Critical Vulnerabilities in the IT Monitoring Tool – Stefan Schiller, SonarSource
Through their deep dive into the technical details of this vulnerability chain, SonarSource determined how an attacker can escalate to the Checkmk automation user by exploiting an authenticated arbitrary file read in NagVis. Stefan will discuss the multiple vulnerabilities that were discovered, how they can be prevented, and the risks organizations face if they have yet to address SonarSource’s recommendations.
Transcript
This is texturung TV. Hey everyone, welcome back to techstrunk TV. Our next guest today on Tech strong is Stefan Schiller stuff on his with sonosaurus Stefan.
Welcome to techstrong TV. Thank you very much. Ellen.
Great to be here. It's a pleasure Stefan. Well, let's start with you.
What do you do you're at sonosaurus obviously, but what would what's your story? What do you do there? What's your background?
Sure. Um, yes since my Village side, I've been passionate about software and programming and so I started my career as a software developer. So my attention was quickly drawn to the offensive side of it security and that's where I've been working for.
Almost a decade now at Sonos was I'm working as a vulnerability researcher in the research and development team where I help to find and response, please close vulnerabilities and popular open source software. I got it, excellent. And of course as you mentioned you work with sonar sarson, look our audience is very heavy cyber and obviously Tech a lot of them know sooner Source, but for those who maybe aren't sure or not familiar, how would you describe sonar source to them?
Yeah, I'm gonna provide some industry leading source code analysis solution which enables developers to write clean code and remediate existing code organically. This allows developers to focus on the works. They love and maximize the values.
They create for businesses. It's not it's an office three different products. So now Lins so now cloud and Sonic you and a huge part of this is actually open source and more than 400,000 organizations and 7 million develops us trust sooner Solutions.
Which of kind of course makes us proud. Absolutely, and then you should be so Stefan. Let's jump into what we want to talk about today recent recently.
The the sonar research team uncovered some vulnerabilities. Yes. Exactly.
So to give a little background on this preventing security issues is an essential part of clean code and because of this sauna has a dedicated research team which finds and Analysis analyzes vulnerabilities and modern open source software. This allows us to study real world examples tests and fine-tune our rules and improve the product for also now sooner users and in the research team, we try to find new vulnerabilities which are not discovered by a product yet because this is an important part of what's the research team is about we want to discover new vulnerabilities in popular software, which has already been ordered a lot by the community or other Security Professionals. And this way we can unveil blind spots in the software and sharp more products to enable soon as user to even find those rasa tricky vulnerabilities in their own code.
And regarding the findings and check mpk. We we can get back on. The one of these vulnerabilities was actually discovered by sooner cloud in the first place and with our feedback to our application security team.
We can find even more sales of vulnerabilities soon as new rules are implemented for these and it's pretty cool because once a new rule is adopted everything a user can profit from it and find a similar level vulnerabilities and their own code. excellent so This particular vulnerability. Can you give us kind of the the taxonomy if you will right?
What how did this all come about? What what's going on since and also like you know, why why do our readers really care about this? Readers viewers, I'm sorry doing old passion.
And so there's a vulnerability switches covered where in a software called chicken K, which is a modern it infrastructure morning Towing solution developed in Python and c++, and there's a monitoring solution. It's usually deployed at the central position within a company's networks and has connectivity to all monitor devices. This makes it a high profile Target For Thread actors and the vulnerabilities we discovered allow in an authenticated attacker to fully compromise check in case of so if you have a server running a vulnerable version and the tickets can reach his server, they can fully take over the server and really really bad because the morning traveling Sarah is a central component within a company's Network.
It has connectivity to all monitor devices and it even it may even contain credentials or monitor devices. And yeah, what devices do you want? For devices that are very important and sensitive like database servers file servers.
