How did hackers take control of Ferrari's website?

Red Ferrari Enzo image

Ethical hacker and bug bounty hunter Sam Curry reported that Ferrari’s subdomain forms.ferrari.com was hosting a fake NFT (Non-Fungible Token) scam. The attackers exploited a flaw in the Adobe Experience Manager on the official website of Ferrari to hijack its subdomain and host the encrypted NFT scam content. After looking deeper, it seems this was an Adobe Experience Manager exploit.

What website vulnerability was exploited by hackers?

The attackers exploited a flaw in the Adobe Experience Manager on the official website of Ferrari to hijack its subdomain and host the encrypted NFT scam content. The bug in Adobe Experience Manager (AEM) was detected by two members of Detectify’s ethical hacking community. If left unchecked, the weakness allows attackers to bypass authentication and gain access to CRX Package Manager, leaving applications open to remote code execution (RCE) attacks.

How could the hack have been prevented?

There are some general steps to avoid such attacks. Keeping software up-to-date and applying security patches is a good first step. But most critically it is important to continuously monitor the website for all open subdomains and endpoints. It is also important to regularly monitor your website for suspicious activity and to have a plan in place for responding to security incidents.

By using this website you agree to our Cookie Policy.

Cookie Settings

We use cookies to improve user experience. Choose what cookie categories you allow us to use. You can read more about our Cookie Policy by clicking on Cookie Policy below.

These cookies enable strictly necessary cookies for security, language support and verification of identity. These cookies can’t be disabled.

These cookies collect data to remember choices users make to improve and give a better user experience. Disabling can cause some parts of the site to not work properly.

These cookies help us to understand how visitors interact with our website, help us measure and analyze traffic to improve our service.

These cookies help us to better deliver marketing content and customized ads.