Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 
Beccara
1469 posts

Uber Geek

ID Verified

  #2744367 15-Jul-2021 08:58
Send private message

If this is true then it's pretty messed up and poor form on Kaseya's part

 





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 



mobiusnz
457 posts

Ultimate Geek


  #2744379 15-Jul-2021 09:24
Send private message

Beccara:

 

If this is true then it's pretty messed up and poor form on Kaseya's part

 

 

Good write up here (That you might have read) 

 

https://blog.truesec.com/2021/07/06/kaseya-vsa-zero-day-exploit/

 

That code example looks like a case of some seriously lazy programming with noone looking over the code - I know its pseudocode as an example but its supposed to be indicative of the real code. Basically "I can't think of a way we'd come out the bottom of this If/Else block of code so I'll just slap a Else login ok at the bottom" where if should have been an Else login failed."

 

Its scary how many exploits recently have been the result of someone finding a GAPING hole that should have been found in a code review.

 

The whole Microsoft Exchange flaw revolved in part around the fact that there was a hard coded with the same HMAC key on all installs where it should have had a randomly generated key for each install.

 

I know hackers are so well monetised now which is why they are getting some much more effective but it still seems often the flaws found by external people should have been easily found by people with the actual source code.

 

Its a scary world.





Matt Beechey Mobius Network Solutions


networkn
Networkn
32353 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2744420 15-Jul-2021 10:05
Send private message

Considering the maximum amount of claim under the Kaseya MSP agreement is 2 months of costs, and whilst I haven't seen one recently, acts of terror or war used to be excluded, it doesn't seem likely they will be punished severely for their woefully poor coding practices. Some MSP's may move away, and secretly they may contribute to MSP's costs, most MSP's probably hold the view that moving RMM provider isn't likely going to afford them significantly better security and that it could have been any single one of the top 5 RMM providers that got hit instead. 

 

To some degree the age and size of the codebase will have some bearing on how secure a product might be. That Makes Connectwise and Kaseya the two potentially worst to be with, especially since they are the two worst for saying but not doing the right things in my experience. 

 

To Kaseya's credit, however, they have offered all Kaseya customers free WAF, which is a positive step, and likely, their management and lawyers are insisting on code reviews for all authentication and privilege escalation. 

 

The problem is, and continues to be, that it takes far too long for issues like this to be plugged. They were advised in April. In my business, if something like this is identified, it's a 'everyone stop what you are doing, and don't do anything else until it's fixed' type scenario. 

 

The partner in NZ who was hit, I wonder if the Fair Trading Act will trump the agreement they signed, giving them some level of recourse legally? Of course the costs of this are likely huge and massively time consuming. 

 

 

 

 




CYaBro
4586 posts

Uber Geek

ID Verified
Trusted

  #2748586 23-Jul-2021 09:43
Send private message

Looks like a decryption tool has been created. :)

 

The Kaseya Ransomware Nightmare Is Almost Over | WIRED





Opinions are my own and not the views of my employer.


networkn
Networkn
32353 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2748637 23-Jul-2021 09:45
Send private message

CYaBro:

 

Looks like a decryption tool has been created. :)

 

The Kaseya Ransomware Nightmare Is Almost Over | WIRED

 

 

Created or bought?

 

It's going to be too late for the Victims of this attack surely? You'd either already have paid, restored from backup, or decided to do something else for a living if your systems had been down as long as this?

 

I mean, don't get me wrong, good work on getting it.


Beccara
1469 posts

Uber Geek

ID Verified

  #2748822 23-Jul-2021 16:59
Send private message

Cynic in me says a middle man "created" the tool for the price of the uber-ransom + 10%.





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 

networkn
Networkn
32353 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2748906 23-Jul-2021 19:29
Send private message

Beccara:

 

Cynic in me says a middle man "created" the tool for the price of the uber-ransom + 10%.

 

 

Why +10%? Why would anyone pay more when the original offer would have given them the same thing for 10% less?

 

 


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
Beccara
1469 posts

Uber Geek

ID Verified

  #2749032 24-Jul-2021 09:12
Send private message

Cover/Spin, "see we totally didn't pay the bad guys!" very few large companies pay the ransom but there seems to be a trend of external parties coming in to help them decrypt. Sometime they are legit and the bad guys used the same key on everything/everyone but there's always a few ones where eyebrows have been raised about suddenly being able to decrypt something that was well built





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 

mobiusnz
457 posts

Ultimate Geek


  #2749883 26-Jul-2021 12:04
Send private message

networkn:

 

Beccara:

 

Cynic in me says a middle man "created" the tool for the price of the uber-ransom + 10%.

 

 

Why +10%? Why would anyone pay more when the original offer would have given them the same thing for 10% less?

 



If I was a gambling man I'd say Kaseya and the "hackers" came to an agreement on a payment for a master key. Providing a tool to reverse encryption on the messy stuff that isn't backed up (And in the case of some end users there might have been a lot not backed up) might go a long way toward taking some of the nasty taste in people mouth that'll linger associated with the Kaseya brand. If it looks like one way of another they went the extra mile to make amends it might keep some loyalty.

 

Not sure if possible but it might be they had some insurance that might have chipped in even with all of the "War on hacking" exclusions etc.

Its all very well to say "Never pay extortion money" but if someone has a gun to a family members head and paying is likely to see them safe people will do it. We are all selfish and do whats best for us not best for society as a whole.





Matt Beechey Mobius Network Solutions


Beccara
1469 posts

Uber Geek

ID Verified

  #2749889 26-Jul-2021 12:20
Send private message

It's certainly a little fishy that the tool is behind an NDA and hasn't just been sent to every client by default





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 

1 | 2 | 3 | 4 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.