HomeSecurityHackers close Shitrix security hole for everyone except...

Hackers close Shitrix security hole for everyone but themselves

Just over a week ago, it was revealed that hackers were exploiting a vulnerability to compromise VPN gateways used by many businesses worldwide.

The vulnerability, officially known as CVE-2019-19781 but informally called “Shitrix,” was found in Citrix Application Delivery Controller and Citrix Gateway servers (known as Netscaler ADC and Netscaler Gateway respectively) but so far Citrix has not yet released a patch.

hackers

Well, there's good news and bad news.

First the good news:

Hackers exploit the Shitrix flaw to gain access to vulnerable servers, clean known malware infections (such as cryptocurrency mining code) on behalf , and implement Citrix's recommended mitigations to prevent future attempts to exploit the exploit.

Well, that sounds kind of like it, doesn't it?

So, here's the bad news:

As FireEye researchers describe, the mitigation code executed by the hacking to protect Citrix servers from further exploitation contains a secret backdoor.

In short, hackers have locked other hackers out of vulnerable servers – but not themselves.

The FireEye team has compiled the previous payload installed by the hackers, NOTROBIN.

“FireEye believes that hackers are deploying NOTROBIN to prevent exploitation of the CVE-2019-19781 vulnerability while maintaining backdoor access to compromised NetScaler devices. The mitigation works by deleting the staged exploit code found within the NetScaler templates before it can be used. However, when the hacker provides the hardcoded key during subsequent exploitation, NOTROBIN does not remove the payload. This allows the hacker to regain access to the vulnerable device later.”

“In multiple investigations, FireEye has tracked hackers deploying NOTROBIN with unique keys. For example, we have recovered approximately 100 keys from different binary files. These look like MD5 hashes, although FireEye failed to recover any plain text. The use of complex, unique keys makes it difficult for third parties, such as competitive attackers or FireEye, to easily detect NetScaler appliances “protected” by NOTROBIN. This hacker is following a strong password policy!”

NOTROBIN can successfully inoculate vulnerable devices from Shitrix attacks, but also open those devices up to future cybercriminal campaigns . This doesn't sound like "Robin Hood" behavior to me.

It's always better to defend your systems yourself or have someone you trust do it for you, rather than having an unknown gang of hackers come to clean up the mess. After all, you can't be sure they won't have ulterior motives.

Citrix has promised firmware updates for vulnerable systems by the end of the month.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS