This Week in Security: The Internet Archive, Glitching With a Lighter, and Firefox In-the-wild Jonathan Bennett | usagoldmines.com

The Internet Archive has been hacked. This is an ongoing story, but it looks like this started at least as early as September 28, while the site itself was showing a creative message on October 9th, telling visitors they should be watching for their email addresses to show up on Have I Been Pwnd.

Hi folks, yes, I’m aware of this. I’ve been in communication with the Internet Archive over the last few days re the data breach, didn’t know the site was defaced until people started flagging it with me just now. More soon. https://t.co/uRROXX1CF9

— Troy Hunt (@troyhunt) October 9, 2024

There are questions still. The site defacement seems to have included either a subdomain takeover, or a long tail attack resulting from the polyfill takeover. So far my money is on something else as the initial vector, and the polyfill subdomain as essentially a red herring.

Troy Hunt has confirmed that he received 31 million records, loaded them into the HIBP database, and sent out notices to subscribers. The Internet Archive had email addresses, usernames, and bcrypt hashed passwords.

In addition, the Archive has been facing Distributed Denial of Service (DDoS) attacks off and on this week. It’s open question whether the same people are behind the breach, the message, and the DDoS. So far it looks like one group or individual is behind both the breach and vandalism, and another group, SN_BLACKMETA, is behind the DDoS.

Palo Alto Expedition

Researchers at HORIZON3 started with a known vulnerability in Palo Alto’s Expedition application. This follows a pattern we’ve seen many times before. A vulnerability is found, usually in a codebase or niche that hadn’t been considered interesting to researchers. A new vulnerability is announced, and suddenly the boring code seems interesting.

The new vulnerability was pretty straightforward — an HTTP call to a specific endpoint resets the admin password to default. The obvious next step was to look for something to do with this new admin power. Expedition uses cron to schedule tasks, and while there didn’t seem to be a way to directly set the command, the start time wasn’t sanitized, and ended up part of a string executed in bash. Yes, it’s a simple command line injection. Sometimes the simple approach just works.

The flaws were fixed with 1.2.96. As Expedition is intended for network migration, it’s not expected to be run indefinitely. Shodan lists a whopping 23 Expedition servers on the Internet. Don’t be like those guys.

Arbitrary Write, But Read Only Filesystem

[Stefan Schiller] from Sonar had an interesting challenge. He had found an arbitrary file upload widget in a node.js application. This sort of write anything anywhere flaw is usually an instant exploit, with many options to choose from. This particular application was hardened: The filesystem was read only. This is a great strategy for making exploitation harder. But as we see here, it’s not foolproof. In Unix, everything is a file. And that means that file write vulnerabilities are useful even with a read-only FS.

In this case, the weak point was an anonymous pipe, an inter-process communication (IPC) construction. The Linux procfs puts those pipes on the filesystem. Listening on the other end of one of those pipes was libuv, a signal handling library. One of the things this library does with these messages is to jump execution to a pointer in the message, as a callback function implementation. Build this data structure properly, and you have shell code execution. Nifty!

Glitching With a Lighter

Memory glitching attacks are really cool. And most of the time, they’re pretty difficult to pull off. Getting access often means physically attacking a chip, or using some expensive EM generator. [David Buchanan] wanted to know if that style of attack is possible with makeshift tools. So, he channeled his inner MacGyver, and looked at the junk in his pockets. A scrap of wire and a pocket lighter? Perfect!

That lighter didn’t use flint and steel, but instead a piezo-electric trigger. Solder the wire onto the memory chip of a laptop, and flick the lighter right next to it. That scrap of wire is suddenly an antenna, and the em burst from the lighter is enough to flip a bit. It’s rowhammer, with an antenna.

And yes, using similar techniques to rowhammer, it’s quite possible to use this to compromise a machine, assuming you can get some arbitrary data somewhere in memory. It’s a clever bit of magic, and while not particularly useful as an attack, it’s really great to see someone working with these attacks on a shoestring budget and making it work.

Firefox 0-day

It’s time to update Firefox. Mozilla has released an emergency update, version 131.0.2, to fix a critical use-after-free vulnerability in Animation timelines, part of the Web Animations API. Not much is known about this vulnerability, but it’s being used in real-world attacks already. We know that ESET discovered the flaw, but not yet whether that discovery was from observing it in use. Regardless, the fix is now available.

Bits and Bytes

We normally think of data breaches as leaking personal information, and then brace for the inevitable targeted spam. Here’s your reminder that it can be worse than that. AT&T seems to have an ongoing data breach where someone with access to shipping information for new iPhones is sending it to organized porch pirate rings.

