News

To attack government networks, hackers combine Zerologon problem with VPN vulnerabilities

Representatives of the FBI and the Cybersecurity and Infrastructure Protection Agency, part of the US Department of Homeland Security (DHS CISA), issued a warning that hackers combine the Zerologon problem (CVE-2020-1472) with various VPN bugs to attack governmental networks.

Attacks on government and nongovernmental networks have already been reported.

“CISA is aware of a number of cases, when such activities have led to unauthorized access to electoral support systems. However, to date, CISA has no evidence that the integrity of this data has been compromised”, — says the warning.

According to law enforcement officials, in the course of such attacks, cybercriminals exploit at least two vulnerabilities: CVE-2018-13379 and CVE-2020-1472.

The first issue (CVE-2018-13379) was discovered as part of the Fortinet FortiOS Secure Socket Layer (SSL) VPN, a local VPN commonly used as a secure gateway to access corporate networks from remote locations.

The second issue (CVE-2018-13379) allows attackers to upload malicious files to unsecured systems and take over Fortinet VPN servers.

As for the Zerologon vulnerability, let me remind you that it relies on a weak cryptographic algorithm used in the Netlogon authentication process. The problem was named Zerologon, since the attack is carried out by adding zeros to certain Netlogon authentication parameters.

As a result, the bug allows an attacker to manipulate authentication, namely:

  • impersonate any computer on the network during authentication with a domain controller;
  • disable security mechanisms during Netlogon authentication;
  • change the computer password in the Active Directory domain controller.

The CISA and the FBI explain that hackers combine these vulnerabilities, starting by taking over Fortinet servers and then moving on to taking over the internal network with Zerologon.

Experts also warned that in addition to bugs in Fortinet products, hackers can use any other vulnerabilities in VPN solutions and gateways, because there have been a lot of such bugs recently.

Suffice it to recall the following problems:

  • corporate VPN Pulse Secure Connect (CVE-2019-11510);
  • VPN Global Protect from Palo Alto Networks (CVE-2019-1579);
  • Citrix ADC servers and Citrix network gateways (CVE-2019-19781);
  • Servers for managing mobile devices MobileIron (CVE-2020-15505);
  • F5 BIG-IP load balancers (CVE-2020-5902).

Let me remind you that US autorities are afraid of attacks by foreign hackers and ransomware attacks during presidential election.

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove Kurlibat.xyz pop-up ads (Virus Removal Guide)

Kurlibat.xyz is a site that tries to trick you into clik to its browser notifications…

14 hours ago

Remove Initiateintenselyrenewedthe-file.top pop-up ads (Virus Removal Guide)

Initiateintenselyrenewedthe-file.top is a domain that tries to trick you into clik to its browser notifications…

14 hours ago

Remove Wotigorn.xyz pop-up ads (Virus Removal Guide)

Wotigorn.xyz is a site that tries to force you into subscribing to its browser notifications…

14 hours ago

Remove Initiateintenselyprogressivethe-file.top pop-up ads (Virus Removal Guide)

Initiateintenselyprogressivethe-file.top is a domain that tries to force you into clik to its browser notifications…

14 hours ago

Remove Nuesobatoxylors.co.in pop-up ads (Virus Removal Guide)

Nuesobatoxylors.co.in is a domain that tries to trick you into subscribing to its browser notifications…

18 hours ago

Remove Helistym.xyz pop-up ads (Virus Removal Guide)

Helistym.xyz is a site that tries to force you into clik to its browser notifications…

18 hours ago