{"id":103424,"date":"2022-02-24T15:36:49","date_gmt":"2022-02-24T13:36:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd"},"modified":"2022-02-24T15:36:49","modified_gmt":"2022-02-24T13:36:49","slug":"reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd","title":{"rendered":"Rilascio di OpenSSH 8.9 con correzione della vulnerabilit\u00e0 in sshd","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dopo sei mesi di sviluppo, \u00e8 stato presentato il rilascio di OpenSSH 8.9, un'implementazione open source di client e server per il protocollo SSH 2.0 e SFTP. Nella nuova versione \u00e8 stata corretta una vulnerabilit\u00e0 in sshd che potenzialmente permetteva l'accesso senza autenticazione. Il problema \u00e8 causato da un overflow intero nel codice di autenticazione, ma l'esploitazione \u00e8 possibile solo in combinazione con altri errori logici nel codice.    <\/p>\n<p> Nella sua forma attuale, la vulnerabilit\u00e0 non \u00e8 sfruttabile con l'attivazione della modalit\u00e0 di separazione dei privilegi, poich\u00e9 la sua manifestazione \u00e8 bloccata da controlli specifici eseguiti nel codice di monitoraggio della separazione dei privilegi. La modalit\u00e0 di separazione dei privilegi \u00e8 attivata di default dal 2002, a partire da OpenSSH 3.2.2, ed \u00e8 obbligatoria a partire dal rilascio di OpenSSH 7.5, pubblicato nel 2017. Inoltre, nelle versioni portabili di OpenSSH a partire dalla versione 6.5 (2014), la vulnerabilit\u00e0 \u00e8 bloccata dalla compilazione con l'attivazione dei flag di protezione contro gli overflow interi.       <\/p>\n<p>Altre modifiche:  <\/p>\n<ul>\n<li class=\"l\"> Nella versione portabile di OpenSSH, \u00e8 stata rimossa la supporto integrato per l'hashing delle password utilizzando l'algoritmo MD5 (\u00e8 consentito il collegamento a librerie esterne, come libxcrypt).\n<li class=\"l\"> In ssh, sshd, ssh-add and ssh-agent, a subsystem has been implemented to restrict the forwarding and usage of keys added to the ssh-agent. This subsystem allows you to set rules that define how and where keys can be used in ssh-agent. For example, to add a key that can only be used for authenticating any user connecting to the host scylla.example.org, user perseus to the host cetus.example.org, and user medea to the host charybdis.example.org with redirection through the intermediary host scylla.example.org, you can use the following command: $ ssh-add -h 'perseus@cetus.example.org' \\ -h 'scylla.example.org' \\ -h 'scylla.example.org&gt;medea@charybdis.example.org' \\ ~\/ .ssh\/id_ed25519\n<li class=\"l\"> In ssh and sshd, the list of KexAlgorithms, which defines the order of key exchange methods, has added a hybrid algorithm 'sntrup761x25519-sha512@openssh.com' (ECDH\/x25519 + NTRU Prime) by default, which is resilient against brute force attacks by quantum computers. In OpenSSH version 8.9, this negotiation method has been added between ECDH and DH methods, but it is planned to be used by default in the next release.\n<li class=\"l\"> In ssh-keygen, ssh e ssh-agent \u00e8 stata migliorata la gestione delle chiavi dei token FIDO utilizzati per la verifica del dispositivo, comprese le chiavi per l'autenticazione biometrica.\n<li class=\"l\"> In ssh-keygen, the command 'ssh-keygen -Y match-principals' has been added to check user names in the list of allowed names file.\n<li class=\"l\"> In ssh-add e ssh-agent \u00e8 stata fornita la possibilit\u00e0 di aggiungere chiavi FIDO protette da PIN nell'ssh-agent (la richiesta del PIN viene visualizzata al momento dell'autenticazione).\n<li class=\"l\"> In ssh-keygen \u00e8 stata consentita la scelta dell'algoritmo di hashing (sha512 o sha256) durante la generazione della firma.\n<li class=\"l\"> In ssh e sshd, per migliorare le prestazioni, \u00e8 stato implementato il caricamento diretto dei dati di rete nel buffer dei pacchetti in entrata, bypassando il buffering intermedio nello stack. Analogamente, \u00e8 stato realizzato il posizionamento diretto dei dati ricevuti nel buffer del canale.\n<li class=\"l\"> In ssh, nella direttiva PubkeyAuthentication, \u00e8 stata ampliata l'elenco dei parametri supportati (yes|no|unbound|host-bound) per fornire la possibilit\u00e0 di scegliere l'opzione di estensione del protocollo utilizzato.      <\/ul>\n<p>In uno dei prossimi rilasci, si prevede di passare per impostazione predefinita l'utilit\u00e0 scp all'uso di SFTP invece del protocollo obsoleto SCP\/RCP. In SFTP vengono utilizzati metodi di gestione dei nomi pi\u00f9 prevedibili e non viene effettuata la gestione dei modelli glob nei nomi dei file tramite shell sul lato di un altro host, che crea problemi di sicurezza. In particolare, quando si utilizza SCP e RCP, il server decide quali file e cartelle inviare al client, mentre il client controlla solo la correttezza dei nomi degli oggetti restituiti, il che, in assenza di controlli adeguati da parte del client, consente <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-shicago\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2906\">server<\/a> to pass other file names that differ from the requested ones. The SFTP protocol lacks the mentioned issues, but does not support revealing special paths such as '~\/'. To address this difference, in the previous release of OpenSSH, a new extension to the SFTP protocol was proposed to reveal the paths ~\/ and ~user\/.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56751\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.9, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u0412 \u043d\u043e\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432 sshd \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0431\u0435\u0437 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0446\u0435\u043b\u043e\u0447\u0438\u0441\u043b\u0435\u043d\u043d\u044b\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0432 \u043a\u043e\u0434\u0435 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0438 \u0441 \u0434\u0440\u0443\u0433\u0438\u043c\u0438 \u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0448\u0438\u0431\u043a\u0430\u043c\u0438 \u0432 \u043a\u043e\u0434\u0435. \u0412 \u0442\u0435\u043a\u0443\u0449\u0435\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103424","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.9, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 sshd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.9, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-02-24T13:36:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-02-24T13:36:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Rilascio di OpenSSH 8.9 con la correzione di una vulnerabilit\u00e0 in sshd | ProHoster","description":"Dopo sei mesi di sviluppo, \u00e8 stato presentato il rilascio di OpenSSH 8.9, un'implementazione open-source del client e del server per l'operativit\u00e0 su protocolli SSH 2.0 e SFTP.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.9 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 sshd | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.9, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-8-9-s-ustraneniem-uyazvimosti-v-sshd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-02-24T13:36:49+00:00","article:modified_time":"2022-02-24T13:36:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103424","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-02-24 13:37:31","updated":"2026-02-09 21:42:01","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103424"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103424\/revisions"}],"predecessor-version":[{"id":160186,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103424\/revisions\/160186"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}