Do you see the authorization form? No. Neither do I. But it's there 🤔
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Do you see the authorization form? No. Neither do I. But it’s there 🤔
During a recent investigation of one of the incidents, we encountered exploitation by attackers of a vulnerability in CMS Bitrix related to the many available endpoints for authentication.
Despite the fact that this vulnerability is not new, a considerable number of websites are still susceptible to it.
Many administrators restrict access to the /bitrix/admin page, while not realizing that there are a number of other scripts that use the prolog_admin_before.php component, thanks to which it is possible to gain access to the authorization form 🤕
Among them, the following can be highlighted:
— /bitrix/components/bitrix/desktop/admin_settings.php
— /bitrix/components/bitrix/map.yandex.search/settings/settings.php
— /bitrix/components/bitrix/player/player_playlist_edit.php
— /bitrix/tools/autosave.php
— /bitrix/tools/get_catalog_menu.php
— /bitrix/tools/upload.php
It was specifically the player_playlist_edit.php endpoint that was used by the attackers for authentication:
POST /bitrix/components/bitrix/player/player_playlist_edit.php?login=yes
Probably, standard credentials were used to access the system, since in the web server logs we saw only a few POST requests preceding the start of the session.
👀 This vulnerability — along with many others — is described in the Bitrix vulnerability report (section 1.4.1).
Apparently, the attackers also used this same report during the attack: some requests that fully match those given in the text of the report were discovered by us during log analysis. For example:
GET /ololo/?SEF_APPLICATION_CUR_PAGE_URL=/bitrix/admin/
In addition, the attackers made a request to each of the above endpoints for authentication.
#dfir #detect #cve #web
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



