HomeSecurityHackers exploit vulnerability and attack millions of Exim mail servers

Hackers exploit vulnerability and attack millions of Exim mail servers

Exim It was recently discovered that some hackers are carrying out attacks on mail servers running vulnerable versions of the Exim mail transfer agent (MTA).

To carry out the attacks, hackers exploit a critical vulnerability (CVE-2019-10149), which affects versions 4.87 to 4.91 of the Exim mail transfer agent (MTA).

This vulnerability could allow unauthorized remote attackers to execute arbitrary commands on mail servers.

The issue is in the deliver_message() function in /src/deliver.c. The cause is improper validation of recipient addresses. Hackers who exploit this vulnerabilitycan execute code remotely.

The CVE-2019-10149 bug was fixed by Exim developers with the release of version 4.92 in February. However, there are still a large number of vulnerable operating systems.

The vulnerable versions of Exim currently installed are approximately 3,655,524, and most are located in the United States (1,984,5538).

In contrast, update version 4.92, which fixes the vulnerability, is installed on approximately 1,795,332 systems.

The vulnerability CVE-2019-10149 was discovered on June 5 and is used to carry out attacks on exim servers.

Some attacks by different hackers have already been reported, exploiting this specific flaw.

In one of these attacks, hackers do the following: first, they scan the Internet for vulnerable mail servers. Once the servers are compromised, the initially deployed script will download a second script, which is designed to check if OpenSSH is installed on the compromised machine.

If OpenSSH is not available, the hacker installs it and thus obtains root logins via SSH, using a private/public RSA key for authentication.

In the second wave of attacks, which was detected on June 9, the attackers were constantly changing the type of malware and scripts they used to infect victims' systems. This likely means that the hackers did not have a clear method of exploiting the vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS