{"id":35281,"date":"2019-10-31T22:03:25","date_gmt":"2019-10-31T19:03:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\/"},"modified":"2019-10-31T22:03:25","modified_gmt":"2019-10-31T19:03:25","slug":"massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","title":{"rendered":"Sulm masiv n\u00eb server\u00ebt e post\u00ebs elektronike t\u00eb cenuesh\u00ebm t\u00eb bazuar n\u00eb Exim","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p> K\u00ebrkuesit e siguris\u00eb nga kompania Cybereason <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability\">paralajm\u00ebruan<\/a><\/noindex> administratoret e server\u00ebve t\u00eb post\u00ebs p\u00ebr identifikimin e nj\u00eb sulmi masiv t\u00eb automatizuar q\u00eb shfryt\u00ebzon <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">nj\u00eb dob\u00ebsi kritike<\/a><\/noindex> (CVE-2019-10149) n\u00eb Exim, e zbuluar jav\u00ebn e kaluar. Gjat\u00eb sulmit, sulmuesit arrit\u00ebn t\u00eb ekzekutonin kodin e tyre me t\u00eb drejta root dhe t\u00eb instalonin software t\u00eb d\u00ebmsh\u00ebm p\u00ebr miniera kriptomonedhash n\u00eb server.<\/p>\n<p>Sipas raportit t\u00eb qershorit <noindex><a rel=\"nofollow\" href=\"http:\/\/www.securityspace.com\/s_survey\/data\/man.201905\/mxsurvey.html\">anket\u00ebn e automatizuar<\/a><\/noindex> pjesa e Exim p\u00ebrb\u00ebn 57.05% (nj\u00eb vit m\u00eb par\u00eb 56.56%), Postfix p\u00ebrdoret n\u00eb 34.52% (33.79%) t\u00eb server\u00ebve t\u00eb post\u00ebs, Sendmail \u2014 4.05% (4.59%), Microsoft Exchange \u2014 0.57% (0.85%). Sipas <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/report\/uSLHrfCA\">t\u00eb dh\u00ebnave<\/a><\/noindex> sh\u00ebrbimit Shodan, mbeten potencialisht t\u00eb cenuesh\u00ebm m\u00eb shum\u00eb se 3.6 milion server\u00eb t\u00eb post\u00ebs n\u00eb rrjetin global, t\u00eb cil\u00ebt nuk jan\u00eb azhurnuar n\u00eb versionin m\u00eb t\u00eb fundit t\u00eb Exim 4.92. Rreth 2 milion server\u00eb potencialisht t\u00eb cenuesh\u00ebm jan\u00eb vendosur n\u00eb SHBA, 192 mij\u00eb n\u00eb Rusi. Sipas <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D89Gf0KUcAAJY44.jpg\">informacioni<\/a><\/noindex> kompanis\u00eb RiskIQ, 70% e server\u00ebve me Exim kan\u00eb kaluar n\u00eb versionin 4.92.<\/p>\n<p><center><img decoding=\"async\" alt=\"Sulm masiv n\u00eb server\u00ebt e post\u00ebs elektronike t\u00eb cenuesh\u00ebm t\u00eb bazuar n\u00eb Exim\" src=\"\/wp-content\/uploads\/2019\/06\/f179c76afaa02fedfe6c542f99dbcb9c.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Administratoret k\u00ebshillohen urgjentisht t\u00eb instalojn\u00eb p\u00ebrdit\u00ebsimet, t\u00eb cilat ishin p\u00ebrgatitur jav\u00ebn e kaluar nga distribuimet (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">Debian<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-10149.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-10149\">openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/community\/x86_64\/exim\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-7b741dcaa4\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">EPEL p\u00ebr RHEL\/CentOS<\/a><\/noindex>). N\u00eb rast se n\u00eb sistem ndodhet nj\u00eb dob\u00ebsi e prekshme e versionit Exim (nga 4.87 deri n\u00eb 4.91 p\u00ebrfshir\u00eb), duhet t\u00eb siguroheni q\u00eb sistemi nuk \u00ebsht\u00eb komprometuar, duke kontrolluar crontab p\u00ebr thirrje t\u00eb dyshimta dhe t\u00eb siguroheni p\u00ebr munges\u00ebn e \u00e7el\u00ebsave shtes\u00eb n\u00eb katalogun \/root\/.ssh. Nj\u00eb tregues tjet\u00ebr p\u00ebr sulmin mund t\u00eb jet\u00eb prezenca n\u00eb logun e firewall-it e aktiviteteve nga hostet an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io dhe an7kmd2wp4xo7hpr.onion.sh, t\u00eb cilat p\u00ebrdoren p\u00ebr ngarkimin e software t\u00eb d\u00ebmsh\u00ebm. <\/p>\n<p>P\u00ebrpjekjet e para t\u00eb sulmit ndaj server\u00ebve Exim <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/freddieleeman\/status\/1137729455181500421\">jan\u00eb regjistruar<\/a><\/noindex> ishin m\u00eb 9 qershor. Deri m\u00eb 13 qershor, sulmi <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/0xAmit\/status\/1139165487093420035\">mori<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/forums.zimbra.org\/viewtopic.php?t=65932&#038;start=140\">karakter masiv.