{"id":80245,"date":"2020-05-04T19:42:04","date_gmt":"2020-05-04T17:42:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack"},"modified":"2020-05-04T19:42:04","modified_gmt":"2020-05-04T17:42:04","slug":"vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack","title":{"rendered":"Exploitation of LineageOS infrastructure through a vulnerability in SaltStack","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Developers of the mobile platform <noindex><a rel=\"nofollow\" href=\"https:\/\/lineageos.org\/\">LineageOS<\/a><\/noindex>, which replaced CyanogenMod, <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/LineageAndroid\/status\/1256821056100163584\">warned<\/a><\/noindex> reported on the discovery of traces of a breach in the project's infrastructure. It is noted that at 6 a.m. (MSK) on May 3, the attacker was able to gain access to the main server of the centralized configuration management system <noindex><a rel=\"nofollow\" href=\"https:\/\/www.saltstack.com\/\">SaltStack<\/a><\/noindex> through the exploitation of an unpatched vulnerability. Currently, an investigation into the incident is underway and details are not yet available. <\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/status.lineageos.org\/issues\/5eae596b4a0ebd114676545f\">It is reported<\/a><\/noindex> However, the attack did not affect the keys used for generating digital signatures, the build system, or the platform's source code \u2014 keys. <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/zifnab06\/status\/1256870980523196417\">were stored<\/a><\/noindex>  on hosts that were completely isolated from the main infrastructure, managed via SaltStack, and the builds were stopped for technical reasons on April 30. According to the data on the page <noindex><a rel=\"nofollow\" href=\"https:\/\/status.lineageos.org\/\">status.lineageos.org<\/a><\/noindex> the developers have already restored the server with the code review system Gerrit, the website, and the wiki. The build server (builds.lineageos.org), the file download portal (download.lineageos.org), email servers, and the mirror coordination system remain disconnected. <\/p>\n<p>The attack was made possible because the network port (4506) for accessing SaltStack <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/zifnab06\/status\/1256870980523196417\">was not<\/a><\/noindex> It was blocked for external requests by the firewall \u2014 the attacker had to wait for a critical vulnerability in SaltStack to appear and exploit it before administrators could apply the fix. All SaltStack users are urgently advised to update their systems and check for signs of compromise.<\/p>\n<p>Apparently, the attacks through SaltStack were not limited to the LineageOS breach and became widespread \u2014 throughout the day, various users who had not updated SaltStack were affected. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/issues\/57057\">note<\/a><\/noindex> identified compromises in their infrastructures with code for mining or backdoors placed on their servers. In particular <noindex><a rel=\"nofollow\" href=\"https:\/\/status.ghost.org\/incidents\/tpn078sqk973\">it is reported<\/a><\/noindex> about a similar breach of the content management system <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/TryGhost\/Ghost\">Ghost<\/a><\/noindex>, which affected the Ghost(Pro) websites and billing (it is claimed that credit card numbers were not compromised, but hashes of Ghost users' passwords may have fallen into the hands of attackers).<\/p>\n<p>On April 29, updates for the SaltStack platform were <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/releases\">released<\/a><\/noindex> in which vulnerabilities were addressed <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.saltstack.com\/en\/latest\/topics\/releases\/3000.2.html\">3000.2<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.saltstack.com\/en\/2019.2\/topics\/releases\/2019.2.4.html\">2019.2.4<\/a><\/noindex>, details about the vulnerabilities were published on April 30, assigned the highest level of danger as they allow access without authentication <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/blob\/v3000.2_docs\/doc\/topics\/releases\/3000.2.rs\">were fixed in Salt<\/a><\/noindex> them to be accessed <noindex><a rel=\"nofollow\" href=\"https:\/\/labs.f-secure.com\/advisories\/saltstack-authorization-bypass\">allow<\/a><\/noindex> Remote code execution both on the management host (salt-master) and on all servers managed through it.<\/p>\n<ul>\n<li class=\"l\"> The first vulnerability (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-11651\">CVE-2020-11651<\/a><\/noindex>) is caused by a lack of proper checks when calling methods of the ClearFuncs class during the salt-master process. This vulnerability allows a remote user to access certain methods without authentication. Notably, through the problematic methods, an attacker can obtain a token for root access to the master server and execute any commands on the managed hosts running the <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.saltstack.com\/en\/latest\/ref\/cli\/salt-minion.html\">salt-minion<\/a><\/noindex>. A patch addressing this vulnerability was released <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/commit\/a67d76b15615983d467ed81371b38b4a17e4f3b7\">has been published<\/a><\/noindex> 20 days ago, but after its application, there were <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/issues\/57016\">regressive<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/saltstack\/salt\/issues\/57027\">changes<\/a><\/noindex>, leading to failures and file synchronization disruptions.\n<li class=\"l\"> The second vulnerability (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-11652\">CVE-2020-11652<\/a><\/noindex>) allows access to methods through manipulation of the ClearFuncs class by passing specially formatted paths, which can be used for full access to arbitrary directories in the master server's file system with root rights, but requires authenticated access (such access can be obtained via the first vulnerability and the second vulnerability can be used for complete compromise of the entire infrastructure).\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52872\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b LineageOS, \u043f\u0440\u0438\u0448\u0435\u0434\u0448\u0435\u0433\u043e \u043d\u0430 \u0441\u043c\u0435\u043d\u0443 CyanogenMod, \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u0441\u043b\u0435\u0434\u043e\u0432 \u0432\u0437\u043b\u043e\u043c\u0430 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043f\u0440\u043e\u0435\u043a\u0442\u0430. \u041e\u0442\u043c\u0435\u0447\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u0432 6 \u0447\u0430\u0441\u043e\u0432 \u0443\u0442\u0440\u0430 (MSK) 3 \u043c\u0430\u044f \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0435\u0439 SaltStack \u0447\u0435\u0440\u0435\u0437 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044e \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0438\u0434\u0451\u0442 \u0440\u0430\u0437\u0431\u043e\u0440 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0430 \u0438 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043f\u043e\u043a\u0430 \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b. \u0421\u043e\u043e\u0431\u0449\u0430\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e, \u0447\u0442\u043e \u0430\u0442\u0430\u043a\u0430 \u043d\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-80245","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b LineageOS, \u043f\u0440\u0438\u0448\u0435\u0434\u0448\u0435\u0433\u043e \u043d\u0430 \u0441\u043c\u0435\u043d\u0443 CyanogenMod,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u0437\u043b\u043e\u043c \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b LineageOS \u0447\u0435\u0440\u0435\u0437 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SaltStack | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b LineageOS, \u043f\u0440\u0438\u0448\u0435\u0434\u0448\u0435\u0433\u043e \u043d\u0430 \u0441\u043c\u0435\u043d\u0443 CyanogenMod,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-04T17:42:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-04T17:42:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Hacking the LineageOS infrastructure through a vulnerability in SaltStack | ProHoster","description":"Developers of the mobile platform LineageOS, which replaced CyanogenMod,","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u0437\u043b\u043e\u043c \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b LineageOS \u0447\u0435\u0440\u0435\u0437 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SaltStack | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b LineageOS, \u043f\u0440\u0438\u0448\u0435\u0434\u0448\u0435\u0433\u043e \u043d\u0430 \u0441\u043c\u0435\u043d\u0443 CyanogenMod,","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vzlom-infrastruktury-lineageos-cherez-uyazvimost-v-saltstack","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-04T17:42:04+00:00","article:modified_time":"2020-05-04T17:42:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"80245","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:21:23","updated":"2022-09-28 08:26:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/80245","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=80245"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/80245\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=80245"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=80245"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=80245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}