{"id":37310,"date":"2019-10-31T22:16:54","date_gmt":"2019-10-31T19:16:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\/"},"modified":"2019-10-31T22:16:54","modified_gmt":"2019-10-31T19:16:54","slug":"v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","title":{"rendered":"Nel rest-client e in altri 10 pacchetti Ruby \u00e8 stato rilevato codice dannoso","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel popolare pacchetto gem <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\">rest-client<\/a><\/noindex>, che conta in totale 113 milioni di download, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713\">identificata<\/a><\/noindex> l'inserimento di codice dannoso (CVE-2019-15224), che carica comandi eseguibili e invia informazioni a un host esterno. L'attacco \u00e8 stato realizzato tramite <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713#issuecomment-522735093\">la compromissione<\/a><\/noindex> di un account sviluppatore di rest-client nel repository rubygems.org, dopo di che i malintenzionati hanno pubblicato il 13 e il 14 agosto le versioni 1.6.10-1.6.13, contenenti modifiche dannose. Prima della rimozione delle versioni dannose, circa mille utenti le hanno scaricate (gli attaccanti per non attirare l'attenzione hanno rilasciato aggiornamenti di versioni precedenti).<\/p>\n<p>La modifica dannosa sovrascrive il metodo \u00ab#authenticate\u00bb nella classe<br \/>\nIdentity, dopodich\u00e9 ogni chiamata al metodo porta all'invio dell'email e della password fornita durante il tentativo di autenticazione all'host dei malintenzionati. In questo modo si effettua un intercettazione dei parametri di accesso degli utenti di servizi che utilizzano la classe Identity e hanno installato una versione vulnerabile della libreria rest-client, che <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\/reverse_dependencies\">figurano<\/a><\/noindex> come dipendenza in molti pacchetti Ruby popolari, tra cui ast (64 milioni di download), oauth (32 milioni), fastlane (18 milioni) e kubeclient (3,7 milioni).<\/p>\n<p>Inoltre, nel codice \u00e8 stato aggiunto un backdoor che consente di eseguire codice Ruby arbitrario tramite la funzione eval. Il codice viene trasmesso tramite cookie, firmati con la chiave dell'attaccante. Per informare i malintenzionati dell'installazione del pacchetto dannoso su un host esterno, viene inviatato un URL del sistema della vittima e un insieme di informazioni sull'ambiente, come password salvate per database e servizi cloud. Utilizzando il suddetto codice dannoso, sono state registrate tentativi di caricare script per il mining di criptovalute.<\/p>\n<p>Dopo aver analizzato il codice dannoso, \u00e8 emerso <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/issues\/2097\">identificate<\/a><\/noindex>, che modifiche simili sono presenti in <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/wiki\/Gems-yanked-and-accounts-locked#19-aug-2019\">10 pacchetti<\/a><\/noindex> in Ruby Gems, che non sono stati catturati, ma preparati appositamente dai malintenzionati sulla base di altre librerie popolari con nomi simili, in cui il trattino \u00e8 stato sostituito con un sottolineato o viceversa (ad esempio, sulla base di <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron-parser\">cron-parser<\/a><\/noindex> \u00e8 stato creato il pacchetto dannoso cron_parser, mentre sulla base di <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge_coin\">doge_coin<\/a><\/noindex> \u00e8 stato creato il pacchetto dannoso doge-coin). Pacchetti problematici:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coin_base\">coin_base<\/a><\/noindex>: 4.2.2, 4.2.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/blockchain_wallet\">blockchain_wallet<\/a><\/noindex>: 0.0.6, 0.0.7\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/awesome-bot\">awesome-bot<\/a><\/noindex>: 1.18.0\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge-coin\">doge-coin<\/a><\/noindex>: 1.0.2\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/capistrano-colors\">capistrano-colors<\/a><\/noindex>: 0.5.5\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/bitcoin_vanity\">bitcoin_vanity<\/a><\/noindex>: 4.3.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/lita_coin\">lita_coin<\/a><\/noindex>: 0.0.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coming-soon\">coming-soon<\/a><\/noindex>: 0.2.8\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/omniauth_amazon\">omniauth_amazon<\/a><\/noindex>: 1.0.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron_parser\">cron_parser<\/a><\/noindex>: 1.0.12, 1.0.13, 0.1.4\n<\/ul>\n<p>Il primo pacchetto dannoso di questo elenco \u00e8 stato pubblicato il 12 maggio, ma la maggior parte \u00e8 apparsa a luglio. In totale, i pacchetti indicati sono stati scaricati circa 2500 volte.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 (CVE-2019-15224), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043d\u0430 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u0445\u043e\u0441\u0442. \u0410\u0442\u0430\u043a\u0430 \u0431\u044b\u043b\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u0435\u0434\u0435\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044e \u0443\u0447\u0451\u0442\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 rest-client \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 rubygems.org, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 13 \u0438 14 \u0430\u0432\u0433\u0443\u0441\u0442\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 1.6.10-1.6.13, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f. \u0414\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 \u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37310","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nel rest-client e in altri 10 pacchetti Ruby \u00e8 stato rilevato codice dannoso | ProHoster","description":"Nel popolare pacchetto gem rest-client, che conta in totale 113 milioni di download,","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:54+00:00","article:modified_time":"2019-10-31T19:16:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37310","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:14:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:29:58","updated":"2026-01-23 17:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/37310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=37310"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/37310\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=37310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=37310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=37310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}