{"id":35980,"date":"2019-10-31T22:08:56","date_gmt":"2019-10-31T19:08:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\/"},"modified":"2019-10-31T22:08:56","modified_gmt":"2019-10-31T19:08:56","slug":"zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","title":{"rendered":"\u00c8 stata rilevata l'inserzione di codice malevolo nel pacchetto Ruby Strong_password","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/versions\/0.0.7\">pubblicato<\/a><\/noindex> nel numero del 25 giugno del pacchetto gem Strong_password 0.7 <noindex><a rel=\"nofollow\" href=\"https:\/\/withatwist.dev\/strong-password-rubygem-hijacked.html\">identificato<\/a><\/noindex>  modifica dannosa (<noindex><a rel=\"nofollow\" href=\"https:\/\/rubysec.com\/advisories\/strong_password-CVE-2019-13354\">CVE-2019-13354<\/a><\/noindex>), che carica e esegue codice esterno controllato da un attaccante sconosciuto, ospitato sul servizio Pastebin. Il numero totale di download del progetto \u00e8 di 247.000, mentre la versione 0.6 ha circa 38.000 download. Per la versione dannosa, il numero di download \u00e8 indicato in 537, ma non \u00e8 chiaro quanto corrisponda alla realt\u00e0, considerando che questa versione \u00e8 gi\u00e0 stata rimossa da Ruby Gems.<\/p>\n<p>La libreria Strong_password fornisce strumenti per verificare la robustezza della password selezionata dall'utente durante la registrazione.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/strong_password\/reverse_dependencies\">Tra<\/a><\/noindex> che utilizzano Strong_password, i pacchetti think_feel_do_engine (65 mila download), think_feel_do_dashboard (15 mila download) e<br \/>\nsuperhosting (1.5 mila). Si segnala che la modifica dannosa \u00e8 stata aggiunta da un soggetto sconosciuto che ha intercettato il controllo del repository dall'autore. <\/p>\n<p>Il codice dannoso \u00e8 stato aggiunto solo su RubyGems.org, <noindex>repository Git<\/noindex> il progetto non ha subito danni. Il problema \u00e8 stato scoperto dopo che uno degli sviluppatori che utilizzava Strong_password nei suoi progetti ha iniziato a indagare sul motivo per cui l'ultima modifica era stata aggiunta al repository oltre sei mesi fa, ma su RubyGems \u00e8 uscito un nuovo rilascio, pubblicato da un nuovo manutentore di cui nessuno aveva mai sentito parlare prima.<\/p>\n<p>L'attaccante potrebbe aver organizzato l'esecuzione di codice arbitraio su server che utilizzano la versione vulnerabile di Strong_password. Al momento della scoperta del problema su Pastebin, veniva caricato uno script per eseguire qualsiasi codice inviato dal cliente attraverso il Cookie \u00ab__id\u00bb e codificato utilizzando il metodo Base64. Il codice dannoso inviava anche i parametri dell'host su cui era installata la versione dannosa di Strong_password a un server controllato dall'attaccante. <\/p>\n<p><center><img decoding=\"async\" alt=\"\u00c8 stata rilevata l&#039;inserzione di codice malevolo nel pacchetto Ruby Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/3d08a0f65fb7acf0f8225c388b60c721.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><center><img decoding=\"async\" alt=\"\u00c8 stata rilevata l&#039;inserzione di codice malevolo nel pacchetto Ruby Strong_password\" src=\"\/wp-content\/uploads\/2019\/07\/798a680ce803618409606044b21c66ef.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51056\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 (CVE-2019-13354), \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0449\u0435\u0435 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044e\u0449\u0435\u0435 \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0439 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u043a\u043e\u0434, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0439 \u043d\u0430 \u0441\u0435\u0440\u0432\u0438\u0441\u0435 Pastebin. \u041e\u0431\u0449\u0435\u0435 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 247 \u0442\u044b\u0441\u044f\u0447, \u0430 \u0432\u0435\u0440\u0441\u0438\u0438 0.6 &#8212; \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447. \u0414\u043b\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0447\u0438\u0441\u043b\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0443\u043a\u0430\u0437\u0430\u043d\u043e 537, \u043d\u043e \u043d\u0435 \u044f\u0441\u043d\u043e \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043d\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0441 \u0443\u0447\u0451\u0442\u043e\u043c \u0442\u043e\u0433\u043e, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26895,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:08:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Registrato l'inserimento di codice dannoso nel pacchetto Ruby Strong_password | ProHoster","description":"Nel numero del 25 giugno del pacchetto gem Strong_password 0.7","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 Ruby-\u043f\u0430\u043a\u0435\u0442 Strong_password | ProHoster","og:description":"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c 25 \u0438\u044e\u043d\u044f \u0432\u044b\u043f\u0443\u0441\u043a\u0435 gem-\u043f\u0430\u043a\u0435\u0442\u0430 Strong_password 0.7","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/zafiksirovana-podstanovka-vredonosnogo-koda-v-ruby-paket-strong_password","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:08:56+00:00","article:modified_time":"2019-10-31T19:08:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35980","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 01:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:52:26","updated":"2026-01-22 01:31:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=35980"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35980\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/26895"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=35980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=35980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=35980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}