W lutym austriacki Christian Haschek opublikował na swoim blogu interesujący artykuł zatytułowany . Oczywiście byłem ciekaw, co się stanie, jeśli powtórzę to badanie, ale z Ukrainą. Kilka tygodni intensywnego zbierania informacji, jeszcze kilka dni na opracowanie artykułu, a w trakcie tego badania rozmowy z różnymi przedstawicielami naszego społeczeństwa, aby wyjaśnić pewne wątpliwości lub dowiedzieć się więcej. Proszę o przeczytanie poniżej…
TL;DR
Do zbierania informacji nie używano żadnych specjalnych narzędzi (choć kilka osób sugerowało użycie OpenVAS, aby badanie było bardziej kompleksowe i informacyjne). Moim zdaniem sytuacja z bezpieczeństwem IP związanych z Ukrainą (o tym, jak je określano, piszę poniżej) wygląda dość źle (i na pewno gorzej niż w Austrii). Żadne próby wykorzystania wykrytych podatnych serwerów nie zostały przeprowadzone ani nie są planowane.
Przede wszystkim: jak można uzyskać wszystkie adresy IP, które należą do danego kraju?
To w rzeczywistości bardzo proste. Adresy IP nie są generowane przez sam kraj, ale przydzielane mu. Dlatego istnieje lista (i jest ona publiczna) wszystkich krajów i wszystkich adresów IP, które do nich należą.
Każdy może , a następnie przefiltrować ją grep Ukraine IP2LOCATION-LITE-DB1.CSV> ukraine.csv
, pozwala przekształcić listę w bardziej użyteczną formę.
Ukraina ma prawie tyle samo adresów IPv4, co Austria, ponad 11 mln. 11 640 409, jeśli być dokładnym (dla porównania w Austrii — 11 170 487).
Jeśli nie chcesz bawić się w adresy IP samodzielnie (i nie ma sensu tego robić!), możesz skorzystać z usługi .
Czy w Ukrainie są niepoprawnie zabezpieczone maszyny z systemem Windows mające bezpośredni dostęp do Internetu?
Oczywiście żaden świadomy Ukrainiec nie otworzyłby takiego dostępu dla swoich komputerów. A może jednak?
masscan -p445 --rate 300 -iL ukraine.ips -oG ukraine.445.scan && cat ukraine.445.scan | wc -lZnaleziono 5669 maszyn z systemem Windows z bezpośrednim dostępem do sieci (w Austrii było tylko 1273, ale to również dużo).
Ups. Are there any among them that could be attacked using ETHERNALBLUE exploits, known since 2017? There weren't any such machines in Austria, and I was hoping none would be found in Ukraine either. Unfortunately, that's pointless. 198 IP addresses were found that haven't closed this "hole" on their end.
DNS, DDoS, and the rabbit hole depth
Enough about Windows. Let's see what we have with the DNS servers that are open resolvers and can be used for DDoS attacks.
It works something like this. The attacker sends a small DNS request, and the vulnerable server responds to the victim with a packet that is 100 times larger. Boom! Corporate networks can crash fairly quickly from such data volume, and modern smartphones can provide the necessary bandwidth for the attack. And such attacks have been even on GitHub.
Let's see if there are such servers in Ukraine.
masscan -pU 53 -iL ukraine.ips -oG ukraine.53.scan && cat ukraine.53.scan | wc -lThe first step is to find those that have an open port 53. We end up with a list of 58,730 IP addresses, but that doesn't mean they can all be used for DDoS attacks. The second requirement is that they need to be open resolvers.
For this, we can use a simple dig command to see what we can "dig up": dig +short test.openresolver.com TXT @ip.of.dns.server. If the server responded open-resolver-detected, then it can be considered a potential attack target. Open resolvers make up about 25%, which is comparable to Austria. In terms of total numbers, that’s about 0.02% of all Ukrainian IPs.
What else can be found in Ukraine?
Glad you asked. It’s easier (and personally most interesting for me) to look for IPs with an open port 80 and see what’s "running" on it.
web servers
260,849 Ukrainian IPs respond on port 80 (http). 125,444 addresses responded positively (200 status) to a simple GET request that your browser can make. The rest returned various errors. Interestingly, 853 servers returned a 500 status, and the rarest statuses were 407 (proxy authorization request) and an absolutely non-standard 602 (IP not in the "whitelist") with one response.
Apache absolutely dominates — 114,544 servers use it. The oldest version I found in Ukraine is 1.3.29, released on October 29, 2003 (!!!). Nginx is in second place with 61,659 servers.
11 serwerów używa WinCE, która wyszła w 1996 roku, a ostatnie poprawki wprowadzono w 2013 roku (w Austrii takich jest tylko 4).
Protokół HTTP/2 wykorzystuje 5 144 serwery, HTTP/1.1 — 256 836, HTTP/1 — 13 491.
Drukarki… bo… czemu nie?
2 HP, 5 Epson i 4 Canon, które są dostępne w sieci, niektóre z nich bez żadnej autoryzacji.

kamery internetowe
To nie nowość, że na Ukrainie jest BARDZO dużo kamer internetowych, które transmitują na żywo, zebranych z różnych źródeł. Co najmniej 75 kamer transmituje w internecie bez żadnej ochrony. Można je obejrzeć .

Co dalej?
Ukraina to mały kraj, podobnie jak Austria, ale ma te same problemy w dziedzinie IT, co duże kraje. Musimy wypracować lepsze zrozumienie tego, co jest bezpieczne, a co niebezpieczne, a także producenci sprzętu powinni dostarczać bezpieczną konfigurację wstępną swojego sprzętu.
Ponadto zbieram firmy partnerskie (), które mogą pomóc zapewnić bezpieczeństwo Twojej infrastruktury IT. Następnym krokiem planuję przegląd bezpieczeństwa ukraińskich stron internetowych. Nie przełączaj się!
Źródło: habr.com
