 9, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by 380°
Buongiorno,
(that's why I love Lista Nexa!)
grazie Antonio per i link, davvero preziosi, specialmente il Gist!
"Marco A. Calamari" <marcoc_maillist(a)marcoc.it> writes:
> On mer, 2023-02-08 at 17:54 +0100, Antonio wrote:
[...]
>> Ma alla fine, un dubbio rimane. Quanti saranno state le /vittime/
>> dell'attacco?
>> Eccoli qua: 3805 indirizzi IP di cui 22 italiani [5].
>
> Vabbe, avranno usato Shodan per contare gli IP con la porta di default del
> servizio aperta.
Non credo abbiano usato solo quel tipo di scansione perché la tabella in
CSV allegata al gist [5] indica anche (Bitcoin wallet) "address", che
non è un'informazione che si può ricavare scansionando gli IP:
--8<---------------cut here---------------start------------->8---
ip,address,city,country,country_code,port,dns_names,reverse_dns
78.46.39.83,1HTZ1dKiwWQKBHT3QaAkypPBngaK4z76PB,,Germany,DE,443,[],[esxi]
78.46.86.170,16oEskLDvAKHa7u6PASJUijCsRgjMFD3Ff,,Germany,DE,443,[lara.smart1.eu],[lara.smart1.eu]
78.46.72.169,1HjigJrc711d2rYy8PM9GHJua3pqUxUYT9,,Germany,DE,443,[static.169.72.46.78.clients.your-server.de],[static.169.72.46.78.clients.your-server.de]
[...]
--8<---------------cut here---------------end--------------->8---
(estratto da https://gist.githubusercontent.com/cablej/bdc2ee2c84915d0b68eec9d4d4747e19/…)
Il Gist (pubblicato da Jack Cable [6] fondatore di Ransomwhere [7])
dice: «A list of ESXi victims Censys, published by Ransomwhere»
Censys [8] è un servizio di map scanning globale che fornisce ai propri
clienti servizi per consultare la "mappa di tutto su Internet":
--8<---------------cut here---------------start------------->8---
The Leading Internet Intelligence Platform for Threat Hunting and
Exposure Management. Censys empowers security teams with the most
comprehensive, accurate, and up-to-date map of the internet to defend
attack surfaces and hunt for threats.
[...] Censys Search leads the industry in internet scanning capabilities
to provide the largest, most comprehensive dataset of internet
intelligence available.
[...] The foundation of the Censys Platform is our data. Founded by the
creators of ZMap, Censys’ proprietary map of the internet offers the
most coverage, fastest discovery, and the deepest insights available.
[...] Censys has the widest breadth and depth of internet scanning data
available. We scan the top 137 ports and the top 1440 ports in the cloud
on a daily basis, while refreshing all known services within a 24 hour
time frame.
[...] Censys provides a rich understanding of everything on the
internet, enabling security teams to understand asset connections,
current configurations, and discovered threat details. Additionally,
security teams get access to the potential impacts of each risk and
recommended steps for remediation.
[...] Censys provides the most comprehensive and accurate relationship
of things on the internet. Through our advanced attribution engine, seed
data is exposed to show connected assets, which are then enriched with
contextual data for even deeper visibility.
--8<---------------cut here---------------end--------------->8---
Censys usa ZMap [9] come "motore", il software libero che ha
letteralmente cambiato il modo di fare net-scanning:
--8<---------------cut here---------------start------------->8---
ZMap is capable scanning the entire public IPv4 address space in under
45 minutes. With a 10gigE connection and PF_RING, ZMap can scan the IPv4
address space in under 5 minutes.
--8<---------------cut here---------------end--------------->8---
(da https://github.com/zmap/zmap)
Inoltre, Censys collabora con Stanford pubblicando due (degli attuali
tre) dataset liberamente disponibili su "Stanford Internet Research Data
Repository": https://scans.io/
Quindi Ransomwhere (via Jack Cable) ha usato i servizi Censys per
estrarre la tabella
Come hanno fatto a raccogliere i dati su questo ransomware è descritto
in questo post di Censys (bingo! trovato l'articolo più interessante in
assoluto in merito a questo attacco):
https://censys.io/esxwhy-a-look-at-esxiargs-ransomware/
«ESXWhy: A Look at ESXiArgs Ransomware»
--8<---------------cut here---------------start------------->8---
Executive Summary
* A ransomware campaign targeting VMWare ESXi servers began in early Februrary, 2023. The
ransomware, dubbed ESXiArgs, peaked in infections on February 3, with Censys observing 3,551
infected hosts.
* Typically, ransomware takes hosts offline and leaves few artifacts
visible to the public Internet. ESXiArgs ransomware, however, presents
ransom notes to the Internet, making them visible to Censys’ passive
scanners.
