
The MOVEit Hack In Retrospect
Source: YouTube · John Hammond · published Nov 17, 2023 · 43:07
John Hammond details the MOVEit Transfer exploitation by the Cl0p ransomware gang, highlighting how a critical SQL injection vulnerability led to mass data exfiltration and significant cloud security risks via Azure integration 3:05.
Key Takeaways:
• The attack impacted roughly 2,500 exposed servers and millions of individuals through the supply chain, with major victims including British Airways and Shell 4:14.
• Attackers used SQL injection to fabricate a session ID in the database, achieving authentication bypass without valid credentials 17:00.
• Researchers discovered the exploit chain went further, utilizing deserialization to achieve remote code execution (RCE) and full server control 18:46.
• The human2.aspx webshell included features to steal Azure storage keys, directly bridging the on-premise compromise to cloud security risks 21:18.
• Subsequent analysis revealed initial patches were incomplete, leading to the discovery of additional CVEs in MOVEit and critical vulnerabilities in WS_FTP 24:04.
Collaboration between researchers, CISA, and the vendor was vital to mitigate the threat, emphasizing the need for rigorous third-party security audits 32:00.
Sources:
- 3:05 Introduction to MOVEit Transfer and the incident context.
- 4:14 Discussion of the number of exposed servers and supply chain impact.
- 17:00 Explanation of the SQL injection authentication bypass.
- [18:46](https://www.youtube.com/watch?v=cuWGWnvnN
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right hello everyone and welcome to today's cloudsec 360 session with John Hammond we're all super excited to have you join us today and we appreciate the time you're taking from your busy schedules to join whiz and John on this great presentation called move it or lose it supply chain threats are Cloud security risks the favorite and best part of the presentation is the housekeeping so I will do that also you can find a link to John's presentation slides today in the doc section so it has all the amazing screenshots John will be walking through today has all of the information is going to be covering so there are the slides and you can go have access to that under the doc section there's also a lot of related links in that doc section if you want to learn more about the movid transfer…