{"id":57935,"date":"2022-03-28T05:15:03","date_gmt":"2022-03-28T07:15:03","guid":{"rendered":"https:\/\/teknomers.com\/fr\/muhstik-botnet-ciblant-les-serveurs-redis-a-laide-dune-vulnerabilite-recemment-divulguee\/"},"modified":"2022-03-28T05:15:27","modified_gmt":"2022-03-28T07:15:27","slug":"muhstik-botnet-ciblant-les-serveurs-redis-a-laide-dune-vulnerabilite-recemment-divulguee","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/muhstik-botnet-ciblant-les-serveurs-redis-a-laide-dune-vulnerabilite-recemment-divulguee\/","title":{"rendered":"Muhstik Botnet ciblant les serveurs Redis \u00e0 l&#8217;aide d&#8217;une vuln\u00e9rabilit\u00e9 r\u00e9cemment divulgu\u00e9e"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Muhstik, un botnet tristement c\u00e9l\u00e8bre pour se propager via des exploits d&#8217;applications Web, a \u00e9t\u00e9 observ\u00e9 ciblant des serveurs Redis en utilisant une vuln\u00e9rabilit\u00e9 r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans le syst\u00e8me de base de donn\u00e9es.<\/p>\n<p>La vuln\u00e9rabilit\u00e9 concerne <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-0543\" target=\"_blank\">CVE-2022-0543<\/a>une <a rel=\"nofollow noopener\" href=\"https:\/\/www.ubercomp.com\/posts\/2022-01-20_redis_on_debian_rce\" target=\"_blank\">Faille d&#8217;\u00e9chappement du bac \u00e0 sable Lua<\/a> dans le magasin de donn\u00e9es open source, en m\u00e9moire et cl\u00e9-valeur qui pourrait \u00eatre utilis\u00e9 de mani\u00e8re abusive pour r\u00e9aliser l&#8217;ex\u00e9cution de code \u00e0 distance sur la machine sous-jacente.  La vuln\u00e9rabilit\u00e9 est not\u00e9e 10 sur 10 pour la gravit\u00e9.<\/p>\n<p>&#8220;En raison d&#8217;un probl\u00e8me d&#8217;empaquetage, un attaquant distant ayant la capacit\u00e9 d&#8217;ex\u00e9cuter des scripts Lua arbitraires pourrait \u00e9ventuellement \u00e9chapper au bac \u00e0 sable Lua et ex\u00e9cuter du code arbitraire sur l&#8217;h\u00f4te&#8221;, a not\u00e9 Ubuntu dans un avis publi\u00e9 le mois dernier.<\/p>\n<p>Selon <a rel=\"nofollow noopener\" href=\"https:\/\/blogs.juniper.net\/en-us\/security\/muhstik-gang-targets-redis-servers\" target=\"_blank\">donn\u00e9es de t\u00e9l\u00e9m\u00e9trie<\/a> recueillies par Juniper Threat Labs, les attaques exploitant la nouvelle faille auraient commenc\u00e9 le 11 mars 2022, conduisant \u00e0 la r\u00e9cup\u00e9ration d&#8217;un script shell malveillant (&#8220;russia.sh&#8221;) \u00e0 partir d&#8217;un serveur distant, qui est ensuite utilis\u00e9 pour r\u00e9cup\u00e9rer et ex\u00e9cuter les binaires du botnet \u00e0 partir d&#8217;un autre serveur.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646124018_583_Le-logiciel-malveillant-Daxin-lie-a-la-Chine-a-cible.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Premi\u00e8re <a rel=\"nofollow noopener\" href=\"https:\/\/blog.netlab.360.com\/gpon-exploit-in-the-wild-i-muhstik-botnet-among-others-en\/\" target=\"_blank\">document\u00e9<\/a> par la soci\u00e9t\u00e9 de s\u00e9curit\u00e9 chinoise Netlab 360, Muhstik est connu pour \u00eatre <a rel=\"nofollow noopener\" href=\"https:\/\/www.lacework.com\/blog\/meet-muhstik-iot-botnet-infecting-cloud-servers\/\" target=\"_blank\">actif<\/a> depuis mars 2018 et est mon\u00e9tis\u00e9 pour mener des activit\u00e9s d&#8217;extraction de pi\u00e8ces et organiser des attaques par d\u00e9ni de service distribu\u00e9 (DDoS).