{"id":5368,"date":"2022-11-23T10:00:00","date_gmt":"2022-11-23T07:00:00","guid":{"rendered":"https:\/\/rockvell.com\/?p=5368"},"modified":"2022-11-23T10:09:04","modified_gmt":"2022-11-23T07:09:04","slug":"az%c9%99rbaycanda-microsoft-sql-server-d%c9%99n-istifad%c9%99-edil%c9%99n-hucumlarin-sayinda-artim-musahid%c9%99-olunub","status":"publish","type":"post","link":"https:\/\/rockvell.com\/?p=5368","title":{"rendered":"Az\u0259rbaycanda Microsoft SQL Server-d\u0259n istifad\u0259 edil\u0259n h\u00fccumlar\u0131n say\u0131nda art\u0131m m\u00fc\u015fahid\u0259 olunub"},"content":{"rendered":"\n<p class=\"has-medium-font-size\"><strong>Az\u0259rbaycanda Microsoft SQL Server-d\u0259n istifad\u0259 edil\u0259n h\u00fccumlar\u0131n say\u0131nda art\u0131m m\u00fc\u015fahid\u0259 olunub<\/strong><\/p>\n\n\n\n<p>Kaspersky-nin m\u0259lumat\u0131na g\u00f6r\u0259, Az\u0259rbaycanda Microsoft SQL Server-d\u0259n istifad\u0259 vasit\u0259sil\u0259 h\u0259yata ke\u00e7iril\u0259n h\u00fccumlar\u0131n say\u0131 artmaqdad\u0131r: m\u0259s\u0259l\u0259n, bu ilin avqustundan sentyabr ay\u0131na kimi onun aktivliyind\u0259 art\u0131m m\u00fc\u015fahid\u0259 olunub. Microsoft SQL Server d\u00fcnya \u00fczr\u0259 korporasiyalar\u0131n v\u0259 ki\u00e7ik \u015firk\u0259tl\u0259rin m\u0259lumat bazalar\u0131n\u0131 idar\u0259 etm\u0259k \u00fc\u00e7\u00fcn istifad\u0259 etdiyi \u0259sas proqram olaraq qal\u0131r. T\u0259cav\u00fczkarlar onun vasit\u0259sil\u0259 korporativ infrastruktura daxil olma\u011fa \u00e7al\u0131\u015f\u0131rlar.<\/p>\n\n\n\n<p>\u201cBir \u00e7ox \u015firk\u0259tl\u0259r Microsoft SQL Server proqram t\u0259minat\u0131ndan istifad\u0259 edir, lakin onlar\u0131n he\u00e7 d\u0259 ham\u0131s\u0131 onun istifad\u0259si il\u0259 ba\u011fl\u0131 t\u0259hl\u00fck\u0259l\u0259rd\u0259n qorunma\u011fa laz\u0131mi diqq\u0259ti yetirmir. Bu c\u00fcr h\u00fccumlar \u00e7oxdan m\u0259lum olsa da, h\u0259l\u0259 d\u0259 t\u0259cav\u00fczkarlara u\u011fur g\u0259tirir\u201d &#8211; dey\u0259 Kaspersky-nin Kibert\u0259hl\u00fck\u0259sizliyin Monitorinq M\u0259rk\u0259zinin r\u0259hb\u0259ri Sergey Soldatov qeyd edir.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/rockvell.com\/wp-content\/uploads\/2022\/11\/K_-1.png\" alt=\"\" class=\"wp-image-5073\" srcset=\"https:\/\/rockvell.com\/wp-content\/uploads\/2022\/11\/K_-1.png 1024w, https:\/\/rockvell.com\/wp-content\/uploads\/2022\/11\/K_-1-300x200.png 300w, https:\/\/rockvell.com\/wp-content\/uploads\/2022\/11\/K_-1-768x512.png 768w, https:\/\/rockvell.com\/wp-content\/uploads\/2022\/11\/K_-1-360x240.png 360w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>PowerShell skriptl\u0259ri v\u0259 PNG fayllar\u0131<\/strong>. Bu insidentl\u0259rd\u0259n birinin texniki t\u0259f\u0259rr\u00fcatlar\u0131 Kaspersky Managed Detection and Response hesabat\u0131nda \u0259ks olunub. Kaspersky m\u00fct\u0259x\u0259ssisl\u0259ri burada server agentinin yerin\u0259 yetirdiyi \u0259mrl\u0259rin ard\u0131c\u0131ll\u0131\u011f\u0131n\u0131 \u0259trafl\u0131 t\u0259svir edirl\u0259r.<\/p>\n\n\n\n<p>\u201cT\u0259cav\u00fczkarlar PowerShell vasit\u0259sil\u0259 z\u0259r\u0259rli proqram\u0131 i\u015f\u0259 salmaq \u00fc\u00e7\u00fcn server konfiqurasiyas\u0131n\u0131 d\u0259yi\u015fdirm\u0259y\u0259 v\u0259 \u0259mrl\u0259r panelin\u0259 giri\u015f \u0259ld\u0259 etm\u0259y\u0259 \u00e7al\u0131\u015f\u0131blar. \u018fl\u0259 ke\u00e7irilmi\u015f SQL Server bir \u00e7ox xarici IP \u00fcnvanlar\u0131 il\u0259 \u0259laq\u0259 yaradan z\u0259r\u0259rli PowerShell skriptini i\u015f\u0259 salma\u011fa c\u0259hd edib. Skript \u201cMsiMake\u201d atributundan istifad\u0259 ed\u0259r\u0259k, bu IP \u00fcnvanlarda yerl\u0259\u015f\u0259n v\u0259 .png fayllar\u0131 kimi maskalanm\u0131\u015f z\u0259r\u0259rli proqram\u0131 i\u015f\u0259 sal\u0131b ki, bu da b\u00f6y\u00fck \u00f6l\u00e7\u00fcd\u0259 PurpleFox z\u0259r\u0259rli proqram t\u0259minat\u0131n\u0131n davran\u0131\u015f\u0131n\u0131 xat\u0131rlad\u0131r\u201d, &#8211; Soldatov izah edir.