The next wave of Log4J attacks will be brutal

[ad_1]

a week ago, The Internet has experienced an earthquake.thanks A vulnerability in Log4j, A popular open source library, many servers around the world are Suddenly exposed to relatively simple attacks. The first wave of hacker attacks is underway. But the next thing should worry you.

So far, the pioneers of Log4j hackers have mainly included crypto miners, malware that steal resources from affected systems to mine cryptocurrencies. (These used to be Very popular a few years ago Before, everyone realized that the real money was Ransomware.) According to recent reports from Microsoft and other companies, some nation-state spies are also involved. What seems to be missing are ransomware, ransomware, and destructive attacks that have defined most of the past two years or so. This situation will not last long.

Hype prevails in the field of cybersecurity, as does the spread of fear, uncertainty, and doubt.Many software are flawed; they can’t all be so bad. However, in all respects, the Log4j vulnerability (also known as Log4Shell) deserves its name for a variety of reasons. The first is the universality of Log4j itself. As a logging framework, it can help developers track everything that happens inside their applications. Because it is open source and reliable, it has become standard practice to plug in Log4j instead of building your own log library from scratch. In addition, so much modern software is pieced together by different vendors and products that it may even be difficult (if not impossible) for many potential victims to know the full extent of their exposure. If the Matryoshka doll in your code runs Log4j, then good luck finding it.

But wait, there is more! Log4Shell is also relatively easy to use. Just send a piece of malicious code and wait for it to be recorded. Once it happens, congratulations; you can now remotely run any code you want on the affected server. (Warning: this is the short version. In practice it is a bit complicated. Also, Log4j versions prior to 2.0 don’t seem to be affected, although there is some controversy there.)

It is this combination of severity, simplicity, and universality that disturbs the security community. “This is the largest and most serious vulnerability to date,” said Amit Yoran, CEO of cyber security company Tenable and founding director of US-CERT, an organization responsible for coordinating public and private responses to digital threats.

However, so far, the disaster does not seem to be manifested. The hackers are definitely targeting Log4j; according to spokesperson Ekram Ahmed, security company Check Point has seen more than 1.8 million attempts to exploit the vulnerability since Friday. At some point, they saw more than 100 attempts per minute. National funding groups from China and Iran were found to use Log4Shell to establish a foothold in various goals. Nevertheless, for now, crypto miners still dominate.

Sean Gallagher, a senior threat researcher at the cyber security company Sophos, said: “Miners are usually the first to participate in these things because they are the lowest risk form of cybercrime.” “Apart from entering, they don’t need a lot of hacking. It takes a lot of hands-on keyboard skills to deploy. They are usually packaged and ready; all they need is an accessible weakness.”

[ad_2]

Source link