{"id":113601,"date":"2024-02-15T04:02:43","date_gmt":"2024-02-15T02:02:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu"},"modified":"2024-02-15T04:02:43","modified_gmt":"2024-02-15T02:02:43","slug":"sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","title":{"rendered":"Scenario di attacco all'elaboratore delle applicazioni non installate in Ubuntu","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>I ricercatori di Aqua Security hanno messo in evidenza la possibilit\u00e0 di un attacco agli utenti della distribuzione Ubuntu, sfruttando le peculiarit\u00e0 dell'implementazione del gestore \"command-not-found\", che fornisce suggerimenti nel caso in cui si tenti di avviare un programma non presente nel sistema. Il problema \u00e8 che, nella valutazione dei comandi non trovati nel sistema, \"command-not-found\" non considera solo i pacchetti dei repository ufficiali, ma anche i pacchetti snap dal catalogo snapcraft.io.    <\/p>\n<p>Nella formulazione del suggerimento basato sul contenuto del catalogo snapcraft.io, il gestore \"command-not-found\" non tiene conto dello stato del pacchetto e include pacchetti aggiunti da utenti non verificati. Di conseguenza, un attaccante pu\u00f2 caricare su snapcraft.io un pacchetto con contenuti dannosi nascosti e un nome che coincide con pacchetti DEB esistenti, programmi inizialmente assenti nel repository o applicazioni fasulle i cui nomi riflettono errori tipici e refusi degli utenti durante la digitazione di nomi di utilit\u00e0 popolari.     <\/p>\n<p>Ad esempio, \u00e8 possibile caricare pacchetti \"tracert\" e \"tcpdamp\" sperando che l'utente commetta un errore digitando i nomi delle utilit\u00e0 \"traceroute\" e \"tcpdump\", e \"command-not-found\" raccomander\u00e0 di installare i pacchetti dannosi caricati su snapcraft.io. L'utente potrebbe non accorgersi dell'inganno e credere che il sistema raccomandi solo pacchetti verificati. L'attaccante potrebbe anche caricare su snapcraft.io un pacchetto il cui nome coincide con pacchetti deb esistenti, e in questo caso \"command-not-found\" fornir\u00e0 due raccomandazioni per l'installazione dei pacchetti deb e snap, e l'utente potrebbe scegliere lo snap, ritenendolo pi\u00f9 sicuro o attratto da una versione pi\u00f9 recente.    <center><img decoding=\"async\" alt=\"Scenario di attacco all&#039;elaboratore delle applicazioni non installate in Ubuntu\" src=\"\/wp-content\/uploads\/2024\/02\/5ed4b661fcc1bf13a7edc101b829b185.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Le applicazioni in formato snap, per le quali snapcraft.io consente la revisione automatica, possono essere eseguite solo in un ambiente isolato (i pacchetti snap senza isolamento possono essere pubblicati solo dopo una revisione manuale). Per l'attaccante potrebbe essere sufficiente eseguire in un ambiente isolato con accesso alla rete, ad esempio per il mining di criptovalute, attacchi DDoS o invio di spam.    <\/p>\n<p>L'aggressore potrebbe anche utilizzare metodi per bypassare l'isolamento in pacchetti dannosi, come sfruttare vulnerabilit\u00e0 non corrette nel kernel e nei meccanismi di isolamento, utilizzare interfacce snap per accedere a risorse esterne (per registrazioni nascoste audio e video) o catturare l'input da tastiera quando si utilizza il protocollo X11 (per creare keylogger operanti in ambienti sandbox).<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60602\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &#171;command-not-found&#187;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0439 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043f\u0440\u0438 \u043e\u0446\u0435\u043d\u043a\u0435 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u0430\u043d\u0434, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, &#171;command-not-found&#187; \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043f\u0440\u0438 \u0432\u044b\u0431\u043e\u0440\u0435 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0430\u0446\u0438\u0438 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0430\u043a\u0435\u0442\u044b \u0438\u0437 \u0448\u0442\u0430\u0442\u043d\u044b\u0445 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432, \u043d\u043e snap-\u043f\u0430\u043a\u0435\u0442\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":113602,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-113601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0432 Ubuntu | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-02-15T02:02:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-02-15T02:02:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Scenario di attacco al gestore delle applicazioni non installate in Ubuntu | ProHoster","description":"I ricercatori di Aqua Security hanno notato la possibilit\u00e0 di un attacco agli utenti della distribuzione Ubuntu, sfruttando le caratteristiche dell'implementazione del gestore \"command-not-found\", che fornisce suggerimenti.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0432 Ubuntu | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Aqua Security \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Ubuntu, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 &quot;command-not-found&quot;, \u0432\u044b\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u043f\u043e\u0434\u0441\u043a\u0430\u0437\u043a\u0443 \u0432.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/sczenarij-ataki-na-obrabotchik-ne-ustanovlennyh-prilozhenij-v-ubuntu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-02-15T02:02:43+00:00","article:modified_time":"2024-02-15T02:02:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/113601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=113601"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/113601\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/113602"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=113601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=113601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=113601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}