{"id":121960,"date":"2025-02-16T20:22:05","date_gmt":"2025-02-16T18:22:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust"},"modified":"2025-02-16T20:22:05","modified_gmt":"2025-02-16T18:22:05","slug":"v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust","title":{"rendered":"In PostgreSQL \u00e8 stata risolta una vulnerabilit\u00e0 sfruttata nell'attacco a BeyondTrust","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sono stati rilasciati aggiornamenti correttivi per tutti i rami supportati di PostgreSQL 17.3, 16.7, 15.11, 14.16 e 13.19, che correggono oltre 70 errori e risolvono una vulnerabilit\u00e0 (CVE-2025-1094), utilizzata alla fine di dicembre in un attacco contro l'azienda BeyondTrust e il Ministero delle Finanze degli Stati Uniti. Il problema in PostgreSQL \u00e8 stato individuato durante l'analisi di una vulnerabilit\u00e0 remota (CVE-2024-12356) nei servizi BeyondTrust PRA (Privileged Remote Access) e BeyondTrust RS (Remote Support), durante l'exploitation della quale \u00e8 stata ulteriormente sfruttata una vulnerabilit\u00e0 sconosciuta (0-day) in libpq.      <\/p>\n<p>A seguito dell'attacco, gli aggressori sono riusciti ad ottenere una chiave di accesso all'API utilizzata per la fornitura remota di servizi di supporto tecnico ai clienti dei servizi SaaS di BeyondTrust. Questa API \u00e8 stata utilizzata per reimpostare le password e compromettere l'infrastruttura del Ministero delle Finanze degli Stati Uniti, che utilizza i prodotti BeyondTrust. Durante l'attacco, gli aggressori sono stati in grado di scaricare documenti riservati e ottenere accesso ai posti di lavoro dei dipendenti del ministero.          <\/p>\n<p>La vulnerabilit\u00e0 si manifesta nella libreria libpq, che fornisce un'API per interagire con il DBMS da programmi in linguaggio C (sopra la libreria sono inoltre implementate librerie di wrapping per C++, Perl, PHP e Python). Il problema riguarda le applicazioni che utilizzano le funzioni PQescapeLiteral(), PQescapeIdentifier(), PQescapeString() o PQescapeStringConn() per l'escaping dei caratteri speciali e la neutralizzazione delle virgolette.     <\/p>\n<p>L'attaccante pu\u00f2 ottenere l'inserimento del proprio SQL se il testo ricevuto dall'esterno \u00e8 sottoposto a escaping utilizzando le suddette funzioni libpq prima dell'utilizzo all'interno della query SQL. Nelle applicazioni BeyondTrust, le query cos\u00ec escatate venivano inviate tramite l'utilit\u00e0 da riga di comando psql. La vulnerabilit\u00e0 \u00e8 causata dall'assenza di verifica della correttezza dei caratteri Unicode utilizzati nel testo nelle funzioni di escaping, che consente di eludere la normalizzazione delle virgolette specificando sequenze multibyte UTF-8 non valide.       <\/p>\n<p>Per sfruttare la vulnerabilit\u00e0, si pu\u00f2 usare un carattere UTF-8 non corretto, composto dai byte 0xC0 e 0x27 (\u2514'). Il byte 0x27 in ASCII corrisponde a un apostrofo ('), che deve essere eseguito l'escaping. Nel codice di escaping, la combinazione di byte 0xC0 e 0x27 viene trattata come un singolo carattere Unicode. Di conseguenza, il byte 0x27 in questa sequenza rimane non eseguito l'escaping, mentre durante l'elaborazione della query SQL nell'utility psql viene trattato come un apostrofo.        <\/p>\n<p>Durante <a href=\"https:\/\/prohoster.info\/it\/hosting\/hosting-phpmyadmin\/\"  data-wpil-monitor-id=\"2439\">l'esecuzione di query SQL<\/a> Utilizzando l'utility psql per organizzare l'esecuzione di codice arbitrario, si pu\u00f2 utilizzare la sostituzione nella stringa del comando [!], progettata in psql per avviare programmi arbitrari. Ad esempio, per avviare <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2743\">server<\/a> l'utility 'id' si pu\u00f2 passare il valore 'hax[0xC0\u2032; ! id #'. Nell'esempio seguente, per l'escaping viene chiamato lo script PHP dbquote, che utilizza la funzione PHP pg_escape_string, che opera sopra la funzione PQescapeString di libpq: $ echo -e 'hello [0xC0\u2019world' | .\/dbquote 'hello \u2514\u2019world' $ quoted=$(echo -e 'hax[0xC0\u2032; ! id # ' | .