{"id":35281,"date":"2019-10-31T22:03:25","date_gmt":"2019-10-31T19:03:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\/"},"modified":"2019-10-31T22:03:25","modified_gmt":"2019-10-31T19:03:25","slug":"massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","title":{"rendered":"Massiver Angriff auf verwundbare Mailserver auf Basis von Exim","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p> Sicherheitsexperten von Cybereason <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability\">haben gewarnt<\/a><\/noindex> Mailserveradministratoren \u00fcber die Entdeckung eines massiven automatisierten Angriffs, der <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">eine kritische Schwachstelle<\/a><\/noindex> (CVE-2019-10149) in Exim, die in der letzten Woche entdeckt wurde. Bei dem Angriff gelingt es den Angreifern, ihren Code mit Root-Rechten auszuf\u00fchren und Schadsoftware zur Kryptow\u00e4hrungs-Mining auf dem Server zu installieren.<\/p>\n<p>Laut dem Juni-Bericht <noindex><a rel=\"nofollow\" href=\"http:\/\/www.securityspace.com\/s_survey\/data\/man.201905\/mxsurvey.html\">Automatisierten Umfrage<\/a><\/noindex> Der Anteil von Exim betr\u00e4gt 57,05 % (vor einem Jahr 56,56 %), Postfix wird auf 34,52 % (33,79 %) der Mailserver verwendet, Sendmail \u2013 4,05 % (4,59 %), Microsoft Exchange \u2013 0,57 % (0,85 %). Laut <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/report\/uSLHrfCA\">Angaben<\/a><\/noindex> Shodan-Diensten sind \u00fcber 3,6 Millionen Mailserver im globalen Netz potenziell anf\u00e4llig, die nicht auf die neueste Version 4.92 von Exim aktualisiert wurden. Von diesen befinden sich etwa 2 Millionen potenziell gef\u00e4hrdete Server in den USA und 192.000 in Russland. Nach <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D89Gf0KUcAAJY44.jpg\">Informationen<\/a><\/noindex> RiskIQ hat bereits 70 % der Server mit Exim auf Version 4.92 aktualisiert.<\/p>\n<p><center><img decoding=\"async\" alt=\"Massiver Angriff auf verwundbare Mailserver auf Basis von Exim\" src=\"\/wp-content\/uploads\/2019\/06\/f179c76afaa02fedfe6c542f99dbcb9c.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Administratoren wird dringend empfohlen, die Updates umgehend zu installieren, die bereits in der letzten Woche von den Distributoren vorbereitet wurden (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">Debian<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-10149.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-10149\">openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/community\/x86_64\/exim\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-7b741dcaa4\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">EPEL f\u00fcr RHEL\/CentOS<\/a><\/noindex>). Wenn in dem System eine verwundbare Version von Exim (zwischen 4.87 und 4.91 einschlie\u00dflich) vorhanden ist, sollte \u00fcberpr\u00fcft werden, dass das System nicht kompromittiert wurde, indem crontab auf verd\u00e4chtige Aufrufe \u00fcberpr\u00fcft und sichergestellt wird, dass keine zus\u00e4tzlichen Schl\u00fcssel im Verzeichnis \/root\/.ssh vorhanden sind. Ein Hinweis auf den Angriff kann auch sein, wenn im Firewall-Log Aktivit\u00e4ten von den Hosts an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io und an7kmd2wp4xo7hpr.onion.sh festgestellt werden, die w\u00e4hrend des Downloads von Schadsoftware verwendet werden. <\/p>\n<p>Die ersten Angriffsversuche auf Exim-Server <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/freddieleeman\/status\/1137729455181500421\">Angriffe mit dieser Schwachstelle dokumentiert wurden und sich ein funktionierendes Exploit in den H\u00e4nden von Angreifern befindet. Allen Firefox-Nutzern wird dringend empfohlen, den Browser umgehend zu aktualisieren, w\u00e4hrend Nutzer des Tor Browsers<\/a><\/noindex> fanden am 9. Juni statt. Bis zum 13. Juni nahm der Angriff <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/0xAmit\/status\/1139165487093420035\">massive<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/forums.zimbra.org\/viewtopic.php?t=65932&#038;start=140\">Ausma\u00dfe an. Nach der Ausnutzung der Schwachstelle wird \u00fcber Tor2web-Gateways vom Hidden Service Tor (an7kmd2wp4xo7hpr) ein Skript geladen, das \u00fcberpr\u00fcft, ob OpenSSH vorhanden ist (wenn nicht<\/a><\/noindex> wird es installiert <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gM2mWsAAhwD4.jpg\">), \u00e4ndert die Konfiguration (<\/a><\/noindex>erlaubt<noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gZ0sX4AAeHgm.jpg\">den Root-Zugang und die Authentifizierung \u00fcber Schl\u00fcssel) und richtet f\u00fcr den Benutzer root<\/a><\/noindex> einen RSA-Schl\u00fcssel <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/aserper\/e36d382668c6cf2c996c5143025097c0#file-gistfile1-txt\">, der privilegierten Zugriff auf das System \u00fcber SSH bietet.<\/a><\/noindex>, der privilegierten Zugriff auf das System \u00fcber SSH gew\u00e4hrt.<\/p>\n<p>Nach der Installation des Backdoors wird ein Port-Scanner auf dem System eingerichtet, um andere verwundbare Server zu identifizieren. Es wird auch nach bereits vorhandenen Mining-Systemen im System gesucht, die im Falle einer Entdeckung entfernt werden. In der letzten Phase wird der eigene Miner heruntergeladen und im crontab registriert. Der Miner wird als ico-Datei geladen (tats\u00e4chlich handelt es sich um ein zip-Archiv mit dem Passwort \u201eno-password\u201c), in dem eine ausf\u00fchrbare Datei im ELF-Format f\u00fcr Linux mit Glibc 2.7+ verpackt ist.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50870\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0445 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043c\u0430\u0441\u0441\u043e\u0432\u043e\u0439 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-10149) \u0432 Exim, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u043d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u043d\u0435\u0434\u0435\u043b\u0435. \u0412 \u0445\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0434\u043e\u0431\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0434\u043b\u044f \u043c\u0430\u0439\u043d\u0438\u043d\u0433\u0430 \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442. \u0412 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u0438\u044e\u043d\u044c\u0441\u043a\u0438\u043c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043e\u043f\u0440\u043e\u0441\u043e\u043c \u0434\u043e\u043b\u044f Exim \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 57.05% (\u0433\u043e\u0434 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Massenangriff auf anf\u00e4llige Mailserver auf der Basis von Exim | ProHoster","description":"Sicherheitsforscher von Cybereason haben gewarnt.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:03:25+00:00","article:modified_time":"2019-10-31T19:03:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35281","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 22:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:06:25","updated":"2026-01-21 22:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/35281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=35281"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/35281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/26492"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=35281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=35281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=35281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}