{"id":12595,"date":"2023-05-03T11:37:57","date_gmt":"2023-05-03T05:37:57","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=12595"},"modified":"2023-05-03T11:37:57","modified_gmt":"2023-05-03T05:37:57","slug":"summary-of-the-investigation-related-to-cve-2023-0669","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/summary-of-the-investigation-related-to-cve-2023-0669\/","title":{"rendered":"Summary of the Investigation Related to CVE-2023-0669"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-12596 size-large\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/05\/Blog-image-1920-\u00d7-1080-px-31-1024x576.png\" alt=\"\" width=\"1024\" height=\"576\" \/><\/p>\n<p>We\u2019d like to provide an update on our investigation into the suspicious activity detected in our Fortra GoAnywhere MFT solution. Working with Unit 42, we have completed our investigation and have compiled a factual summary of the investigation, as well as continuous improvement actions Fortra is taking to further strengthen our systems and recommended actions customers can take to secure their data and improve their security posture using available features in the GoAnywhere MFT solution.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>What happened:<\/strong><\/p>\n<p>On January 30, 2023, we were made aware of suspicious activity within certain instances of our GoAnywhere MFTaaS solution. We quickly implemented a temporary service outage and commenced an investigation.<\/p>\n<p>We discovered between January 28, 2023, and January 30, 2023, an unauthorized party used a previously unknown, zero-day remote code execution (RCE) vulnerability to access certain GoAnywhere customers\u2019 systems. This vulnerability was assigned CVE-2023-0669.<\/p>\n<p>Our initial investigation revealed the unauthorized party used CVE-2023-0669 to create unauthorized user accounts in some MFTaaS customer environments. For a subset of these customers, the unauthorized party leveraged these user accounts to download files from their hosted MFTaaS environments. We prioritized communication with each of these customers to share as much relevant information as available to their specific instance of the GoAnywhere platform.<\/p>\n<p>During the investigation, we discovered the unauthorized party used CVE-2023-0669 to install up to two additional tools &#8211; \u201cNetcat\u201d and \u201cErrors.jsp\u201d &#8211; in some MFTaaS customer environments between January 28, 2023 and January 31, 2023. The threat actor was not able to install both tools in every customer environment, and neither tool was consistently installed in every environment.<\/p>\n<p>When we identified the tools used in the attack, we communicated directly with each customer if either of these tools were discovered in their environment. We reprovisioned a clean and secure MFTaaS environment and worked with each MFTaaS customer to implement mitigation measures. While we continue to monitor our hosted environment, there is no evidence of unauthorized access to customer environments that have been mitigated and reprovisioned by our team.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>On Premise Customers<\/strong><\/p>\n<p>As the investigation unfolded, we were made aware the same CVE-2023-0669 was used against a small number of on-premise implementations running a specific configuration of the GoAnywhere MFT solution. Based on reports from customers, this activity pushed the unauthorized activity timeline to January 18.<\/p>\n<p>We determined that customers running an admin portal exposed to the internet, which represents a small minority of customers, were at an increased risk and promptly communicated with those customers regarding mitigation of this risk. We urgently notified all on-premise customers that a patch was available and shared additional mitigation guidance. It is important to note that Fortra does not administer the infrastructure for on-premise instances, and we worked with customers to provide support and indicators of compromise.<\/p>\n<p>At this time, we can confirm this issue was isolated to our GoAnywhere MFT solution and does not involve any other aspects of the Fortra business, or its customers.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Next Steps<\/strong><\/p>\n<p>As we move forward from this event, we will continuously review our operating practices and security program to ensure we emerge stronger as an organization. We are committed to continuous improvement as an organization on our current practices in areas such as:<\/p>\n<ul>\n<li>Secure development and supply chain<\/li>\n<li>Solution operations, support, and architecture<\/li>\n<li>Customer communications and best practice documentation<\/li>\n<\/ul>\n<p>For all customers, we recommend they follow the mitigation actions listed below, as well as employ industry specific configuration practices regarding data protection available in our customer center. For on-premise GoAnywhere customers, we recommend following our stated implementation guidelines including not allowing admin portal access from the internet.<\/p>\n<p>GoAnywhere continues to include a number of security features that our customers may implement to help further safeguard data within their GoAnywhere MFT environment. Customers should download and follow the best practices defined in the manuals available in the customer portal: <a href=\"https:\/\/my.goanywhere.com\/\">https:\/\/my.goanywhere.com\/<\/a> including the \u201cGoAnywhere MFT Hardening Guide.\u201d<\/p>\n<p>Customers should also review the GoAnywhere Compliance Center: <a href=\"https:\/\/www.goanywhere.com\/solutions\/compliance\">https:\/\/www.goanywhere.com\/solutions\/compliance<\/a><\/p>\n<p>Customers are responsible for ensuring their use and configuration of the GoAnywhere product complies with all applicable laws and regulations. The compliance center features guidance on leveraging the GoAnywhere product for customers across industries and geographic locations. We recommend customers review their specific data protection requirements and ensure they enable appropriate features in their MFT environment to meet the relevant current data security standards.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>RECOMMENDED ACTIONS FOLLOWING MITIGATION\/REMEDIATION:<\/strong><\/p>\n<ul>\n<li>Rotate your Master Encryption Key.<\/li>\n<li>Reset all credentials &#8211; keys and\/or passwords &#8211; including for all external trading partners\/systems.<\/li>\n<li>Review audit logs and delete any suspicious admin and\/or web user accounts.<\/li>\n<\/ul>\n<p><strong>IMPORTANT:<\/strong><\/p>\n<p>Customers should determine whether their instances included stored credentials for other systems in the environment and make sure those credentials have been revoked. This includes passwords and keys used to access any external systems with which GoAnywhere is integrated. Ensure that all credentials have been revoked from those external systems and review relevant access logs related to those systems. This also includes passwords and keys used to encrypt files within the system.<\/p>\n<p>Source: <a href=\"https:\/\/www.fortra.com\/blog\/summary-investigation-related-cve-2023-0669\">https:\/\/www.fortra.com\/blog\/summary-investigation-related-cve-2023-0669<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>We\u2019d like to provide an update on our investigation into the suspicious activity detected in our Fortra GoAnywhere MFT solution. Working with Unit 42, we have completed our investigation and have compiled a factual summary of the investigation, as well as continuous improvement actions Fortra is taking to further strengthen our systems and recommended actions customers can take to secure their data and improve their security posture using available features in the GoAnywhere MFT solution.<\/p>","protected":false},"author":11,"featured_media":12596,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-12595","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=12595"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12595\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/12596"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=12595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=12595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=12595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}