bk99.de entertain the web since 1997

Security hole in SugarCRM servers actively exploited

Summary

In early 2023 attackers exploited a critical hole in SugarCRM (CVE-2023-22952) to take over servers and install malware. Authentication could be bypassed via the path /index.php/, after which a POST request uploaded a PNG file containing PHP code that was executed when called up later. By 11 January Censys found 354 compromised servers, just under twelve percent of all 3,059 reachable instances.

Ideas

  • Exploit code was circulating publicly even before the hotfix.
  • An image file with embedded PHP code served as a backdoor.
  • Only installations with the Sugaridentity identity management were not affected.
  • Cloud instances operated by SugarCRM were patched immediately.

Insights

  • Self-hosted business software is only as secure as its operators’ patching speed.
  • After a patch, you also have to check whether a break-in has already happened.

Facts

  • SugarCRM published an advisory and hotfix on 5 January 2023.
  • Most compromised servers were in the USA, Germany, Australia and France.

References

Critique

  • The report refers to Censys’ indicators of compromise but does not list them itself.

Recommendations

  • After critical holes, check your own servers against published indicators of compromise.
  • In web applications, prevent scripts from being executed in upload and cache directories.

Read the original article

Search the Web Archive