{"id":86356,"date":"2020-06-24T13:42:00","date_gmt":"2020-06-24T11:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda"},"modified":"2020-06-24T13:42:00","modified_gmt":"2020-06-24T11:42:00","slug":"uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","title":{"rendered":"Vulnerabilidad en el navegador seguro Bitdefender SafePay que permite la ejecuci\u00f3n de c\u00f3digo","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Vladimir Palant, creador de Adblock Plus, <noindex><a rel=\"nofollow\" href=\"https:\/\/palant.info\/2020\/06\/22\/exploiting-bitdefender-antivirus-rce-from-any-website\/\">detectado<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.bitdefender.com\/support\/security-advisories\/insufficient-url-sanitization-validation-safepay-browser-va-8631\/\">vulnerabilidad<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-8102\">CVE-2020-8102<\/a><\/noindex>) en el navegador web especializado Safepay, basado en el motor Chromium, que se ofrece como parte del paquete antivirus Bitdefender Total Security 2020 y est\u00e1 dise\u00f1ado para aumentar la seguridad del usuario en la red global (por ejemplo, proporciona aislamiento adicional al acceder a bancos y sistemas de pago). La vulnerabilidad permite que los sitios abiertos en el navegador ejecuten c\u00f3digo arbitrario a nivel del sistema operativo.<\/p>\n<p>La causa del problema es que el antivirus Bitdefender realiza un intercepci\u00f3n local del tr\u00e1fico HTTPS mediante la sustituci\u00f3n del certificado TLS original del sitio. En el sistema del cliente se instala un certificado ra\u00edz adicional que permite ocultar la operaci\u00f3n del sistema de inspecci\u00f3n de tr\u00e1fico utilizado. El antivirus se infiltra en el tr\u00e1fico seguro y a\u00f1ade su propio c\u00f3digo JavaScript en algunas p\u00e1ginas para implementar la funci\u00f3n Safe Search, y en caso de problemas con el certificado de conexi\u00f3n segura, reemplaza la p\u00e1gina de error generada con una propia. Dado que la nueva p\u00e1gina de error se presenta en nombre del servidor abierto, otras p\u00e1ginas de este servidor tienen acceso total al contenido insertado por Bitdefender.<\/p>\n<p>Al abrir un sitio web controlado por un atacante, este sitio puede enviar una solicitud XMLHttpRequest y simular un problema con el certificado HTTPS en la respuesta, lo que lleva a mostrar una p\u00e1gina de error modificada por Bitdefender. Dado que la p\u00e1gina de error se abre en el contexto del dominio del atacante, este puede leer el contenido de la p\u00e1gina alterada con los par\u00e1metros de Bitdefender. En la p\u00e1gina de Bitdefender de reemplazo tambi\u00e9n se encuentra una clave de sesi\u00f3n que permite, mediante la API interna de Bitdefender, iniciar una sesi\u00f3n separada del navegador Safepay, especificando cualquier bandera de l\u00ednea de comandos, y as\u00ed ejecutar cualquier comando del sistema usando la bandera \u00ab--utility-cmd-prefix\u00bb. Ejemplo de exploit (param1 y param2 son valores obtenidos de la p\u00e1gina de error):<\/p>\n<p>   var request = new XMLHttpRequest();<br \/>\n   request.open(\u2018POST\u2019, Math.random());<br \/>\n   request.setRequestHeader(\u2018Content-type\u2019, \u2018application\/x-www-form-urlencoded\u2019);<br \/>\n   request.setRequestHeader(\u2018BDNDSS_B67EA559F21B487F861FDA8A44F01C50\u2019, param1);<br \/>\n   request.setRequestHeader(\u2018BDNDCA_BBACF84D61A04F9AA66019A14B035478\u2019, param2);<br \/>\n   request.setRequestHeader(\u2018BDNDWB_5056E556833D49C1AF4085CB254FC242\u2019, \u2018obk.run\u2019);<br \/>\n   request.setRequestHeader(\u2018BDNDOK_4E961A95B7B44CBCA1907D3D3643370D\u2019, location.href);<br \/>\n   request.send(\u2018data:text\/html,nada \u2014utility-cmd-prefix=\\cmd.exe \/k whoami &amp; echo\\&gt;\u2019);<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/palant.info\/2020\/06\/22\/exploiting-bitdefender-antivirus-rce-from-any-website\/rce.png\"><img decoding=\"async\" alt=\"Vulnerabilidad en el navegador seguro Bitdefender SafePay que permite la ejecuci\u00f3n de c\u00f3digo\" src=\"\/wp-content\/uploads\/2020\/06\/63506c8918fac4714433bbb539926777.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Recordemos que el estudio realizado en 2017  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=45996\">demostr\u00f3<\/a><\/noindex>, que 24 de los 26 productos antivirus probados, que inspeccionan el tr\u00e1fico HTTPS mediante sustituci\u00f3n de certificados, reduc\u00edan el nivel general de seguridad de la conexi\u00f3n HTTPS.<br \/>\nConjuntos de cifrado actualizados solo estaban disponibles en 11 de los 26 productos. 5 sistemas no verificaban los certificados (Kaspersky Internet Security 16 Mac, NOD32 AV 9, CYBERsitter, Net Nanny 7 Win, Net Nanny 7 Mac). Los productos Kaspersky Internet Security y Total Security fueron vulnerables a ataques <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=34869\">CRIME<\/a><\/noindex>, mientras que los productos AVG, Bitdefender y Bullguard tambi\u00e9n fueron atacados <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=42270\">Logjam<\/a><\/noindex> y <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=40833\">POODLE<\/a><\/noindex>. El producto Dr.Web Antivirus 11 permite volver a cifrados exportados inseguros (ataque <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41782\">FREAK<\/a><\/noindex>).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53223\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-8102) \u0432 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c web-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Safepay, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043f\u0430\u043a\u0435\u0442\u0430 Bitdefender Total Security 2020 \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u043c \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 \u0433\u043b\u043e\u0431\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u0430\u044f \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u043a \u0431\u0430\u043d\u043a\u0430\u043c \u0438 \u043f\u043b\u0430\u0442\u0451\u0436\u043d\u044b\u043c \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c\u044b\u043c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u0441\u0430\u0439\u0442\u0430\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":86357,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-86356","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u043c \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Bitdefender SafePay, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-24T11:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-24T11:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Una vulnerabilidad en el navegador seguro Bitdefender SafePay que permite la ejecuci\u00f3n de c\u00f3digo | ProHoster","description":"Vladimir Palant, creador de Adblock Plus, descubri\u00f3","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u043c \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Bitdefender SafePay, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster","og:description":"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-24T11:42:00+00:00","article:modified_time":"2020-06-24T11:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"86356","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:17:32","updated":"2022-09-28 12:42:50","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/86356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=86356"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/86356\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/86357"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=86356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=86356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=86356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}