{"id":112136,"date":"2023-12-11T15:10:27","date_gmt":"2023-12-11T13:10:27","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere"},"modified":"2023-12-11T15:10:27","modified_gmt":"2023-12-11T13:10:27","slug":"uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een Buildroot care permit executarea de cod pe serverul de build printr-un atac MITM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen sistemul de construire Buildroot, destinat realiz\u0103rii mediilor Linux bootabile pentru sisteme \u00eencorporate, au fost identificate \u0219ase vulnerabilit\u0103\u021bi care permit, \u00een contextul intercept\u0103rii traficului de tip MITM, modificarea imaginilor de sistem generate sau executarea de cod la nivelul sistemului de construire. Vulnerabilit\u0103\u021bile au fost remediate \u00een versiunile Buildroot 2023.02.8, 2023.08.4 \u0219i 2023.11.      <\/p>\n<p>Primele cinci vulnerabilit\u0103\u021bi (CVE-2023-45841, CVE-2023-45842, CVE-2023-45838, CVE-2023-45839, CVE-2023-45840) afecteaz\u0103 codul de verificare a integrit\u0103\u021bii pachetelor pe baza hash-urilor. Problemele se reduc la posibilitatea utiliz\u0103rii HTTP pentru desc\u0103rcarea fi\u0219ierelor \u0219i lipsa fi\u0219ierelor hash de verificare pentru unele pachete, ceea ce permite substituirea con\u021binutului acestor pachete, av\u00e2nd oportunitatea de a interveni \u00een traficul de construire. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3734\">server<\/a> (de exemplu, \u00een cazul \u00een care utilizatorul se conecteaz\u0103 printr-o re\u021bea wireless controlat\u0103 de atacator).     <\/p>\n<p>\u00cen special, pachetele aufs \u0219i aufs-util erau desc\u0103rcate prin HTTP \u0219i nu erau verificate prin hash-uri. De asemenea, hash-urile lipseau pentru pachetele riscv64-elf-toolchain, versal-firmware \u0219i mxsldr, care, \u00een mod implicit, erau desc\u0103rcate prin HTTPS, dar \u00een caz de probleme se revenea la desc\u0103rcarea f\u0103r\u0103 criptare de pe hostul http:\/\/sources.buildroot.net. \u00cen absen\u021ba fi\u0219ierelor '.hash', instrumentul Buildroot considera verifica\u021bia reu\u0219it\u0103 \u0219i procesa pachetele desc\u0103rcate, inclusiv aplica patch-urile incluse \u00een pachete \u0219i rula scenariile de compilare. Av\u00e2nd posibilitatea de a modifica pachetele desc\u0103rcate, un atacator putea ad\u0103uga \u00een ele propriile patch-uri sau fi\u0219iere de compilare Makefiles, ceea ce permitea schimbarea imaginii rezultate sau a scripturilor sistemului de compilare \u0219i execu\u021bia propriului cod.      <\/p>\n<p>A \u0219asea vulnerabilitate (CVE-2023-43608) este cauzat\u0103 de o eroare \u00een implementarea func\u021bionalit\u0103\u021bii BR_NO_CHECK_HASH_FOR, care permite dezactivarea verific\u0103rii integrit\u0103\u021bii prin hash-uri pentru pachetele selectate. Anumite pachete, cum ar fi kernelul Linux, U-Boot \u0219i versal-firmware, permiteau desc\u0103rcarea celor mai recente versiuni pentru care nu erau \u00eenc\u0103 formate hash-uri de verificare. Pentru aceste versiuni se aplica op\u021biunea BR_NO_CHECK_HASH_FOR, care dezactiva verificarea prin hash. Datele erau desc\u0103rcate prin HTTPS, dar \u00een mod implicit, \u00een caz de e\u0219ec al desc\u0103rc\u0103rii, se revenea la apelarea source.buildroot.net f\u0103r\u0103 criptare prin protocolul http:\/\/. Atacatorul, \u00een timpul unui atac MITM, putea bloca conexiunea la serverul HTTPS, iar astfel desc\u0103rcarea revenea la http:\/\/sources.buildroot.net.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60270\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 Buildroot, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0445 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 \u0434\u043b\u044f \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432 \u0445\u043e\u0434\u0435 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0432 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0435 \u043e\u0431\u0440\u0430\u0437\u044b \u0438\u043b\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u0441\u0431\u043e\u0440\u043e\u0447\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 Buildroot 2023.02.8, 2023.08.4 \u0438 2023.11. \u041f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45841, CVE-2023-45842, CVE-2023-45838, CVE-2023-45839, CVE-2023-45840) \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112136","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 Buildroot, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0445 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 \u0434\u043b\u044f \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432 \u0445\u043e\u0434\u0435 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Buildroot, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0447\u0435\u0440\u0435\u0437 MITM-\u0430\u0442\u0430\u043a\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0431\u043e\u0440\u043e\u0447\u043d\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 Buildroot, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0445 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 \u0434\u043b\u044f \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432 \u0445\u043e\u0434\u0435 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-12-11T13:10:27+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-12-11T13:10:27+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u0103\u021bile din Buildroot care permit executarea de cod pe serverul de build printr-o atac MITM | ProHoster","description":"\u00cen sistemul de build Buildroot, destinat cre\u0103rii de medii Linux bootabile pentru sisteme \u00eencorporate, au fost identificate \u0219ase vulnerabilit\u0103\u021bi care permit, \u00een timpul intercept\u0103rii traficului \u00een tranzit (MITM), efectuarea de modific\u0103ri.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Buildroot, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0447\u0435\u0440\u0435\u0437 MITM-\u0430\u0442\u0430\u043a\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0431\u043e\u0440\u043e\u0447\u043d\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster","og:description":"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 Buildroot, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0445 Linux-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 \u0434\u043b\u044f \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432 \u0445\u043e\u0434\u0435 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u043d\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-buildroot-pozvolyayushhie-cherez-mitm-ataku-vypolnit-kod-na-sborochnom-servere","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-12-11T13:10:27+00:00","article:modified_time":"2023-12-11T13:10:27+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"112136","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-22 15:30:24","updated":"2026-02-22 15:30:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/112136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=112136"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/112136\/revisions"}],"predecessor-version":[{"id":162262,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/112136\/revisions\/162262"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=112136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=112136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=112136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}