{"id":78849,"date":"2020-04-22T13:42:05","date_gmt":"2020-04-22T11:42:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki"},"modified":"2020-04-22T13:42:05","modified_gmt":"2020-04-22T11:42:05","slug":"bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","title":{"rendered":"Die meisten Antivirenprogramme waren anf\u00e4llig f\u00fcr Angriffe \u00fcber symbolische Links.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Forscher von RACK911 Labs <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rack911labs.com\/research\/exploiting-almost-every-antivirus-software\/\">stellten fest<\/a><\/noindex> , dass fast alle Antivirenpakete f\u00fcr Windows, Linux und macOS anf\u00e4llig f\u00fcr Angriffe waren, die Zustandsrennen (race conditions) beim L\u00f6schen von Dateien ausnutzten, in denen Malware gefunden wurde.<\/p>\n<p>F\u00fcr einen Angriff muss eine Datei hochgeladen werden, die das Antivirenprogramm als sch\u00e4dlich erkennt (zum Beispiel kann eine Testsignatur verwendet werden), und nach einer bestimmten Zeit, nachdem die sch\u00e4dliche Datei vom Antivirenprogramm erkannt wurde, aber bevor die Funktion zum L\u00f6schen aufgerufen wird, muss das Verzeichnis mit einer symbolischen Verkn\u00fcpfung ersetzt werden. In Windows wird derselbe Effekt durch das Ersetzen des Verzeichnisses mit einer Junction Point erreicht. Das Problem ist, dass fast alle Antivirenprogramme nicht richtig auf symbolische Verkn\u00fcpfungen \u00fcberpr\u00fcften, und w\u00e4hrend sie dachten, dass sie die sch\u00e4dliche Datei l\u00f6schen, l\u00f6schten sie die Datei im Verzeichnis, auf das die symbolische Verkn\u00fcpfung zeigt. <\/p>\n<p>In Linux und macOS wird gezeigt, wie ein privilegierter Benutzer auf diese Weise die Datei \/etc\/passwd oder eine andere Systemdatei l\u00f6schen kann, w\u00e4hrend in Windows die DLL-Bibliothek des Antivirenprogramms selbst blockiert wird (in Windows ist der Angriff auf das L\u00f6schen von Dateien beschr\u00e4nkt, die zurzeit nicht von anderen Anwendungen verwendet werden). Beispielsweise kann der Angreifer ein Verzeichnis \u201eexploit\u201c erstellen und eine Datei EpSecApiLib.dll mit einer Testvirus-Signatur hochladen, bevor er das Verzeichnis \u201eexploit\u201c vor dem L\u00f6schen durch einen Link \u201eC:\\Program Files (x86)\\McAfee\\Endpoint Security\\Endpoint Security Platform\u201c ersetzt, was zur L\u00f6schung der Bibliothek EpSecApiLib.dll aus dem Antivirenverzeichnis f\u00fchrt. Ein \u00e4hnliches Verfahren kann in Linux und macOS durch den Austausch des Verzeichnisses gegen einen Link \u201e\/etc\u201c durchgef\u00fchrt werden.<\/p>\n<p>   #!\/bin\/sh<br \/>\n   rm -rf \/home\/user\/exploit ; mkdir \/home\/user\/exploit\/<br \/>\n   wget -q https:\/\/www.eicar.org\/download\/eicar.com.txt -O \/home\/user\/exploit\/passwd<br \/>\n   while inotifywait -m \"\/home\/user\/exploit\/passwd\" | grep -m 5 \"OPEN\"<br \/>\n   do<br \/>\n      rm -rf \/home\/user\/exploit ; ln -s \/etc \/home\/user\/exploit<br \/>\n   fertig<\/p>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"iVC_QJLOVt8\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/iVC_QJLOVt8\/hqdefault.jpg\" alt=\"Video abspielen\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><br \/>\n<\/center><\/p>\n<p>Dar\u00fcber hinaus wurde in vielen Antivirenprogrammen f\u00fcr Linux und macOS festgestellt, dass sie vorhersehbare Dateinamen bei der Arbeit mit tempor\u00e4ren Dateien im Verzeichnis \/tmp und \/private\/tmp verwendeten, was zur Erh\u00f6hung der Privilegien bis zum Benutzer root genutzt werden konnte.  <\/p>\n<p>Bis jetzt wurden die Probleme von den meisten Anbietern behoben, aber bemerkenswert ist, dass die ersten Benachrichtigungen \u00fcber das Problem den Herstellern bereits im Herbst 2018 zugesandt wurden. Obwohl nicht alle Hersteller Updates ver\u00f6ffentlicht haben, hatten sie mindestens 6 Monate Zeit zur Behebung, und RACK911 Labs ist der Meinung, dass sie nun berechtigt sind, Informationen \u00fcber die Schwachstellen offenzulegen. Es wird angemerkt, dass RACK911 Labs schon lange an der Identifizierung von Sicherheitsanf\u00e4lligkeiten arbeitet, aber nicht gedacht h\u00e4tte, dass die Zusammenarbeit mit Kollegen aus der Antivirenindustrie so schwierig sein w\u00fcrde, da die Ver\u00f6ffentlichung von Updates hinausgez\u00f6gert und die Notwendigkeit der schnellen Behebung von Sicherheitsproblemen ignoriert wurde.<\/p>\n<p>Produkte, die von dem Problem betroffen sind (das freie Antivirenpaket ClamAV ist nicht in der Liste enthalten):<\/p>\n<ul>\n<li class=\"l\"> Linux\n<ul>\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> Eset File Server Security\n<li class=\"l\"> F-Secure Linux Security\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Sophos Anti-Virus for Linux\n<\/ul>\n<li class=\"l\"> Windows\n<ul>\n<li class=\"l\"> Avast Free Anti-Virus\n<li class=\"l\"> Avira Free Anti-Virus\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> F-Secure Computer Protection\n<li class=\"l\"> FireEye Endpoint Security\n<li class=\"l\"> Intercept X (Sophos)\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> Malwarebytes f\u00fcr Windows\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Panda Dome\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<li class=\"l\"> macOS\n<ul>\n<li class=\"l\"> DURCHSCHNITT\n<li class=\"l\"> BitDefender Total Security\n<li class=\"l\"> Eset Cyber Security\n<li class=\"l\"> Kaspersky Internet Security\n<li class=\"l\"> McAfee Total Protection\n<li class=\"l\"> Microsoft Defender (BETA)\n<li class=\"l\"> Norton Security\n<li class=\"l\"> Sophos Home\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52779\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0434\u043b\u044f Windows, Linux \u0438 macOS \u0431\u044b\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c \u0433\u043e\u043d\u043a\u0438 (race conditions) \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441 \u0440\u0430\u0441\u043f\u043e\u0437\u043d\u0430\u0435\u0442 \u043a\u0430\u043a \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0442\u0435\u0441\u0442\u043e\u0432\u0443\u044e \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0443), \u0430 \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78849","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die meisten Antivirenprogramme waren anf\u00e4llig f\u00fcr Angriffe durch symbolische Links | ProHoster","description":"Forscher von RACK911 Labs haben festgestellt, dass fast alle.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-22T11:42:05+00:00","article:modified_time":"2020-04-22T11:42:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78849","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:49:47","updated":"2022-09-27 18:43:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/78849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=78849"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/78849\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=78849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=78849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=78849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}