Construction firms breached in brute force attacks on accounting software

Share:

Hackers are brute-forcing passwords for highly privileged accounts on exposed Foundation accounting servers, widely used in the construction industry, to breach corporate networks.

The malicious activity was first spotted by Huntress, whose researchers detected the attacks on September 14, 2024.

Huntress has already seen active breaches through these attacks at plumbing, HVAC, concrete, and other sub-industry companies.

Open ports and weak passwords

In these attacks, the attackers are taking advantage of a combination of exposed services amplified by users not changing default credentials on privileged accounts.

Huntress explains that the Foundation software includes a Microsoft SQL Server (MSSQL) that can be configured to be publicly accessible via TCP port 4243 to support a companion mobile app.

However, this also exposes the Microsoft SQL server to external attacks that try and brute force MSSQL accounts configured on the server.

By default, MSSQL has an admin account named ‘sa’ while Foundation has added a second one named ‘dba.’

Users who have not changed the default passwords on these accounts are susceptible to hijacks by external actors. Those who did but picked weak passwords may still be compromised via brute-forcing.

Huntress reports that it observed very aggressive brute-force attacks against these servers, sometimes reaching up to 35,000 attempts on a single host over an hour before they successfully guessed a password.

Once the attackers gain access, they enable the MSSQL ‘xp_cmdshell’ feature, which allows the threat actors to execute commands in the operating system through an SQL query.

For example, the EXEC xp_cmdshell 'ipconfig' query will cause the ipconfig command to be executed in a Windows command shell, and the output will be displayed in the response.

SQL server process spawning cmd for command execution on Windows
SQL server process spawning cmd for command execution on Windows
Source: Huntress

Two commands observed in the attacks are ‘ipconfig,’ to retrieve network configuration details, and ‘wmic,’ to extract information about the hardware, OS, and user accounts.

Huntress’s investigation from the three million endpoints under its protection unveiled 500 hosts running the targeted accounting software, 33 of which publicly exposed MSSQL databases with default admin credentials.

Huntress told BleepingComputer it had alerted Foundation of its findings, and the software vendor responded by saying the issue only affected the on-premise version of its application and not their cloud-based product.

Foundation also noted that not all servers have port 4243 open, and not all targeted accounts use the same default credentials.

Huntress recommends that Foundation admins rotate account credentials and ensure they’re not publicly exposing the MSSQL server if not needed.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:06 pm, Jan 24, 2025
weather icon 8°C
L: 6° | H: 9°
scattered clouds
Humidity: 86 %
Pressure: 1000 mb
Wind: 6 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:49 am
Sunset: 4:35 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
6° | 9°°C 1 mm 100% 7 mph 91 % 1010 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 19 mph 90 % 1000 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 8°°C 0 mm 0% 5 mph 87 % 1000 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 7°°C 0 mm 0% 4 mph 88 % 1000 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 5°°C 1 mm 100% 7 mph 91 % 1001 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 73 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,817.25
0.85%
Ethereum(ETH)
€3,162.98
0.09%
XRP(XRP)
€2.95
-0.75%
Tether(USDT)
€0.95
-0.02%
Solana(SOL)
€242.44
1.51%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.333759
-0.56%
Shiba Inu(SHIB)
€0.000019
-1.03%
Pepe(PEPE)
€0.000014
-0.19%
Peanut the Squirrel(PNUT)
€0.341611
3.03%
Scroll to Top