Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hackers Scanning for Apache Tomcat Servers Vulnerable to Ghostcat Attacks

Hackers have started scanning the web in search of Apache Tomcat servers affected by a recently disclosed vulnerability tracked as CVE-2020-1938 and dubbed Ghostcat.

Hackers have started scanning the web in search of Apache Tomcat servers affected by a recently disclosed vulnerability tracked as CVE-2020-1938 and dubbed Ghostcat.

Threat intelligence service Bad Packets reported on March 1 that it had started seeing mass scanning activity targeting the vulnerability and urged organizations to patch their installations as soon as possible.

Bad Packets told SecurityWeek on Wednesday that the scanning activity they have detected is designed to enumerate vulnerable servers by checking for the path “/WEB-INF/web.xml”.Ghostcat

Proof-of-concept (PoC) exploits have been released by various researchers and several of them reference this path.

“Outside of known security researchers, we’ve detected hundreds of unique scans originating from hosts in China checking for the vulnerability,” Bad Packets said.

The Ghostcat vulnerability has existed for more than a decade and it affects versions 6, 7, 8 and 9 of Apache Tomcat. The flaw was reported by Chinese cybersecurity firm Chaitin Tech to the Apache Software Foundation on January 3. Patches were made available last month with the release of versions 9.0.31, 8.5.51 and 7.0.100.

The security hole is related to the Apache JServ Protocol (AJP) protocol, which is designed to improve performance by proxying inbound requests from a web server through to an application server.

Advertisement. Scroll to continue reading.

A remote, unauthenticated attacker can exploit it to access configuration and source code files. If the server allows users to upload files, the flaw can also be exploited for arbitrary code execution.

Ghostcat affects the default configuration of Tomcat and many servers are vulnerable to attacks directly from the internet. ONYPHE reported in late February that a scan had identified over 170,000 potentially vulnerable devices.

Related: Symantec Warns of Apache Tomcat Server Worm

Related: Code Execution Flaws Patched in Apache Tomcat

Related: Information Disclosure, DoS Flaws Patched in Apache Tomcat

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.