{"id":78849,"date":"2020-04-22T13:42:05","date_gmt":"2020-04-22T11:42:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki"},"modified":"2020-04-22T13:42:05","modified_gmt":"2020-04-22T11:42:05","slug":"bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","title":{"rendered":"Die meisten Antiviren-Programme waren anf\u00e4llig f\u00fcr Angriffe \u00fcber symbolische Links","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Forscher von RACK911 Labs <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rack911labs.com\/research\/exploiting-almost-every-antivirus-software\/\">achten darauf<\/a><\/noindex> dass fast alle Antivirus-Pakete f\u00fcr Windows, Linux und macOS anf\u00e4llig f\u00fcr Angriffe sind, die mit Race Conditions w\u00e4hrend der Dateil\u00f6schung arbeiten, wenn Malware erkannt wird.<\/p>\n<p>F\u00fcr einen Angriff ist es erforderlich, eine Datei herunterzuladen, die vom Antivirus als b\u00f6sartig erkannt wird (z. B. kann ein Test-Signatur verwendet werden), und nach einer bestimmten Zeit, nachdem der b\u00f6sartige Inhalt erkannt wurde, aber direkt bevor die Funktion zum L\u00f6schen der Datei aufgerufen wird, das Verzeichnis durch einen symbolischen Link zu ersetzen. In Windows erfolgt die Verzeichnisumleitung zur Erreichung desselben Effekts durch die Verwendung einer Verzeichnisschneidstelle (directory junction). Das Problem ist, dass nahezu alle Antivirus-Programme die symbolischen Links nicht ordnungsgem\u00e4\u00df \u00fcberpr\u00fcften und im Glauben, die b\u00f6sartige Datei zu l\u00f6schen, die Datei im Verzeichnis entfernten, auf das der symbolische Link zeigt. <\/p>\n<p>In Linux und macOS wird gezeigt, wie ein nicht privilegierter Benutzer auf diese Weise die Datei \/etc\/passwd oder jede andere Systemdatei l\u00f6schen kann, w\u00e4hrend in Windows die DDL-Bibliothek des Antivirenprogramms selbst entfernt wird, um dessen Funktionalit\u00e4t zu blockieren (in Windows ist der Angriff auf das L\u00f6schen von Dateien beschr\u00e4nkt, die im aktuellen Moment von anderen Anwendungen nicht verwendet werden). Zum Beispiel kann der Angreifer ein Verzeichnis namens \u201eexploit\u201c erstellen und die Datei EpSecApiLib.dll mit einer Testvirus-Signatur darin hochladen, bevor er das Verzeichnis \u201eexploit\u201c durch einen Link zu \u201eC:\\Program Files (x86)\\McAfee\\Endpoint Security\\Endpoint Security Platform\u201c ersetzt, was zur L\u00f6schung der Bibliothek EpSecApiLib.dll aus dem Antivirenverzeichnis f\u00fchrt. In Linux und macOS kann ein \u00e4hnlicher Trick durch Ersetzen des Verzeichnisses durch einen Link zu \u201e\/etc\u201c durchgef\u00fchrt werden.<\/p>\n<p>   #!\/bin\/sh<br \/>\n   rm -rf \/home\/user\/exploit ; mkdir \/home\/user\/exploit\/<br \/>\n   wget -q https:\/\/www.eicar.org\/download\/eicar.com.txt -O \/home\/user\/exploit\/passwd<br \/>\n   while inotifywait -m \"\/home\/user\/exploit\/passwd\" | grep -m 5 \"OPEN\"<br \/>\n   do<br \/>\n      rm -rf \/home\/user\/exploit ; ln -s \/etc \/home\/user\/exploit<br \/>\n   fertig<\/p>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"iVC_QJLOVt8\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/iVC_QJLOVt8\/hqdefault.jpg\" alt=\"Video abspielen\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><br \/>\n<\/center><\/p>\n<p>Dar\u00fcber hinaus wurde in vielen Antivirus-Programmen f\u00fcr Linux und macOS die Verwendung von vorhersagbaren Dateinamen bei der Arbeit mit tempor\u00e4ren Dateien im Verzeichnis \/tmp und \/private\/tmp festgestellt, was zur Erh\u00f6hung der Berechtigungen auf den Benutzer root verwendet werden k\u00f6nnte.  <\/p>\n<p>Bis zu diesem Zeitpunkt haben die meisten Anbieter die Probleme bereits behoben, bemerkenswert ist jedoch, dass die ersten Benachrichtigungen \u00fcber das Problem bereits im Herbst 2018 an die Hersteller gesendet wurden. Obwohl nicht alle Hersteller aktualisierte Versionen herausgebracht haben, erhielten sie mindestens 6 Monate Zeit zur Behebung, und RACK911 Labs ist der Meinung, dass es jetzt das Recht hat, Informationen \u00fcber Schwachstellen offenzulegen. Es wird darauf hingewiesen, dass das Unternehmen RACK911 Labs bereits seit langem an der Identifizierung von Schwachstellen arbeitet, aber nicht damit gerechnet hat, dass die Zusammenarbeit mit Kollegen aus der Antivirenindustrie aufgrund von Verz\u00f6gerungen bei der Ver\u00f6ffentlichung von Updates und der Ignorierung der Notwendigkeit einer sofortigen Behebung von Sicherheitsproblemen so schwierig sein w\u00fcrde.<\/p>\n<p>Produkte, die von dem Problem betroffen sind (das kostenlose Antivirenpaket ClamAV ist nicht aufgef\u00fchrt):<\/p>\n<ul>\n<li class=\"l\"> Linux\n<ul>\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> Eset File Server Security\n<li class=\"l\"> F-Secure Linux Security\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Sophos Anti-Virus f\u00fcr Linux\n<\/ul>\n<li class=\"l\"> Windows\n<ul>\n<li class=\"l\"> Avast Free Anti-Virus\n<li class=\"l\"> Avira Free Anti-Virus\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> F-Secure Computerschutz\n<li class=\"l\"> FireEye Endpoint Security\n<li class=\"l\"> Intercept X (Sophos)\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> Malwarebytes f\u00fcr Windows\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Panda Dome\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<li class=\"l\"> macOS\n<ul>\n<li class=\"l\"> AVG\n<li class=\"l\"> BitDefender Total Security\n<li class=\"l\"> Eset Cyber Security\n<li class=\"l\"> Kaspersky Internet Security\n<li class=\"l\"> McAfee Total Protection\n<li class=\"l\"> Microsoft Defender (BETA)\n<li class=\"l\"> Norton Security\n<li class=\"l\"> Sophos Home\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52779\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0434\u043b\u044f Windows, Linux \u0438 macOS \u0431\u044b\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c \u0433\u043e\u043d\u043a\u0438 (race conditions) \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441 \u0440\u0430\u0441\u043f\u043e\u0437\u043d\u0430\u0435\u0442 \u043a\u0430\u043a \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0442\u0435\u0441\u0442\u043e\u0432\u0443\u044e \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0443), \u0430 \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78849","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die meisten Antivirenprogramme waren anf\u00e4llig f\u00fcr Angriffe \u00fcber symbolische Links | ProHoster","description":"Forscher von RACK911 Labs wiesen darauf hin, dass nahezu alle betroffen sind.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-22T11:42:05+00:00","article:modified_time":"2020-04-22T11:42:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78849","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:49:47","updated":"2022-09-27 18:43:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/78849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=78849"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/78849\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=78849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=78849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=78849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}