HomeSecurityDangerous backdoor discovered in popular strong_password Ruby library

Dangerous backdoor discovered in popular strong_password Ruby library

A, which checks how strong the passwords users choose are. dangerous backdoor has been discovered in a popular Ruby library, strong_password

The malicious code checks whether the library is being used in a test or production environment. If it is in a production environment, it will download and execute a second payload that will be uploaded from Pastebin.com, a text hosting portal.

backdoor

This second payload will create the actual backdoor to applications and websites that used the strong_password library.

The backdoor will send the URL of each infected website to “smiley.zzz.com.ua” and then wait for instructions.

The instructions are cookie, which the backdoor will unpack and run through an “eval” function.

Basically, this mechanism allows the hacker to run any code they want within an application that has the backdoored library.

The backdoor mechanism was discovered by developer Tute Costa during the regular security checks he performs before updating components used in the production environment.

Dangerous backdoor discovered in popular strong_password Ruby library

Costa discovered that the hacker managed to replace the real developer as the owner of the RubyGems library, the main Ruby package repository.

The hacker created a new version of the strong_password library, version 0.0.7, which contains the malicious code. According to statistics, 537 users downloaded this malicious version.

The backdoor was never uploaded to the GitHub account. It was only distributed through RubyGems.

Costa notified both the library owner and the RubyGems security team of his discovery. The malicious version was removed within a week of being uploaded.

Because the strong_password library is commonly used in applications and websites that manage user accounts, any project that uses this library should conduct a thorough security audit to detect any possible breach and theft of user data.

backdoor

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS