Hacking victim Bit9 blames SQL injection flaw

The company's breach came after it failed to install its own security software

Bit9 said a common Web application vulnerability was responsible for allowing hackers to ironically use the security vendor's systems as a launch pad for attacks on other organizations.

Based in Waltham, Massachusetts, the company sells a security platform that is designed in part to stop hackers from installing their own malicious software. In an embarrassing admission, Bit9 said earlier this month that it neglected to install its own software on a part of its network, which lead to the compromise.

In a more detailed explanation on its blog on Monday, Bit9 said attackers gained access by exploiting a SQL injection flaw in one of its Internet-facing Web servers. A SQL injection flaw can allow a hacker to enter commands into a web-based form and get the backend database to respond.

The compromise happened around July 2012, wrote Bit9's CTO Harry Sverdlove. Once inside Bit9, the hackers accessed a virtual machine used to digitally sign code for Bit9, a security measure that verifies the company's code is legitimate.

The compromised server was shut down for about six months, but was brought back online in January. Bit9 then discovered the problem. "We took immediate containment and remediation steps, revoked the certificate in question and reached out to our entire customer base," Sverdlove wrote.

The hackers used Bit9's certificate to sign 32 of their own malicious files and scripts. Sverdlove described some of the malware as backdoors with the names "HiKit" and "HomeUNIX."

With Bit9's certificate, the malware would look legitimate to other security software. As its investigation unfolded, Bit9 found that the hackers planted the malware on other websites, constructing what is known as a drive-by-download attack.

That attack would exploit users running outdated versions of Oracle's Java software, which had been found to contain numerous vulnerabilities in recent months.

"We believe the attackers inserted a malicious Java applet onto those sites that used a vulnerability in Java to deliver additional malicious files, including files signed by the compromised certificate," Sverdlove wrote.

All told, three Bit9 customers were attacked, but Sverdlove did not reveal their names. More than 1,000 companies use Bit9's software, including Fortune 500 companies in banking, energy, aerospace and defense and U.S. federal government agencies.

Sverdlove wrote that the attacks appeared to be designed to "infiltrate select US organizations in a very narrow market space." Utilities, banks and government entities were not affected, he wrote.

Once the malware was installed, it communicated with servers on IP ranges belonging to network providers including New Century InfoComm Tech Co., Ltd. of Taiwan, the Asia Pacific Network Information Centre in South Brisbane, Australia, and Sparkstation in Singapore.

Bit9 said its product code was not affected, but it is reviewing its entire code base. The company also is undergoing a security audit and "addressed the errors that led to the compromise," Sverdlove wrote.

"While we believe Bit9 is the most effective protection you can have on your endpoints, I've always said there is no silver bullet to security," he wrote. "This incident has only fortified what we already knew...the enemy is persistent, sophisticated and motivated.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags intrusionsecurityBit9Exploits / vulnerabilitiesmalware

Struggling for Christmas presents this year? Check out our Christmas Gift Guide for some top tech suggestions and more.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service

Most Popular Reviews

Follow Us

Best Deals on GoodGearGuide

Shopping.com

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Latest Jobs

Shopping.com

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?