{"id":31103,"date":"2018-12-11T15:45:00","date_gmt":"2018-12-11T15:45:00","guid":{"rendered":"https:\/\/fr.cryptonews.com\/?p=31103"},"modified":"2023-06-26T11:07:37","modified_gmt":"2023-06-26T11:07:37","slug":"a-new-wave-of-attacks-on-ethereum-mining-rigs-2485","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/","title":{"rendered":"Une nouvelle vague d&#8217;attaques sur les rigs de minage Ethereum"},"content":{"rendered":"<p>Une autre campagne massive ciblant les rigs de minage <a href=\"https:\/\/cryptonews.com\/fr\/tags\/ethereum\/\">Ethereum<\/a> est en cours depuis au moins une semaine, a rapport&eacute; <i>ZDNet<\/i>, citant <b>Troy Mursch<\/b>, cofondateur de <b>Bad Packets LLC<\/b>, une soci&eacute;t&eacute; de cybers&eacute;curit&eacute;. Les pirates analysent les appareils dont le port 8545 est expos&eacute; en ligne &#8211; ce qui a co&ucirc;t&eacute; plus de 20 millions USD aux mineurs insouciants en juin de cette ann&eacute;e, alors que la m&ecirc;me chose s&rsquo;&eacute;tait produite.<\/p><figure><img decoding=\"async\" src=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg\" sizes=\"(min-width: 640px) 720px, 100vw\" srcset=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg 300w, https:\/\/cimg.co\/w\/articles-attachments\/2\/5c0\/fa45ecfac6.jpg 600w, https:\/\/cimg.co\/w\/articles-attachments\/3\/5c0\/fa45ecfac6.jpg 720w, https:\/\/cimg.co\/w\/articles-attachments\/4\/5c0\/fa45ecfac6.jpg 900w, https:\/\/cimg.co\/w\/articles-attachments\/0\/5c0\/fa45ecfac6.jpg 1254w\" alt=\"\" class=\"content-img\"><figcaption>Source: iStock\/GoodLifeStudio<\/figcaption><\/figure><p>Le port 8545 est standard pour l&#8217;interface JSON-RPC pour de nombreux portefeuilles Ethereum et &eacute;quipements miniers. Certaines applications Ethereum peuvent &ecirc;tre configur&eacute;es pour exposer un appel de proc&eacute;dure distante (RPC), dont le but est de fournir un acc&egrave;s &agrave; une API de programmation (interface de programmation d&#8217;application) &agrave; partir de laquelle un service ou une application tierce approuv&eacute; peut interroger et interagir ou r&eacute;cup&eacute;rer des donn&eacute;es depuis le service original bas&eacute; sur Ethereum. L&#8217;interface RPC peut &eacute;galement autoriser l&#8217;acc&egrave;s &agrave; des fonctions tr&egrave;s sensibles, telles que des cl&eacute;s priv&eacute;es, des informations personnelles, etc.<\/p><p>En th&eacute;orie, l&#8217;interface ne devrait &ecirc;tre expos&eacute;e que localement, mais certaines applications de portefeuilles et certains &eacute;quipements de minage le permettent sur toutes les interfaces. De plus, cette interface JSON-RPC, lorsqu&#8217;elle est activ&eacute;e, ne comporte pas non plus de mot de passe dans les configurations par d&eacute;faut et repose sur la d&eacute;finition par l&#8217;utilisateur. Si cela reste expos&eacute; sur Internet, les assaillants peuvent librement transf&eacute;rer des fonds de l&rsquo;adresse de la victime &agrave; la leur.<\/p><oembed url=\"https:\/\/twitter.com\/zero_B_S\/status\/1072146649064112128?ref_src=twsrc%5Etfw\"><\/oembed><p>De nombreux vendeurs d&rsquo;&eacute;quipements de minage et fabricants d&#8217;applications de portemonnaies ont pris des pr&eacute;cautions pour limiter l&#8217;exposition du port 8545 ou ont totalement supprim&eacute; l&#8217;interface JSON-RPC. L&rsquo;&eacute;quipe Ethereum a envoy&eacute; un avis de s&eacute;curit&eacute; &agrave; tous les utilisateurs d&rsquo;Ethereum sur les dangers de l&rsquo;utilisation du mat&eacute;riel de minage et du logiciel Ethereum qui expose cette interface API sur Internet, recommandant aux utilisateurs de prendre des pr&eacute;cautions en ajoutant un mot de passe sur l&rsquo;interface ou en utilisant un pare-feu pour filtrer le trafic entrant pour le port 8545.<\/p><p>Pour illustrer la vuln&eacute;rabilit&eacute; de nombreux appareils de minage, <i>ZDNet<\/i> &eacute;crit &laquo;qu&rsquo;une recherche rapide dans <b>Shodan<\/b> [moteur de recherche pour les p&eacute;riph&eacute;riques connect&eacute;s &agrave; Internet] montre que pr&egrave;s de 4 700 p&eacute;riph&eacute;riques, dont la plupart sont des &eacute;quipements Geth et des portefeuilles Parity, exposent actuellement leurs ports 8545&raquo;. Bien que le prix de ETH atteigne de nouveaux plus bas, se situant autour de 90 USD &agrave; la date de r&eacute;daction du pr&eacute;sent document, cela n&rsquo;a pas dissuad&eacute; les assaillants de rechercher des solutions faciles.