Construction firms breached in brute force attacks on accounting software

Share:

Hackers are brute-forcing passwords for highly privileged accounts on exposed Foundation accounting servers, widely used in the construction industry, to breach corporate networks.

The malicious activity was first spotted by Huntress, whose researchers detected the attacks on September 14, 2024.

Huntress has already seen active breaches through these attacks at plumbing, HVAC, concrete, and other sub-industry companies.

Open ports and weak passwords

In these attacks, the attackers are taking advantage of a combination of exposed services amplified by users not changing default credentials on privileged accounts.

Huntress explains that the Foundation software includes a Microsoft SQL Server (MSSQL) that can be configured to be publicly accessible via TCP port 4243 to support a companion mobile app.

However, this also exposes the Microsoft SQL server to external attacks that try and brute force MSSQL accounts configured on the server.

By default, MSSQL has an admin account named ‘sa’ while Foundation has added a second one named ‘dba.’

Users who have not changed the default passwords on these accounts are susceptible to hijacks by external actors. Those who did but picked weak passwords may still be compromised via brute-forcing.

Huntress reports that it observed very aggressive brute-force attacks against these servers, sometimes reaching up to 35,000 attempts on a single host over an hour before they successfully guessed a password.

Once the attackers gain access, they enable the MSSQL ‘xp_cmdshell’ feature, which allows the threat actors to execute commands in the operating system through an SQL query.

For example, the EXEC xp_cmdshell 'ipconfig' query will cause the ipconfig command to be executed in a Windows command shell, and the output will be displayed in the response.

SQL server process spawning cmd for command execution on Windows
SQL server process spawning cmd for command execution on Windows
Source: Huntress

Two commands observed in the attacks are ‘ipconfig,’ to retrieve network configuration details, and ‘wmic,’ to extract information about the hardware, OS, and user accounts.

Huntress’s investigation from the three million endpoints under its protection unveiled 500 hosts running the targeted accounting software, 33 of which publicly exposed MSSQL databases with default admin credentials.

Huntress told BleepingComputer it had alerted Foundation of its findings, and the software vendor responded by saying the issue only affected the on-premise version of its application and not their cloud-based product.

Foundation also noted that not all servers have port 4243 open, and not all targeted accounts use the same default credentials.

Huntress recommends that Foundation admins rotate account credentials and ensure they’re not publicly exposing the MSSQL server if not needed.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:49 am, Jan 26, 2025
weather icon 2°C
L: -0° | H: 3°
clear sky
Humidity: 82 %
Pressure: 1008 mb
Wind: 5 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:47 am
Sunset: 4:38 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
-0° | 3°°C 1 mm 100% 19 mph 93 % 1008 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 9°°C 1 mm 100% 25 mph 88 % 980 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 22 mph 84 % 999 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 18 mph 91 % 1001 mb 0 mm/h
Thu Jan 30 9:00 pm
weather icon
6° | 7°°C 1 mm 100% 9 mph 93 % 1024 mb 0 mm/h
Today 3:00 am
weather icon
2° | 3°°C 0 mm 0% 6 mph 79 % 1008 mb 0 mm/h
Today 6:00 am
weather icon
3° | 4°°C 0 mm 0% 10 mph 77 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
5° | 5°°C 0 mm 0% 14 mph 82 % 1000 mb 0 mm/h
Today 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 18 mph 77 % 996 mb 0 mm/h
Today 3:00 pm
weather icon
5° | 5°°C 1 mm 100% 19 mph 93 % 989 mb 0 mm/h
Today 6:00 pm
weather icon
8° | 8°°C 1 mm 100% 13 mph 81 % 986 mb 0 mm/h
Today 9:00 pm
weather icon
8° | 8°°C 0 mm 0% 13 mph 85 % 984 mb 0 mm/h
Tomorrow 12:00 am
weather icon
9° | 9°°C 1 mm 100% 25 mph 88 % 976 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,634.35
0.12%
Ethereum(ETH)
€3,162.74
1.10%
XRP(XRP)
€2.97
0.39%
Tether(USDT)
€0.95
-0.02%
Solana(SOL)
€243.73
2.67%
Dogecoin(DOGE)
€0.337852
2.10%
USDC(USDC)
€0.95
0.01%
Shiba Inu(SHIB)
€0.000019
1.31%
Pepe(PEPE)
€0.000014
3.26%
Peanut the Squirrel(PNUT)
€0.341643
3.03%
Scroll to Top