{"id":86335,"date":"2022-04-12T17:22:51","date_gmt":"2022-04-12T19:22:51","guid":{"rendered":"https:\/\/teknomers.com\/fr\/nginx-partage-des-mesures-dattenuation-pour-le-bogue-zero-day-affectant-limplementation-de-ldap\/"},"modified":"2022-04-12T17:22:59","modified_gmt":"2022-04-12T19:22:59","slug":"nginx-partage-des-mesures-dattenuation-pour-le-bogue-zero-day-affectant-limplementation-de-ldap","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/nginx-partage-des-mesures-dattenuation-pour-le-bogue-zero-day-affectant-limplementation-de-ldap\/","title":{"rendered":"NGINX partage des mesures d&#8217;att\u00e9nuation pour le bogue Zero-Day affectant l&#8217;impl\u00e9mentation de LDAP"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Les mainteneurs du projet de serveur Web NGINX ont publi\u00e9 des mesures d&#8217;att\u00e9nuation pour rem\u00e9dier aux faiblesses de s\u00e9curit\u00e9 de son protocole d&#8217;acc\u00e8s \u00e0 l&#8217;annuaire l\u00e9ger (<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Lightweight_Directory_Access_Protocol\" target=\"_blank\">LDAP<\/a>) Impl\u00e9mentation de r\u00e9f\u00e9rence.<\/p>\n<p>&#8220;NGINX Open Source et NGINX Plus ne sont pas eux-m\u00eames concern\u00e9s, et aucune action corrective n&#8217;est n\u00e9cessaire si vous n&#8217;utilisez pas l&#8217;impl\u00e9mentation de r\u00e9f\u00e9rence&#8221;, Liam Crilly et Timo Stark de F5 Networks <a rel=\"nofollow noopener\" href=\"https:\/\/www.nginx.com\/blog\/addressing-security-weaknesses-nginx-ldap-reference-implementation\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un avis publi\u00e9 lundi.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset2\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Alertes-CISA-sur-les-failles-activement-exploitees-dans-la-plate-forme.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>NGINX a d\u00e9clar\u00e9 que le <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/nginxinc\/nginx-ldap-auth\" target=\"_blank\">impl\u00e9mentation de r\u00e9f\u00e9rence<\/a>qui <a rel=\"nofollow noopener\" href=\"https:\/\/www.nginx.com\/blog\/nginx-plus-authenticate-users\/\" target=\"_blank\">utilise LDAP pour authentifier les utilisateurs<\/a>n&#8217;est impact\u00e9 que sous trois conditions si les d\u00e9ploiements impliquent &#8211;<\/p>\n<ul>\n<li>Param\u00e8tres de ligne de commande pour configurer le d\u00e9mon d&#8217;impl\u00e9mentation de r\u00e9f\u00e9rence bas\u00e9 sur Python<\/li>\n<li>Param\u00e8tres de configuration facultatifs inutilis\u00e9s et<\/li>\n<li>Appartenance \u00e0 un groupe sp\u00e9cifique pour effectuer l&#8217;authentification LDAP<\/li>\n<\/ul>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"308\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1649791371_906_NGINX-partage-des-mesures-dattenuation-pour-le-bogue-Zero-Day-affectant.jpg\" \/><\/div>\n<p>Si l&#8217;une des conditions susmentionn\u00e9es est remplie, un attaquant pourrait potentiellement remplacer les param\u00e8tres de configuration en envoyant des en-t\u00eates de requ\u00eate HTTP sp\u00e9cialement con\u00e7us et m\u00eame contourner les exigences d&#8217;appartenance au groupe pour forcer l&#8217;authentification LDAP \u00e0 r\u00e9ussir m\u00eame lorsque l&#8217;utilisateur faussement authentifi\u00e9 n&#8217;appartient pas au groupe.<\/p>\n<p>Comme contre-mesures, les responsables du projet ont recommand\u00e9 aux utilisateurs de s&#8217;assurer que les caract\u00e8res sp\u00e9ciaux sont supprim\u00e9s du champ du nom d&#8217;utilisateur dans le formulaire de connexion pr\u00e9sent\u00e9 lors de l&#8217;authentification et de mettre \u00e0 jour les param\u00e8tres de configuration appropri\u00e9s avec une valeur vide (&#8220;&#8221;).<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Les mainteneurs ont \u00e9galement soulign\u00e9 que l&#8217;impl\u00e9mentation de r\u00e9f\u00e9rence LDAP \u00ab\u00a0d\u00e9crit principalement les m\u00e9canismes de fonctionnement de l&#8217;int\u00e9gration et tous les composants n\u00e9cessaires pour v\u00e9rifier l&#8217;int\u00e9gration\u00a0\u00bb et qu&#8217;\u00ab\u00a0il ne s&#8217;agit pas d&#8217;une solution LDAP de niveau production\u00a0\u00bb.<\/p>\n<p>La r\u00e9v\u00e9lation vient apr\u00e8s <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/AgainstTheWest\/NginxDay\/blob\/main\/README.md\" target=\"_blank\">des d\u00e9tails<\/a> du probl\u00e8me est apparu dans le domaine public au cours du week-end lorsqu&#8217;un groupe hacktiviste appel\u00e9 BlueHornet <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/_Blue_hornet\/status\/1512759109275242497\" target=\"_blank\">mentionn\u00e9<\/a> il avait &#8220;mis la main sur un exploit exp\u00e9rimental pour NGINX 1.18&#8221;.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/nginx-shares-mitigations-for-zero-day.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Les mainteneurs du projet de serveur Web NGINX ont publi\u00e9 des mesures d&#8217;att\u00e9nuation pour rem\u00e9dier aux faiblesses de s\u00e9curit\u00e9 de son protocole d&#8217;acc\u00e8s \u00e0 l&#8217;annuaire l\u00e9ger (LDAP) Impl\u00e9mentation de r\u00e9f\u00e9rence. &#8220;NGINX Open Source et NGINX Plus ne sont pas eux-m\u00eames concern\u00e9s, et aucune action corrective n&#8217;est n\u00e9cessaire si vous n&#8217;utilisez pas l&#8217;impl\u00e9mentation de r\u00e9f\u00e9rence&#8221;, Liam [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":86336,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[34911,6813,4168,4158,4165,4161,48257,133,4157,4159,4171,4170,48259,48258,4167,659,4160,48256,4163,4162,604,185,4172,4169,4166,4164,35759],"class_list":["post-86335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affectant","tag-bogue","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dattenuation","tag-des","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-ldap","tag-limplementation","tag-logiciel-malveillant-de-ransomware","tag-mesures","tag-mises-a-jour-de-la-cybersecurite","tag-nginx","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-partage","tag-pour","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/86335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=86335"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/86335\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/86336"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=86335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=86335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=86335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}