ืขื“ื›ืŸ ืืช RouterOS ื‘-MikroTik ืฉืœืš

ืขื“ื›ืŸ ืืช RouterOS ื‘-MikroTik ืฉืœืš
ื‘ืขืจื‘ ื”-10 ื‘ืžืจืฅ, ืฉื™ืจื•ืช ื”ืชืžื™ื›ื” ืฉืœ Mail.ru ื”ื—ืœ ืœืงื‘ืœ ืชืœื•ื ื•ืช ืžืžืฉืชืžืฉื™ื ืขืœ ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ืชื—ื‘ืจ ืœืฉืจืชื™ IMAP/SMTP ืฉืœ Mail.ru ื‘ืืžืฆืขื•ืช ืชื•ื›ื ื•ืช ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™. ื™ื—ื“ ืขื ื–ืืช, ื—ืœืง ืžื”ื—ื™ื‘ื•ืจื™ื ืœื ืขื‘ืจื•, ื•ื—ืœืง ืžืจืื™ื ืฉื’ื™ืืช ืื™ืฉื•ืจ. ื”ืฉื’ื™ืื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”"ืฉืจืช" ืฉืžื ืคื™ืง ืื™ืฉื•ืจ TLS ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช.
 
ืขื“ื›ืŸ ืืช RouterOS ื‘-MikroTik ืฉืœืš
ื‘ืžืฉืš ื™ื•ืžื™ื™ื, ื™ื•ืชืจ ืž-10 ืชืœื•ื ื•ืช ื”ื’ื™ืขื• ืžืžืฉืชืžืฉื™ื ื‘ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืจืฉืชื•ืช ื•ืขื ืžื’ื•ื•ืŸ ืžื›ืฉื™ืจื™ื, ืžื” ืฉื”ื•ืคืš ืืช ื–ื” ืœื ืกื‘ื™ืจ ืฉื”ื‘ืขื™ื” ื”ื™ื™ืชื” ื‘ืจืฉืช ืฉืœ ืกืคืง ืื—ื“. ื ื™ืชื•ื— ืžืคื•ืจื˜ ื™ื•ืชืจ ืฉืœ ื”ื‘ืขื™ื” ื’ื™ืœื” ืฉืฉืจืช imap.mail.ru (ื›ืžื• ื’ื ืฉืจืชื™ ื“ื•ืืจ ื•ืฉื™ืจื•ืชื™ื ืื—ืจื™ื) ืžื•ื—ืœืฃ ื‘ืจืžืช ื”-DNS. ื™ืชืจื” ืžื›ืš, ื‘ืขื–ืจืชื ื”ืคืขื™ืœื” ืฉืœ ื”ืžืฉืชืžืฉื™ื ืฉืœื ื•, ืžืฆืื ื• ืฉื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื™ืชื” ื›ื ื™ืกื” ืฉื’ื•ื™ื” ื‘ืžื˜ืžื•ืŸ ืฉืœ ื”ื ืชื‘ ืฉืœื”ื, ืฉื”ื•ื ื’ื ืคื•ืชืจ DNS ืžืงื•ืžื™, ื•ืืฉืจ ื‘ืžืงืจื™ื ืจื‘ื™ื (ืืš ืœื ื‘ื›ื•ืœื) ื”ืชื‘ืจืจ ื›-MikroTik. ืžื›ืฉื™ืจ, ืคื•ืคื•ืœืจื™ ืžืื•ื“ ื‘ืจืฉืชื•ืช ืืจื’ื•ื ื™ื•ืช ืงื˜ื ื•ืช ื•ืžืกืคืงื™ ืื™ื ื˜ืจื ื˜ ืงื˜ื ื™ื.

