{"id":101307,"date":"2021-09-17T10:22:35","date_gmt":"2021-09-17T08:22:35","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure"},"modified":"2021-09-17T10:22:35","modified_gmt":"2021-09-17T08:22:35","slug":"udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","title":{"rendered":"Vulnerabilitate exploatat\u0103 la distan\u021b\u0103 \u00een agentul OMI, impus \u00een mediile Linux Microsoft Azure","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Clien\u021bii platformei cloud Microsoft Azure care utilizeaz\u0103 Linux \u00een ma\u0219inile virtuale s-au confruntat cu o vulnerabilitate critic\u0103 (CVE-2021-38647) care permite execu\u021bia de cod de la distan\u021b\u0103 cu privilegii de root. Vulnerabilitatea este cunoscut\u0103 sub numele de OMIGOD \u0219i este notabil\u0103 deoarece problema este prezent\u0103 \u00een aplica\u021bia OMI Agent, care este instalat\u0103 discret \u00een medii Linux.    <\/p>\n<p>OMI Agent este instalat \u0219i activat automat la utilizarea unor servicii precum Azure Automation, Azure Automatic Update, Azure Operations Management Suite, Azure Log Analytics, Azure Configuration Management, Azure Diagnostics \u0219i Azure Container Insights. De exemplu, sunt expuse atacurilor mediile Linux din Azure pentru care este activat monitorizarea. Agentul face parte din pachetul deschis OMI (Open Management Infrastructure Agent) cu implementarea stivei DMTF CIM\/WBEM pentru gestionarea infrastructurii IT.      <\/p>\n<p>OMI Agent este instalat \u00een sistem sub utilizatorul omsagent \u0219i creeaz\u0103 set\u0103ri \u00een \/etc\/sudoers pentru a rula o serie de scripturi cu privilegii de root. \u00cen procesul de func\u021bionare a unora dintre servicii, sunt create socket-uri de re\u021bea ascult\u0103toare pe porturile de re\u021bea 5985, 5986 \u0219i 1270. Scanarea \u00een serviciul Shodan arat\u0103 c\u0103 \u00een re\u021bea exist\u0103 peste 15.000 de medii Linux vulnerabile. \u00cen prezent, un prototip func\u021bional al exploit-ului este deja disponibil public, permi\u021b\u00e2nd executarea de cod cu privilegii de root pe astfel de sisteme.     <\/p>\n<p>Problema este agravat\u0103 de faptul c\u0103 \u00een Azure aplicarea OMI nu este documentat\u0103, iar OMI Agent este instalat f\u0103r\u0103 avertisment \u2014 este suficient s\u0103 accepta\u021bi termenii serviciului ales la configurarea mediului, iar OMI Agent va fi activat automat, adic\u0103 majoritatea utilizatorilor nici nu b\u0103nuiesc de existen\u021ba sa.      <\/p>\n<p>Metoda de exploatare este trivial\u0103 \u2014 este suficient s\u0103 trimite\u021bi o solicitare XML c\u0103tre agent, elimin\u00e2nd antetul responsabil de autentificare. OMI folose\u0219te autentificarea atunci c\u00e2nd prime\u0219te mesaje de control, verific\u00e2nd c\u0103 clientul are dreptul de a trimite anumite comenzi. Esen\u021ba vulnerabilit\u0103\u021bii const\u0103 \u00een faptul c\u0103, prin eliminarea antetului \u201eAuthentication\u201d responsabil de autentificare din mesaj, <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/\"   title=\"serverul\" data-wpil-keyword-link=\"linked\">serverul<\/a> consider\u0103 c\u0103 verificarea este reu\u0219it\u0103, accept\u0103 mesajul de control \u0219i permite executarea comenzilor cu privilegii de root. Pentru a executa comenzi arbitrare \u00een sistem, este suficient s\u0103 folosi\u021bi \u00een mesaj comanda standard ExecuteShellCommand_INPUT. De exemplu, pentru a rula utilitarul \u201eid\u201d este suficient s\u0103 trimite\u021bi cererea:       curl -H \"Content-Type: application\/soap+xml;charset=UTF-8\" -k --data-binary \"@http_body.txt\" https:\/\/10.0.0.5:5986\/wsman       <s>        \u2026        <s>           <p>              <p>id<\/p>              <p>0<\/p>           <\/p>        <\/s>     <\/s>               <\/p>\n<p>Compania Microsoft a lansat deja actualizarea OMI 1.6.8.1 cu corectarea vulnerabilit\u0103\u021bii, dar aceasta nu a fost \u00eenc\u0103 distribuit\u0103 utilizatorilor Microsoft Azure (\u00een medii noi este \u00eenc\u0103 instalat\u0103 vechea versiune OMI). Actualizarea automat\u0103 a agentului nu este suportat\u0103, a\u0219a c\u0103 utilizatorii trebuie s\u0103 efectueze actualizarea pachetului manual, folosind comenzile \u201edpkg -l omi\u201d \u00een Debian\/Ubuntu sau \u201erpm -qa omi\u201d \u00een Fedora\/RHEL. Ca solu\u021bie alternativ\u0103 de protec\u021bie, se recomand\u0103 blocarea accesului la porturile de re\u021bea 5985, 5986 \u0219i 1270.        <\/p>\n<p>Pe l\u00e2ng\u0103 CVE-2021-38647, OMI 1.6.8.1 a remediat \u0219i alte trei vulnerabilit\u0103\u021bi (CVE-2021-38648, CVE-2021-38645 \u0219i CVE-2021-38649), care permit unui utilizator local f\u0103r\u0103 privilegii s\u0103 \u00ee\u0219i execute codul cu drepturi de root.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55813\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f OMIGOD \u0438 \u043f\u0440\u0438\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0430 \u0442\u0435\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0438 OMI Agent, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0431\u0435\u0437 \u043b\u0438\u0448\u043d\u0435\u0439 \u043e\u0433\u043b\u0430\u0441\u043a\u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f. OMI Agent \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0438 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0442\u0430\u043a\u0438\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432, \u043a\u0430\u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-101307","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OMI-\u0430\u0433\u0435\u043d\u0442\u0435, \u043d\u0430\u0432\u044f\u0437\u044b\u0432\u0430\u0435\u043c\u043e\u043c \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 Microsoft Azure | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-17T08:22:35+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-09-17T08:22:35+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate exploatabil\u0103 de la distan\u021b\u0103 \u00een agentul OMI, impus \u00een medii Linux pe Microsoft Azure | ProHoster","description":"Clien\u021bii platformei cloud Microsoft Azure care folosesc Linux \u00een ma\u0219ini virtuale s-au confruntat cu o vulnerabilitate critic\u0103 (CVE-2021-38647) care permite executarea de cod de la distan\u021b\u0103 cu drepturi de root.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OMI-\u0430\u0433\u0435\u043d\u0442\u0435, \u043d\u0430\u0432\u044f\u0437\u044b\u0432\u0430\u0435\u043c\u043e\u043c \u0432 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 Microsoft Azure | ProHoster","og:description":"\u041a\u043b\u0438\u0435\u043d\u0442\u044b \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Microsoft Azure, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 Linux \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445, \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e (CVE-2021-38647), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-omi-agente-navyazyvaemom-v-linux-okruzheniyah-microsoft-azure","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-09-17T08:22:35+00:00","article:modified_time":"2021-09-17T08:22:35+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"101307","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-09-17 08:49:36","updated":"2022-10-07 00:05:27","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/101307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=101307"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/101307\/revisions"}],"predecessor-version":[{"id":172940,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/101307\/revisions\/172940"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=101307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=101307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=101307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}