Mitigate the impact of the Log4Shell vulnerability

Cyber criminals move to exploit Log4j2
Source: Ensign. Ng.
Organisations must take immediate steps to protect themselves against exploitation and mitigate the impact of the Log4Shell vulnerability, found in the Log4j2 Java library, said Ensign. 

"As Log4j is one of the most popular open-source Java logging libraries, it is integrated into many applications and services. Due to its widespread usage, this vulnerability impacts many organisations across various sectors globally. Furthermore, as the vulnerability is easy to exploit, the ramifications of this vulnerability are expected to be extensive," said Steven Ng, CIO and EVP of Managed Security Services, Ensign. 

Ensign advises organisations to: 

Identify  

"The vulnerability is highly exploited in the wild, with massive reconnaissance activity. Organisations should assess the use and impact of Apache Log4j2 library services in their environment and infrastructure as soon as possible, and identify affected assets, starting with externally-facing servers and applications," Ng said. 

"If third-party applications are impacted, organisations need to remain up-to-date and understand the vendor-specific recommended short-term mitigation measures, in addition to the timeframe for when a patch or update path will be made available, as the situation develops. 

"Organisations should keep a lookout for the release of scanning templates to identify this vulnerability and leverage internal and external vulnerability scanning tools. They should scan the environment to ascertain if this vulnerability exists. Additionally, they can use open-source vulnerability toolsets to identify vulnerable Log4j instances."  

Contain 

"Organisations must prioritise mitigation activities and patch applications as soon as the updates are released," Ng added. "For external-facing and vulnerable servers, organisations should restrict all Internet outbound traffic to the bare minimum to reduce the risk of remote code execution (RCE). Organisations can reduce the attack surface of impacted applications and servers by limiting access to the application interfaces that could be exploited."  

Detect 

"Organisations should focus on enhancing their visibility to identify attackers exploiting the vulnerability," Ng elaborated. 

He said they can also hunt for the Log4Shell exploitation by: 

- Searching for requests containing reference to the Java Naming and Directory Interface (JNDI) in available logs. 

- Hunting for known indicators of compromise (IOCs). 

"If an organisation identifies any exploitation on the server, it should verify if the server was vulnerable to the Log4Shell vulnerability during the timeframes of the suspicious access attempts. It should also investigate the identified payload for any malicious activity, for instance, dropped files, encoded commands, Java class loading etc," Ng said. 

"Organisations can check their systems to see if there are signs of compromise from 1 December 2021 before patching (to 2.15.0)," Ng added. 

"Organisations can search for outgoing LDAP connections to destinations not seen before 1 December. If such connections are found, they can search the host for the presence of Log4j. If there were DNS queries logged, they would need to review the queries to check for any possible exfiltration via DNS protocol."  

Remediate 

If a compromised Log4j instance is identified, organisations should conduct a forensic investigation, and implement remediation measures, such as removing any potentially malicious artifacts or backdoors, Ng continued. 

"An attacker can leverage environment variables that contain credentials or keys to obtain additional infrastructure (on-premises or cloud-based). If a compromised Log4j instance is running on a server where credentials are stored, organisations need to rotate and change the passwords or keys that could have been exposed," he noted.

Comments

Popular posts from this blog

NVIDIA brings secure agent workspaces and confidential computing to AI factories

Fortinet enhances FortiRecon to align with CTEM framework

Agnes AI enters global top 10 AI lab rankings