<\/p>\n<p>Capable de se propager sur les appareils Linux et IoT tels que le routeur domestique GPON, le routeur DD-WRT et <a rel=\"nofollow noopener\" href=\"https:\/\/unit42.paloaltonetworks.com\/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices\/\" target=\"_blank\">Routeurs de tomates<\/a>Muhstik a \u00e9t\u00e9 rep\u00e9r\u00e9 en train de militariser un certain nombre de d\u00e9fauts au fil des ans &#8211;<\/p>\n<ul>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2017-10271\" target=\"_blank\"><strong>CVE-2017-10271<\/strong><\/a>  (Score CVSS\u00a0: 7,5) &#8211; Une vuln\u00e9rabilit\u00e9 de validation d&#8217;entr\u00e9e dans le composant Oracle WebLogic Server d&#8217;Oracle Fusion Middleware<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-7600\" target=\"_blank\"><strong>CVE-2018-7600<\/strong><\/a>  (Score CVSS\u00a0: 9,8) &#8211; Vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance Drupal<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-2725\" target=\"_blank\"><strong>CVE-2019-2725<\/strong><\/a>  (Score CVSS\u00a0: 9,8) &#8211; Vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance Oracle WebLogic Server<\/li>\n<li><strong>CVE-2021-26084<\/strong> (score CVSS : 9,8) \u2013 Une faille d&#8217;injection OGNL (Object-Graph Navigation Language) dans Atlassian Confluence, et<\/li>\n<li><strong>CVE-2021-44228<\/strong> (Score CVSS\u00a0: 10,0) &#8211; Vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance Apache Log4j (alias Log4Shell)<\/li>\n<\/ul>\n<p>&#8220;Ce bot se connecte \u00e0 un serveur IRC pour recevoir des commandes telles que\u00a0: t\u00e9l\u00e9charger des fichiers, des commandes shell, des attaques par inondation, [and] Force brute SSH&#8221;, ont d\u00e9clar\u00e9 les chercheurs de Juniper Threat Labs dans un rapport publi\u00e9 la semaine derni\u00e8re.<\/p>\n<p>\u00c0 la lumi\u00e8re de l&#8217;exploitation active de la faille de s\u00e9curit\u00e9 critique, il est fortement recommand\u00e9 aux utilisateurs d&#8217;agir rapidement pour mettre \u00e0 jour leurs services Redis vers la derni\u00e8re version.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/muhstik-botnet-targeting-redis-servers.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Muhstik, un botnet tristement c\u00e9l\u00e8bre pour se propager via des exploits d&#8217;applications Web, a \u00e9t\u00e9 observ\u00e9 ciblant des serveurs Redis en utilisant une vuln\u00e9rabilit\u00e9 r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans le syst\u00e8me de base de donn\u00e9es. La vuln\u00e9rabilit\u00e9 concerne CVE-2022-0543une Faille d&#8217;\u00e9chappement du bac \u00e0 sable Lua dans le magasin de donn\u00e9es open source, en m\u00e9moire et cl\u00e9-valeur [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":57936,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[5464,4175,4168,4158,4165,4161,19144,1326,4157,4159,4171,4170,1151,65,4167,4160,37828,4163,4162,12363,37829,4172,4169,8541,4166,3667,4164],"class_list":["post-57935","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-botnet","tag-ciblant","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-divulguee","tag-dune","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-laide","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-muhstik","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-recemment","tag-redis","tag-securite-informatique","tag-securite-internet","tag-serveurs","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/57935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=57935"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/57935\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/57936"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=57935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=57935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=57935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}