The Register Home Page

back to article Massive password-stealing attack hits 75k Fortinet firewalls

UPDATED If you have a Fortinet firewall, it's time to stop and change your passwords. Intruders somehow gained access to around 75,000 Fortinet firewall devices and stole credentials belonging to major corporations across 194 countries, in some cases leading to full network compromise. Security researchers say that they have …

  1. TechnoTechno
    FAIL

    wheeeeeee

    Sigh

    1. CrazyOldCatMan Silver badge

      Re: wheeeeeee

      My previous orkplace (they of the "thank you for 17 years of service, now go away (with this big wedge of cash)") uses Fortinet.

      I almost smiled when all this came out.

  2. Yet Another Anonymous coward Silver badge

    Rotate your passwords

    Staple-Horse-Battery it is then

    1. tfewster

      Re: Rotate your passwords

      Correct!

    2. Anonymous Coward
      Anonymous Coward

      Re: Rotate your passwords

      Beware of closing the staple after your horse has battered - batteryed? - oh, forget it.

      1. IanRS

        Re: Rotate your passwords

        Fish are commonly battered, but horses less so.

        1. Phil O'Sophical Silver badge

          Re: Rotate your passwords

          Whereas chickens are the ones usually batteried...

        2. seven of five Silver badge

          Re: Rotate your passwords

          Depends on you appetite...

    3. BartyFartsLast Silver badge

      Re: Rotate your passwords

      That old staple, horse battery is just flogging a dead equine

      1. Yet Another Anonymous coward Silver badge

        Re: Rotate your passwords

        Is it still current? It has potential.

  3. David Austin

    mmmh, don't like that statement from Fortinet, which basically boils down to "lol, skill issue."

    1. Naselus

      Also, can't help but feel that "This is nothing to worry about, all our customer's login data leaked ages ago" isn't quite the gotcha that they think it is

  4. DrewPH Silver badge

    If this involved cracking hashes then Fortinet are using the wrong kind of hashes.

    1. CrazyOldCatMan Silver badge

      If this involved cracking hashes then Fortinet are using the wrong kind of hashes.

      Probably using the really cheap 'brown lump of something' hashes [1] rather than the delicious, hand-cooked goodness that a proper hash-brown could be.

      [1] As found in most American-style burgers that include hash browns..

    2. Piro

      Yeah, exactly, they upgraded that a while back, but hashes were leaked and cracked.

      If all those credentials had been recently changed (after the fw was updated) then the hash wouldn't be as vulnerable, even if leaked again.

  5. Anonymous Coward
    Anonymous Coward

    In Moscow tonight

    Good news comrades, the turnip ration has just been increased!

    1. Fred Daggy Silver badge

      Re: In Moscow tonight

      Comrade Baldrick, is most please and cunning plan has.

  6. Phil Kingston
    Coat

    #FortiFail

  7. DLYONS

    what is fortinet doing.

    They used to be so good but how many major snafus has it been this year. I feel like i cant turn on El -reg without see another hack bug major level 10 issue. or am i just not seeing the rest?

    1. David Austin

      Re: what is fortinet doing.

      To be fair, I think every major SMB/Enterprise firewall vendor has had major security issues in the last 12 months; SonicWall, Cisco, Fortigate, Watchguard, just off the top of my head from some messes I've cleaned up.

      I have a degree of sympathy: As the gateway between The Enterprise and the World Wide Web, they are high profile, valuable targets, and worth putting effort in to pop open, but that just means the security standard we expect from these companies has to be higher.

  8. J__M__M

    domains?

    Could someone explain why they are associating compromised units with domain names? Doesn't exactly narrow it down...

    1. Anonymous Coward
      Anonymous Coward

      Re: domains?

      my assumption would be that you point your VPN client at a VPN gateway via a URL/hostname: vpn.somecompany.com for example.

      if your domain name is on the list, then that specific vpn gateway is at risk.

  9. Acrimonius

    The end is nigh

    It's breach-a-day. Which breach will finally lay a claim to fame by ending it all for all us. No more Intenet as we know it

    1. fg_swe Silver badge

      No

      We just have to start using well-known computer science techniques instead of QUICK AND DIRTY ENGINEERING.

      1.) Well-educated, experience software engineers developing security-critical systems. Computer Science Degree. No more half-educated pastors and chemists.

      2.) Well-defined, strictly scanned+parsed languages from machine code to JSON input. No serialization shortcuts

      3.) Mathematical verification of critical components such as SSH. See also seL4, CompCert, MST(https://github.com/DiplIngFrankGerlach/MST)

      4.) K.I.S.S. instead of SSL/TLS-type of BLOAT.

      5.) Memory-Safe, strongly typed Programming Languages instead of the C-Hamburger (also see https://sappeur.di-fg.de/LanguageAnalogy.html)

      The bottom line is: the internet accepted your challenge. You will lose.

      1. Tron Silver badge

        Re: No

        Whack-a-mole won't work. Anything connected to the internet is at risk due to the complexity of systems and the methods of production, sale. implementation and maintenance.

        You can only design out the problem. Take as much as you can offline. Use thin systems online. Airgap. For some that isn't an option, but the more you can take completely offline, the safer you are.

        1. fg_swe Silver badge

          The Problem At Hand (And The Entire Class of Admin-Console Flaws)

          ...could have been fixed 30 years ago with a mathematical proven correct, KISS cipher library. 2000 LOC C++.

          Here is an attempt https://di-fg.de/WhyMST.html

          It looks like Silly Valley DOES NOT WANT to do that.

  10. fg_swe Silver badge

    How To Fix This Once And Forever

    Satellites, data center servers, firewalls, industrial control systems (water supply, electrical substations, sewage treatment plants, etc.), sensors, and their control computers require remote monitoring and operation. Remote Desktop Protocol and X11 are among such applications. Clearly, these command interfaces must be protected against unauthorized or hostile access; a wide range of private and state-sponsored cyber actors—such as "hackers" and cyber-warfare personnel—must be fended off. Fortunately, however, there is no need to process potentially hostile data packets at the application layer. This allows the security challenge to be reduced entirely to a problem of cryptographic engineering. In turn, the cryptographic design should be minimalist, thereby allowing its correctness to be mathematically proven.

    More: https://di-fg.de/MinimalesChiffrierSystem.html (use GT for a version in your language)

  11. HAL-9000
    Big Brother

    Oops

    Did anyone else notice the predictable UK government inclusion, foreign and commonwealth office, on that list at Hudson Rock.

  12. Anonymous Coward
    Anonymous Coward

    CVE-panicking

    CVE-panicking at it's best!

    Only affected devices/setup as of the current information:

    Devices that have the Admin-Interface exposed to the Internet.

    If in the year 2026 somebody exposes the Admin-Interface to the Internet that's the worst practice.

    1. fg_swe Silver badge

      Correction

      "exposing a complex, shoddy HTTP interface to the internet" is worst practice. If you just expose a minimalist, proven correct, cipher library, you can do this.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon