{"id":117002,"date":"2024-07-06T21:43:04","date_gmt":"2024-07-06T19:43:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan"},"modified":"2024-07-06T21:43:04","modified_gmt":"2024-07-06T19:43:04","slug":"v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan","title":{"rendered":"Des informations sur le dark web indiquent que GRUB a \u00e9t\u00e9 compromis","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Des informations sur le dark web indiquent que GRUB a \u00e9t\u00e9 compromis\" src=\"\/wp-content\/uploads\/2024\/07\/a954ed8353ccfaad566145c2d316a9bf.jpg\" style=\"display:block;margin: 0 auto;\" \/>                                      <\/p>\n<p>Un exploit pour une vuln\u00e9rabilit\u00e9 0day est d\u00e9j\u00e0 en vente sur des forums appropri\u00e9s.<\/p>\n<p>Le 21 juin, une information concernant la vente d'un exploit pour une vuln\u00e9rabilit\u00e9 0day dans le chargeur GRUB de Linux, permettant une \u00e9l\u00e9vation de privil\u00e8ges locale (LPE), est apparue sur l'un des forums.<\/p>\n<p>Selon Dark Web Intelligence, l'attaquant affirme avoir trouv\u00e9 une vuln\u00e9rabilit\u00e9 dans GRUB qui lui permet de contourner les m\u00e9canismes d'authentification et d'obtenir des droits root sur le syst\u00e8me.<\/p>\n<p>Selon un membre d'un forum sombre sous le pseudonyme \u00ab Cas \u00bb, la vuln\u00e9rabilit\u00e9 concerne GRUB \u2014 un composant critique de la plupart des syst\u00e8mes Linux qui g\u00e8re le processus de d\u00e9marrage, permettant aux attaquants d'installer des malwares cach\u00e9s et persistants, dont la d\u00e9tection et l'\u00e9limination peuvent s'av\u00e9rer tr\u00e8s probl\u00e9matiques. L'exploit est propos\u00e9 au prix de 90 000 dollars.<\/p>\n<p>Il est \u00e0 noter que GRUB a d\u00e9j\u00e0 \u00e9t\u00e9 la cible d'attaques dans le pass\u00e9. En 2015, une vuln\u00e9rabilit\u00e9, CVE-2015-8370, a \u00e9t\u00e9 d\u00e9couverte, permettant de contourner l'authentification en appuyant sur la touche backspace 28 fois lors de la saisie du nom d'utilisateur dans GRUB. Cette vuln\u00e9rabilit\u00e9 a touch\u00e9 les versions GRUB de 1.98 \u00e0 2.02 et a \u00e9t\u00e9 largement exploit\u00e9e jusqu'\u00e0 la publication du patch. En 2020, une autre vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e \u2014 CVE-2020-10713, \u00e9galement connue sous le nom de BootHole, permettant d'installer des malwares lors du d\u00e9marrage.<\/p>\n<p>Les principales distributions Linux, telles que Debian, RedHat et Ubuntu, ont rapidement publi\u00e9 des recommandations et des patches pour les vuln\u00e9rabilit\u00e9s ant\u00e9rieures de GRUB et agiront probablement de la m\u00eame mani\u00e8re cette fois-ci. Cependant, le probl\u00e8me est aggrav\u00e9 par le fait que la vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte par des cybercriminels et non par des hackers \u00e9thiques. Cela signifie que sa d\u00e9couverte et sa correction par les chercheurs en s\u00e9curit\u00e9 pourraient prendre un certain temps.<\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/17658407\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u042d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f 0day-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0436\u0435 \u043f\u0440\u043e\u0434\u0430\u0451\u0442\u0441\u044f \u043d\u0430 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0444\u043e\u0440\u0443\u043c\u0430\u0445. 21 \u0438\u044e\u043d\u044f \u043d\u0430 \u043e\u0434\u043d\u043e\u043c \u0438\u0437 \u0444\u043e\u0440\u0443\u043c\u043e\u0432 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u0440\u043e\u0434\u0430\u0436\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043a \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0432 GRUB-\u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 (LPE). \u041f\u043e \u0434\u0430\u043d\u043d\u044b\u043c Dark Web Intelligence, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442, \u0447\u0442\u043e \u043d\u0430\u0448\u0451\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GRUB, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0431\u043e\u0439\u0442\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0421\u043e\u0433\u043b\u0430\u0441\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":117003,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-117002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u042d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f 0day-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0436\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u0434\u0430\u0440\u043a\u043d\u0435\u0442\u0435 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f, \u0447\u0442\u043e GRUB \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u042d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f 0day-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0436\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-07-06T19:43:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-07-06T19:43:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Des informations ont circul\u00e9 sur le darkweb indiquant que GRUB a \u00e9t\u00e9 compromis | ProHoster","description":"Un exploit pour une vuln\u00e9rabilit\u00e9 0day est d\u00e9j\u00e0 disponible.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u0434\u0430\u0440\u043a\u043d\u0435\u0442\u0435 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f, \u0447\u0442\u043e GRUB \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d | ProHoster","og:description":"\u042d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f 0day-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0436\u0435.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-darknete-poyavilas-informacziya-chto-grub-skomprometirovan","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-07-06T19:43:04+00:00","article:modified_time":"2024-07-06T19:43:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"117002","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 03:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 03:39:19","updated":"2026-01-23 03:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/117002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=117002"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/117002\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media\/117003"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=117002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=117002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=117002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}