{"id":113601,"date":"2024-02-15T04:02:43","date_gmt":"2024-02-15T02:02:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu"},"modified":"2024-02-15T04:02:43","modified_gmt":"2024-02-15T02:02:43","slug":"sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","title":{"rendered":"Escenario de ataque en el manejador de aplicaciones no instaladas en Ubuntu","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Investigadores de Aqua Security han se\u00f1alado la posibilidad de realizar un ataque contra los usuarios de la distribuci\u00f3n Ubuntu, aprovechando las particularidades del manejador 'command-not-found', que ofrece sugerencias cuando se intenta ejecutar un programa que no est\u00e1 presente en el sistema. El problema es que al evaluar los comandos que no existen, 'command-not-found' utiliza no solo los paquetes de los repositorios oficiales, sino tambi\u00e9n paquetes snap del cat\u00e1logo snapcraft.io.    <\/p>\n<p>Al generar recomendaciones basadas en el contenido del cat\u00e1logo snapcraft.io, el manejador 'command-not-found' no tiene en cuenta el estado de los paquetes y abarca aquellos a\u00f1adidos por usuarios no verificados. As\u00ed, un atacante puede subir a snapcraft.io un paquete con contenido malicioso oculto y un nombre que se cruza con los DEB existentes, programas que inicialmente no est\u00e1n presentes en el repositorio o aplicaciones ficticias cuyos nombres reflejan errores tipogr\u00e1ficos comunes de los usuarios al escribir nombres de utilidades populares.     <\/p>\n<p>Por ejemplo, se pueden subir paquetes 'tracert' y 'tcpdamp' con la expectativa de que el usuario cometa un error al escribir los nombres de las utilidades 'traceroute' y 'tcpdump', y 'command-not-found' recomiende instalar desde snapcraft.io los paquetes maliciosos subidos por el atacante. El usuario puede no notar la trampa y pensar que el sistema solo recomienda paquetes verificados. El atacante tambi\u00e9n puede subir a snapcraft.io un paquete cuyo nombre se cruza con los DEB existentes, y en este caso 'command-not-found' ofrecer\u00e1 dos recomendaciones de instalaci\u00f3n, deb y snap, y el usuario podr\u00eda elegir snap, pensando que es m\u00e1s seguro o atra\u00eddo por una versi\u00f3n m\u00e1s nueva.    <center><img decoding=\"async\" alt=\"Escenario de ataque en el manejador de aplicaciones no instaladas en Ubuntu\" src=\"\/wp-content\/uploads\/2024\/02\/5ed4b661fcc1bf13a7edc101b829b185.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Las aplicaciones en formato snap, para las cuales se permite la revisi\u00f3n autom\u00e1tica en snapcraft.io, solo pueden ejecutarse en un entorno aislado (los paquetes snap sin aislamiento se publican solo tras una revisi\u00f3n manual). Para el atacante, puede ser suficiente realizar operaciones en un entorno aislado con acceso a la red, por ejemplo, para minar criptomonedas, llevar a cabo ataques DDoS o enviar spam.    <\/p>\n<p>Un atacante tambi\u00e9n puede utilizar m\u00e9todos en paquetes maliciosos para eludir el aislamiento, como explotar vulnerabilidades no parcheadas en el n\u00facleo y en los mecanismos de aislamiento, emplear interfaces snap para acceder a recursos externos (para grabaci\u00f3n encubierta de audio y video) o capturar entradas del teclado al utilizar el protocolo X11 (para crear keyloggers que funcionen en un entorno sandbox).<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60602\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &#171;command-not-found&#187;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0439 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043f\u0440\u0438 \u043e\u0446\u0435\u043d\u043a\u0435 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u0430\u043d\u0434, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, &#171;command-not-found&#187; \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043f\u0440\u0438 \u0432\u044b\u0431\u043e\u0440\u0435 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0438 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0430\u043a\u0435\u0442\u044b \u0438\u0437 \u0448\u0442\u0430\u0442\u043d\u044b\u0445 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432, \u043d\u043e snap-\u043f\u0430\u043a\u0435\u0442\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":113602,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-113601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0432 Ubuntu | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-02-15T02:02:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-02-15T02:02:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Escenario de ataque del manejador de aplicaciones no instaladas en Ubuntu | ProHoster","description":"Investigadores de la empresa Aqua Security han se\u00f1alado la posibilidad de llevar a cabo un ataque contra usuarios de la distribuci\u00f3n Ubuntu, aprovechando las caracter\u00edsticas de implementaci\u00f3n del manejador \"command-not-found\", que proporciona sugerencias.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0432 Ubuntu | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-02-15T02:02:43+00:00","article:modified_time":"2024-02-15T02:02:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/113601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=113601"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/113601\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/113602"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=113601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=113601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=113601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}