<\/p><p>Comme indiqu&eacute; pr&eacute;c&eacute;demment, il n&rsquo;est pas si difficile de se prot&eacute;ger de ces attaques. La premi&egrave;re &eacute;tape consiste &agrave; lire les avertissements qui accompagnent l&#8217;application que vous utilisez. Bien s&ucirc;r, si vous avez une bonne raison d&#8217;activer l&#8217;interface RPC, s&eacute;curisez-la &agrave; l&#8217;aide d&#8217;une liste de contr&ocirc;le d&#8217;acc&egrave;s (ACL), d&#8217;un pare-feu ou d&#8217;un autre syst&egrave;me d&#8217;authentification.<\/p>","protected":false},"excerpt":{"rendered":"<p>Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch, cofondateur de Bad Packets LLC, une soci&eacute;t&eacute; de cybers&eacute;curit&eacute;. Les pirates analysent les appareils dont le port 8545 est expos&eacute; en ligne &#8211; ce qui a co&ucirc;t&eacute; plus de 20 millions [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[7,1],"tags":[51,62,48,83],"editors":[2550],"sponsored_companies":[],"class_list":["post-31103","post","type-post","status-publish","format-standard","hentry","category-ethereum-news","category-news","tag-ethereum","tag-minage","tag-piratage","tag-securite","editors-jurgen-hoffman"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Une nouvelle vague d&#039;attaques sur les rigs de minage Ethereum<\/title>\n<meta name=\"description\" content=\"Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch,\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Une nouvelle vague d&#039;attaques sur les rigs de minage Ethereum\" \/>\n<meta property=\"og:description\" content=\"Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch,\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2018-12-11T15:45:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-26T11:07:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/news\/23948\/6221\/5c0fa4681771c.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Une nouvelle vague d'attaques sur les rigs de minage Ethereum","description":"Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch,","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/","og_locale":"fr_FR","og_type":"article","og_title":"Une nouvelle vague d'attaques sur les rigs de minage Ethereum","og_description":"Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch,","og_url":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/","og_site_name":"Cryptonews France","article_published_time":"2018-12-11T15:45:00+00:00","article_modified_time":"2023-06-26T11:07:37+00:00","og_image":[{"url":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_image":"https:\/\/cimg.co\/news\/23948\/6221\/5c0fa4681771c.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/"},"author":{"name":"giedrius","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/5d79e712f570715212460260f4f9cc0f"},"headline":"Une nouvelle vague d&#8217;attaques sur les rigs de minage Ethereum","datePublished":"2018-12-11T15:45:00+00:00","dateModified":"2023-06-26T11:07:37+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/"},"wordCount":624,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg","keywords":["Ethereum","Minage","Piratage","S\u00e9curit\u00e9"],"articleSection":["Actualit\u00e9s Ethereum","News"],"inLanguage":"fr-FR","copyrightYear":"2018","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/","url":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/","name":"Une nouvelle vague d'attaques sur les rigs de minage Ethereum","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg","datePublished":"2018-12-11T15:45:00+00:00","dateModified":"2023-06-26T11:07:37+00:00","description":"Une autre campagne massive ciblant les rigs de minage Ethereum est en cours depuis au moins une semaine, a rapport&eacute; ZDNet, citant Troy Mursch,","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#primaryimage","url":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg","contentUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5c0\/fa45ecfac6.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/a-new-wave-of-attacks-on-ethereum-mining-rigs-2485\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Une nouvelle vague d&#8217;attaques sur les rigs de minage Ethereum"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/31103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=31103"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/31103\/revisions"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=31103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=31103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=31103"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=31103"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=31103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}