\/dbquote) $ echo 'SELECT COUNT(1) FROM gw_sessions WHERE session_key = $quoted AND session_type = 'sdcust' AND (expiration IS NULL OR expiration&gt;NOW())' | psql -e SELECT COUNT(1) FROM gw_sessions WHERE session_key = 'hax\u2514'; ERROR: sequenza di byte non valida per la codifica 'UTF8': 0xc0 0x27 uid=1000(myexamplecompany) gid=1000(myexamplecompany)<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62722\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL 17.3, 16.7, 15.11, 14.16 \u0438 13.19, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 70 \u043e\u0448\u0438\u0431\u043e\u043a \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-1094), \u0432 \u043a\u043e\u043d\u0446\u0435 \u0434\u0435\u043a\u0430\u0431\u0440\u044f \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u0432 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044e BeyondTrust \u0438 \u041c\u0438\u043d\u0438\u0441\u0442\u0435\u0440\u0441\u0442\u0432\u043e \u0444\u0438\u043d\u0430\u043d\u0441\u043e\u0432 \u0421\u0428\u0410. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432 PostgreSQL \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u0440\u0438 \u0430\u043d\u0430\u043b\u0438\u0437\u0435 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2024-12356) \u0432 \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445 BeyondTrust PRA (Privileged Remote Access) \u0438 BeyondTrust [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-121960","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL 17.3, 16.7, 15.11, 14.16 \u0438 13.19, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 70 \u043e\u0448\u0438\u0431\u043e\u043a \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-1094), \u0432 \u043a\u043e\u043d\u0446\u0435 \u0434\u0435\u043a\u0430\u0431\u0440\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 PostgreSQL \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043f\u0440\u0438 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 BeyondTrust | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL 17.3, 16.7, 15.11, 14.16 \u0438 13.19, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 70 \u043e\u0448\u0438\u0431\u043e\u043a \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-1094), \u0432 \u043a\u043e\u043d\u0446\u0435 \u0434\u0435\u043a\u0430\u0431\u0440\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-02-16T18:22:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-02-16T18:22:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47In PostgreSQL \u00e8 stata corretta una vulnerabilit\u00e0 utilizzata nell'attacco a BeyondTrust | ProHoster","description":"Sono stati creati aggiornamenti correttivi per tutti i rami supportati PostgreSQL 17.3, 16.7, 15.11, 14.16 e 13.19, in cui sono stati risolti oltre 70 errori e una vulnerabilit\u00e0 (CVE-2025-1094) a fine dicembre.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 PostgreSQL \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043f\u0440\u0438 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 BeyondTrust | ProHoster","og:description":"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL 17.3, 16.7, 15.11, 14.16 \u0438 13.19, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 70 \u043e\u0448\u0438\u0431\u043e\u043a \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-1094), \u0432 \u043a\u043e\u043d\u0446\u0435 \u0434\u0435\u043a\u0430\u0431\u0440\u044f.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/v-postgresql-ustranena-uyazvimost-ispolzovannaya-pri-atake-na-beyondtrust","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-02-16T18:22:05+00:00","article:modified_time":"2025-02-16T18:22:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"121960","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 22:06:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 10:39:20","updated":"2026-02-09 22:06:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/121960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=121960"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/121960\/revisions"}],"predecessor-version":[{"id":160023,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/121960\/revisions\/160023"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=121960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=121960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=121960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}