Scans Targeting Hospitality Applications, (Wed, Sep 16th)

LowSANS Internet Storm Center·

At a glance

Severity
Low
Used in attacks
No flaws named
Industries
Healthcare
Reported by
1 outlet

Earlier today, I noted an odd request showing up in our "First Seen" report:

GET /PIAF-HMS/ HTTP/1.1
Host: [redacted]
User-Agent: Farez-Sorter/1.0
Accept-Encoding: gzip

This request is linked to a rather old application, a "PBX in a Flash Hospitality Management System" [1]. The last update, the addition of a license file, happened 10 years ago, and I would consider the project abandoned. However, I also noted a new vulnerability reported a couple of months ago: An SQL injection issue. A quick scan of the code shows many more, and the author does not believe in input validation at all. I am also not seeing any authentication and access control, but I have a suspicion that this code may never have been used, and may be intended more as a lab/experiment to test some Asterix PBX integration. With that, I was about to move on.

However, looking at the somewhat odd user agent, I found a few other similar requests:

/admin/
/admin/config.php
/ucp/
/hms/
/hotel/

The scans started yesterday and have been continuing today. The only source IP for the scans is 94.102.49.125. This IP address is associated with IP Volume ( AS202425), which is often considered a bulletproof hoster. Hotels are often "soft targets" for attackers seeking to steal valuable personal data. In some cases, they have been compromised to launch MitM attacks against guests. The focus on PBX systems is interesting, and maybe there are some tricks that could be played on guests if an attacker can appear to call from "inside" the property.

Please let me know if you have some insight as to what is going on here.

[1] https://github.com/claudiopizzillo/PIAF-HMS

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.

Read at isc.sans.edu ↗Established Source

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. SANS Internet Storm Center ↗Established SourceFirst reported

    2026-09-16 18:44 UTC

Related stories