{"id":188,"date":"2015-07-31T17:33:16","date_gmt":"2015-07-31T20:33:16","guid":{"rendered":"http:\/\/www.batori.com.br\/blog\/?p=188"},"modified":"2015-07-31T17:50:50","modified_gmt":"2015-07-31T20:50:50","slug":"hacker-rouba-credenciais-de-log-in-de-clientes-bitdefender-as-tentativas-de-chantagem","status":"publish","type":"post","link":"http:\/\/www.batori.com.br\/blog\/hacker-rouba-credenciais-de-log-in-de-clientes-bitdefender-as-tentativas-de-chantagem\/","title":{"rendered":"Hacker rouba credenciais de log-in de clientes da Bitdefender (empresa de antiv\u00edrus) e tenta chantagem"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/images.techhive.com\/images\/article\/2015\/04\/hackers-100580744-primary.idge.jpg\" alt=\"\" border=\"0\" \/><\/p>\n<p><span id=\"result_box\" class=\"\" lang=\"pt\"><span title=\"A hacker extracted customer log-in credentials from a server owned by Bitdefender that hosted the cloud-based management dashboards for its small and medium-size business clients.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Um hacker conseguiu credenciais de log-in dos clientes de um servidor pertencente a Bitdefender que hospeda pain\u00e9is de gerenciamento na<\/span><\/span><span id=\"result_box\" class=\"\" lang=\"pt\"><span title=\"A hacker extracted customer log-in credentials from a server owned by Bitdefender that hosted the cloud-based management dashboards for its small and medium-size business clients.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\"> nuvem para seus clientes de pequenas e m\u00e9dias empresas.<\/span><\/span><\/p>\n<p><span title=\"The antivirus company confirmed the security breach but said in an emailed statement that the attack affected less than 1 percent of its SMB customers, whose passwords have since been reset.\">A empresa de antiv\u00edrus confirmou a falha de seguran\u00e7a, mas disse em um comunicado enviado por email que o ataque afetou menos de 1 por cento de seus clientes SMB, cujas senhas j\u00e1 que foi redefinida. <\/span><span title=\"Consumer and enterprise customers were not affected, the company said.&lt;br \/&gt;&lt;br \/&gt;&lt;br \/&gt; \">Consumidores e clientes corporativos n\u00e3o foram afetadas, segundo a empresa.<\/span><\/p>\n<p><span id=\"result_box\" class=\"\" lang=\"pt\"><span title=\"The hacker, who uses the online alias DetoxRansome, first bragged about the breach on Twitter Saturday and later messaged Bitdefender threatening to release the company's &quot;customer base&quot; unless he was paid $15,000.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">O hacker, que usa o pseud\u00f4nimo on-line DetoxRansome, primeiro se gabava da invas\u00e3o no Twitter no s\u00e1bado e depois\u00a0amea\u00e7ando enviar mensagem para &#8220;base de clientes&#8221; da Bitdefender, a menos que ele recebesse US $ 15.000.<\/span><\/span><\/p>\n<p><span title=\"To prove his point, the next day he published the email addresses and passwords for two Bitdefender customer accounts and one for an account operated by the company itself.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">No dia seguinte ao ataque, para provar a invas\u00e3o, ele publicou os endere\u00e7os de email e senhas de duas contas de clientes BitDefender e de uma conta operada pela pr\u00f3pria empresa.<\/span><\/p>\n<p><span title=\"Travis Doering and Dan McPeake claimed in a blog post that they contacted the hacker, who offered to sell the data to them.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Travis Doering e Dan McPeake afirmaram em um post de blog que eles contataram o hacker\u00a0 que se ofereceu para vender os dados.<\/span><\/p>\n<p><span title=\"The hacker provided a list of user names and matching passwords for more than 250 Bitdefender accounts, some of which were confirmed to be active, the two wrote Wednesday.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">O hacker forneceu uma lista de nomes de usu\u00e1rio e senhas correspondentes em mais de 250 contas da BitDefender, alguns dos quais foram confirmados como ativos.<\/span><\/p>\n<p><span title=\"Doering and McPeake said that they shared the information with Bitdefender.\">Doering e McPeake disse que eles compartilharam a informa\u00e7\u00e3o com a Bitdefender. <\/span><span title=\"When they asked DetoxRansome how he obtained the log-in credentials, he replied that he was &quot;sniffing&quot; one of Bitdefender's &quot;major servers.&quot;&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Quando perguntaram como DetoxRansome obteve as credenciais de log-in, ele respondeu que foi um &#8220;sniffing&#8221;, em um dos principais servidores do BitDefender.<\/span><\/p>\n<p><span title=\"Bitdefender confirmed that the attack did not exploit a zero-day vulnerability, a vulnerability that is previously unknown.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Bitdefender confirmou que o ataque n\u00e3o explorou uma vulnerabilidade &#8220;zero-day&#8221;, e sim uma vulnerabilidade que era desconhecida pela empresa.<\/span><\/p>\n<p><span title=\"The issue was the result of human error.\">O problema foi o resultado de erro humano. <\/span><span title=\"During an infrastructure increase, a single server was deployed with an outdated software package that had a known flaw, enabling the extraction of information, but not a full system compromise, said Catalin Cosoi, chief security strategist at Bitdefender.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Durante um aumento da infra-estrutura, um \u00fanico servidor foi implantado com um pacote de software desatualizado que tinha uma falha conhecida, permitindo a extra\u00e7\u00e3o de informa\u00e7\u00f5es, mas n\u00e3o foi um compromisso total do sistema, disse Catalin Cosoi, estrategista-chefe de seguran\u00e7a da Bitdefender.<\/span><\/p>\n<p><span title=\"He declined to name the vulnerable package.&lt;\/p&gt;&lt;br \/&gt;&lt;br \/&gt; &lt;p&gt;\">Ele n\u00e3o quis citar qual foi o pacote vulner\u00e1vel.<\/span><\/p>\n<p><span title=\"The issue was resolved and additional security measures have been put in place to prevent its reoccurrence, the company said in its statement.\">O problema foi resolvido e as medidas de seguran\u00e7a adicionais foram postas em pr\u00e1tica para evitar a sua repeti\u00e7\u00e3o, disse a empresa em comunicado. <\/span><span title=\"&quot;Our investigation revealed no other server or services were impacted.&quot;\">&#8220;Nossa investiga\u00e7\u00e3o revelou que nenhum outro servidor ou servi\u00e7o foi afetado.&#8221;<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Um hacker conseguiu credenciais de log-in dos clientes de um servidor pertencente a Bitdefender que hospeda pain\u00e9is de gerenciamento na nuvem para seus clientes de pequenas e m\u00e9dias empresas. A empresa de antiv\u00edrus confirmou a falha de seguran\u00e7a, mas disse &hellip; <a href=\"http:\/\/www.batori.com.br\/blog\/hacker-rouba-credenciais-de-log-in-de-clientes-bitdefender-as-tentativas-de-chantagem\/\">Continue lendo <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":125,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/posts\/188"}],"collection":[{"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/users\/125"}],"replies":[{"embeddable":true,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/comments?post=188"}],"version-history":[{"count":5,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/posts\/188\/revisions"}],"predecessor-version":[{"id":194,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/posts\/188\/revisions\/194"}],"wp:attachment":[{"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/media?parent=188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/categories?post=188"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.batori.com.br\/blog\/wp-json\/wp\/v2\/tags?post=188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}