ISP Based attack vector for Credentials

DStvNothingOn

Expert Member
Joined
May 21, 2011
Messages
1,745
Reaction score
1,729
Location
46°38'13.5"S 37°56'25.6"E
Don’t know if any local ISP use the for mentioned software, but hopefully mine doesn’t.
Very interesting attack

“The administrative control allows VersaMem to run with the necessary privileges to hook the Versa authentication methods, meaning the web shell can hijack the execution flow to make it introduce new functions. One of the functions VersaMem added includes capturing credentials at the moment an ISP customer enters them and before they are cryptographically hashed. Once in possession of the credentials, the threat actors work to compromise the customers. Black Lotus didn’t identify any of the affected ISPs, MSPs, or downstream customers.”


 
Top
Sign up to the MyBroadband newsletter
X