{"id":35281,"date":"2019-10-31T22:03:25","date_gmt":"2019-10-31T19:03:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\/"},"modified":"2019-10-31T22:03:25","modified_gmt":"2019-10-31T19:03:25","slug":"massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","title":{"rendered":"Ataque masivo a servidores de correo vulnerables basados en Exim","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p> Investigadores de seguridad de Cybereason <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability\">advirtieron<\/a><\/noindex> a los administradores de servidores de correo sobre el descubrimiento de un ataque automatizado masivo que explota <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">una vulnerabilidad cr\u00edtica<\/a><\/noindex> (CVE-2019-10149) en Exim, identificada la semana pasada. Durante el ataque, los atacantes logran ejecutar c\u00f3digo con privilegios de root e instalar malware para minar criptomonedas en el servidor.<\/p>\n<p>De acuerdo con la encuesta automatizada de junio, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.securityspace.com\/s_survey\/data\/man.201905\/mxsurvey.html\">la cuota de Exim es del 57.05% (hace un a\u00f1o era del 56.56%), Postfix se utiliza en el 34.52% (33.79%) de los servidores de correo, Sendmail - 4.05% (4.59%), Microsoft Exchange - 0.57% (0.85%). Seg\u00fan<\/a><\/noindex> La cuota de Exim es del 57.05% (hace un a\u00f1o era del 56.56%), Postfix se utiliza en el 34.52% (33.79%) de servidores de correo, Sendmail \u2014 4.05% (4.59%), Microsoft Exchange \u2014 0.57% (0.85%). Seg\u00fan <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/report\/uSLHrfCA\">los datos<\/a><\/noindex> la informaci\u00f3n <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D89Gf0KUcAAJY44.jpg\">de RiskIQ, ya han migrado a la versi\u00f3n 4.92 el 70% de los servidores con Exim.<\/a><\/noindex> Se recomienda a los administradores instalar urgentemente las actualizaciones que ya fueron preparadas la semana pasada por las distribuciones (<\/p>\n<p><center><img decoding=\"async\" alt=\"Ataque masivo a servidores de correo vulnerables basados en Exim\" src=\"\/wp-content\/uploads\/2019\/06\/f179c76afaa02fedfe6c542f99dbcb9c.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>openSUSE<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">Debian<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-10149.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-10149\">EPEL para RHEL\/CentOS<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/community\/x86_64\/exim\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-7b741dcaa4\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">). En caso de tener en el sistema una versi\u00f3n de Exim vulnerable (de 4.87 a 4.91 inclusive), es necesario asegurarse de que el sistema no est\u00e9 comprometido revisando el crontab por llamadas sospechosas y asegur\u00e1ndose de que no haya claves adicionales en el directorio \/root\/.ssh. La presencia de actividad en el registro del cortafuegos proveniente de hosts an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io y an7kmd2wp4xo7hpr.onion.sh puede indicar la actividad de carga de malware.<\/a><\/noindex>Los primeros intentos de ataque a servidores Exim <\/p>\n<p>se registraron <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/freddieleeman\/status\/1137729455181500421\">el 9 de junio. Para el 13 de junio, el ataque<\/a><\/noindex> tom\u00f3 <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/0xAmit\/status\/1139165487093420035\">car\u00e1cter masivo. Despu\u00e9s de explotar la vulnerabilidad a trav\u00e9s de puertas de enlace tor2web del servicio oculto Tor (an7kmd2wp4xo7hpr), se carga un script que verifica la presencia de OpenSSH (si no est\u00e1<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/forums.zimbra.org\/viewtopic.php?t=65932&#038;start=140\">instala<\/a><\/noindex> ), cambia su configuraci\u00f3n ( <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gM2mWsAAhwD4.jpg\">permite<\/a><\/noindex>el acceso como root y la autenticaci\u00f3n por clave) y establece para el usuario root<noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gZ0sX4AAeHgm.jpg\">una clave RSA<\/a><\/noindex> , que proporciona acceso privilegiado al sistema a trav\u00e9s de SSH. <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/aserper\/e36d382668c6cf2c996c5143025097c0#file-gistfile1-txt\">Clave RSA<\/a><\/noindex>, que proporciona acceso privilegiado al sistema a trav\u00e9s de SSH.<\/p>\n<p>Despu\u00e9s de configurar el backdoor, se instala un esc\u00e1ner de puertos en el sistema para identificar otros servidores vulnerables. Tambi\u00e9n se busca en el sistema si ya existen sistemas de miner\u00eda, los cuales se eliminan en caso de ser detectados. En la etapa final, se carga y se graba en crontab un minero propio. El minero se carga bajo la apariencia de un archivo ico (en realidad es un archivo zip con la contrase\u00f1a \u00abno-password\u00bb), que contiene un archivo ejecutable en formato ELF para Linux con Glibc 2.7+.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50870\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0445 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043c\u0430\u0441\u0441\u043e\u0432\u043e\u0439 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-10149) \u0432 Exim, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u043d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u043d\u0435\u0434\u0435\u043b\u0435. \u0412 \u0445\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0434\u043e\u0431\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0434\u043b\u044f \u043c\u0430\u0439\u043d\u0438\u043d\u0433\u0430 \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442. \u0412 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u0438\u044e\u043d\u044c\u0441\u043a\u0438\u043c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043e\u043f\u0440\u043e\u0441\u043e\u043c \u0434\u043e\u043b\u044f Exim \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 57.05% (\u0433\u043e\u0434 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Ataque masivo a servidores de correo vulnerables basados en Exim | ProHoster","description":"Investigadores de seguridad de la empresa Cybereason han advertido.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:03:25+00:00","article:modified_time":"2019-10-31T19:03:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35281","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 22:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:06:25","updated":"2026-01-21 22:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/35281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=35281"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/35281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/26492"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=35281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=35281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=35281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}