{"id":37310,"date":"2019-10-31T22:16:54","date_gmt":"2019-10-31T19:16:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\/"},"modified":"2019-10-31T22:16:54","modified_gmt":"2019-10-31T19:16:54","slug":"v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","title":{"rendered":"Un code malveillant a \u00e9t\u00e9 d\u00e9tect\u00e9 dans rest-client et 10 autres paquets Ruby","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans le populaire paquet gem <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\">rest-client<\/a><\/noindex>, qui totalise 113 millions de t\u00e9l\u00e9chargements, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex> , une injection de code malveillant (CVE-2019-15224) qui ex\u00e9cute des commandes et envoie des informations vers un h\u00f4te externe. L'attaque a \u00e9t\u00e9 r\u00e9alis\u00e9e via <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713#issuecomment-522735093\">la compromission<\/a><\/noindex> du compte d\u00e9veloppeur de rest-client sur le d\u00e9p\u00f4t rubygems.org, apr\u00e8s quoi les attaquants ont publi\u00e9 les versions 1.6.10-1.6.13 les 13 et 14 ao\u00fbt, incluant des modifications malveillantes. Avant le blocage des versions malveillantes, environ mille utilisateurs les avaient t\u00e9l\u00e9charg\u00e9es (les attaquants, pour ne pas attirer l'attention, ont publi\u00e9 des mises \u00e0 jour de versions anciennes).<\/p>\n<p>La modification malveillante red\u00e9finit la m\u00e9thode \u00ab #authenticate \u00bb dans la classe<br \/>\nIdentity, chaque appel \u00e0 cette m\u00e9thode entra\u00eenant l'envoi de l'email et du mot de passe fournis lors de la tentative d'authentification vers l'h\u00f4te des attaquants. Cela permet l'interception des param\u00e8tres de connexion des utilisateurs de services utilisant la classe Identity et ayant install\u00e9 une version vuln\u00e9rable de la biblioth\u00e8que rest-client, qui <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\/reverse_dependencies\">est pr\u00e9sente<\/a><\/noindex> comme d\u00e9pendance dans de nombreux paquets Ruby populaires, y compris ast (64 millions de t\u00e9l\u00e9chargements), oauth (32 millions), fastlane (18 millions) et kubeclient (3,7 millions).<\/p>\n<p>De plus, un backdoor a \u00e9t\u00e9 ajout\u00e9 au code, permettant l'ex\u00e9cution de code Ruby arbitraire via la fonction eval. Le code est transmis via un cookie sign\u00e9 par la cl\u00e9 de l'attaquant. Pour informer les attaquants de l'installation du paquet malveillant sur un h\u00f4te externe, un URL du syst\u00e8me de la victime et un ensemble d'informations sur l'environnement, telles que les mots de passe enregistr\u00e9s pour les bases de donn\u00e9es et les services cloud, sont envoy\u00e9s. Des tentatives de chargement de scripts pour le minage de cryptomonnaies ont \u00e9t\u00e9 enregistr\u00e9es en utilisant le code malveillant mentionn\u00e9 ci-dessus.<\/p>\n<p>Apr\u00e8s avoir analys\u00e9 le code malveillant, il a \u00e9t\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/issues\/2097\">d\u00e9tect\u00e9<\/a><\/noindex>, not\u00e9 que des modifications similaires sont pr\u00e9sentes dans <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/wiki\/Gems-yanked-and-accounts-locked#19-aug-2019\">10 paquets<\/a><\/noindex> dans Ruby Gems, qui n'ont pas \u00e9t\u00e9 captur\u00e9s, mais sp\u00e9cialement pr\u00e9par\u00e9s par les attaquants sur la base d'autres biblioth\u00e8ques populaires avec des noms similaires, dans lesquels le tiret a \u00e9t\u00e9 remplac\u00e9 par un underscore ou inversement (par exemple, bas\u00e9 sur <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron-parser\">cron-parser<\/a><\/noindex> un paquet malveillant cron_parser a \u00e9t\u00e9 cr\u00e9\u00e9, et sur la base de <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge_coin\">doge_coin<\/a><\/noindex> le paquet malveillant doge-coin). Paquets probl\u00e9matiques :<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coin_base\">coin_base<\/a><\/noindex>: 4.2.2, 4.2.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/blockchain_wallet\">blockchain_wallet<\/a><\/noindex>: 0.0.6, 0.0.7\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/awesome-bot\">awesome-bot<\/a><\/noindex>: 1.18.0\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge-coin\">doge-coin<\/a><\/noindex>: 1.0.2\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/capistrano-colors\">capistrano-colors<\/a><\/noindex>: 0.5.5\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/bitcoin_vanity\">bitcoin_vanity<\/a><\/noindex>: 4.3.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/lita_coin\">lita_coin<\/a><\/noindex>: 0.0.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coming-soon\">coming-soon<\/a><\/noindex>: 0.2.8\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/omniauth_amazon\">omniauth_amazon<\/a><\/noindex>: 1.0.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron_parser\">cron_parser<\/a><\/noindex>: 1.0.12, 1.0.13, 0.1.4\n<\/ul>\n<p>Le premier paquet malveillant de cette liste a \u00e9t\u00e9 publi\u00e9 le 12 mai, mais la plupart sont apparus en juillet. En tout, ces paquets ont \u00e9t\u00e9 t\u00e9l\u00e9charg\u00e9s environ 2500 fois.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 (CVE-2019-15224), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043d\u0430 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u0445\u043e\u0441\u0442. \u0410\u0442\u0430\u043a\u0430 \u0431\u044b\u043b\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u0435\u0434\u0435\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044e \u0443\u0447\u0451\u0442\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 rest-client \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 rubygems.org, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 13 \u0438 14 \u0430\u0432\u0433\u0443\u0441\u0442\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 1.6.10-1.6.13, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f. \u0414\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 \u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37310","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Du code malveillant a \u00e9t\u00e9 d\u00e9tect\u00e9 dans rest-client et 10 autres paquets Ruby | ProHoster","description":"Dans le populaire paquet gem rest-client, qui compte au total 113 millions de t\u00e9l\u00e9chargements,","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:54+00:00","article:modified_time":"2019-10-31T19:16:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37310","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:14:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:29:58","updated":"2026-01-23 17:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=37310"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37310\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=37310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=37310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=37310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}