{"id":101307,"date":"2021-09-17T10:22:35","date_gmt":"2021-09-17T08:22:35","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure"},"modified":"2021-09-17T10:22:35","modified_gmt":"2021-09-17T08:22:35","slug":"udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","title":{"rendered":"Vulnerabilidad explotable de forma remota en el agente OMI, impuesto en entornos Linux de Microsoft Azure","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Los clientes de la plataforma en la nube Microsoft Azure que utilizan Linux en m\u00e1quinas virtuales han enfrentado una vulnerabilidad cr\u00edtica (CVE-2021-38647) que permite la ejecuci\u00f3n remota de c\u00f3digo con privilegios de root. La vulnerabilidad se ha denominado OMIGOD y es notable porque el problema se encuentra en la aplicaci\u00f3n OMI Agent, que se instala discretamente en entornos Linux.    <\/p>\n<p>OMI Agent se instala y activa autom\u00e1ticamente al utilizar servicios como Azure Automation, Azure Automatic Update, Azure Operations Management Suite, Azure Log Analytics, Azure Configuration Management, Azure Diagnostics y Azure Container Insights. Por ejemplo, los entornos Linux en Azure que tienen habilitada la monitorizaci\u00f3n son vulnerables. El agente es parte del paquete abierto OMI (Open Management Infrastructure Agent) con la implementaci\u00f3n de la pila DMTF CIM\/WBEM para la gesti\u00f3n de la infraestructura de TI.      <\/p>\n<p>OMI Agent se instala en el sistema bajo el usuario omsagent y crea configuraciones en \/etc\/sudoers para ejecutar una serie de scripts con privilegios de root. Durante la operaci\u00f3n de algunos servicios, se crean sockets de red que escuchan en los puertos de red 5985, 5986 y 1270. Un escaneo en el servicio Shodan muestra la existencia en la red de m\u00e1s de 15,000 entornos Linux vulnerables. Actualmente, ya est\u00e1 disponible en acceso p\u00fablico un prototipo funcional de un exploit que permite ejecutar su c\u00f3digo con privilegios de root en sistemas similares.     <\/p>\n<p>El problema se agrava porque en Azure no est\u00e1 documentado claramente el uso de OMI y el OMI Agent se instala sin previo aviso; simplemente se necesita aceptar los t\u00e9rminos del servicio seleccionado al configurar el entorno y el OMI Agent se activar\u00e1 autom\u00e1ticamente, lo que significa que la mayor\u00eda de los usuarios ni siquiera son conscientes de su existencia.      <\/p>\n<p>El m\u00e9todo de explotaci\u00f3n es trivial: basta con enviar una solicitud XML al agente, eliminando el encabezado que gestiona la autenticaci\u00f3n. OMI utiliza autenticaci\u00f3n al recibir mensajes de control, verificando que el cliente tenga permiso para enviar determinado comando. La esencia de la vulnerabilidad radica en que, al eliminar en el mensaje el encabezado \"Authentication\", responsable de la autenticaci\u00f3n, <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\"   title=\"servidor\" data-wpil-keyword-link=\"linked\">servidor<\/a> se considera que pasa la verificaci\u00f3n con \u00e9xito, acepta el mensaje de control y permite la ejecuci\u00f3n de comandos con privilegios de root. Para ejecutar comandos arbitrarios en el sistema, solo se necesita utilizar en el mensaje el comando est\u00e1ndar ExecuteShellCommand_INPUT. Por ejemplo, para ejecutar la utilidad \"id\", basta con enviar la siguiente solicitud:       curl -H \"Content-Type: application\/soap+xml;charset=UTF-8\" -k --data-binary \"@http_body.txt\" https:\/\/10.0.0.5:5986\/wsman       <s>        \u2026        <s>           <p>              <p>id<\/p>              <p>0<\/p>           <\/p>        <\/s>     <\/s>               <\/p>\n<p>Microsoft ya ha lanzado la actualizaci\u00f3n OMI 1.6.8.1 que corrige la vulnerabilidad, pero a\u00fan no se ha desplegado para los usuarios de Microsoft Azure (en los nuevos entornos todav\u00eda se instala la versi\u00f3n antigua de OMI). La autoactualizaci\u00f3n del agente no es compatible, por lo que los usuarios deben actualizar el paquete manualmente, utilizando los comandos \"dpkg -l omi\" en Debian\/Ubuntu o \"rpm -qa omi\" en Fedora\/RHEL. Como soluci\u00f3n temporal de protecci\u00f3n, se recomienda bloquear el acceso a los puertos de red 5985, 5986 y 1270.        <\/p>\n<p>Adem\u00e1s de CVE-2021-38647, en OMI 1.6.8.1 tambi\u00e9n se han corregido tres vulnerabilidades (CVE-2021-38648, CVE-2021-38645 y CVE-2021-38649), que permiten a un usuario local no privilegiado ejecutar su c\u00f3digo con privilegios de root.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55813\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f OMIGOD \u0438 \u043f\u0440\u0438\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0430 \u0442\u0435\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0438 OMI Agent, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0431\u0435\u0437 \u043b\u0438\u0448\u043d\u0435\u0439 \u043e\u0433\u043b\u0430\u0441\u043a\u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f. OMI Agent \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0438 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0442\u0430\u043a\u0438\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432, \u043a\u0430\u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-101307","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OMI-\u0430\u0433\u0435\u043d\u0442\u0435, \u043d\u0430\u0432\u044f\u0437\u044b\u0432\u0430\u0435\u043c\u043e\u043c \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 Microsoft Azure | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-17T08:22:35+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-09-17T08:22:35+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilidad explotable de forma remota en el agente OMI, impuesto en entornos Linux de Microsoft Azure | ProHoster","description":"Los clientes de la plataforma en la nube Microsoft Azure que utilizan Linux en m\u00e1quinas virtuales se han enfrentado a una vulnerabilidad cr\u00edtica (CVE-2021-38647) que permite ejecutar c\u00f3digo de forma remota con privilegios de root.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OMI-\u0430\u0433\u0435\u043d\u0442\u0435, \u043d\u0430\u0432\u044f\u0437\u044b\u0432\u0430\u0435\u043c\u043e\u043c \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 Microsoft Azure | ProHoster","og:description":"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-09-17T08:22:35+00:00","article:modified_time":"2021-09-17T08:22:35+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"101307","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-09-17 08:49:36","updated":"2022-10-07 00:05:27","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/101307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=101307"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/101307\/revisions"}],"predecessor-version":[{"id":172940,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/101307\/revisions\/172940"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=101307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=101307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=101307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}