{"id":35980,"date":"2019-10-31T22:08:56","date_gmt":"2019-10-31T19:08:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\/"},"modified":"2019-10-31T22:08:56","modified_gmt":"2019-10-31T19:08:56","slug":"zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","title":{"rendered":"Fissata la sostituzione di codice dannoso nel pacchetto Ruby Strong_password","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/versions\/0.0.7\">pubblicato<\/a><\/noindex> nel rilascio del 25 giugno del pacchetto gem Strong_password 0.7 <noindex><a rel=\"nofollow\" href=\"https:\/\/withatwist.dev\/strong-password-rubygem-hijacked.html\">identificate<\/a><\/noindex>  modifica dannosa (<noindex><a rel=\"nofollow\" href=\"https:\/\/rubysec.com\/advisories\/strong_password-CVE-2019-13354\">CVE-2019-13354<\/a><\/noindex>), che carica ed esegue codice esterno controllato da un criminale sconosciuto, ospitato sul servizio Pastebin. Il numero totale di download del progetto \u00e8 di 247.000, mentre la versione 0.6 ha circa 38.000 download. Per la versione malevola, il numero di download \u00e8 indicato come 537, ma non \u00e8 chiaro quanto questo corrisponda alla realt\u00e0, dato che questa versione \u00e8 gi\u00e0 stata rimossa da Ruby Gems.<\/p>\n<p>La libreria Strong_password offre strumenti per verificare la robustezza della password fornita dall'utente al momento della registrazione.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/reverse_dependencies\">Tra<\/a><\/noindex> utilizzando pacchetti Strong_password come think_feel_do_engine (65.000 download), think_feel_do_dashboard (15.000 download) e<br \/>\nsuperhosting (1,5 m). Si segnala che la modifica dannosa \u00e8 stata aggiunta da un soggetto sconosciuto che ha sequestrato il controllo del repository dall'autore. <\/p>\n<p>Il codice dannoso \u00e8 stato aggiunto solo su RubyGems.org, <noindex>Git repository<\/noindex> il progetto non ha subito danni. Il problema \u00e8 stato identificato dopo che uno degli sviluppatori che utilizzava Strong_password nei propri progetti ha iniziato a indagare sul motivo per cui l'ultimo cambiamento nel repository risaliva a oltre 6 mesi fa, mentre su RubyGems era apparso un nuovo rilascio pubblicato a nome di un nuovo maintainer, di cui nessuno aveva mai sentito parlare.<\/p>\n<p>L'attaccante avrebbe potuto organizzare l'esecuzione di codice arbitrario sui server che utilizzano la versione problematica di Strong_password. Al momento della scoperta del problema con Pastebin, veniva caricato uno script per avviare qualsiasi codice, trasmesso dal cliente tramite il cookie \u00ab__id\u00bb e codificato utilizzando il metodo Base64. Il codice malevolo inviava anche i parametri dell'host su cui era installata la versione malevola di Strong_password al server controllato dal criminale. <\/p>\n<p><center><img decoding=\"async\" alt=\"Fissata la sostituzione di codice dannoso nel pacchetto Ruby Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/3d08a0f65fb7acf0f8225c388b60c721.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><center><img decoding=\"async\" alt=\"Fissata la sostituzione di codice dannoso nel pacchetto Ruby Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/798a680ce803618409606044b21c66ef.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51056\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 (CVE-2019-13354), \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0449\u0435\u0435 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044e\u0449\u0435\u0435 \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0439 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u043a\u043e\u0434, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0439 \u043d\u0430 \u0441\u0435\u0440\u0432\u0438\u0441\u0435 Pastebin. \u041e\u0431\u0449\u0435\u0435 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 247 \u0442\u044b\u0441\u044f\u0447, \u0430 \u0432\u0435\u0440\u0441\u0438\u0438 0.6 &#8212; \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447. \u0414\u043b\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0443\u043a\u0430\u0437\u0430\u043d\u043e 537, \u043d\u043e \u043d\u0435 \u044f\u0441\u043d\u043e \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043d\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0441 \u0443\u0447\u0451\u0442\u043e\u043c \u0442\u043e\u0433\u043e, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26895,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c8 stata rilevata l'inserzione di codice dannoso nel pacchetto Ruby Strong_password | ProHoster","description":"Nel rilascio del 25 giugno del pacchetto gem Strong_password 0.7","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster","og:description":"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:08:56+00:00","article:modified_time":"2019-10-31T19:08:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35980","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 01:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:52:26","updated":"2026-01-22 01:31:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=35980"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35980\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/26895"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=35980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=35980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=35980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}