Hackers Exploit Misconfigured Security Testing Apps to Breach Fortune 500 Firms
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
What Happened
Threat actors are taking advantage of misconfigured security testing applications, including DVWA, OWASP Juice Shop, Hackazon, and bWAPP, to infiltrate the cloud environments of Fortune 500 firms. An investigation by Pentera revealed 1,926 vulnerable applications exposed on the public internet, often associated with overly privileged IAM roles and deployed on cloud platforms like AWS, GCP, and Azure.
Among the affected companies are Cloudflare, F5, and Palo Alto Networks, which have since addressed the vulnerabilities. Many of these applications exposed sensitive cloud credentials, did not adhere to least-privilege practices, and in over half of the cases, still used default credentials, making them easy targets for attackers.
Implications for Security
The investigation confirmed that these vulnerabilities are actively being exploited, with evidence of attackers deploying crypto miners and webshells on compromised systems. For instance, out of 616 discovered DVWA instances, approximately 20% contained artifacts from malicious actors, including the XMRig tool for mining Monero cryptocurrency.
Additionally, a persistence mechanism was found using a script named ‘watchdog.sh’, which could restore itself and re-download the mining tool if deleted. Another threat involved a PHP webshell named ‘filemanager.php’ that allowed attackers to execute commands and manage files on compromised servers.
This situation highlights the critical need for organizations to maintain a comprehensive inventory of all cloud resources, including testing applications, and to isolate them from production environments. Implementing least-privilege IAM roles for non-production systems and changing default credentials are essential steps to mitigate these risks.
Organizations should also consider setting up automatic expiration for temporary resources to further enhance their security posture. The findings from Pentera’s investigation serve as a reminder of the vulnerabilities that can arise from misconfigured applications and the importance of proactive security measures.
Key Takeaways
- Conduct a thorough inventory of all cloud resources, including security testing applications.
- Isolate testing applications from production environments to minimize risk.
- Implement least-privilege IAM roles for non-production systems to limit access.
- Change default credentials for all applications to prevent easy exploitation.
- Set up automatic expiration for temporary resources to enhance security.
Key Terms & Concepts
- DVWA: DVWA stands for Damn Vulnerable Web Application, a PHP/MySQL web application that is intentionally vulnerable for security testing.
- XMRig: XMRig is a popular open-source cryptocurrency mining software used to mine Monero.
- webshell: A webshell is a script that can be uploaded to a web server to enable remote administration of the server.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.