Saturday, April 1, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7
No Result
View All Result

Home > Cybersecurity > Fortra’s GoAnywhere managed file transfer is under attack

Fortra’s GoAnywhere managed file transfer is under attack

Fortra's GoAnywhere MFT (managed file transfer) is facing a zero-day remote code injection exploit.


Ezgi Koc Ezgi Koc
February 6, 2023
2 min read
Fortra's GoAnywhere managed file transfer is under attack
  • The GoAnywhere MFT (Managed File Transfer) faces a zero-day remote code injection exploit and a patch is not yet available.
  • The vulnerability allows unauthorized people to gain access to the administrative console of an application, which means they can change or delete information.
  • The company has issued a security advisory which is behind a membership wall, which shows ways to evaluate and mitigate your possible exposure to the exploit.

The GoAnywhere MFT (managed file transfer) is a storage device that can be used with any operating system. It is developed to provide convenient and reliable backup of data stored on your computer’s hard drive, as well as remote access to files and folders. Fortra’s GoAnywhere MFT is warning users about a zero-day remote code injection exploit. The company is taking steps to address the issue by temporarily shutting down its service.

How to spot if you have been affected

The vulnerability is utilized to get access to the administrative console of an application, which means malicious actors can do things like change or delete information. So it’s essential to keep the application safe from being accessed by the public internet. Since this exploit requires access to the administrative console of the application, which is usually only accessible from within a private company network, through a VPN, or if the application is running in a cloud environment, such as Azure or AWS.

On its security advisory, which security reporter Brian Krebs provided since the advisory seems to be only accessible by members, the company provided ways to evaluate and mitigate your possible exposure to the exploit:

1. Review all administrator users

Evaluate your admin user accounts for anything suspicious. Key indicators on these accounts include unrecognized usernames. You can view more details by clicking the cog icon next to any User Name listed and selecting the “View” option.

If the timing of the account creation seems recent or suspicious, investigate further. You can search the Administration log for activity (Reporting -> Audit Logs -> Administration). Search for anything created by the root user. Click the magnifying glass next to the log of suspicious activity to view more details.

2. Apply mitigation configuration

On the file system where GoAnywhere MFT is installed, edit the file [install_dir]/adminroot/WEB_INF/web.xml. Find and remove (delete or comment out) the following servlet and servlet-mapping configuration in the screenshot below.

cloud7news GoAnywhere MFT

If GoAnywhere MFT is clustered, this change needs to happen on every instance node in the cluster.

Fortra has not released a patch or update as of writing this.

See more Cybersecurity News

A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


Tags: FortraGoAnywhere MFT
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7. She graduated from Ege University with a bachelor's degree in English Language and Literature. She has always had great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
Travis Spencer

Cloud7 Expert Series: Travis Spencer from Curity

Related News

7 best practices and tools to use for Linux security

7 best practices and tools to use for Linux security

March 24, 2023 5:00 pm
CISA aims to identify vulnerabilities that attract ransomware

CISA aims to identify vulnerabilities that attract ransomware

March 22, 2023 2:10 pm
7 best cybersecurity schools

7 best cybersecurity schools

March 21, 2023 9:00 pm
Akamai researchers warn about the new HinataBot botnet

Akamai researchers warn about the new HinataBot botnet

March 20, 2023 6:10 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Recent News

  • How to take a screenshot on Windows 11
  • 7 games you can play on the Linux terminal
  • Leostream announces hybrid cloud environments with WorkSpaces Core
  • Now you can move Yandex Mail to ispmanager
  • 7 best SEO plugins for WordPress

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • Artificial Intelligence
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About Us
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.