{"id":78849,"date":"2020-04-22T13:42:05","date_gmt":"2020-04-22T11:42:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki"},"modified":"2020-04-22T13:42:05","modified_gmt":"2020-04-22T11:42:05","slug":"bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","title":{"rendered":"La maggior parte degli antivirus si \u00e8 rivelata vulnerabile agli attacchi tramite collegamenti simbolici.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>I ricercatori di RACK911 Labs <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rack911labs.com\/research\/exploiting-almost-every-antivirus-software\/\">hanno osservato<\/a><\/noindex> che quasi tutti i pacchetti antivirus per Windows, Linux e macOS erano vulnerabili ad attacchi che manipolano le condizioni di corsa (race conditions) durante l'eliminazione di file contenenti malware.<\/p>\n<p>Per eseguire un attacco, \u00e8 necessario caricare un file che l'antivirus riconosca come dannoso (ad esempio, si pu\u00f2 utilizzare una firma di test), e dopo un certo periodo, dopo che l'antivirus ha identificato il file dannoso, ma immediatamente prima di chiamare la funzione per la sua eliminazione, sostituire la directory con un collegamento simbolico. In Windows, per ottenere lo stesso effetto, si utilizza un collegamento di directory (directory junction). Il problema \u00e8 che quasi tutti gli antivirus non controllavano correttamente i collegamenti simbolici e, credendo di eliminare il file dannoso, eliminavano il file nella directory a cui punta il collegamento simbolico. <\/p>\n<p>In Linux e macOS \u00e8 mostrato come un utente non privilegiato possa eliminare \/etc\/passwd o qualsiasi altro file di sistema, mentre in Windows si pu\u00f2 rimuovere la libreria DDL dell'antivirus stesso per bloccare il suo funzionamento (in Windows l'attacco \u00e8 limitato solo alla cancellazione di file che al momento non sono in uso da altre applicazioni). Ad esempio, un attaccante pu\u00f2 creare una cartella 'exploit' e caricare al suo interno il file EpSecApiLib.dll con una firma virale di test, dopo di che prima di eliminarla pu\u00f2 sostituire la cartella 'exploit' con un link a 'C:\\Program Files (x86)\\McAfee\\Endpoint Security\\Endpoint Security Platform', il che porter\u00e0 alla rimozione della libreria EpSecApiLib.dll dalla cartella dell'antivirus. In Linux e macOS si pu\u00f2 eseguire una manovra simile sostituendo la cartella con un link a '\/etc'.<\/p>\n<p>   #!\/bin\/sh<br \/>\n   rm -rf \/home\/user\/exploit ; mkdir \/home\/user\/exploit\/<br \/>\n   wget -q https:\/\/www.eicar.org\/download\/eicar.com.txt -O \/home\/user\/exploit\/passwd<br \/>\n   while inotifywait -m \"\/home\/user\/exploit\/passwd\" | grep -m 5 \"OPEN\"<br \/>\n   do<br \/>\n      rm -rf \/home\/user\/exploit ; ln -s \/etc \/home\/user\/exploit<br \/>\n   fatto<\/p>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"iVC_QJLOVt8\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/iVC_QJLOVt8\/hqdefault.jpg\" alt=\"Riproduci video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><br \/>\n<\/center><\/p>\n<p>Inoltre, in molti antivirus per Linux e macOS \u00e8 stata rilevata l'uso di nomi di file prevedibili durante la gestione dei file temporanei nelle directory \/tmp e \/private\/tmp, che potrebbero essere utilizzati per elevare i privilegi a utente root.  <\/p>\n<p>Attualmente, i problemi sono stati risolti dalla maggior parte dei fornitori, ma \u00e8 interessante notare che le prime segnalazioni del problema erano state inviate ai produttori nell'autunno del 2018. Anche se non tutti i produttori hanno rilasciato aggiornamenti, avevano a disposizione almeno 6 mesi per correggere, e RACK911 Labs ritiene di poter ora rivelare le informazioni sulle vulnerabilit\u00e0. Va notato che RACK911 Labs lavora da tempo per identificare vulnerabilit\u00e0, ma non si aspettava che sarebbe stato cos\u00ec difficile collaborare con i colleghi dell'industria antivirus a causa dei ritardi nel rilascio delle patch e dell'ignoranza della necessit\u00e0 di risolvere rapidamente i problemi di sicurezza.<\/p>\n<p>I prodotti soggetti al problema (il pacchetto antivirus gratuito ClamAV non \u00e8 incluso nella lista):<\/p>\n<ul>\n<li class=\"l\"> Linux\n<ul>\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> Eset File Server Security\n<li class=\"l\"> F-Secure Linux Security\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Sophos Anti-Virus for Linux\n<\/ul>\n<li class=\"l\"> Windows\n<ul>\n<li class=\"l\"> Avast Free Anti-Virus\n<li class=\"l\"> Avira Free Anti-Virus\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> F-Secure Computer Protection\n<li class=\"l\"> FireEye Endpoint Security\n<li class=\"l\"> Intercept X (Sophos)\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> Malwarebytes for Windows\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Panda Dome\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<li class=\"l\"> macOS\n<ul>\n<li class=\"l\"> AVG\n<li class=\"l\"> BitDefender Total Security\n<li class=\"l\"> Eset Cyber Security\n<li class=\"l\"> Kaspersky Internet Security\n<li class=\"l\"> McAfee Total Protection\n<li class=\"l\"> Microsoft Defender (BETA)\n<li class=\"l\"> Norton Security\n<li class=\"l\"> Sophos Home\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52779\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0434\u043b\u044f Windows, Linux \u0438 macOS \u0431\u044b\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c \u0433\u043e\u043d\u043a\u0438 (race conditions) \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441 \u0440\u0430\u0441\u043f\u043e\u0437\u043d\u0430\u0435\u0442 \u043a\u0430\u043a \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0442\u0435\u0441\u0442\u043e\u0432\u0443\u044e \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0443), \u0430 \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78849","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47La maggior parte degli antivirus si sono rivelati vulnerabili agli attacchi tramite collegamenti simbolici | ProHoster","description":"I ricercatori della RACK911 Labs hanno notato che quasi tutti.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-22T11:42:05+00:00","article:modified_time":"2020-04-22T11:42:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78849","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:49:47","updated":"2022-09-27 18:43:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/78849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=78849"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/78849\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=78849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=78849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=78849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}