bk99.de entertain the web since 1997

Wednesday: Meta annoys AR developers, security hole at internet providers

Summary

Alongside Meta ending third-party AR effects and the Polaris Dawn launch, heise’s news round-up of 28 August 2024 reported an attack on internet providers. An unpatched hole in the network software Versa Director (CVE-2024-39717) was used to gain a foothold in at least four ISPs. There the attackers intercepted customer credentials in plain text before they were stored hashed; Lumen attributed the attack to the Chinese group Volt Typhoon.

Ideas

  • Attackers first broke into customer routers and then into the providers themselves.
  • Passwords were captured before hash protection could take effect.
  • A known hole that had not been closed everywhere was enough as a way in.
  • State-sponsored groups target infrastructure, not individuals.

Insights

  • Hashing does not protect if attackers read passwords before they are hashed.
  • Network management software is a high-value target because it touches many customers at once.

Facts

  • At least three ISPs in the USA and one outside were affected.
  • Meta closed its AR platform Spark to third parties on 14 January 2025.

References

Critique

  • As a round-up, the text deals with the security incident only briefly and without technical details on the hole.

Recommendations

  • Where possible, use second factors for provider access so that intercepted passwords alone are not enough.
  • Prioritise updates for management software that manages many customers or sites.

Read the original article

Search the Web Archive