<\/p>\n\n\n\n<p>Biznes \u00fc\u00e7\u00fcn Kaspersky Endpoint Security v\u0259 Kaspersky Managed Detection and Response h\u0259ll\u0259ri bu c\u00fcr h\u00fccumlar\u0131 u\u011furla a\u015fkar edir.<\/p>\n\n\n\n<p>Hesabat\u0131n tam versiyas\u0131n\u0131 <a href=\"https:\/\/securelist.com\/server-side-attacks-cc-in-public-clouds-and-other-mdr-cases-we-observed\/107826\/\">Securelist.ru<\/a> sayt\u0131ndan oxuya bil\u0259rsiniz.<\/p>\n\n\n\n<p>\u015eirk\u0259tinizi bu c\u00fcr t\u0259hl\u00fck\u0259l\u0259rd\u0259n qorumaq \u00fc\u00e7\u00fcn Kaspersky m\u00fct\u0259x\u0259ssisl\u0259ri t\u00f6vsiy\u0259 edir:<\/p>\n\n\n\n<ul><li>z\u0259iflikl\u0259r vasit\u0259sil\u0259 t\u0259cav\u00fczkarlar\u0131n \u015f\u0259b\u0259k\u0259y\u0259 daxil olmas\u0131n\u0131n qar\u015f\u0131s\u0131n\u0131 almaq \u00fc\u00e7\u00fcn istifad\u0259 olunan b\u00fct\u00fcn proqramlar\u0131 m\u00fct\u0259madi olaraq yenil\u0259yin v\u0259 h\u0259m\u00e7inin yamaqlar d\u0259rc olunduqda onlar\u0131 d\u0259rhal sonra qura\u015fd\u0131r\u0131n;<\/li><li>t\u0259cav\u00fczkarlar\u0131n taktika, texnika v\u0259 prosedurlar\u0131ndan x\u0259b\u0259rdar olmaq \u00fc\u00e7\u00fcn kibert\u0259hdidl\u0259r haqq\u0131nda <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/threat-intelligence\">\u0259n yeni analitik m\u0259lumatlardan<\/a> istifad\u0259 edin;<\/li><li><a href=\"https:\/\/www.kaspersky.ru\/small-to-medium-business-security\/endpoint-select\">Biznes \u00fc\u00e7\u00fcn Kaspersky Endpoint Security<\/a> kimi davran\u0131\u015f a\u015fkarlama moduluna v\u0259 m\u0259lum v\u0259 nam\u0259lum t\u0259hl\u00fck\u0259l\u0259rd\u0259n effektiv m\u00fcdafi\u0259 \u00fc\u00e7\u00fcn anomaliyalar\u0131 idar\u0259 etm\u0259k qabiliyy\u0259tin\u0259 malik etibarl\u0131 t\u0259hl\u00fck\u0259sizlik h\u0259llind\u0259n istifad\u0259 edin;<\/li><li><a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/managed-detection-and-response\">Kaspersky Managed Detection and Response<\/a> kimi h\u00fccumlar\u0131 t\u0259cav\u00fczkarlar \u0259h\u0259miyy\u0259tli d\u0259r\u0259c\u0259d\u0259 z\u0259r\u0259r vurma\u011fa macal tapmam\u0131\u015f erk\u0259n m\u0259rh\u0259l\u0259d\u0259 tan\u0131ya v\u0259 dayand\u0131ra bil\u0259n EDR h\u0259lli v\u0259 xidm\u0259tini t\u0259tbiq edin. \u018fg\u0259r insident a\u015fkarlasan\u0131z, xidm\u0259t siz\u0259 ona d\u00fczg\u00fcn reaksiya verm\u0259y\u0259 v\u0259 n\u0259tic\u0259l\u0259ri minimuma endirm\u0259y\u0259 k\u00f6m\u0259k ed\u0259c\u0259k, x\u00fcsus\u0259n d\u0259 t\u0259hl\u00fck\u0259y\u0259 m\u0259ruz qalm\u0131\u015f qov\u015faqlar\u0131 m\u00fc\u0259yy\u0259n ed\u0259c\u0259k v\u0259 g\u0259l\u0259c\u0259kd\u0259 infrastrukturu ox\u015far h\u00fccumlardan qoruyacaq.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Az\u0259rbaycanda Microsoft SQL Server-d\u0259n istifad\u0259 edil\u0259n h\u00fccumlar\u0131n say\u0131nda art\u0131m m\u00fc\u015fahid\u0259 olunub Kaspersky-nin m\u0259lumat\u0131na g\u00f6r\u0259, Az\u0259rbaycanda Microsoft SQL Server-d\u0259n istifad\u0259 vasit\u0259sil\u0259 h\u0259yata ke\u00e7iril\u0259n h\u00fccumlar\u0131n say\u0131 artmaqdad\u0131r: m\u0259s\u0259l\u0259n, bu ilin avqustundan sentyabr ay\u0131na kimi onun aktivliyind\u0259 art\u0131m&#8230;<\/p>\n","protected":false},"author":2,"featured_media":5369,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/5368"}],"collection":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5368"}],"version-history":[{"count":1,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/5368\/revisions"}],"predecessor-version":[{"id":5370,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/5368\/revisions\/5370"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/media\/5369"}],"wp:attachment":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}