{"id":37292,"date":"2019-10-31T22:16:49","date_gmt":"2019-10-31T19:16:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root\/"},"modified":"2019-10-31T22:16:49","modified_gmt":"2019-10-31T19:16:49","slug":"v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root","title":{"rendered":"Se ha encontrado un backdoor en Webmin que permite acceso remoto con privilegios de root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el paquete <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/webmin\/webmin\/\">Webmin<\/a><\/noindex>, que proporciona herramientas para la gesti\u00f3n remota del servidor, <noindex><a rel=\"nofollow\" href=\"https:\/\/groups.google.com\/forum\/#!msg\/virtualmin-announce\/hCCtMJfvhTI\/_JOodz2BDQAJ\">detectado<\/a><\/noindex> un backdoor (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-15107\">CVE-2019-15107<\/a><\/noindex>), encontrado en las versiones oficiales del proyecto, <noindex><a rel=\"nofollow\" href=\"https:\/\/sourceforge.net\/projects\/webadmin\/files\/webmin\/\">distribuidas<\/a><\/noindex> a trav\u00e9s de Sourceforge y <noindex><a rel=\"nofollow\" href=\"http:\/\/webmin.com\/download.html\">recomendadas<\/a><\/noindex> en el sitio principal. El backdoor estuvo presente en las versiones desde 1.882 hasta 1.921 inclusive (en el repositorio git el c\u00f3digo con el backdoor est\u00e1 ausente) y permit\u00eda ejecutar comandos shell arbitrarios en el sistema con privilegios de root sin pasar por la autenticaci\u00f3n. <\/p>\n<p>Para llevar a cabo el ataque, es suficiente con tener un puerto de red abierto con Webmin y la actividad en la interfaz web de la funci\u00f3n de cambio de contrase\u00f1a obsoleta (que por defecto est\u00e1 habilitada en las versiones 1.890, pero est\u00e1 desactivada en las dem\u00e1s versiones). El problema <noindex><a rel=\"nofollow\" href=\"http:\/\/webmin.com\/security.html\">se solucion\u00f3<\/a><\/noindex> en <noindex><a rel=\"nofollow\" href=\"https:\/\/groups.google.com\/forum\/#!msg\/virtualmin-announce\/hCCtMJfvhTI\/_JOodz2BDQAJ\">de la plataforma Android se ha eliminado una vulnerabilidad cr\u00edtica<\/a><\/noindex> 1.930. Como medida temporal para bloquear el backdoor, basta con eliminar la configuraci\u00f3n \"passwd_mode=\" del archivo de configuraci\u00f3n \/etc\/webmin\/miniserv.conf. Se ha preparado para las pruebas <noindex><a rel=\"nofollow\" href=\"https:\/\/pentest.com.tr\/exploits\/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html\">un prototipo de exploit<\/a><\/noindex>.<\/p>\n<p>El problema fue <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.firosolutions.com\/exploits\/webmin\/\">detectada<\/a><\/noindex> en el script password_change.cgi, en el que para verificar la antigua contrase\u00f1a introducida en el formulario web <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/webmin\/webmin\/blob\/e89ffcfa6961274e00e7565217fb98fa28596cd7\/password_change.cgi#L163\">se utiliza<\/a><\/noindex> la funci\u00f3n unix_crypt, a la que se le pasa la contrase\u00f1a recibida del usuario sin realizar la escapatoria de los caracteres especiales. En el repositorio git esta funci\u00f3n <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/webmin\/webmin\/blob\/1e2545b06e3ab875bb5e1edfbe01d8ae6f58af23\/web-lib-funcs.pl#L10118\">es<\/a><\/noindex>  una envoltura sobre el m\u00f3dulo Crypt::UnixCrypt y no representa un peligro, pero en el archivo adjunto disponible en el sitio de Sourceforge, se llama a un c\u00f3digo que accede directamente a \/etc\/shadow, pero lo hace a trav\u00e9s de una construcci\u00f3n de shell. Para el ataque, es suficiente indicar en el campo de la antigua contrase\u00f1a el s\u00edmbolo \"|\" y el siguiente c\u00f3digo que sigue ser\u00e1 ejecutado con los derechos de root en el servidor.<\/p>\n<p>Por <noindex><a rel=\"nofollow\" href=\"https:\/\/www.reddit.com\/r\/netsec\/comments\/crk77z\/0day_remote_code_execution_for_webmin\/excgwnt\/\">declaraci\u00f3n<\/a><\/noindex> los desarrolladores de Webmin, el c\u00f3digo malicioso se insert\u00f3 como resultado de la intervenci\u00f3n en la infraestructura del proyecto. A\u00fan no se han comunicado detalles, por lo que no est\u00e1 claro si la brecha se limit\u00f3 a la toma de control de la cuenta en Sourceforge o afect\u00f3 a otros elementos de la infraestructura de desarrollo y construcci\u00f3n de Webmin. El c\u00f3digo malicioso estuvo presente en los archivos desde marzo de 2018. El problema tambi\u00e9n afect\u00f3 <noindex><a rel=\"nofollow\" href=\"https:\/\/sourceforge.net\/projects\/webadmin\/files\/usermin\/\">las versiones de Usermin<\/a><\/noindex>. En la actualidad, todos los archivos comprimidos han sido reconstruidos a partir de Git.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51315\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Webmin, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c, \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0431\u044d\u043a\u0434\u043e\u0440 (CVE-2019-15107), \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0439 \u0432 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0441\u0431\u043e\u0440\u043a\u0430\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u0430, \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u043c\u044b\u0445 \u0447\u0435\u0440\u0435\u0437 Sourceforge \u0438 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c \u0441\u0430\u0439\u0442\u0435. \u0411\u044d\u043a\u0434\u043e\u0440 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b \u0432 \u0441\u0431\u043e\u0440\u043a\u0430\u0445 \u0441 1.882 \u043f\u043e 1.921 \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e (\u0432 git-\u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043a\u043e\u0434 \u0441 \u0431\u044d\u043a\u0434\u043e\u0440\u043e\u043c \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b) \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u043b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0435 shell-\u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0414\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37292","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Webmin, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Webmin \u043d\u0430\u0439\u0434\u0435\u043d \u0431\u044d\u043a\u0434\u043e\u0440, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Webmin, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Se ha encontrado un backdoor en Webmin que permite acceso remoto con privilegios de root | ProHoster","description":"En el paquete Webmin, que proporciona herramientas para la gesti\u00f3n remota del servidor,","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Webmin \u043d\u0430\u0439\u0434\u0435\u043d \u0431\u044d\u043a\u0434\u043e\u0440, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster","og:description":"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Webmin, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c,","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/v-webmin-najden-bekdor-pozvolyayushhij-udalyonno-poluchit-dostup-s-pravami-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:49+00:00","article:modified_time":"2019-10-31T19:16:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37292","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:08:31","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:29:59","updated":"2026-01-23 17:08:31","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=37292"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37292\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=37292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=37292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=37292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}