* Bitcoin wallet addresses are posted on the ransom pages, allowing us
to track payments associated with this ransomware.
* France, US, Germany, Canada, and other countries have seen attacks,
with many occurring in France, particularly against hosts on French
cloud provider OVH.
--8<---------------cut here---------------end--------------->8---
Quindi a quanto pare Censys ha dei "passive scanners" [9]... facendo
scaping (lo scraping è passivo?!? :-D ) delle "ransom notes" pubblicate
dagli attaccanti su Internet.
In fondo all'articolo è pubblicato l'URL della query al database Censys:
https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&v…
Per facilità di lettura, il testo della query è:
--8<---------------cut here---------------start------------->8---
services.http.response.body: "How to Restore Your Files" and services.http.response.html_title:"How to Restore Your Files"
--8<---------------cut here---------------end--------------->8---
Adesso quella query restituisce 1,510 hosts, perché man mano le pagine
con la richiesta di riscatto stanno sparendo
...sottolineo: non ho scritto che i server sono stati ripristinati (sono
liberi da backdoors), ho scritto che le pagine con la richiesta di
riscatto stanno pian piano sparendo, probabilmente perché sono state
"applicate le patch"
Riusciranno i nostri eroi a garantirsi che le proprie macchine con su
VMware ESXi siano prive di backdoors? :-O
> Ma a quanti server corrispondono, ed a quante macchine virtuali
> corrispondono?
Credo che ci sia una e una sola "ransom note" per server fisico (bare
metal) con VMware ESXi compromesso... le macchine virtuali potrebbero
essere anche centinaia per ciascun nodo fisico
> Sennò come si può stimare l'entità del rischio/danno?
Da fuori l'entità del rischio è **inestimabile**, quindi anche del
danno: (giustamente) solo i proprietari dei server sanno cosa ci gira
dentro
> E sopratutto. Chi sono i 22 italiani ....?
Nel CVS del Gist [5] ci sono tutti gli IP dei 22 (non ho contato) server
italiani, pare che nessuno sia istituzionale per fortuna
(continua...)
Saluti, 380°
[5] https://gist.github.com/cablej/bdc2ee2c84915d0b68eec9d4d4747e19
[6] https://en.wikipedia.org/wiki/Jack_Cable_(software_developer)
[7] https://ransomwhe.re/
[8] https://censys.io/
[9] https://en.wikipedia.org/wiki/ZMap_(software)
[10] un "passive scanner" non interagisce con il sistema monitorato
inviando un pacchetto IP o richiedendo una risposta ad un pacchetto IP
[...]
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
Feb. 9, 2023
Re: [nexa] ransomware per VMware ESXi e problemi su Internet di Domenica 5
by Giacomo Tesio
> Beh, il ransomware almeno è visibile ma chi chi lo sa in questi due anni
> (e per quanto prima?) altri "enti" sono stati in grado di portare a
> termine attacchi di tipo hyperjacking [5] senza essere stati scoperti,
> semplicemente limitandosi a spiare o a compromettere le "build chains"
> del software compilato da macchine virtuali sotto VMware ESXi?
Ma che domande fai 380°?
È ovvio che è successo decine di volte?
Per ogni violazione tanto maldestra da farsi scoprire, ne avvengono decine prima.
Ma tanto faranno tutti finta che basti aggiornare e riavviare tutto.
Come hanno fatto con log4shell.
Giacomo
Il 8 Febbraio 2023 15:12:40 UTC, "380°" <g380(a)biscuolo.net> ha scritto:
>(...continua)
>
>Il miglior report che sono riuscito a trovare è quello di Julien Levrard
>di OVH:
>
>https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/
>
>«Ransomware targeting VMware ESXi»
>
>--8<---------------cut here---------------start------------->8---
>
>[...] These attacks are detected globally. According to experts from the
>ecosystem as well as authorities, the malware is probably using
>CVE-2021-21974 as compromission vector. Investigation are still ongoing
>to confirm those assumptions.
>
>[...] In addition to the recovery procedure described earlier, we noted
>that the encryption process is only impacting a small amount of data
>within the file. Depending of your VM OS and file system type, you might
>be able to recover data with data revery tools, at least partially.
>
>[...] So far we identified the following behavior:
>
>* The compromission vector is confirmed to use a OpenSLP vulnerability
> that might be CVE-2021-21974 (still to be confirmed). The logs actually
> show the user dcui as involved in the compromission process.
>
>* Encryption is using a public key deployed by the malware in
> /tmp/public.pem
>
>* The encryption process is specifically targeting virtual machines
> files (“.vmdk”, “.vmx”, “.vmxf”, “.vmsd”, “.vmsn”, “.vswp”, “.vmss”,
> “.nvram”,”*.vmem”)
>
>* The malware tries to shutdown virtual machines by killing the VMX
> process to unlock the files. This function is not systematically
> working as expected resulting in files remaining locked.
