MCKSys Argentina(@MCKSysAr) 's Twitter Profile Photo

As promised, here's a pic of the Poc for CVE-2023-35036 (Progress MOVEit Transfer). As soon as I can get RCE, I'll upload the final PoC to github. Any ideas/suggestions are welcomed!

As promised, here's a pic of the Poc for CVE-2023-35036 (Progress MOVEit Transfer). As soon as I can get RCE, I'll upload the final PoC to github. Any ideas/suggestions are welcomed!
account_circle
Ken Buckler - Cyber Security, Caffeinated.(@CaffSec) 's Twitter Profile Photo

update - I used Shodan to pull a list of possible orgs/domains which appeared to be utilizing MOVEit. Lists are broken down by several different discovery methods.
github.com/kenbuckler/MOV…
urity

account_circle
Madison Liquidators(@MadLiquidators) 's Twitter Profile Photo

A new sit stand desk will revolutionize the way you work! Available in several different sizes, styles and finishes. Click and have it shipped direct to your door!

account_circle
FBI(@FBI) 's Twitter Profile Photo

Users of software are being attacked through publicly disclosed vulnerabilities. The FBI urges users to follow recommended mitigations to protect against exploitation. If you are victimized, report to IC3.gov and include . cisa.gov/news-events/al…

Users of #MOVEit software are being attacked through publicly disclosed vulnerabilities. The FBI urges users to follow recommended mitigations to protect against exploitation. If you are victimized, report to IC3.gov and include #MOVEit. cisa.gov/news-events/al…
account_circle
John Hammond(@_JohnHammond) 's Twitter Profile Photo

cl0p ransomware gang looks to have actually listed file downloads for the Shell oil company.

None of the other named victims have downloads.

cl0p ransomware gang looks to have actually listed file downloads for the Shell oil company. 

None of the other named victims have downloads. #MOVEit
account_circle
BleepingComputer(@BleepinComputer) 's Twitter Profile Photo

NortonLifeLock has confirmed to BleepingComputer they were impacted by Clop's MOVEit Transfer attacks.

Only employee data was impacted, and they have been notified.

Statement below.

NortonLifeLock has confirmed to BleepingComputer they were impacted by Clop's MOVEit Transfer attacks.

Only employee data was impacted, and they have been notified.

Statement below.
account_circle
𝙎𝙮𝙣𝙛𝙞𝙣𝙣𝙚𝙧 ༼ つ ◕_◕ ༽つ(@synfinner) 's Twitter Profile Photo

It's almost like exposing 'enterprise' http-based file transfer and management services to the broader internet was a bad idea.

- MOVEit
- GoAnywhere
- Kaseya
- Solarwinds
- Veeam
- Accellion
- PaperCut

Do we not have allowlists anymore? *le sigh*

I'm going to go cry now.

account_circle
ISO8601(@SMarr311) 's Twitter Profile Photo

Updated list - Ofcom announced:
bbc.co.uk/news/technolog…

Now 3 known declared, of the ~45 known big UK orgs running MOVEit.

Updated list - Ofcom announced:
bbc.co.uk/news/technolog…

Now 3 known declared, of the ~45 known big UK orgs running MOVEit.
account_circle
Brian in Pittsburgh(@arekfurt) 's Twitter Profile Photo

I'm not going to call out which org on the Ransomware Task Force got bit by MOVEit, but you can look at the membership list and compare to the names that have been publicly reported.
Just as a reminder, the RTF came out against ransomware payment restrictions anytime soon:

I'm not going to call out which org on the Ransomware Task Force got bit by MOVEit, but you can look at the membership list and compare to the names that have been publicly reported.
Just as a reminder, the RTF came out against ransomware payment restrictions anytime soon:
account_circle
W01fh4cker(@W01fh4cker) 's Twitter Profile Photo

Fofa Dork: app='Progress-MOVEit'
Shodan Dork: title:'BridgeFi'
Quake Dork: title:'BridgeFi'
ZoomEye Dork: title:'BridgeFi'
github.com/horizon3ai/CVE…
-2023-34362

Fofa Dork: app='Progress-MOVEit'
Shodan Dork: title:'BridgeFi'
Quake Dork: title:'BridgeFi'
ZoomEye Dork: title:'BridgeFi'
github.com/horizon3ai/CVE…
#CVE-2023-34362 #0day #1day #nday #MOVEit #Fofa #Shodan #Quake #ZoomEye
account_circle
Horizon3 Attack Team(@Horizon3Attack) 's Twitter Profile Photo

CVE-2023-34362, affecting MOVEit Transfer, enables unauth RCE through a series of issues:
🔺 Custom Header abuse to SSRF
🔺 SQL injection
🔺 Forging External Trusted IdP Tokens
🔺 .NET Deserialization to RCE

Check out our latest post by James Horseman and Zach Hanley

CVE-2023-34362, affecting MOVEit Transfer, enables unauth RCE through a series of issues:
🔺 Custom Header abuse to SSRF
🔺 SQL injection
🔺 Forging External Trusted IdP Tokens
🔺 .NET Deserialization to RCE

Check out our latest post by @JamesHorseman2 and @hacks_zach…
account_circle
Caitlin Condon(@catc0n) 's Twitter Profile Photo

Rapid7 has released a full exploit chain for Transfer CVE-2023-34362. The write-up we've published in AttackerKB contains more than 30 pages of analysis and code — huge shout-out to Ron Bowes, Stephen Fewer, and Curt Fielding for their work on this. attackerkb.com/topics/mXmV0Yp…

account_circle
ググタス(@MoveIt_MoveIt) 's Twitter Profile Photo

タガメ@沼の底から イスラム教徒「たまには食うよ」
ノンケ「たまには同性でも」
小泉「たまには日頃やらない事をやります」
・・ないない

account_circle