{"id":23732,"date":"2022-03-21T00:25:05","date_gmt":"2022-03-20T23:25:05","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=23732"},"modified":"2022-03-21T00:25:05","modified_gmt":"2022-03-20T23:25:05","slug":"solarwinds-kunden-sollten-web-help-desk-entfernen","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/03\/21\/solarwinds-kunden-sollten-web-help-desk-entfernen\/","title":{"rendered":"SolarWinds customers should remove Web Help Desk"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/03\/21\/solarwinds-kunden-sollten-web-help-desk-entfernen\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]U.S. manufacturer Solarwinds warns its customers of possible cyber attacks and recommends uninstalling Web Help Desk (WHD) 12.7.5 in a security message dated March 15, 2022. The background is attacks on Web Help Desk (WHD) 12.7.5 reported by customers. So far it is still unclear what exactly happened, it is probably a precautionary measure.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg02.met.vgwort.de\/na\/0045d2f43ac9401b9c6d6740a1fbdbee\" width=\"1\" height=\"1\">SolarWinds was, after all, the victim of a supply chain attack in 2020, where customers' systems were hacked. Suspected state hackers had managed to manipulate SolarWinds' widely deployed network and security products around the world. A supply chain attack rolled out a Trojan or the SunBurst backdoor with a software update. This affected a great many SolarWinds customers. <\/p>\n<p>Therefore, it is no wonder that the US vendor SolarWinds is now reacting very quickly and on suspicion. I came across the security alert <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/whd1275\" target=\"_blank\" rel=\"noopener\">Advisory \/ Unauthenticated Access in Web Help Desk (WHD) 12.7.5<\/a>&nbsp; via the following <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1504872763407831040\" target=\"_blank\" rel=\"noopener\">tweet<\/a> as well as other press reports.<\/p>\n<p><a href=\"https:\/\/twitter.com\/campuscodi\/status\/1504872763407831040\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"SolarWinds Security Alert\" alt=\"SolarWinds Security Alert\" src=\"https:\/\/i.imgur.com\/SFt6Gwu.png\"><\/a><\/p>\n<p>The advisory states that a SolarWinds customer noticed and reported an external attack attempt on its instance of Web Help Desk (WHD) 12.7.5. The customer's Endpoint Detection and Response (EDR) system blocked the attack and alerted the customer to the problem. SolarWinds, which was hobbled by a supply chain attack, is currently investigating the report. The vendor writes that it was not able to reproduce the scenario. But they are working with the customer to continue the investigation.<\/p>\n<p>SolarWinds recommends all Web Help Desk customers whose Web Help Desk implementation is accessible from the Internet remove it from the public, Internet-accessible, infrastructure as a precaution until the vendor has further insight. Those who cannot do so should monitor the SolarWinds infrastructure for attacks using EDR software.<\/p>\n<p><strong>Similar articles:<\/strong><br \/><a href=\"https:\/\/www.borncity.com\/blog\/2020\/12\/09\/fireeye-wenn-hacker-eine-sicherheitsfirma-plndern\/\">FireEye hacked, Red Team tools stolen<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/14\/us-finanzministerium-und-weitere-us-behrde-gehackt\/\">US Treasury and US NTIA hacked<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/14\/solarwinds-produkte-mit-sunburst-backdoor-ursache-fr-fireeye-und-us-behrden-hacks\/\">SolarWinds products with SunBurst backdoor, cause of FireEye and US government hacks?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/15\/sloppiness-at-solarwinds-responsible-for-compromised-software\/\">Sloppiness at SolarWinds responsible for compromised software?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/16\/neues-im-kampf-gegen-die-sunburst-infektion-domain-beschlagnahmt\/\">News in the fight against SUNBURST infection, domain seized<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/17\/sunburst-malware-analytic-tool-solarflare-a-kill-switch-and-einsteins-fail\/\">SUNBURST malware: Analytic Tool SolarFlare, a 'Kill Switch' and EINSTEIN's fail<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/17\/sunburst-malware-was-injected-into-solarwinds-source-code-base\/\">SUNBURST malware was injected into SolarWind's source code base<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/18\/sunburst-hack-auch-us-atomwaffenbehrde-gehackt-neue-erkenntnisse\/\">SUNBURST: US nuclear weapons agency also hacked, new findings<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/18\/solarwinds-hack-auch-microsoft-co-betroffen\/\">SolarWinds hack: Microsoft and others also affected?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/21\/sunburst-hack-microsofts-analysen-und-neues\/\">SUNBURST hack: Microsoft's analysis and news<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/12\/22\/solarwinds-systeme-mit-2-backdoor-gefunden\/\">2nd backdoor found on infected SolarWinds systems<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/02\/solarwinds-hacker-hatten-zugriff-auf-microsoft-quellcode\/\">SolarWinds hackers had access to Microsoft source code<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/05\/solarwinds-hack-motive-der-angreifer-outsourcing-als-schwachstelle\/\">SolarWinds hack: Hacker goals; outsourcing are under investigation?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/08\/neues-vom-solarwinds-hack-jetbrains-software-als-einfallstor\/\">News from the SolarWinds hack; JetBrains software as a gateway?<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/12\/kaspersky-solarwinds-sunburst-backdoor-gleicht-russischer-atp-malware\/\">Kaspersky: SolarWinds Sunburst backdoor resembles Russian ATP malware<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/14\/solarleaks-bietet-angeblich-sourcecode-von-cisco-microsoft-und-solarwinds-an\/\">SolarLeaks allegedly offers source code from Cisco, Microsoft and SolarWinds<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/20\/auch-malwarebytes-von-den-solarwinds-angreifern-erfolgreich-gehackt\/\">Malwarebytes also successfully hacked by the SolarWinds attackers<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/01\/27\/vier-sicherheitsanbieter-besttigen-solarwinds-vorflle\/\">Four more security vendors confirm SolarWinds incidents<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/02\/27\/vorwurf-microsoft-hat-beim-solarwinds-hack-bei-der-sicherheit-gepatzt\/\">Accusation: Microsoft failed with security in the SolarWinds hack<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/03\/30\/solawwinds-update-fr-orion-software-angreifer-hatten-zugriff-auf-top-dhs-konten\/\">SolarWinds: Update for Orion software; attackers had access to top DHS accounts<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/07\/13\/solarwinds-patcht-kritische-serv-u-schwachstelle-juli-2021\/\">SolarWinds patches critical Serv-U vulnerability (July 2021)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/08\/01\/27-us-staatsanwaltschaften-von-solarwinds-hack-betroffen\/\">27 U.S. Attorney's Offices Affected by SolarWinds Hack<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/11\/02\/solarwinds-angreifer-nehmen-microsoft-partner-ins-visier\/\">SolarWinds attackers target Microsoft partners \u2013 lack of basic cyber-security<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]U.S. manufacturer Solarwinds warns its customers of possible cyber attacks and recommends uninstalling Web Help Desk (WHD) 12.7.5 in a security message dated March 15, 2022. The background is attacks on Web Help Desk (WHD) 12.7.5 reported by customers. So &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/03\/21\/solarwinds-kunden-sollten-web-help-desk-entfernen\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[69],"class_list":["post-23732","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=23732"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23732\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=23732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=23732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=23732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}