[ << ALL_FEED ]

Do you see the authorization form? No. Neither do I. But it's there 🤔

More in General

Do you see the authorization form? No. Neither do I. But it’s there 🤔

During a recent investigation of one of the incidents, we encountered exploitation by attackers of a vulnerability in CMS Bitrix related to the many available endpoints for authentication.

Despite the fact that this vulnerability is not new, a considerable number of websites are still susceptible to it.

Many administrators restrict access to the /bitrix/admin page, while not realizing that there are a number of other scripts that use the prolog_admin_before.php component, thanks to which it is possible to gain access to the authorization form 🤕

Among them, the following can be highlighted:


— /bitrix/components/bitrix/desktop/admin_settings.php
— /bitrix/components/bitrix/map.yandex.search/settings/settings.php
— /bitrix/components/bitrix/player/player_playlist_edit.php
— /bitrix/tools/autosave.php 
— /bitrix/tools/get_catalog_menu.php
— /bitrix/tools/upload.php

It was specifically the player_playlist_edit.php endpoint that was used by the attackers for authentication:


POST /bitrix/components/bitrix/player/player_playlist_edit.php?login=yes

Probably, standard credentials were used to access the system, since in the web server logs we saw only a few POST requests preceding the start of the session.

👀 This vulnerability — along with many others — is described in the Bitrix vulnerability report (section 1.4.1).

Apparently, the attackers also used this same report during the attack: some requests that fully match those given in the text of the report were discovered by us during log analysis. For example:


GET /ololo/?SEF_APPLICATION_CUR_PAGE_URL=/bitrix/admin/

In addition, the attackers made a request to each of the above endpoints for authentication.

#dfir #detect #cve #web
@ptescalator

More from oUth0R

More from oUth0R

More in General