WEBVTT

1
00:00:03.200 --> 00:00:07.200
This is Decrypted. Thursday, the twenty-fourth of September.

2
00:00:07.200 --> 00:00:11.960
Roundcube's four-month-old patch is now a live attack.

3
00:00:11.960 --> 00:00:17.280
A webmail flaw patched in May is now being used against real servers.

4
00:00:17.280 --> 00:00:26.560
Shadowserver, quoted by BleepingComputer today, tracks more than 523,000 Roundcube instances online.

5
00:00:26.560 --> 00:00:28.640
Not all of them are vulnerable.

6
00:00:28.640 --> 00:00:34.640
The bug is C V E twenty twenty-six, four eight eight four two.

7
00:00:34.640 --> 00:00:42.160
It's a pre-authentication S Q L injection in a Roundcube plugin called virtuser_query.

8
00:00:42.160 --> 00:00:48.880
The Canadian Centre for Cyber Security updated its advisory on 21 September.

9
00:00:48.880 --> 00:00:55.200
It now says open-source reporting shows the bug is being exploited in the wild.

10
00:00:55.200 --> 00:00:57.640
And the fix has been available for four months.

11
00:00:57.640 --> 00:01:01.120
Next.

What actually broke.

12
00:01:01.120 --> 00:01:04.800
Webmail is the front door to the mailroom.

13
00:01:04.800 --> 00:01:10.240
Roundcube shows staff their inbox in a browser, so it usually faces the internet by design.

14
00:01:10.240 --> 00:01:15.760
Behind it sits a database holding account details, settings and address books.

15
00:01:15.760 --> 00:01:20.360
This flaw lets a stranger talk to that database before anyone has logged in.

16
00:01:20.360 --> 00:01:22.560
The mechanism is a classic.

17
00:01:22.560 --> 00:01:28.640
The virtuser_query plugin builds a database question from text a visitor supplies.

18
00:01:28.640 --> 00:01:32.400
The developers tried to neutralise dangerous characters.

19
00:01:32.400 --> 00:01:39.600
But a quirk in how P H P's preg_replace function handles backslashes lets crafted input through.

20
00:01:39.600 --> 00:01:44.200
Picture a receptionist who reads aloud any note handed across the desk.

21
00:01:44.200 --> 00:01:48.720
Now picture a visitor who writes the note so it ends with an extra instruction.

22
00:01:48.720 --> 00:01:52.400
The database can't tell which part came from the visitor.

23
00:01:52.400 --> 00:01:56.720
Versions before 1.6.16 and 1.

24
00:01:56.720 --> 00:02:04.400
7.1 are affected. BleepingComputer reports the attack needs no user interaction, and can steal data from the d

25
00:02:04.400 --> 00:02:08.560
atabase.

And also.

What a defender sees.

26
00:02:08.560 --> 00:02:12.960
Very little. That's my reading, not a reported finding.

27
00:02:12.960 --> 00:02:17.440
Nobody clicks anything, so there's no phishing email for staff to report.

28
00:02:17.440 --> 00:02:25.280
Any trace would sit in web server and database logs, in odd requests to the login page and unexpected queries

29
00:02:25.280 --> 00:02:30.480
. If you don't read those logs, you'll learn about this from whoever holds your stolen data.

30
00:02:30.480 --> 00:02:34.320
And also.

The Secure by Design lesson.

31
00:02:34.320 --> 00:02:38.400
Two lessons matter here, and one design decision worked.

32
00:02:38.400 --> 00:02:45.840
The plugin is optional. Plesk staff said in May that its default setup doesn't enable virtuser_query.

33
00:02:45.840 --> 00:02:48.720
Plesk released Roundcube 1.

34
00:02:48.720 --> 00:02:51.840
6.16 to its customers in early June.

35
00:02:51.840 --> 00:02:56.480
So Plesk customers on default settings were largely out of range.

36
00:02:56.480 --> 00:02:58.640
That's least exposure doing its job.

37
00:02:58.640 --> 00:03:02.640
A feature nobody asked for is a hole nobody can use.

38
00:03:02.640 --> 00:03:05.680
The second lesson is the patch gap.

39
00:03:05.680 --> 00:03:12.731
A pre-authentication bug defeats passwords and multi-factor authentication alike, because the attacker acts b

40
00:03:12.731 --> 00:03:18.160
efore the login matters. Beyond patching, shrink who can reach the page.

41
00:03:18.160 --> 00:03:23.200
Restrict webmail to known networks, or put it behind a gateway, where the business allows.

42
00:03:23.200 --> 00:03:26.720
And finally.

What it costs to apply.

43
00:03:26.720 --> 00:03:34.764
Less than the incident. Ask whoever runs your mail, whether that's an I T supplier, an agency or a hosting p

44
00:03:34.764 --> 00:03:38.400
rovider, three questions. Ask them in writing.

45
00:03:38.400 --> 00:03:40.880
Which Roundcube version are we running?

46
00:03:40.880 --> 00:03:45.120
Is virtuser_query enabled, and does anyone need it?

47
00:03:45.120 --> 00:03:48.840
And who is responsible for updating it, and how quickly?

48
00:03:48.840 --> 00:03:52.560
The Canadian Centre advises updating to 1.

49
00:03:52.560 --> 00:04:02.640
6.16 or 1.7.1. BleepingComputer says administrators who can't update yet can disable or remove the plugin.

50
00:04:02.640 --> 00:04:07.040
The check takes an hour, and disabling the plugin takes minutes.

51
00:04:07.040 --> 00:04:14.293
I suspect small UK firms are most exposed, since webmail often arrives inside a hosting package that nobody o

52
00:04:14.293 --> 00:04:22.160
n the payroll owns. That's opinion, not advice: an unowned server is a vulnerability whether or not it has a C

53
00:04:22.160 --> 00:04:25.320
V E number.

That was Decrypted.

54
00:04:25.320 --> 00:04:28.560
The written version and every source are linked in the show notes.

55
00:04:28.560 --> 00:04:30.000
Thanks for listening.

