Just 24 hours after the release of security update 3.6.4 from the Joomla project that fixed two critical security vulnerabilities, hackers had already started searching for unpatched systems and then launched mass scans of the Internet.
The two vulnerabilities are reported as CVE-2016-8870 and CVE-2016-8869. The former allows attackers to remotely create accounts on Joomla websites, while the latter allows the elevation of account privileges to administrator level.
The Joomla team and Davide Tampellini, the Joomla engineer who discovered the latter flaw, declined to release any technical details about the second flaw. However, many malicious researchers reverse-engineered the 3.6.4 update, singled out the modifications, and were able to discern the exploit methodology. They created numerous weaponized exploits that were released online.
The Sucuri security team, which reverse engineered update 3.6.4, published a PoC (proof-of-concept) on the website and added the exploit code to its web firewall.
This gave Sucuri the ability to detect hacking attempts for both of these vulnerabilities. The company reported that about 24 hours after Joomla released the 3.6.4 update, they saw three IP addresses from Romania attacking some of the largest Joomla sites around the world.
The attackers were trying to exploit the two bugs and create a user with the name “db_cfg” and password “fsugmze3″.
Twelve hours after that, the three IPs began performing mass scans of the internet, searching for every website using Joomla.
Shortly after, a second perpetrator using an IP from Latvia began his own mass scans, using random user account names with “ringcoslio1981@gmail.com” as the email address.
Watch out for these IPs
82.76.195.141
82.77.15.204
81.196.107.174
185.129.148.216
Sucuri recommends that Joomla website administrators search their website logs for the above IP addresses.
Attackers will generally try to access the following URL:
/index.php/component/users/?task=user.register
“We believe that any Joomla! website that has not been updated is already at risk,” says Daniel Cid, Founder and CTO of Sucuri.
“Every Joomla site on our network was hit (and blocked by the Sucuri Firewall) and I assume it has happened to pretty much every site.”
The same thing happened last year, when the Joomla project patched the zero-day CVE-2015-8562 in version 3.4.6, which was released in mid-December. By the end of the year, attackers were averaging about 16,600 scans per day trying to exploit the flaw.
