U.S. ports and port authorities hit by Web SQL injection attack

Year

2016

Month

August

Reference number

20160801

Impact area

Shore

Incident location

Houston TX, Atlanta GA, Norfolk VA

Incident country

USA

Victim country

USA

Victim identity

U.S. ports and 13 organizations’ port authorities and logistics operators worldwide using Navis Webacces.

Victim Type

Port

Method

SQL injection

Summary:

in August 2016, U.S. ports and 13 organizations’ port authorities and logistics operators worldwide using Navis Webacces got hit by a SQL injection. In this attack the hacker released a fully working exploit online without notifying the vendor in advance. The hacker was able to view/ modify/ delete data. In 2016 an ethical hacker "bRpsd" revealed that Navis WebAccess - a web-based app that provides transport operators real-time access to operational logistics information - was highly vulnerable to a critical SQL injection vulnerability. (CVE-2016-5817) A vulnerability that could be exploited by a remote attacker to read or modify data stored in the application’s database. The patch management was well-timed, the software vendor, Navis, was informed about the vulnerability on August 9, just a day after Rpsd published the PoC exploit. Navis released custom patches on August 10.

Reference URL

https://www.securitynewspaper.com/2016/08/24/navis-webaccess-app-used-us-ports-affected-sql-injection-flaw/
https://news.softpedia.com/news/us-ports-targeted-with-zero-day-sql-injection-flaw-507566.shtml
https://www.cisa.gov/uscert/ics/advisories/ICSA-16-231-01
https://threatspan.com/2017/12/29/top-11-maritime-security-compromises-of-all-time/