A contact form let attackers onto the server – then they rented it out
Security firm Huntress has written up an intrusion from 26 June that began with something almost every business website has: a form.
The page did not properly check what visitors typed into it. That let an attacker send instructions through the form and have them carried out by the database behind the website – a decades-old trick that still works whenever a form is built without the check that stops it.
What happened next is the interesting part. They did not steal the data and leave. They created an administrator account for themselves and switched on remote access. They added modules to the web server that quietly serve different pages to search engines than to real visitors, which is used to run search-ranking scams. They installed cryptocurrency mining software as a Windows service so it would restart with the machine. Then they turned off Windows Defender.
Who this affects
Anyone whose website does more than sit there. A contact form, a booking page, a quote request, a members’ area, a search box – anything that takes what a visitor types and does something with it is the surface being described here.
It is worth being clear about what the damage looks like, because it is not the usual picture. Nothing was ransomed and no customer got a letter. Instead the business quietly ended up running somebody else’s business: its server burning electricity to mine cryptocurrency, and its good name lent to search-ranking fraud. The likely first symptoms are a sluggish website, a larger hosting bill, and eventually Google deciding your site is not what it claimed to be.
The most uncomfortable detail is that the defences were switched off from inside. Once somebody has administrator rights on the machine, the antivirus is theirs to disable.
What to check
- Ask who built your forms, and whether input is validated. That is the whole root cause. Whoever looks after your site should be able to answer without hesitating.
- Keep the website software current. Not just the site itself but whatever it runs on. Old web applications are where this class of flaw survives.
- Look at your hosting bill and your site speed. Both are cheap early warnings. A server working hard at three in the morning is working for somebody.
- Check for accounts and services nobody added. A new administrator account and a new Windows service were the giveaways here.
- If you find something, find the way in as well. Removing the mining software and leaving the form unfixed simply invites the next visit.
Nobody notices a quiet break-in
Ransomware announces itself. This does not, which is why it ran long enough to be worth writing up. The businesses that catch this kind of thing are the ones where somebody is looking at the server rather than only at the website.
Keeping sites and their underlying software patched is what our website maintenance is for, and hosting security covers the machine underneath – watched round the clock, so a new service starting itself at three in the morning is a phone call rather than a slow month.
Call us on 01202 237 273 or book a call.