Intercepted encrypted traffic from jabber.ru and xmpp.ru

The administrator of the Jabber server jabber.ru (xmpp.ru) identified a user traffic decryption attack (MITM) occurring for a duration of between 90 days to 6 months at the German hosting providers Hetzner and Linode, where the project server and auxiliary VPS environments are hosted. The attack was organized through traffic redirection to a transit node that replaces the TLS certificate for XMPP connections encrypted using the STARTTLS extension.

The attack was noticed due to an error by its organizers, who failed to renew the TLS certificate used for the substitution. On October 16, the administrator of jabber.ru, upon attempting to connect to the service, received an error message due to the expiration of the certificate, but the certificate hosted on the server was not expired. It was ultimately discovered that the certificate received by the client differed from the certificate sent by the server. The first counterfeit TLS certificate was obtained on April 18, 2023, through the Let’s Encrypt service, where the attacker, having the ability to intercept traffic, was able to confirm access to the websites jabber.ru and xmpp.ru.

Initially, there was a suspicion of server compromise and a substitution on its part. However, the conducted audit found no signs of a breach. At the same time, a brief disconnection and reconnection of the network interface (NIC Link is Down/NIC Link is Up) was noted in the server log, which occurred on July 18 at 12:58 and could indicate manipulation with the server's connection to the switch. Notably, two counterfeit TLS certificates were generated just minutes before this — on July 18 at 12:49 and 12:38.

Moreover, the substitution occurred not only in the Hetzner provider's network, where the main server is located, but also in Linode's network, where the VPS environments with auxiliary proxies redirecting traffic from other addresses were hosted. Indirectly, it was found that traffic to port 5222 (XMPP STARTTLS) in both providers’ networks was being redirected through an additional host, which provided grounds to believe that the attack was carried out by someone with access to the providers' infrastructure.

Theoretically, the substitution could have taken place since April 18 (the date of the creation of the first fake certificate for jabber.ru), but confirmed cases of certificate substitution were recorded only from July 21 to October 19. All this time, encrypted data exchange with jabber.ru and xmpp.ru can be considered compromised. The substitution ceased after the investigation began, tests were conducted, and on October 18, requests were sent to the support services of providers Hetzner and Linode. Additionally, an extra hop in packet routing sent to port 5222 of one of servers Linode is still observed, but the certificate is no longer being substituted.

It is assumed that the attack could have been carried out with the knowledge of the providers at the request of law enforcement agencies, as a result of a breach of the infrastructure of both providers, or by an employee who had access to both providers. Having the ability to intercept and modify XMPP traffic, the attacker could have accessed all data related to the accounts, such as the message exchange history stored on the server, and could send messages on behalf of others and make changes to other messages. Messages sent using end-to-end encryption (OMEMO, OTR, or PGP) can be considered uncompromised if the encryption keys are verified by users on both sides of the connection. Users of jabber.ru are advised to change their access passwords and check the OMEMO and PGP keys in their PEP stores for possible substitution.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster