
What can we learn from a BGP hijacking that poisoned production software. BGP hijack infecting networks caused by a comedy of errors that’s not funny at all. Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Hackers carried out a supply-chain attack that installed malware on networks using unusual technique: hijacking a chunk of Internet space used to update cloud-management software used by hosting providers, data centers, and other large infrastructure companies.
In a well-coordinated operation, the unknown attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. The lapses allowed the attackers to successfully perform a BGP ( Border Gateway Protocol) hijacking to obtain control over IP addresses assigned to Softaculous. The cmpany, based in the United Arab Emirates, is the maker of a platform for installing and managing Web software and the developer of Virtualizor, a management platform for virtualized environments.
Softaculous used the IPs to issue updates and host a client and billing site. With control over the hijacked space, the attacker was now using the addresses to push malware masquerading as updates to unsuspecting users. Silly, preventable mistakes Lax configuration of routing security in Softacular’s hosting provider Hetzner Online’s was the major contributor to the hack.
A large number of other errors other errors contributed to the success of the attack.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
