Wednesday: Meta annoys AR developers, security hole at internet providers
Summary
Alongside Meta ending third-party AR effects and the Polaris Dawn launch, heise’s news round-up of 28 August 2024 reported an attack on internet providers. An unpatched hole in the network software Versa Director (CVE-2024-39717) was used to gain a foothold in at least four ISPs. There the attackers intercepted customer credentials in plain text before they were stored hashed; Lumen attributed the attack to the Chinese group Volt Typhoon.
Ideas
- Attackers first broke into customer routers and then into the providers themselves.
- Passwords were captured before hash protection could take effect.
- A known hole that had not been closed everywhere was enough as a way in.
- State-sponsored groups target infrastructure, not individuals.
Insights
- Hashing does not protect if attackers read passwords before they are hashed.
- Network management software is a high-value target because it touches many customers at once.
Facts
- At least three ISPs in the USA and one outside were affected.
- Meta closed its AR platform Spark to third parties on 14 January 2025.
References
Critique
- As a round-up, the text deals with the security incident only briefly and without technical details on the hole.
Recommendations
- Where possible, use second factors for provider access so that intercepted passwords alone are not enough.
- Prioritise updates for management software that manages many customers or sites.
Links to the original source and the Web Archive open in a new tab.