<\/a><\/noindex> Pas shfryt\u00ebzimit t\u00eb dob\u00ebsis\u00eb p\u00ebrmes porteve tor2web nga sh\u00ebrbimi i fshehur Tor (an7kmd2wp4xo7hpr) ngarkohet nj\u00eb skenar q\u00eb kontrollon pranin\u00eb e OpenSSH (n\u00ebse nuk ka <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gM2mWsAAhwD4.jpg\">instalon<\/a><\/noindex>), ndryshon konfigurimin e tij (<noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gZ0sX4AAeHgm.jpg\">lejon<\/a><\/noindex> hyn\u00eb me root dhe autentikimin p\u00ebrmes \u00e7el\u00ebsave) dhe instalon p\u00ebr p\u00ebrdoruesin root <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/aserper\/e36d382668c6cf2c996c5143025097c0#file-gistfile1-txt\">\u00e7el\u00ebsin RSA<\/a><\/noindex>, i cili ofron qasje privilegjuar n\u00eb sistem p\u00ebrmes SSH.<\/p>\n<p>Pas instalimit t\u00eb backdoor-it n\u00eb sistem, vendoset nj\u00eb skaner portesh p\u00ebr t\u00eb identifikuar server\u00eb t\u00eb tjer\u00eb vulnerab\u00ebl. Gjithashtu, b\u00ebhet k\u00ebrkim n\u00eb sistem p\u00ebr minat ekzistuese, t\u00eb cilat hiqen n\u00eb rast se identifikohen. N\u00eb faz\u00ebn e fundit, ngarkohet dhe regjistrohet n\u00eb crontab nj\u00eb miner t\u00eb vetin. Miner\u2019i ngarkohet si nj\u00eb file ico (n\u00eb t\u00eb v\u00ebrtet\u00eb \u00ebsht\u00eb nj\u00eb arkiv zip me fjal\u00ebkalimin 'no-password'), n\u00eb t\u00eb cilin \u00ebsht\u00eb i paketuar nj\u00eb skedar ekzekutiv n\u00eb formatin ELF p\u00ebr Linux me Glibc 2.7+.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50870\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0445 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043c\u0430\u0441\u0441\u043e\u0432\u043e\u0439 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-10149) \u0432 Exim, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u043d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u043d\u0435\u0434\u0435\u043b\u0435. \u0412 \u0445\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0434\u043e\u0431\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0434\u043b\u044f \u043c\u0430\u0439\u043d\u0438\u043d\u0433\u0430 \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442. \u0412 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u0438\u044e\u043d\u044c\u0441\u043a\u0438\u043c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043e\u043f\u0440\u043e\u0441\u043e\u043c \u0434\u043e\u043b\u044f Exim \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 57.05% (\u0433\u043e\u0434 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sulmi masiv ndaj server\u00ebve t\u00eb post\u00ebs s\u00eb ndjesh\u00ebm t\u00eb bazuar n\u00eb Exim | ProHoster","description":"K\u00ebrkuesit e siguris\u00eb nga kompania Cybereason paralajm\u00ebruan.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:03:25+00:00","article:modified_time":"2019-10-31T19:03:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35281","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 22:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:06:25","updated":"2026-01-21 22:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/35281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=35281"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/35281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/26492"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=35281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=35281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=35281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}