{"id":71434,"date":"2022-04-04T16:49:15","date_gmt":"2022-04-04T18:49:15","guid":{"rendered":"https:\/\/teknomers.com\/fr\/le-botnet-ddos-beastmode-exploite-de-nouveaux-bogues-totolink-pour-asservir-davantage-de-routeurs\/"},"modified":"2022-04-04T16:49:23","modified_gmt":"2022-04-04T18:49:23","slug":"le-botnet-ddos-beastmode-exploite-de-nouveaux-bogues-totolink-pour-asservir-davantage-de-routeurs","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/le-botnet-ddos-beastmode-exploite-de-nouveaux-bogues-totolink-pour-asservir-davantage-de-routeurs\/","title":{"rendered":"Le botnet DDoS Beastmode exploite de nouveaux bogues TOTOLINK pour asservir davantage de routeurs"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Une variante du botnet Mirai appel\u00e9e <b>Mode b\u00eate<\/b> a \u00e9t\u00e9 observ\u00e9 adoptant des vuln\u00e9rabilit\u00e9s nouvellement r\u00e9v\u00e9l\u00e9es dans les routeurs TOTOLINK entre f\u00e9vrier et mars 2022 pour infecter des appareils non corrig\u00e9s et \u00e9tendre potentiellement sa port\u00e9e.<\/p>\n<p>&#8220;La campagne DDoS bas\u00e9e sur Beastmode (alias B3astmode) Mirai a mis \u00e0 jour de mani\u00e8re agressive son arsenal d&#8217;exploits&#8221;, a d\u00e9clar\u00e9 l&#8217;\u00e9quipe de recherche FortiGuard Labs de Fortinet. <a rel=\"nofollow noopener\" href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/totolink-vulnerabilities-beastmode-mirai-campaign\" target=\"_blank\">mentionn\u00e9<\/a>.  &#8220;Cinq nouveaux exploits ont \u00e9t\u00e9 ajout\u00e9s en un mois, dont trois ciblant diff\u00e9rents mod\u00e8les de routeurs TOTOLINK.&#8221;<\/p>\n<p>La liste des vuln\u00e9rabilit\u00e9s exploit\u00e9es dans les routeurs TOTOLINK est la suivante &#8211;<\/p>\n<ul>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-26210\" target=\"_blank\"><strong>CVE-2022-26210<\/strong><\/a>  (Score CVSS\u00a0: 9,8) &#8211; Une vuln\u00e9rabilit\u00e9 d&#8217;injection de commande qui pourrait \u00eatre exploit\u00e9e pour obtenir l&#8217;ex\u00e9cution de code arbitraire<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-26186\" target=\"_blank\"><strong>CVE-2022-26186<\/strong><\/a>  (Score CVSS\u00a0: 9,8) &#8211; Une vuln\u00e9rabilit\u00e9 d&#8217;injection de commande affectant les routeurs TOTOLINK N600R et A7100RU, et<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/EPhaha\/IOT_vuln\/tree\/main\/TOTOLink\" target=\"_blank\"><strong>CVE-2022-25075 \u00e0 CVE-2022-25084<\/strong><\/a>  (Scores CVSS\u00a0: 9,8) &#8211; Une vuln\u00e9rabilit\u00e9 d&#8217;injection de commande affectant plusieurs routeurs TOTOLINK, entra\u00eenant l&#8217;ex\u00e9cution de code<\/li>\n<\/ul>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d2\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Des-experts-chinois-decouvrent-les-details-de-loutil-de-piratage.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Les autres exploits cibl\u00e9s par Beastmode incluent des failles dans la cam\u00e9ra IP TP-Link Tapo C200 (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-4045\" target=\"_blank\">CVE-2021-4045<\/a>score CVSS : 9,8), routeurs Huawei HG532 (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-17215\" target=\"_blank\">CVE-2017-17215<\/a>score CVSS : 8,8), les solutions de vid\u00e9osurveillance de NUUO et Netgear (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-5674\" target=\"_blank\">CVE-2016-5674<\/a>score CVSS\u00a0: 9,8) et les produits D-Link abandonn\u00e9s (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-45382\" target=\"_blank\">CVE-2021-45382<\/a>score CVSS : 9,8).<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Botnet DDoS Beastmode\" border=\"0\" data-original-height=\"559\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1649098155_335_Le-botnet-DDoS-Beastmode-exploite-de-nouveaux-bogues-TOTOLINK-pour.jpg\" title=\"Botnet DDoS Beastmode\" \/><\/div>\n<p>Pour \u00e9viter que les mod\u00e8les concern\u00e9s ne soient repris par le botnet, il est fortement recommand\u00e9 aux utilisateurs de mettre \u00e0 jour leurs appareils avec le <a rel=\"nofollow noopener\" href=\"https:\/\/www.totolink.net\/home\/news\/me_name\/id\/39\/menu_listtpl\/DownloadC.html\" target=\"_blank\">derni\u00e8re version<\/a>.<\/p>\n<p>&#8220;M\u00eame si l&#8217;auteur original de Mirai a \u00e9t\u00e9 arr\u00eat\u00e9 \u00e0 l&#8217;automne 2018, [the latest campaign] souligne comment les acteurs de la menace, tels que ceux \u00e0 l&#8217;origine de la campagne Beastmode, continuent d&#8217;incorporer rapidement le code d&#8217;exploitation nouvellement publi\u00e9 pour infecter les appareils non corrig\u00e9s \u00e0 l&#8217;aide du malware Mirai \u00bb, ont d\u00e9clar\u00e9 les chercheurs.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/beastmode-ddos-botnet-exploiting-new.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Une variante du botnet Mirai appel\u00e9e Mode b\u00eate a \u00e9t\u00e9 observ\u00e9 adoptant des vuln\u00e9rabilit\u00e9s nouvellement r\u00e9v\u00e9l\u00e9es dans les routeurs TOTOLINK entre f\u00e9vrier et mars 2022 pour infecter des appareils non corrig\u00e9s et \u00e9tendre potentiellement sa port\u00e9e. &#8220;La campagne DDoS bas\u00e9e sur Beastmode (alias B3astmode) Mirai a mis \u00e0 jour de mani\u00e8re agressive son arsenal d&#8217;exploits&#8221;, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":71435,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[42994,42992,14862,5464,4168,4158,4165,4161,4616,2890,7727,4157,4159,4171,4170,4167,4160,4588,4163,4162,185,29603,4172,4169,42993,4166,4164],"class_list":["post-71434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-asservir","tag-beastmode","tag-bogues","tag-botnet","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-davantage","tag-ddos","tag-exploite","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouveaux","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-routeurs","tag-securite-informatique","tag-securite-internet","tag-totolink","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/71434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=71434"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/71434\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/71435"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=71434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=71434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=71434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}