HomeSecurityLooney Tunables: Hackers steal cloud credentials on Linux system

Looney Tunables: Hackers steal cloud credentials on Linux system

The Kinsing malware operators are targeting cloud environments on systems,” a Linux security issue identified as CVE-2023-4911 that allows a local attacker to gain root on the system.

See also: GNOME Linux: Exposed to RCE attacks via file downloads

Looney Tunes

Looney Tunables is a buffer overflow issue in the glibc dynamic loader (ld.so), which was introduced in glibc version 2.34 in April 2021, but became known in early October 2023. A few days after the publication, PoCs were made publicly available.

In a report from cloud security firm Aqua Nautilus, researchers describe a attack , where the malicious actor exploited CVE-2023-4911 to elevate privileges on a compromised machine.

Kinsing is known for compromising cloud‑based systems and the applications on them (e.g., Kubernetes, Docker APIs, Redis and Jenkins) to install cryptomining software. Recently, Microsoft observed that they target Kubernetes clusters via misconfigured PostgreSQL containers.

Aqua Nautilus researchers report that the attack begins by exploiting a known vulnerability in the PHP testing framework 'PHPUnit' to capture a key code execution, followed by triggering the "Looney Tunables" bug to gain more privileges.

“Using a simple but typical vulnerability exploit in PHPUnit, a component of the ongoing Kinsing attack, we discovered the attacker’s manual attempts to abuse Looney Tunables,” the Aqua Nautilus report states.

See also: Looney Tunables: Linux bug gives admin access to major distributions

Exploiting the PHPUnit vulnerability (CVE-2017-9841) results in the opening of a reverse shell on port 1337 on the compromised system, which Kinsing operators exploit to execute identity commands such as 'uname -a' and 'passwrd'. Additionally, the attackers drop a script named “gnu-acme.py” on the system, which exploits CVE-2023-4911 for privilege escalation. The Looney Tunables exploit was retrieved directly from the repository of the researcher who published a PoC, presumably to cover his tracks.

cloud credentials

Attackers also download a PHP script, which installs a JavaScript ('wesobase.js') that supports the next stages of the attack. Specifically, the backdoor allows attackers to execute commands, perform file management actions, collect network and server information, and perform encryption/decryption operations.

Ultimately, Kinsing showed interest in the credentials of the cloud service provider (CSP), especially in accessing the identity data of the AWS instance, which AquaSec characterizes as a significant shift towards more advanced and malicious activities for the said threat actor.

Researchers believe that this campaign was an experiment, as the malicious actor relied on different tactics and expanded the scope of the attack to collect credentials of Cloud Service Providers.

See also: Windows 11: Adds support for 11 archive files

There are known cases and reports of the exploitation of the Looney Tunables Linux bug. These exploits have been documented by researchers and security organizations. Attacks that exploit this flaw can lead to the disclosure of sensitive information, system denial, or even cause the user to lose control of their account.

Looney Tunables Linux bug exploits can attack various areas of the system, such as the Linux kernel, user permissions, network services , and more. The attacks can be extremely dangerous and cause serious losses for users and businesses.

The exploits of the Looney Tunables Linux bug typically require system access with root privileges, but there may also be variants that allow attacks with limited user privileges. Users should be careful and stay informed about security updates that are released for their system.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS