{"id":78849,"date":"2020-04-22T13:42:05","date_gmt":"2020-04-22T11:42:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki"},"modified":"2020-04-22T13:42:05","modified_gmt":"2020-04-22T11:42:05","slug":"bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","title":{"rendered":"Majoritatea antivirusurilor s-au dovedit a fi vulnerabile la atacuri prin linkuri simbolice","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Cercet\u0103torii de la RACK911 Labs <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rack911labs.com\/research\/exploiting-almost-every-antivirus-software\/\">au observat<\/a><\/noindex> c\u0103 aproape toate pachetele antivirus pentru Windows, Linux \u0219i macOS erau vulnerabile la atacuri care manipuleaz\u0103 condi\u021biile de concuren\u021b\u0103 \u00een timpul \u0219tergerii fi\u0219ierelor \u00een care a fost detectat malware.<\/p>\n<p>Pentru a efectua un atac, este necesar s\u0103 se \u00eencarce un fi\u0219ier pe care antivirusul \u00eel recunoa\u0219te ca fiind malware (de exemplu, se poate folosi o semn\u0103tur\u0103 de test) \u0219i, dup\u0103 un anumit timp, dup\u0103 ce a fost identificat fi\u0219ierul mali\u021bios de c\u0103tre antivirus, dar \u00eenainte de a apela func\u021bia pentru \u0219tergerea acestuia, s\u0103 se \u00eenlocuiasc\u0103 directorul cu fi\u0219ierul printr-un link simbolic. \u00cen Windows, pentru a ob\u021bine acela\u0219i efect, se face o \u00eenlocuire a directorului printr-o jonc\u021biune de director. Problema este c\u0103 aproape toate antivirusurile nu verificau corespunz\u0103tor linkurile simbolice \u0219i, consider\u00e2nd c\u0103 \u0219terg fi\u0219ierul mali\u021bios, \u0219tergeau fi\u0219ierul din directorul la care face referire linkul simbolic. <\/p>\n<p>Pe Linux \u0219i macOS este demonstrat cum un utilizator neprivilegiat poate \u0219terge \/etc\/passwd sau orice alt fi\u0219ier de sistem, iar \u00een Windows o bibliotec\u0103 DDL a antivirusului pentru a-i bloca func\u021bionarea (\u00een Windows atacul este limitat doar la \u0219tergerea fi\u0219ierelor care \u00een acel moment nu sunt folosite de alte aplica\u021bii). De exemplu, atacatorul poate crea un director numit &#171;exploit&#187; \u0219i s\u0103 \u00eencarce \u00een el fi\u0219ierul EpSecApiLib.dll cu o semn\u0103tur\u0103 de virus de test, dup\u0103 care \u00eenainte de \u0219tergere poate schimba directorul &#171;exploit&#187; cu un link &#171;C:&#092;Program Files (x86)&#092;McAfee&#092;Endpoint Security&#092;Endpoint Security Platform&#187;, ceea ce va duce la \u0219tergerea bibliotecii EpSecApiLib.dll din directorul antivirusului. Pe Linux \u0219i macOS, o abordare similar\u0103 poate fi realizat\u0103 prin \u00eenlocuirea directorului cu un link &#171;\\\/etc&#187;.<\/p>\n<p>   #!\/bin\/sh<br \/>\n   rm -rf \/home\/user\/exploit ; mkdir \/home\/user\/exploit\/<br \/>\n   wget -q https:\/\/www.eicar.org\/download\/eicar.com.txt -O \/home\/user\/exploit\/passwd<br \/>\n   while inotifywait -m &#8220;\\\/home\\\/user\\\/exploit\\\/passwd&#8221; | grep -m 5 &#8220;OPEN&#8221;<br \/>\n   do<br \/>\n      rm -rf \/home\/user\/exploit ; ln -s \/etc \/home\/user\/exploit<br \/>\n   gata<\/p>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"iVC_QJLOVt8\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/iVC_QJLOVt8\/hqdefault.jpg\" alt=\"Reda\u021bi video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><br \/>\n<\/center><\/p>\n<p>\u00cen plus, \u00een multe antivirusuri pentru Linux \u0219i macOS s-a descoperit utilizarea numelui de fi\u0219iere previzibile \u00een lucrul cu fi\u0219iere temporare din directoarele \/tmp \u0219i \/private\/tmp, ceea ce ar putea fi folosit pentru a ob\u021bine privilegii la utilizatorul root.  <\/p>\n<p>La aceast\u0103 dat\u0103, problemele au fost deja solu\u021bionate de majoritatea furnizorilor, dar este remarcabil c\u0103 primele notific\u0103ri despre problem\u0103 au fost trimise produc\u0103torilor \u00eenc\u0103 din toamna anului 2018. Chiar dac\u0103 nu to\u021bi produc\u0103torii au lansat actualiz\u0103ri, le-a fost oferit un termen minim de 6 luni pentru remediere, iar RACK911 Labs consider\u0103 c\u0103 acum are dreptul s\u0103 dezv\u0103luie informa\u021bii despre vulnerabilit\u0103\u021bi. Se men\u021bioneaz\u0103 c\u0103 RACK911 Labs lucreaz\u0103 de mult la identificarea vulnerabilit\u0103\u021bilor, dar nu se a\u0219tepta ca colaborarea cu colegii din industria antivirus s\u0103 fie at\u00e2t de dificil\u0103 din cauza \u00eent\u00e2rzierilor \u00een lansarea actualiz\u0103rilor \u0219i a ignor\u0103rii necesit\u0103\u021bii unei remedieri urgente a problemelor de securitate.<\/p>\n<p>Produse afectate de problem\u0103 (pachetul antivirus gratuit ClamAV nu este inclus \u00een list\u0103):<\/p>\n<ul>\n<li class=\"l\"> Linux\n<ul>\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> Eset File Server Security\n<li class=\"l\"> F-Secure Linux Security\n<li class=\"l\"> Kaspersy Endpoint Security\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Sophos Anti-Virus for Linux\n<\/ul>\n<li class=\"l\"> Windows\n<ul>\n<li class=\"l\"> Avast Free Anti-Virus\n<li class=\"l\"> Avira Free Anti-Virus\n<li class=\"l\"> BitDefender GravityZone\n<li class=\"l\"> Comodo Endpoint Security\n<li class=\"l\"> F-Secure Computer Protection\n<li class=\"l\"> FireEye Endpoint Security\n<li class=\"l\"> Intercept X (Sophos)\n<li class=\"l\"> Kaspersky Endpoint Security\n<li class=\"l\"> Malwarebytes for Windows\n<li class=\"l\"> McAfee Endpoint Security\n<li class=\"l\"> Panda Dome\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<li class=\"l\"> macOS\n<ul>\n<li class=\"l\"> AVG\n<li class=\"l\"> BitDefender Total Security\n<li class=\"l\"> Eset Cyber Security\n<li class=\"l\"> Kaspersky Internet Security\n<li class=\"l\"> McAfee Total Protection\n<li class=\"l\"> Microsoft Defender (BETA)\n<li class=\"l\"> Norton Security\n<li class=\"l\"> Sophos Home\n<li class=\"l\"> Webroot Secure Anywhere\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52779\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0434\u043b\u044f Windows, Linux \u0438 macOS \u0431\u044b\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c \u0433\u043e\u043d\u043a\u0438 (race conditions) \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441 \u0440\u0430\u0441\u043f\u043e\u0437\u043d\u0430\u0435\u0442 \u043a\u0430\u043a \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0442\u0435\u0441\u0442\u043e\u0432\u0443\u044e \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0443), \u0430 \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78849","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-22T11:42:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Majoritatea antivirusurilor s-au dovedit a fi vulnerabile la atacuri prin link-uri simbolice | ProHoster","description":"Cercet\u0103torii de la RACK911 Labs au observat c\u0103 aproape toate.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0430\u0442\u0430\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0432\u043e\u043b\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 RACK911 Labs \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0438 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/bolshinstvo-antivirusov-okazalis-podverzheny-atake-cherez-simvolicheskie-ssylki","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-22T11:42:05+00:00","article:modified_time":"2020-04-22T11:42:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78849","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:49:47","updated":"2022-09-27 18:43:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/78849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=78849"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/78849\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=78849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=78849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=78849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}