ืžื” ื”ื‘ืขื™ื”

ื‘ืกืคื˜ืžื‘ืจ 2019, ื—ื•ืงืจื™ื ืžืฆืืชื™ ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-MikroTik RouterOS (CVE-2019-3976, CVE-2019-3977, CVE-2019-3978, CVE-2019-3979), ืฉืืคืฉืจื• ื”ืชืงืคืช ื”ืจืขืœืช ืžื˜ืžื•ืŸ DNS, ื›ืœื•ืžืจ. ื”ื™ื›ื•ืœืช ืœื–ื™ื™ืฃ ืจืฉื•ืžื•ืช DNS ื‘ืžื˜ืžื•ืŸ ื”-DNS ืฉืœ ื”ื ืชื‘, ื•-CVE-2019-3978 ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื ืœื—ื›ื•ืช ืฉืžื™ืฉื”ื• ืžื”ืจืฉืช ื”ืคื ื™ืžื™ืช ื™ื‘ืงืฉ ื›ื ื™ืกื” ื‘ืฉืจืช ื”-DNS ืฉืœื• ื›ื“ื™ ืœื”ืจืขื™ืœ ืืช ืžื˜ืžื•ืŸ ื”ืคื•ืชืจ, ืืœื ืœื™ื–ื•ื ื›ื–ื” ื‘ืงืฉื” ื‘ืขืฆืžื• ื“ืจืš ื”ื™ืฆื™ืื” 8291 (UDP ื•-TCP). ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ืขืœ ื™ื“ื™ MikroTik ื‘ื’ืจืกืื•ืช ืฉืœ RouterOS 6.45.7 (ื™ืฆื™ื‘) ื•-6.44.6 (ืœื˜ื•ื•ื— ืืจื•ืš) ื‘-28 ื‘ืื•ืงื˜ื•ื‘ืจ 2019, ืืš ืขืœ ืคื™ ืžื—ืงืจ ืจื•ื‘ ื”ืžืฉืชืžืฉื™ื ืœื ื”ืชืงื™ื ื• ื›ืจื’ืข ืชื™ืงื•ื ื™ื.

ื‘ืจื•ืจ ืฉื”ื‘ืขื™ื” ื”ื–ื• ืžื ื•ืฆืœืช ื›ืขืช ื‘ืื•ืคืŸ ืคืขื™ืœ "ื—ื™".

ืœืžื” ื–ื” ืžืกื•ื›ืŸ

ืชื•ืงืฃ ื™ื›ื•ืœ ืœื–ื™ื™ืฃ ืืช ืจืฉื•ืžืช ื”-DNS ืฉืœ ื›ืœ ืžืืจื— ืฉืืœื™ื• ืžืฉืชืžืฉ ืžืฉืชืžืฉ ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช, ื•ื‘ื›ืš ืœื™ื™ืจื˜ ืชืขื‘ื•ืจื” ืืœื™ื•. ืื ืžื™ื“ืข ืจื’ื™ืฉ ืžื•ืขื‘ืจ ืœืœื ื”ืฆืคื ื” (ืœื“ื•ื’ืžื”, ื“ืจืš http:// ืœืœื TLS) ืื• ืฉื”ืžืฉืชืžืฉ ืžืกื›ื™ื ืœืงื‘ืœ ืชืขื•ื“ื” ืžื–ื•ื™ืคืช, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ืืช ื›ืœ ื”ื ืชื•ื ื™ื ืฉื ืฉืœื—ื™ื ื“ืจืš ื”ื—ื™ื‘ื•ืจ, ื›ื’ื•ืŸ ื›ื ื™ืกื” ืื• ืกื™ืกืžื”. ืœืžืจื‘ื” ื”ืฆืขืจ, ื”ืชืจื’ื•ืœ ืžืจืื” ืฉืื ืœืžืฉืชืžืฉ ื™ืฉ ื”ื–ื“ืžื ื•ืช ืœืงื‘ืœ ืชืขื•ื“ื” ืžื–ื•ื™ืคืช, ื”ื•ื ื™ื ืฆืœ ืื•ืชื”.

ืœืžื” ืฉืจืชื™ SMTP ื•-IMAP, ื•ืžื” ื”ืฆื™ืœ ืžืฉืชืžืฉื™ื

ืžื“ื•ืข ื ื™ืกื• ื”ืชื•ืงืคื™ื ืœื™ื™ืจื˜ ืชืขื‘ื•ืจืช SMTP/IMAP ืฉืœ ื™ื™ืฉื•ืžื™ ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™, ื•ืœื ืชืขื‘ื•ืจืช ืื™ื ื˜ืจื ื˜, ืœืžืจื•ืช ืฉืจื•ื‘ ื”ืžืฉืชืžืฉื™ื ื ื™ื’ืฉื™ื ืœื“ื•ืืจ ืฉืœื”ื ื“ืจืš ื“ืคื“ืคืŸ HTTPS?

