Apache Project Servers Infiltrated Via XSS Bug, Passwords Compromised
WHIR Web Hosting Industry News
April 14, 2010
Hackers gained access to a server used by the Apache Software Foundation (www.apache.org) to keep track of software bugs in an attack that exploited a cross-site scripting bug.
According to an incident report from Apache.org, hackers using a compromised Slicehost server opened a new issue, containing a URL that redirected back to the Apache instance of JIRA, at a special URL containing a cross site scripting attack crafted to steal the session cookie from the user logged-in to JIRA. Several administators clicked on the link, compromising their sessions. Meanwhile, the attackers started a brute force attack against the JIRA login.jsp running thorough hundreds of thousands of password combinations. A day later, one of these attempts was successful, giving the hacker administrator privileges on a JIRA account. They used this account to disable notifications for a project, and to change the path used to upload attachments. They created several new issues and uploaded attachments to them -- including JSP files that gave them backdoor access to the system, and a JSP file that was used to browse and copy the file system, creating copies of many users' home directories and various files.
On the morning of April 9, the attackers had installed a JAR file that would collect and save all passwords upon login. The attacker then sent password reset mails from JIRA to members of the Apache Infrastructure team, who, thinking that JIRA had encountered an innocent bug, logged in using the temporary password sent in the mail, then changed the passwords on their accounts back to their usual passwords. Because one of the recovered passwords had been the same as a local user account on brutus.apache.org, which the attacker used to gain full root access to the machine that hosted the Apache installs of JIRA, Confluence, and Bugzilla.
With root access to brutus.apache.org the attackers found several users that had cached subversion authentication credentials, using them to log into the main shell server, minotaur.apache.org.
|