{"id":97847,"date":"2022-04-19T03:14:22","date_gmt":"2022-04-19T05:14:22","guid":{"rendered":"https:\/\/teknomers.com\/fr\/github-informe-les-victimes-dont-les-donnees-privees-ont-ete-volees-a-laide-de-jetons-oauth\/"},"modified":"2022-04-19T03:14:29","modified_gmt":"2022-04-19T05:14:29","slug":"github-informe-les-victimes-dont-les-donnees-privees-ont-ete-volees-a-laide-de-jetons-oauth","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/github-informe-les-victimes-dont-les-donnees-privees-ont-ete-volees-a-laide-de-jetons-oauth\/","title":{"rendered":"Github informe les victimes dont les donn\u00e9es priv\u00e9es ont \u00e9t\u00e9 vol\u00e9es \u00e0 l&#8217;aide de jetons OAuth"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>GitHub a not\u00e9 lundi qu&#8217;il avait notifi\u00e9 toutes les victimes d&#8217;une campagne d&#8217;attaque, qui impliquait une partie non autoris\u00e9e t\u00e9l\u00e9chargeant le contenu d&#8217;un r\u00e9f\u00e9rentiel priv\u00e9 en profitant de jetons d&#8217;utilisateur OAuth tiers g\u00e9r\u00e9s par Heroku et Travis CI.<\/p>\n<p>&#8220;Les clients doivent \u00e9galement continuer \u00e0 surveiller Heroku et Travis CI pour obtenir des mises \u00e0 jour sur leurs propres enqu\u00eates sur les applications OAuth concern\u00e9es&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/github.blog\/2022-04-15-security-alert-stolen-oauth-user-tokens\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un article mis \u00e0 jour.<\/p>\n<p>L&#8217;incident a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9 \u00e0 l&#8217;origine le 12 avril lorsque GitHub a d\u00e9couvert des signes indiquant qu&#8217;un acteur malveillant avait exploit\u00e9 les jetons d&#8217;utilisateur OAuth vol\u00e9s d\u00e9livr\u00e9s \u00e0 Heroku et Travis-CI pour t\u00e9l\u00e9charger des donn\u00e9es de dizaines d&#8217;organisations, dont NPM.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset2\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Le-celebre-gang-de-logiciels-malveillants-TrickBot-ferme-son-infrastructure.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>La plate-forme appartenant \u00e0 Microsoft a \u00e9galement d\u00e9clar\u00e9 qu&#8217;elle alerterait rapidement les clients si l&#8217;enqu\u00eate en cours identifiait d&#8217;autres victimes.  De plus, il a averti que l&#8217;adversaire pourrait \u00e9galement creuser dans les r\u00e9f\u00e9rentiels pour trouver des secrets qui pourraient \u00eatre utilis\u00e9s dans d&#8217;autres attaques.<\/p>\n<p>Heroku, qui a pris en charge l&#8217;int\u00e9gration de GitHub \u00e0 la suite de l&#8217;incident, <a rel=\"nofollow noopener\" href=\"https:\/\/status.heroku.com\/incidents\/2413\" target=\"_blank\">conseill\u00e9<\/a> que les utilisateurs ont la possibilit\u00e9 d&#8217;int\u00e9grer leurs d\u00e9ploiements d&#8217;applications avec Git ou d&#8217;autres fournisseurs de contr\u00f4le de version tels que GitLab ou Bitbucket.<\/p>\n<p>Prestataire de services d&#8217;int\u00e9gration continue h\u00e9berg\u00e9 Travis CI, dans un <a rel=\"nofollow noopener\" href=\"https:\/\/blog.travis-ci.com\/2022-04-17-securitybulletin\" target=\"_blank\">consultatif<\/a> publi\u00e9 lundi, a d\u00e9clar\u00e9 qu&#8217;il avait &#8220;r\u00e9voqu\u00e9 toutes les cl\u00e9s d&#8217;autorisation et tous les jetons emp\u00eachant tout acc\u00e8s ult\u00e9rieur \u00e0 nos syst\u00e8mes&#8221;.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEj6zHdXd3qpCksF0nkMkrjsOzaw-cxZGPHWoTEp9y7VPIeyPBFGsmIyIX8NTkqI1IDqnIXYnsZuIh4rc9f8TNUn7ndAZqtXc-t58X2oueTaL4Ijb4hgH-b183QvQ0ienXIipuOsqeLP5b8I2prKmp0RWvdZQgnKehVRKbqRQpin1JgfwlZeE_IB4EmesQ\/s1600\/crowdsec-728.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>D\u00e9clarant qu&#8217;aucune donn\u00e9e client n&#8217;a \u00e9t\u00e9 expos\u00e9e, la soci\u00e9t\u00e9 a reconnu que les attaquants avaient viol\u00e9 un service Heroku et acc\u00e9d\u00e9 \u00e0 la cl\u00e9 OAuth d&#8217;une application priv\u00e9e utilis\u00e9e pour int\u00e9grer les applications Heroku et Travis CI.<\/p>\n<p>Mais Travis CI a r\u00e9p\u00e9t\u00e9 qu&#8217;il n&#8217;avait trouv\u00e9 aucune preuve d&#8217;intrusion dans un r\u00e9f\u00e9rentiel client priv\u00e9 ou que les acteurs de la menace avaient obtenu un acc\u00e8s injustifi\u00e9 au code source.<\/p>\n<p>&#8220;Compte tenu des donn\u00e9es dont nous disposions et par prudence, Travis CI a r\u00e9voqu\u00e9 et r\u00e9\u00e9dit\u00e9 toutes les cl\u00e9s et tous les jetons d&#8217;authentification des clients priv\u00e9s int\u00e9grant Travis CI \u00e0 GitHub pour s&#8217;assurer qu&#8217;aucune donn\u00e9e client n&#8217;est compromise&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/github-notifies-victims-whose-private.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitHub a not\u00e9 lundi qu&#8217;il avait notifi\u00e9 toutes les victimes d&#8217;une campagne d&#8217;attaque, qui impliquait une partie non autoris\u00e9e t\u00e9l\u00e9chargeant le contenu d&#8217;un r\u00e9f\u00e9rentiel priv\u00e9 en profitant de jetons d&#8217;utilisateur OAuth tiers g\u00e9r\u00e9s par Heroku et Travis CI. &#8220;Les clients doivent \u00e9galement continuer \u00e0 surveiller Heroku et Travis CI pour obtenir des mises \u00e0 jour [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":97848,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4168,4158,4165,4161,1343,1947,162,50438,23754,50440,4157,4159,4171,4170,1151,65,4167,4160,4163,4162,50441,249,19699,4172,4169,1884,4166,29361,4164],"class_list":["post-97847","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-donnees","tag-dont","tag-ete","tag-github","tag-informe","tag-jetons","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-laide","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-oauth","tag-ont","tag-privees","tag-securite-informatique","tag-securite-internet","tag-victimes","tag-violation-de-donnees","tag-volees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/97847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=97847"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/97847\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/97848"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=97847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=97847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=97847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}