Open cardosec

Case E9E092 · Famous breaches · L3 Applied

MOVEit on your perimeter

Practise as: Incident drill · Interview

Live alertIt is 1 June 2023. You run an internet-facing MOVEit Transfer server. Progress has just disclosed a critical SQL injection being exploited, and you find a file named human2.aspx in wwwroot.

Interview questionYou are the responder. What happens in your first 24 hours?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. human2.aspx is the LEMURLOOT web shell used by Cl0p with CVE-2023-34362: assume compromise, not just exposure
  2. Cut HTTP/HTTPS access to the server, preserve IIS logs, the web shell and DB, then patch per Progress guidance
  3. Scope exfil: review IIS logs for the web shell and the MOVEit audit log for bulk file downloads since late May
  4. Rotate service account creds and Azure keys the app held; remove unknown MOVEit user accounts
  5. Start breach notification analysis: which files, whose data, which regulators and customers

If the interviewer pushes back

  • Cl0p ran this as mass data theft without encryption. How does that change your negotiation and notification plan?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.