{"id":37310,"date":"2019-10-31T22:16:54","date_gmt":"2019-10-31T19:16:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\/"},"modified":"2019-10-31T22:16:54","modified_gmt":"2019-10-31T19:16:54","slug":"v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","title":{"rendered":"Se ha encontrado c\u00f3digo malicioso en rest-client y otros 10 paquetes de Ruby","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el popular paquete gem <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\">rest-client<\/a><\/noindex>, que ha acumulado un total de 113 millones de descargas, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713\">se ha detectado<\/a><\/noindex> la inserci\u00f3n de c\u00f3digo malicioso (CVE-2019-15224), que carga comandos ejecutables y env\u00eda informaci\u00f3n a un host externo. El ataque se llev\u00f3 a cabo a trav\u00e9s de <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713#issuecomment-522735093\">la compromisi\u00f3n<\/a><\/noindex> de la cuenta del desarrollador de rest-client en el repositorio rubygems.org, tras lo cual los atacantes publicaron las versiones 1.6.10-1.6.13 el 13 y 14 de agosto, que inclu\u00edan cambios maliciosos. Antes de que se bloquearan las versiones maliciosas, aproximadamente mil usuarios las hab\u00edan descargado (los atacantes publicaron actualizaciones de versiones antiguas para no atraer atenci\u00f3n).<\/p>\n<p>La modificaci\u00f3n maliciosa anula el m\u00e9todo \u00ab#authenticate\u00bb en la clase<br \/>\nIdentity, haciendo que cada llamada al m\u00e9todo env\u00ede el correo electr\u00f3nico y la contrase\u00f1a proporcionados durante el intento de autenticaci\u00f3n al host de los atacantes. As\u00ed se interceptan los par\u00e1metros de entrada de los usuarios de los servicios que utilizan la clase Identity y han instalado la versi\u00f3n vulnerable de la biblioteca rest-client, que <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\/reverse_dependencies\">aparece<\/a><\/noindex> como una dependencia en muchos paquetes populares de Ruby, incluidos ast (64 millones de descargas), oauth (32 millones), fastlane (18 millones) y kubeclient (3.7 millones).<\/p>\n<p>Adem\u00e1s, se ha a\u00f1adido una puerta trasera al c\u00f3digo, permitiendo ejecutar c\u00f3digo Ruby arbitrario a trav\u00e9s de la funci\u00f3n eval. El c\u00f3digo se env\u00eda a trav\u00e9s de una Cookie, firmada con la clave del atacante. Para informar a los atacantes sobre la instalaci\u00f3n del paquete malicioso en el host externo, se env\u00eda la URL del sistema de la v\u00edctima y un conjunto de informaci\u00f3n sobre el entorno, como contrase\u00f1as almacenadas para bases de datos y servicios en la nube. Con el uso de este c\u00f3digo malicioso mencionado anteriormente, se han registrado intentos de cargar scripts para minar criptomonedas.<\/p>\n<p>Despu\u00e9s de estudiar el c\u00f3digo malicioso, se ha <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/issues\/2097\">detectado<\/a><\/noindex>, que cambios similares est\u00e1n presentes en <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/wiki\/Gems-yanked-and-accounts-locked#19-aug-2019\">10 paquetes<\/a><\/noindex> en Ruby Gems, que no fueron capturados, sino preparados intencionalmente por los atacantes sobre la base de otras bibliotecas populares con nombres similares, donde se reemplaz\u00f3 el gui\u00f3n por un guion bajo o viceversa (por ejemplo, sobre la base de <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron-parser\">cron-parser<\/a><\/noindex> se cre\u00f3 el paquete malicioso cron_parser, y sobre la base de <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge_coin\">doge_coin<\/a><\/noindex> se cre\u00f3 el paquete malicioso doge-coin). Paquetes problem\u00e1ticos:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coin_base\">coin_base<\/a><\/noindex>: 4.2.2, 4.2.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/blockchain_wallet\">blockchain_wallet<\/a><\/noindex>: 0.0.6, 0.0.7\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/awesome-bot\">awesome-bot<\/a><\/noindex>: 1.18.0\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge-coin\">doge-coin<\/a><\/noindex>: 1.0.2\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/capistrano-colors\">capistrano-colors<\/a><\/noindex>: 0.5.5\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/bitcoin_vanity\">bitcoin_vanity<\/a><\/noindex>: 4.3.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/lita_coin\">lita_coin<\/a><\/noindex>: 0.0.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coming-soon\">coming-soon<\/a><\/noindex>: 0.2.8\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/omniauth_amazon\">omniauth_amazon<\/a><\/noindex>: 1.0.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron_parser\">cron_parser<\/a><\/noindex>: 1.0.12, 1.0.13, 0.1.4\n<\/ul>\n<p>El primer paquete malicioso de esta lista fue publicado el 12 de mayo, pero la mayor parte apareci\u00f3 en julio. En total, los paquetes mencionados lograron ser descargados alrededor de 2500 veces.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 (CVE-2019-15224), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043d\u0430 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u0445\u043e\u0441\u0442. \u0410\u0442\u0430\u043a\u0430 \u0431\u044b\u043b\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u0435\u0434\u0435\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044e \u0443\u0447\u0451\u0442\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 rest-client \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 rubygems.org, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 13 \u0438 14 \u0430\u0432\u0433\u0443\u0441\u0442\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 1.6.10-1.6.13, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f. \u0414\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 \u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37310","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Se ha detectado c\u00f3digo malicioso en rest-client y en otros 10 paquetes de Ruby | ProHoster","description":"En el popular paquete gem rest-client, que cuenta en total con 113 millones de descargas,","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:54+00:00","article:modified_time":"2019-10-31T19:16:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37310","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:14:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:29:58","updated":"2026-01-23 17:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=37310"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37310\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=37310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=37310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=37310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}