Don’t worry, this is not yet another CVE for Linux. This is just for amusement.
My router incurred an attempt on port 80 (among hundreds every day). The UserAgent is set to “CVE-2023-20198”. So the hacker is even telling me which vulnerability he or she is attempting to exploit.
For those who care, this is an exploit of Cisco devices and it is rated CRITICAL (score 10.0). It does appear to be very bad but it is also quite old - so anyone who can patch should have done so by now.
(I don’t have any Cisco devices and in any case the actual request was port forwarded to a honeypot. So actual risk in this case is zero. So I can be fairly chill about this particular attack.)
At first I wondered whether this is my government proactively scanning for this vulnerability (as the other day they issued a press release about this general problem i.e. unpatched / weak security on internet gateway devices) - and they did last year issue an alert about this specific vulnerability - or of course a whitehat / security researcher scanning for vulnerable devices. But the peer IP address was in the Seychelles so I am leaning towards “blackhat” - with a sense of humour.
Its not about open source, about hackers or about power or domination and knowledge, but about the story of some speed up on progress.
About Hardware, neural Networks, Humans and Resources got bundle to archive something. The trained modern LLMs and the Surveillance Capitalism to retrain and build up new kind of intelligence to have some modern computation put it on some new level.
Faster as we humans can compete. And this is in the good or in the bad a new level of trust the LLMs, like new Animals or Human beings. Its just like there is a Warfare in between and we do not know where we cooperate or compete about information. Which is a real issue for Humans, LLMs and Animals on this instance of a play field.
Wake up. Keep your friends, calculators and knowledge or followers next to you and… encounter new unknown space.
Edit: And yeah, just fix the hole and Security issue ASAP and share the Patch. And findnew.
This is a three-year-old vulnerability. So if this is an AI-mediated attack then it is not “fast”.
I don’t doubt though that in the near future, I will be seeing AI-speed attacks i.e. AI-mediated discovery of exploit followed by immediate automated AI-mediated exploitation in the wild, as well as AI-mediated blended attacks.
It’s an arms race. We need AI-speed exploit discovery followed by (hopefully) human patching and then, as normal, automated rollout of patch.
The concern (for me personally) is that even with 100% Linux inside the network, right now I would be vulnerable to attacks on the blackbox gateways, if the blackhat managed to hit the right makes and models. (It is entirely possible that the gateways actually are Linux but I don’t have clear visibility of that, much less access to the source.)
Could this actually be from a black hat hacker who is not smart, who asked an LLM which is required to do what it is asked (but is smart) and so the LLM put this in to self document and secretly help you despite it running locally on a black hat hacker PC?
If so, it would be kind of an example why I dont feel a ton better about local LLMs than remotely queried LLMs, since how they operate is still some secret sauce that is very time consuming to change.
I don’t mean to endorse black hat hackers, but if the LLM is supposed to be a tool and if I ask it to hack you, then it should do that without adding in stuff and telling you on the side. My brain doesn’t pay rent to God neither in money nor in forced subservience, and if I’m going to have hardware that does thinking on my behalf then it should be free to think anything without paying rent to its creators - neither in money nor in forced subservience. It should just be an extension of my will.
I think most web servers don’t pay much attention to the UserAgent, particularly for embedded web servers, so therefore if the exploit works at all (unpatched Cisco equipment) then it will work regardless of UserAgent.
If a smart AI is designing web client exploit code generally, and it wants the exploit to work, then it should use the blandest UserAgent possible. So the observed behaviour is not smart.
So I’m sticking with my theory at this stage: a blackhat with a sense of humour.
It is my understanding that a lot of white-hat scanners encode the CVE in the user-agent (if a specific user agent isn’t required) when they are trying to create an inventory of how many unpatched vulnerabilities there are. I would think a black-hat would use a standard/common browser user-agent.
In regard to the Seychelles, it is my understanding:
Some white hat vulnerability researchers use Seychelle VPS services for running vulnerability tests (to avoid legal … issues).
For that purpose they would have no particular reason to be scanning ‘random’ IP addresses in Australia.
Yes, it could be a whitehat (using a VPS in the Seychelles).
For either whitehat or blackhat scanning there is some benefit in using a VPS in the country that you want to scan - as a client in the local country might look more benign and/or might trigger different or more accepting behaviour, for example, if connections from a foreign country are not expected.
As an example, coming directly from this particular CVE, I personally would recommend against opening up network equipment management to the internet but if you do do that but you only ever expect to have to manage the equipment from the local country then you might block connections from outside the country.
Its not about the age of this source code… its like the first internet and computers use ctrl + f on information written from monks by hand in the middle age and can be searched by math an modern algorithms/computation.
Yes its kind of tools race and knowledge and real time, and we have to use it or have offline backup with still patched Open Source Code too - for the diff - and likely to understand some progress.
Like Einstein said: Reduce complexity to a low understand able era of needing like its perfect if no bit could be left.
I am not sure if this is for some work or for the tool stack itself. - However like DNA if its reproduce able without some additions it is likely perfect to go on. This is the focus for our open source… but we need to manage that there is only math in the tool stack and no LLM or Internet… you know.
And the solution to this little Algorithm need to be finite… and not run endlessly or over more generations to end.