ืคื’ื™ืขื•ืช ื‘-Rsync ื”ืžืืคืฉืจืช ื”ื—ืœืคืช ืงื‘ืฆื™ื ื‘ืฆื“ ื”ืœืงื•ื—

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2022-29154) ื‘-rsync, ื›ืœื™ ืขื–ืจ ืœืกื ื›ืจื•ืŸ ื•ื’ื™ื‘ื•ื™ ืงื‘ืฆื™ื, ื”ืžืืคืฉืจ ืœื›ืชื•ื‘ ืื• ืœื“ืจื•ืก ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืกืคืจื™ื™ืช ื”ื™ืขื“ ื‘ืฆื“ ื”ืžืฉืชืžืฉ ื‘ืขืช ื’ื™ืฉื” ืœืฉืจืช rsync ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ืคื•ื˜ื ืฆื™ืืœื™ืช, ื”ืžืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ื’ื ื›ืชื•ืฆืื” ืžื”ืคืจืขื” (MITM) ื‘ืชืขื‘ื•ืจืช ืžืขื‘ืจ ื‘ื™ืŸ ื”ืœืงื•ื— ืœืฉืจืช ื”ืœื’ื™ื˜ื™ืžื™. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจืช ื”ืžื‘ื—ืŸ ืฉืœ Rsync 3.2.5pre1.

ื”ืคื’ื™ืขื•ืช ืžื–ื›ื™ืจื” ื‘ืขื™ื•ืช ืงื•ื“ืžื•ืช ื‘-SCP ื•ื”ื™ื ื ื’ืจืžืช ื’ื ืžื›ืš ืฉื”ืฉืจืช ืžืงื‘ืœ ื”ื—ืœื˜ื” ืœื’ื‘ื™ ืžื™ืงื•ื ื”ืงื•ื‘ืฅ ืฉื™ื™ื›ืชื‘, ื•ื”ืœืงื•ื— ืœื ื‘ื•ื“ืง ื ื›ื•ืŸ ืžื” ื”ืฉืจืช ืžื—ื–ื™ืจ ืขื ืžื” ืฉื”ืชื‘ืงืฉ, ืžื” ืฉืžืืคืฉืจ ืœืฉืจืช ืœื›ืชื•ื‘ ืงื‘ืฆื™ื ืฉืœื ื‘ื™ืงืฉื• ื‘ืžืงื•ืจ ืขืœ ื™ื“ื™ ื”ืœืงื•ื—. ืœื“ื•ื’ืžื”, ืื ืžืฉืชืžืฉ ืžืขืชื™ืง ืงื‘ืฆื™ื ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช, ื”ืฉืจืช ืขืฉื•ื™ ืœื”ื—ื–ื™ืจ ืงื‘ืฆื™ื ื‘ืฉื .bash_aliases ืื• .ssh/authorized_keys ื‘ืžืงื•ื ื”ืงื‘ืฆื™ื ื”ืžื‘ื•ืงืฉื™ื, ื•ื”ื ื™ืื•ื—ืกื ื• ื‘ืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”