And finally, Google Project Zero has a new post out, from [Nick Galloway], chatting about OSS-Fuzz and the Dav1d AV1 decoder. [Nick] expanded the fuzzing setup for Dav1d, and managed to find an integer overflow while at it. And while you’re here, maybe check out the OSS-Fuzz Bounty program, where Google offers to pay programmers for adding Open Source software to the OSS-Fuzz project.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Winamp Taken Down: Too Good For This Open Source World Jenny List | usagoldmines.com
Module Makes Noisy Projects Easy Al Williams | usagoldmines.com
Clockwork Derby: Digital Robo Rally, Steampunk Style Heidi Ulrich | usagoldmines.com
FLOSS Weekly Episode 805: Mastodon — Bring Your Own Algorithm Jonathan Bennett | usagoldmines.com
Keebin’ with Kristina: the One with the Folding Butterfly Keyboard Kristina Panos | usagoldmines.com
Tech In Plain Sight: Tasers Shooting Confetti Al Williams | usagoldmines.com
Linus Live-Codes Music on the Commodore 64 Elliot Williams | usagoldmines.com
Arduboy Cassette Award Explores New Features Tom Nardi | usagoldmines.com
An Arduino Triggers a Flash With Sound Jenny List | usagoldmines.com
Assessing Developer Productivity When Using AI Coding Assistants Maya Posch | usagoldmines.com
Solve: An ESP32-Based Equation Solving Calculator Dave Rowntree | usagoldmines.com
A Phone? A Ham Radio? Relax! It’s Both! Al Williams | usagoldmines.com
Your Battery Holder Is Also Your Power Switch With ToggleSlot Dave Rowntree | usagoldmines.com
Experimenting with MicroPython on the Bus Pirate 5 Chris Lott | usagoldmines.com
Mapping a Fruit Fly’s Brain with Crowdsourced Research Maya Posch | usagoldmines.com
Breaking News: 2024 Supercon SAO Contest Deadline Extended Elliot Williams | usagoldmines.com
ANTIRTOS: No RTOS Needed Dave Rowntree | usagoldmines.com
Modular Magnetic LED Matrix Danie Conradie | usagoldmines.com
What Actually Causes Warping In 3D Prints? Dave Rowntree | usagoldmines.com
A RISC-V LISP Compiler…Written In Lisp Dave Rowntree | usagoldmines.com
New Study Looks at the Potential Carcinogenicity of 3D Printing Dan Maloney | usagoldmines.com
The Greengate DS:3 Part 2: Putting a Retro Sampler to use Adam Fabio | usagoldmines.com
Solving a Retrocomputing Mystery with an Album Cover: Greengate DS:3 Adam Fabio | usagoldmines.com
Calculating the True Per Part Cost for Injection Molding vs 3D Printing Maya Posch | usagoldmines.co...
The Biological Motors That Power Our Bodies Maya Posch | usagoldmines.com
Using the 555 for Everything Bryan Cockfield | usagoldmines.com
Alphabet Soup: Haskell’s Single-Letter Naming Quirks Heidi Ulrich | usagoldmines.com
Portable Pi Palmtop Provides Plenty Jenny List | usagoldmines.com
DIY 3D-Printed Arduino Self-Balancing Cube Heidi Ulrich | usagoldmines.com
Hackaday Links: October 13, 2024 Dan Maloney | usagoldmines.com
A Homebrew Gas Chromatograph That Won’t Bust Your Budget Dan Maloney | usagoldmines.com
Bad Actors Selling Deepfake Tool To Bypass Crypto Exchange Security Protocols, According to Cybersec...
Retro Wi-Fi on a Dime: Amiga’s Slow Lane Connection Heidi Ulrich | usagoldmines.com
Building An Automotive Load Dump Tester Dave Rowntree | usagoldmines.com
Levitating Magnet In A Spherical Copper Cage Danie Conradie | usagoldmines.com
A VIC-20 with no VIC Al Williams | usagoldmines.com
All System Prompts for Anthropic’s Claude, Revealed Donald Papp | usagoldmines.com
Solar Planes Are Hard Danie Conradie | usagoldmines.com
Remembering John Wheeler: You’ve Definitely Heard of His Work Donald Papp | usagoldmines.com
Thousands Drained From Elderly Man’s Bank Account in Sophisticated ‘Hi Dad’ Email Scheme As Lender R...
Cockroaches in Space: Waste Processing and a Healthy Protein Source Combined Maya Posch | usagoldmin...
Three US Banks Reveal Data Breaches, Exposing Hundreds of Customers’ Personal and Account Informatio...
Wells Fargo, Bank of America Customers Lose Thousands of Dollars To Bank Impostor Scams – How One Vi...
Approximating an ADC with Successive Approximation Al Williams | usagoldmines.com
US Bank Customers Deposit Fake $100 Bills As Police Issue Warning on Counterfeit Cash: Report Daily ...
If You Can’t Say Anything Nice Elliot Williams | usagoldmines.com
Have You Heard Of The Liquid Powder Display? Jenny List | usagoldmines.com
