Categories: Technology

Servers running Digium Phones VoiP software are getting backdoored

[ad_1]

Getty Images

Servers running the open source Asterisk communication software for Digium VoiP services are under attack by hackers who are managing to commandeer the machines to install web shell interfaces that give the attackers covert control, researchers have reported.

Researchers from security firm Palo Alto Networks said they suspect the hackers are gaining access to the on-premises servers by exploiting CVE-2021-45461. The critical remote code-execution flaw was discovered as a zero-day vulnerability late last year, when it was being exploited to execute malicious code on servers running fully updated versions of Rest Phone Apps, aka restapps, which is a VoiP package sold by a company called Sangoma.

The vulnerability resides in FreePBX, the world’s most widely used open source software for Internet-based Private Branch Exchange systems, which enable internal and external communications in organizations’ private internal telephone networks. CVE-2021-45461 carries a severity rating of 9.8 out of 10 and allows hackers to execute malicious code that takes complete control of servers.

Now, Palo Alto Networks said hackers are targeting the Elastix system used in Digium phones, which is also based on FreePBX. By sending servers specially crafted packets, the threat actors can install web shells, which give them an HTTP-based window for issuing commands that normally should be reserved for authorized admins.

“As of this writing, we have witnessed more than 500,000 unique malware samples of this family over the period spanning from late December 2021 till the end of March 2022,” Palo Alto Networks researchers Lee Wei, Yang Ji, Muhammad Umer Khan, and Wenjun Hu wrote. “The malware installs multilayer obfuscated PHP backdoors to the web server’s file system, downloads new payloads for execution and schedules recurring tasks to re-infect the host system. Moreover, the malware implants a random junk string to each malware download in an attempt to evade signature defenses based on indicators of compromise (IoCs).”

When the research post went live, parts of the attacker infrastructure remained operational. Those parts included at least two malicious payloads: hxxp[://]37[.]49[.]230[.]74/k[.]php and hxxp[://]37[.]49[.]230[.]74/z/wr[.]php.

The web shell uses random junk comments designed to evade signature-based defenses. For further stealth, the shell is wrapped in multiple layers of Base64 encoding. The shell is further protected by a hardcoded “MD5 authentication hash,” which the researchers believe is uniquely mapped to the victim’s public IPv4 address.

“The web shell is also able to accept an admin parameter, which can either be the value Elastic or Freepbx,” the researchers added. “Then the respective Administrator session will be created.”

Anyone operating a VoiP system based on FreePBX should carefully read the report with particular attention paid to indicators of compromise that can help determine if a system is infected.

[ad_2]
Source link
Admin

Recent Posts

Choosing the Perfect Kitchen Cabinets in Toronto

Hey there, Toronto homeowners! If you're diving into a kitchen renovation, one of the most…

5 hours ago

Kijangwin is the latest online video gaming provider

Kijangwin is your brand-new go-to destination for all things internet gaming. Whether you're an informal…

2 days ago

How to Style Trendy Clothes Effortlessly

Hey there, fashion enthusiasts! Are you ready to dive into the world of trendy clothes…

3 days ago

How to effectively recover your frozen/stolen funds from fraudulent platforms

Hey there! If you're reading this, there's a good chance you've found yourself in the…

3 days ago

Important things about Core 2 . 0 regarding Hemp Users

Hey there, hemp enthusiasts! If you've been on the hunt for the next big thing…

6 days ago

Exploring the Features and Benefits of Strio

Hey there! Have you ever found yourself tangled up in the world of communication and…

1 week ago