>
>* The malware creates argsfile to store arguments passed to the encrypt
> binary (number of MB to skip, number of MB in encryption block, file
> size)
>
>* No data exfiltration occurred.
>
>--8<---------------cut here---------------end--------------->8---
>
>Perché report del genere non sono redatti dalle istituzioni preposte,
>tipo il CSIRT?!?
>
>Non è ancora definitivamente certo che il vettore di attacco sia il
>servizio CVE-2021-21974 datato 4 Gennaio 2021? ...è /quasi/ certo
>
>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21974
>
>--8<---------------cut here---------------start------------->8---
>
>OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before
>ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a
>heap-overflow vulnerability. A malicious actor residing within the same
>network segment as ESXi who has access to port 427 may be able to
>trigger the heap-overflow issue in OpenSLP service resulting in remote
>code execution.
>
>--8<---------------cut here---------------end--------------->8---
>
>OpenSLP [1] è un servizio che implementa "Service Location Protocol
>(SLP)", il cui repository ufficiale Git è su GitHub [2] sin dal 13
>Settembre 2019 [3] **ma** sulle pagine web [1] tutto fa ancora
>riferimento a SourceForge, mailing list comprese (i cui archivi si
>fermano al 2019).
>
>Il fatto che CVE-2021-21974 dica "OpenSLP as used in ESXi" indica molto
>probabilmente che la versione OpenSLP usata da VMware è stata modificata
>e il sorgente non è disponibile in formato sorgente (possono farlo
>perché è BSD), infatti nel CVE non è indicata nessuna patch al sorgente,
>contrariamente a quanto accade con il software "open source". Una
>ricerca alle issues registrate su GitHub [4] pare confermare che la
>versione ufficiale del software non abbia quel problema di
>heap-overflow... o non l'abbiano mai identificata e risolta.
>
>Lunedì 6 VMware emette un suo comunicato in merito:
>
>https://blogs.vmware.com/security/2023/02/83330.html
>
>«VMware Security Response Center (vSRC) Response to ‘ESXiArgs’
>Ransomware Attacks»
>
>--8<---------------cut here---------------start------------->8---
>
>[...] VMware has not found evidence that suggests an unknown
>vulnerability (0-day) is being used to propagate the ransomware used in
>these recent attacks. Most reports state that End of General Support
>(EOGS) and/or significantly out-of-date products are being targeted with
>known vulnerabilities which were previously addressed and disclosed in
>VMware Security Advisories (VMSAs).
>
>[...] With this in mind, we are advising customers to upgrade to the
>latest available supported releases of vSphere components to address
>currently known vulnerabilities. In addition, VMware has recommended
>disabling the OpenSLP service in ESXi. In 2021, ESXi 7.0 U2c and ESXi
>8.0 GA began shipping with the service disabled by default.
>
>--8<---------------cut here---------------end--------------->8---
>
>OK tutto chiaro no? L'attacco ransomware (a volte) è andato a buon fine
>perché non sono stati applicati gli aggiornamenti per tempo.
>
>Tutto risolto allora?
>
>Beh, il ransomware almeno è visibile ma chi chi lo sa in questi due anni
>(e per quanto prima?) altri "enti" sono stati in grado di portare a
>termine attacchi di tipo hyperjacking [5] senza essere stati scoperti,
>semplicemente limitandosi a spiare o a compromettere le "build chains"
>del software compilato da macchine virtuali sotto VMware ESXi?
>
>saluti, 380°
>
>[1] http://www.openslp.org/
>
>[2] https://github.com/openslp-org/openslp
>
>[3] https://sourceforge.net/p/openslp/mailman/message/36762757/
>
>[4] https://github.com/openslp-org/openslp/issues?q=is%3Aissue
>
>[5] https://en.wikipedia.org/wiki/Hyperjacking
>
>
>P.S.: a volte ho l'impressione che, in relazione a notizie come queste,
>si "dipinga" la situazione IT italiana con tinte molto più fosche
>rispetto a /paradisi/ tecologici esteri, tuttavia se si lascia da parte
>il pregiudizio si scopre che nell"universo IT" siamo davvero tutti nella
>stessa barca:
>https://www.voanews.com/a/us-state-court-system-us-eu-universities-hit-by-r…
>
>«US State Court System, US, EU Universities Hit by Ransomware Outbreak»
>
>--
>380° (Giovanni Biscuolo public alter ego)
>
>«Noi, incompetenti come siamo,
> non abbiamo alcun titolo per suggerire alcunché»
>
>Disinformation flourishes because many people care deeply about injustice
>but very few check the facts. Ask me about <https://stallmansupport.org>.
Feb. 8, 2023