What’s Your SWR? Are You Sure? Al Williams | usagoldmines.com
Are CRT TVs Important For Retro Gaming? Dave Rowntree | usagoldmines.com
PC Floppy Copy Protection: Vault Corporation Prolok Jenny List | usagoldmines.com
Repairing a Component on a Flex Connector Al Williams | usagoldmines.com
How To Make Conductive Tin Oxide Coatings On Glass Lewin Day | usagoldmines.com
C64 Gets a Graphics Upgrade Courtesy Of Your Favorite Piano Manufacturer Lewin Day | usagoldmines.co...
Hackaday Podcast Episode 292: Stainless Steel Benchies, Lego Turing Machines, and a Digital Camera M...
The US’s New Nuclear Weapons, Mysterious Fogbanks and Inertial Confinement Fusion Maya Posch | usago...
Easily Program RP2040 Boards With Your Android Device Lewin Day | usagoldmines.com
Tiny Drones Do Distributed Mapping Danie Conradie | usagoldmines.com
Symbolic Nixie Tubes Become Useful For Artistic Purposes Lewin Day | usagoldmines.com
77,099 Americans Exposed As Financial Giant Leaks Private Customer Information, Discloses Data Breac...
10th-Largest US Bank Paying $3,100,000,000 Fine in Historic Admission of Guilt After Criminals ‘Dump...
Sailing the High Steppes Navarre Bartz | usagoldmines.com
A Power Supply With Ultra High Resolution Current Measurement Built In Lewin Day | usagoldmines.com
Building A Sound Camera For Under $400 Lewin Day | usagoldmines.com
Supercon 2023: Receiving Microwave Signals from Deep-Space Probes Lewin Day | usagoldmines.com
Photochromic Dye Makes Up This Novel Optical Memristor Dan Maloney | usagoldmines.com
Meet The Optical Data Format You’ve Never Heard Of Before Lewin Day | usagoldmines.com
The Internet Archive Has Been Hacked Lewin Day | usagoldmines.com
Wimbledon Goes Automated Al Williams | usagoldmines.com
The Punched Card Detective Al Williams | usagoldmines.com
Revolut Says Company Has Prevented $621,880,000 in Potentially Fraudulent Crypto and Fiat Transfers ...
On-Site Viral RNA Detection in Wastewater With Paper and Wax Microfluidics Maya Posch | usagoldmines...
3D Printed Bearings With Filament Rollers Danie Conradie | usagoldmines.com
Fail of the Week: The Case of the Curiously Colored Streetlights Dan Maloney | usagoldmines.com
FLOSS Weekly Episode 804: The AI Alliance — Asimov was Right Jonathan Bennett | usagoldmines.com
Lagrange Points and Why You Want to Get Stuck At Them Maya Posch | usagoldmines.com
Braun TS2 Radio Turns 68, Gets Makeover Al Williams | usagoldmines.com
Dot-Matrix Printer Brings Old School Feel to Today’s Headlines Dan Maloney | usagoldmines.com
What Happened to Duracell PowerCheck? Al Williams | usagoldmines.com
That’ll Go Over Like a Cement Airplane Al Williams | usagoldmines.com
$14,000 Drained From Wells Fargo Account in Alleged Chemical Con Job – Bank Says ‘Your Money Is Gone...
Soaring at Scale: Modular Airship Design Heidi Ulrich | usagoldmines.com
A Flip Digit Clock, Binary Style Jenny List | usagoldmines.com
Mechanical Tool Changing 3D Printing Prototype Al Williams | usagoldmines.com
3D Printering: Listen to Klipper Al Williams | usagoldmines.com
Recycling Tough Plastics Into Precursors With Some Smart Catalyst Chemistry Lewin Day | usagoldmines...
Running Game Boy Games On STM32 MCUs is Peanuts Maya Posch | usagoldmines.com
Printed Rack Holds Pair of LattePandas In Style Tom Nardi | usagoldmines.com
Barbie’s Video Has Never Looked So Good Jenny List | usagoldmines.com
GPS Tracking in the Trackless Land | usagoldmines.com
Using Donor Immune Cells to Mass-Produce CAR-T Autoimmune Therapies | usagoldmines.com
Internet Service Giant Says 237,703 Customers’ Social Security Numbers Exposed in Major Data Breach ...
The Piezoelectric Glitching Attack | usagoldmines.com
The Turing Machine Made Real, In Lego | usagoldmines.com
JawnCon 0x1 Kicks off Friday, Tickets Almost Gone | usagoldmines.com
Hack On Self: The Alt-Tab Annihilator | usagoldmines.com
Vehicle-To-Everything: the Looming Smart Traffic Experience | usagoldmines.com
First Benchies in Stainless Steel, With Lasers | usagoldmines.com
WiFi Meets LoRa for Long Range | usagoldmines.com
2View: The Self-Erasing VHS Tape With Paperclip Hack | usagoldmines.com
3D Printed Hydrofoil Goes From Model Scale To Human Scale With Flight Controller | usagoldmines.com

Leave a Reply