{"id":35980,"date":"2019-10-31T22:08:56","date_gmt":"2019-10-31T19:08:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\/"},"modified":"2019-10-31T22:08:56","modified_gmt":"2019-10-31T19:08:56","slug":"zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","title":{"rendered":"Malicious code injection detected in the Ruby package Strong_password","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/versions\/0.0.7\">published<\/a><\/noindex> in the June 25 release of the Strong_password gem package 0.7 <noindex><a rel=\"nofollow\" href=\"https:\/\/withatwist.dev\/strong-password-rubygem-hijacked.html\">seven vulnerabilities have been identified<\/a><\/noindex>  malicious modification (<noindex><a rel=\"nofollow\" href=\"https:\/\/rubysec.com\/advisories\/strong_password-CVE-2019-13354\">CVE-2019-13354<\/a><\/noindex>), downloading and executing external code controlled by an unknown attacker, hosted on the Pastebin service. The total number of downloads for the project is 247 thousand, while version 0.6 has around 38 thousand downloads. The malicious version has 537 downloads listed, but it's unclear how accurate this number is considering the version has already been removed from Ruby Gems.<\/p>\n<p>The Strong_password library provides tools for verifying the strength of a password set by the user during registration.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/reverse_dependencies\">Among<\/a><\/noindex> using the Strong_password packages think_feel_do_engine (65 thousand downloads), think_feel_do_dashboard (15 thousand downloads), and<br \/>\nsuperhosting (1.5 thousand). It is noted that the malicious modification was added by someone unknown, who intercepted control of the repository from the author. <\/p>\n<p>The malicious code was added only on RubyGems.org, <noindex>Git repository<\/noindex> the project itself was not affected. The issue was discovered after one of the developers using Strong_password in their projects began to investigate why the last change in the repository was made over 6 months ago, yet a new release appeared on RubyGems, published by a new maintainer no one had heard of before.<\/p>\n<p>The attacker may have enabled the execution of arbitrary code on servers using the problematic version of Strong_password. At the time the issue was discovered, a script was being uploaded to Pastebin to facilitate the execution of any code passed by the client through the Cookie '__id' and encoded using the Base64 method. The malicious code also sent the host parameters of the server where the malicious version of Strong_password was installed to an attacker-controlled server. <\/p>\n<p><center><img decoding=\"async\" alt=\"Malicious code injection detected in the Ruby package Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/3d08a0f65fb7acf0f8225c388b60c721.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><center><img decoding=\"async\" alt=\"Malicious code injection detected in the Ruby package Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/798a680ce803618409606044b21c66ef.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51056\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 (CVE-2019-13354), \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0449\u0435\u0435 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044e\u0449\u0435\u0435 \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0439 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u043a\u043e\u0434, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0439 \u043d\u0430 \u0441\u0435\u0440\u0432\u0438\u0441\u0435 Pastebin. \u041e\u0431\u0449\u0435\u0435 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 247 \u0442\u044b\u0441\u044f\u0447, \u0430 \u0432\u0435\u0440\u0441\u0438\u0438 0.6 &#8212; \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447. \u0414\u043b\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0443\u043a\u0430\u0437\u0430\u043d\u043e 537, \u043d\u043e \u043d\u0435 \u044f\u0441\u043d\u043e \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043d\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0441 \u0443\u0447\u0451\u0442\u043e\u043c \u0442\u043e\u0433\u043e, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26895,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Malicious code injection detected in the Ruby package Strong_password | ProHoster","description":"In the June 25 release of the Strong_password gem package 0.7","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster","og:description":"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:08:56+00:00","article:modified_time":"2019-10-31T19:08:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35980","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 01:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:52:26","updated":"2026-01-22 01:31:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=35980"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35980\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/26895"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=35980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=35980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=35980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}