ืœื ื›ืœ ืชื•ื›ื ื•ืช ื”ื“ื•ืืจ ื”ืืœืงื˜ืจื•ื ื™ ื”ืคื•ืขืœื•ืช ื‘ืืžืฆืขื•ืช SMTP ื•-IMAP/POP3 ืžื’ื ื•ืช ืขืœ ื”ืžืฉืชืžืฉ ืžืคื ื™ ืฉื’ื™ืื•ืช, ื•ืžื•ื ืขื•ืช ืžืžื ื• ืœืฉืœื•ื— ื›ื ื™ืกื” ื•ืกื™ืกืžื” ื“ืจืš ื—ื™ื‘ื•ืจ ืœื ืžืื•ื‘ื˜ื— ืื• ื ืคื•ืฅ, ืื ื›ื™ ืœืคื™ ื”ืชืงืŸ RFC 8314, ืฉืื•ืžืฆื• ืขื•ื“ ื‘ืฉื ืช 2018 (ื•ื™ื•ืฉืžื• ื‘-Mail.ru ื”ืจื‘ื” ืงื•ื“ื ืœื›ืŸ), ื”ื ื—ื™ื™ื‘ื™ื ืœื”ื’ืŸ ืขืœ ื”ืžืฉืชืžืฉ ืžืคื ื™ ื™ื™ืจื•ื˜ ืกื™ืกืžื” ื“ืจืš ื›ืœ ื—ื™ื‘ื•ืจ ืœื ืžืื•ื‘ื˜ื—. ื‘ื ื•ืกืฃ, ืคืจื•ื˜ื•ืงื•ืœ OAuth ื ืžืฆื ื‘ืฉื™ืžื•ืฉ ื ื“ื™ืจ ืžืื•ื“ ื‘ืœืงื•ื—ื•ืช ื“ื•ื"ืœ (ื”ื•ื ื ืชืžืš ืขืœ ื™ื“ื™ ืฉืจืชื™ ื“ื•ืืจ Mail.ru), ื•ื‘ืœืขื“ื™ื•, ื”ื›ื ื™ืกื” ื•ื”ืกื™ืกืžื” ืžื•ืขื‘ืจื•ืช ื‘ื›ืœ ื”ืคืขืœื”.

ื“ืคื“ืคื ื™ื ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ืžื•ื’ื ื™ื ืžืขื˜ ื™ื•ืชืจ ืžืคื ื™ ื”ืชืงืคื•ืช Man-in-the-Middle. ื‘ื›ืœ ื”ื“ื•ืžื™ื™ื ื™ื ื”ืงืจื™ื˜ื™ื™ื ืฉืœ mail.ru, ื‘ื ื•ืกืฃ ืœ-HTTPS, ืžื“ื™ื ื™ื•ืช HSTS (HTTP strict transport security) ืžื•ืคืขืœืช. ื›ืืฉืจ HSTS ืžื•ืคืขืœ, ื“ืคื“ืคืŸ ืžื•ื“ืจื ื™ ืื™ื ื• ื ื•ืชืŸ ืœืžืฉืชืžืฉ ืืคืฉืจื•ืช ืงืœื” ืœืงื‘ืœ ืชืขื•ื“ื” ืžื–ื•ื™ืคืช, ื’ื ืื ื”ืžืฉืชืžืฉ ื™ืจืฆื” ื‘ื›ืš. ื‘ื ื•ืกืฃ ืœ-HSTS, ืžืฉืชืžืฉื™ื ื ื™ืฆืœื• ืขืœ ื™ื“ื™ ื”ืขื•ื‘ื“ื” ืฉืžืื– 2017, ืฉืจืชื™ SMTP, IMAP ื•-POP3 ืฉืœ Mail.ru ืื•ืกืจื™ื ืขืœ ื”ืขื‘ืจืช ืกื™ืกืžืื•ืช ื‘ื—ื™ื‘ื•ืจ ืœื ืžืื•ื‘ื˜ื—, ื›ืœ ื”ืžืฉืชืžืฉื™ื ืฉืœื ื• ื”ืฉืชืžืฉื• ื‘-TLS ืœื’ื™ืฉื” ื“ืจืš SMTP, POP3 ื•-IMAP, ื•ื›ืŸ ืœื›ืŸ ื”ืชื—ื‘ืจื•ืช ื•ื”ืกื™ืกืžื” ื™ื›ื•ืœื•ืช ืœื™ื™ืจื˜ ืจืง ืื ื”ืžืฉืชืžืฉ ืขืฆืžื• ืžืกื›ื™ื ืœืงื‘ืœ ืืช ื”ืื™ืฉื•ืจ ื”ืžื–ื•ื™ืฃ.

ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื ื™ื™ื“ื™ื, ืื ื• ืชืžื™ื“ ืžืžืœื™ืฆื™ื ืœื”ืฉืชืžืฉ ื‘ื™ื™ืฉื•ืžื™ Mail.ru ื›ื“ื™ ืœื’ืฉืช ืœื“ื•ืืจ, ื›ื™... ืขื‘ื•ื“ื” ืขื ื“ื•ืืจ ื‘ืชื•ื›ื ื‘ื˜ื•ื—ื” ื™ื•ืชืจ ืžืืฉืจ ื‘ื“ืคื“ืคื ื™ื ืื• ื‘ืœืงื•ื—ื•ืช SMTP/IMAP ืžื•ื‘ื ื™ื.

ืžื” ืฆืจื™ืš ืœืขืฉื•ืช

ื™ืฉ ืฆื•ืจืš ืœืขื“ื›ืŸ ืืช ื”ืงื•ืฉื—ื” ืฉืœ MikroTik RouterOS ืœื’ืจืกื” ืžืื•ื‘ื˜ื—ืช. ืื ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ื–ื” ืœื ืืคืฉืจื™, ื™ืฉ ืฆื•ืจืš ืœืกื ืŸ ืชืขื‘ื•ืจื” ื‘ืคื•ืจื˜ 8291 (tcp ื•-udp), ื–ื” ื™ืกื‘ืš ืืช ื ื™ืฆื•ืœ ื”ื‘ืขื™ื”, ืื ื›ื™ ื–ื” ืœื ื™ื‘ื˜ืœ ืืช ื”ืืคืฉืจื•ืช ืฉืœ ื”ื–ืจืงื” ืคืกื™ื‘ื™ืช ืœืžื˜ืžื•ืŸ ื”-DNS. ืกืคืงื™ ืฉื™ืจื•ืชื™ ืื™ื ื˜ืจื ื˜ ืฆืจื™ื›ื™ื ืœืกื ืŸ ืืช ื”ื™ืฆื™ืื” ื”ื–ื• ื‘ืจืฉืชื•ืช ืฉืœื”ื ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ืžืฉืชืžืฉื™ื ืืจื’ื•ื ื™ื™ื. 

ื›ืœ ื”ืžืฉืชืžืฉื™ื ืฉืงื™ื‘ืœื• ืื™ืฉื•ืจ ื—ืœื•ืคื™ ืฆืจื™ื›ื™ื ืœืฉื ื•ืช ื‘ื“ื—ื™ืคื•ืช ืืช ื”ืกื™ืกืžื” ืœืื™ืžื™ื™ืœ ื•ืœืฉื™ืจื•ืชื™ื ืื—ืจื™ื ืฉืขื‘ื•ืจื ืื™ืฉื•ืจ ื–ื” ื”ืชืงื‘ืœ. ืžืฆื™ื“ื ื•, ื ื•ื“ื™ืข ืœืžืฉืชืžืฉื™ื ืฉื ื™ื’ืฉื™ื ืœื“ื•ืืจ ื“ืจืš ืžื›ืฉื™ืจื™ื ืคื’ื™ืขื™ื.

ื .ื‘. ื™ืฉื ื” ื’ื ืคื’ื™ืขื•ืช ืงืฉื•ืจื” ื”ืžืชื•ืืจืช ื‘ืคื•ืกื˜ ืœื•ืงื” ืกืคื•ื ื•ื‘ "ืคื’ื™ืขื•ืช ืฉืœ ื™ืฆื™ืื•ืช ืื—ื•ืจื™ื•ืช ื‘-RouterOS ืžืกื›ื ืช ืžืื•ืช ืืœืคื™ ืžื›ืฉื™ืจื™ื".

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”