Case E9E092 · Famous breaches · L3 Applied
MOVEit on your perimeter
Practise as: Incident drill · Interview
Live alertIt is 1 June 2023. You run an internet-facing MOVEit Transfer server. Progress has just disclosed a critical SQL injection being exploited, and you find a file named human2.aspx in wwwroot.
Interview questionYou are the responder. What happens in your first 24 hours?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- human2.aspx is the LEMURLOOT web shell used by Cl0p with CVE-2023-34362: assume compromise, not just exposure
- Cut HTTP/HTTPS access to the server, preserve IIS logs, the web shell and DB, then patch per Progress guidance
- Scope exfil: review IIS logs for the web shell and the MOVEit audit log for bulk file downloads since late May
- Rotate service account creds and Azure keys the app held; remove unknown MOVEit user accounts
- Start breach notification analysis: which files, whose data, which regulators and customers
If the interviewer pushes back
- Cl0p ran this as mass data theft without encryption. How does that change your negotiation and notification plan?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.