{"id":125450,"date":"2022-05-03T17:50:14","date_gmt":"2022-05-03T19:50:14","guid":{"rendered":"https:\/\/teknomers.com\/fr\/github-declare-quune-recente-attaque-impliquant-des-jetons-oauth-voles-etait-tres-cible\/"},"modified":"2022-05-03T17:50:23","modified_gmt":"2022-05-03T19:50:23","slug":"github-declare-quune-recente-attaque-impliquant-des-jetons-oauth-voles-etait-tres-cible","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/github-declare-quune-recente-attaque-impliquant-des-jetons-oauth-voles-etait-tres-cible\/","title":{"rendered":"GitHub d\u00e9clare qu&#8217;une r\u00e9cente attaque impliquant des jetons OAuth vol\u00e9s \u00e9tait &quot;Tr\u00e8s cibl\u00e9&quot;"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La plate-forme d&#8217;h\u00e9bergement de code bas\u00e9e sur le cloud GitHub a d\u00e9crit la r\u00e9cente campagne d&#8217;attaque impliquant l&#8217;abus de jetons d&#8217;acc\u00e8s OAuth d\u00e9livr\u00e9s \u00e0 Heroku et Travis-CI comme \u00e9tant de nature &#8220;hautement cibl\u00e9e&#8221;.<\/p>\n<p>&#8220;Ce mod\u00e8le de comportement sugg\u00e8re que l&#8217;attaquant r\u00e9pertoriait uniquement les organisations afin d&#8217;identifier les comptes \u00e0 cibler de mani\u00e8re s\u00e9lective pour r\u00e9pertorier et t\u00e9l\u00e9charger des r\u00e9f\u00e9rentiels priv\u00e9s&#8221;, a d\u00e9clar\u00e9 Mike Hanley de GitHub. <a rel=\"nofollow noopener\" href=\"https:\/\/github.blog\/2022-04-15-security-alert-stolen-oauth-user-tokens\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un article mis \u00e0 jour.<\/p>\n<p>L&#8217;incident de s\u00e9curit\u00e9, d\u00e9couvert le 12 avril, concernait un attaquant non identifi\u00e9 utilisant des jetons d&#8217;utilisateur OAuth vol\u00e9s d\u00e9livr\u00e9s \u00e0 deux int\u00e9grateurs OAuth tiers, Heroku et Travis-CI, pour t\u00e9l\u00e9charger des donn\u00e9es de dizaines d&#8217;organisations, dont NPM.<\/p>\n<p>La soci\u00e9t\u00e9 appartenant \u00e0 Microsoft a d\u00e9clar\u00e9 la semaine derni\u00e8re qu&#8217;elle \u00e9tait en train d&#8217;envoyer un dernier ensemble de notifications aux clients GitHub qui avaient les int\u00e9grations d&#8217;applications Heroku ou Travis CI OAuth autoris\u00e9es dans leurs comptes.<\/p>\n<p>Selon une analyse d\u00e9taill\u00e9e \u00e9tape par \u00e9tape effectu\u00e9e par GitHub, l&#8217;adversaire aurait utilis\u00e9 les jetons d&#8217;application vol\u00e9s pour s&#8217;authentifier aupr\u00e8s de l&#8217;API GitHub, en l&#8217;utilisant pour r\u00e9pertorier tous les <a rel=\"nofollow noopener\" href=\"https:\/\/docs.github.com\/en\/organizations\" target=\"_blank\">organisations d&#8217;utilisateurs concern\u00e9s<\/a>.<\/p>\n<p>Cela a ensuite \u00e9t\u00e9 r\u00e9ussi en choisissant s\u00e9lectivement des cibles en fonction des organisations r\u00e9pertori\u00e9es, en les suivant en r\u00e9pertoriant les r\u00e9f\u00e9rentiels priv\u00e9s de comptes d&#8217;utilisateurs pr\u00e9cieux, avant de finalement passer au clonage de certains de ces r\u00e9f\u00e9rentiels priv\u00e9s.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La soci\u00e9t\u00e9 a \u00e9galement r\u00e9it\u00e9r\u00e9 que les jetons n&#8217;ont pas \u00e9t\u00e9 obtenus via une compromission de GitHub ou de ses syst\u00e8mes, et que les jetons ne sont pas stock\u00e9s dans leurs &#8220;formats originaux et utilisables&#8221;, qui pourraient \u00eatre utilis\u00e9s \u00e0 mauvais escient par un attaquant.<\/p>\n<p>&#8220;Les clients doivent \u00e9galement continuer \u00e0 surveiller <a rel=\"nofollow noopener\" href=\"https:\/\/status.heroku.com\/incidents\/2413\" target=\"_blank\">H\u00e9roku<\/a> et <a rel=\"nofollow noopener\" href=\"https:\/\/blog.travis-ci.com\/2022-04-17-securitybulletin\" target=\"_blank\">Travis CI<\/a> pour obtenir des mises \u00e0 jour sur leurs propres enqu\u00eates sur les applications OAuth concern\u00e9es \u00bb, a not\u00e9 GitHub.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/05\/github-says-recent-attack-involving.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La plate-forme d&#8217;h\u00e9bergement de code bas\u00e9e sur le cloud GitHub a d\u00e9crit la r\u00e9cente campagne d&#8217;attaque impliquant l&#8217;abus de jetons d&#8217;acc\u00e8s OAuth d\u00e9livr\u00e9s \u00e0 Heroku et Travis-CI comme \u00e9tant de nature &#8220;hautement cibl\u00e9e&#8221;. &#8220;Ce mod\u00e8le de comportement sugg\u00e8re que l&#8217;attaquant r\u00e9pertoriait uniquement les organisations afin d&#8217;identifier les comptes \u00e0 cibler de mani\u00e8re s\u00e9lective pour r\u00e9pertorier [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":125451,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1933,59835,4168,4158,4165,4161,250,133,1296,50438,7556,50440,4157,4159,4171,4170,4167,4160,4163,4162,50441,11763,1294,27730,4172,4169,4166,16715,4164],"class_list":["post-125450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-attaque","tag-ciblequot","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-declare","tag-des","tag-etait","tag-github","tag-impliquant","tag-jetons","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-oauth","tag-quottres","tag-quune","tag-recente","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-voles","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/125450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=125450"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/125450\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/125451"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=125450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=125450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=125450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}