So by taking over the monitoring server, I take a good easy to spread on the companies and internal Network. Absolutely and You know with all the attention being paid for like software supply chain security and open source components and all that. We can't lose sight of monitoring tools and other sort of software that oftentimes like as you mentioned sits at the heart at the Nexus of our networks and our you know traffic and you know a vulnerability there is truly, you know, it's an overused word critical, but that's really a critical location to have You know vulnerability in in some software exactly exactly is this and the most exciting thing about these findings.
It's exploitation Shane. We describe in our Block series is that each of the vulnerabilities on its own is East limited or already requires certain access to be exploitable. But combining the vulnerability leads to a domino effect.
So exploiting the first world ability gives attack us the ability to exploit the second one which then give sensibility to explore the third one and so forth this way the security Castle collapses like a house made of cards. Yeah, no, that's exactly what happens. Now just look we also have a lot of non-security non-cyber people out in the audience.
What what you know, what's the bad things that can happen as a result of this? yeah, basically that's your central monitoring server gets compromised and attack us who take over the server can yes free throws internal Network and it's like like some the most thing uses who run such emotions solutions would be afraid about absolutely and You know, look I've been in security a long time myself in today's world, you know the notion of responsible disclosure. Right is pretty well settled you don't have Cowboys.
Yeah, you know announcing vulnerabilities before they notified the companies and and a chance to fix. Can you give if you know the details share with our audience a little bit about kind of what went on here behind the scenes to close this up before you guys went public with the disclosure? Yeah.
Sure. So every time we find everything the first thing is we do we notify the vendor or maintain also software. So we only responsibly disclose any vulnerabilities and this was this time.
This was also really really good for us because the the working together with the checking K team was just just awesome. They were very friendly and they were also yeah really glad about that. We found those vulnerabilities and reported to them.
It's always yeah bad if some like good hackers find those for nobilities and we even work together on yeah developing a patch and at last chicken Kade did provide a comprehensive patch for all the vulner. We reported and yeah now it's only the responsibility of the user or admin to make sure that is using this latest version. Absolutely, and you know, that's the important thing right if you're a user of the software.
You need to upgrade to the latest version. And and this is what we talk about software supply chain security and all of this stuff. Some things don't change in security.
And that is one of the things is you got to stay on top of your patches. You got to stay on top of your updates. You know, you need to be running late.
It's versions and I realize that as organization, you know large Enterprise organizations. It's very hard for them to roll out a patch or to roll out an update because they want to make sure look this thing sits in the middle of their monitoring solution. They can't afford to go blind.
but sometimes it's more important not to be hacked either and and so you need to Right, you need to be on top of you've got to have a regular monitoring. Excuse me, a regular upgrade patching system in place. Exactly.
Exactly. And what's also what this thing also showed us it's you should always stick to and assume breach Paradigm, which is also true like for the patch were patch management, but it's not only something which can be applied to for a network operators. But it's also something a software developer can apply because the term is more commonly used when talking about securing Enterprise networks, but for software developments, it's also through the same way and fundamental point of this is that you should never refrain from securing a component because it's internal only anyway, this can quickly lead to yeah abdominal effect and applies regardless of whether it's component is a server on your network or a software component.
Agreed I agree with you on that. So so the patch for this is available people can get it. You know, give us an idea of the kind the amount of bugs you guys are finding over its owner Source like this.
Yeah, it's depends a little bit about there. Are we usually like For the last year about 50 50 critical vulnerabilities, I would say. so really but I guess that's yeah, that's more than four months one a week.
Yes. Crazy, where can people find out and stay on top of what's the latest research coming at its owner source. Yes, so we run a blog post.
com. And we also run Twitter account for for research, especially which is called Sona research. I love it Stefan.
I want to thank you for coming on here and sharing all this with us today with our audience great work on this and also look, this is the way you do things right it you you make aware the company of the you let them know they're vulnerability you let them fix it before you go public and and you know the work of you and those like you and you know white hats as we call them stuff on really it keeps us all safe for so thanks for all you do and and many thanks to Sonos Source on this. Okay. Thank you very much.
And what's on for me it could honor to have you on Photo Source stuff on Schiller here at techstrong TV. We're gonna take a break. We'll be right back.