DNSpooq - ืฉื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื—ื“ืฉื•ืช ื‘-dnsmasq

ืžื•ืžื—ื™ื ืžืžืขื‘ื“ื•ืช ื”ืžื—ืงืจ JSOF ื“ื™ื•ื•ื—ื• ืขืœ ืฉื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื—ื“ืฉื•ืช ื‘ืฉืจืช ื”-DNS/DHCP dnsmasq. ืฉืจืช dnsmasq ืคื•ืคื•ืœืจื™ ืžืื•ื“ ื•ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ืจื‘ื•ืช, ื›ืžื• ื’ื ื‘ืฆื™ื•ื“ ืจืฉืช ืฉืœ ืกื™ืกืงื•, Ubiquiti ื•ืื—ืจื•ืช. ืคื’ื™ืขื•ื™ื•ืช Dnspooq ื›ื•ืœืœื•ืช ื”ืจืขืœืช ืžื˜ืžื•ืŸ DNS ื•ื›ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง. ื”ืคื’ื™ืขื•ื™ื•ืช ืชื•ืงื ื• ื‘-dnsmasq 2.83.

ื‘ืฉื ืช 2008, ื—ื•ืงืจ ื”ืื‘ื˜ื—ื” ื”ื ื•ื“ืข ื“ืŸ ืงืžื™ื ืกืงื™ ื’ื™ืœื” ื•ื—ืฉืฃ ืคื’ื ืžื”ื•ืชื™ ื‘ืžื ื’ื ื•ืŸ ื”-DNS ืฉืœ ื”ืื™ื ื˜ืจื ื˜. ืงืžื™ื ืกืงื™ ื”ื•ื›ื™ื— ืฉืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœื–ื™ื™ืฃ ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ื•ืœื’ื ื•ื‘ ื ืชื•ื ื™ื. ื–ื” ื ื•ื“ืข ืžืื– ื›"ืžืชืงืคืช ืงืžื™ื ืกืงื™".

DNS ื ื—ืฉื‘ ืœืคืจื•ื˜ื•ืงื•ืœ ืœื ืžืื•ื‘ื˜ื— ื‘ืžืฉืš ืขืฉืจื•ืช ืฉื ื™ื, ืื ื›ื™ ื”ื•ื ืืžื•ืจ ืœื”ื‘ื˜ื™ื— ืจืžื” ืžืกื•ื™ืžืช ืฉืœ ื™ื•ืฉืจื”. ืžืกื™ื‘ื” ื–ื• ืขื“ื™ื™ืŸ ืžืกืชืžื›ื™ื ืขืœื™ื• ืžืื•ื“. ื‘ืžืงื‘ื™ืœ ืคื•ืชื—ื• ืžื ื’ื ื•ื ื™ื ืœืฉื™ืคื•ืจ ื”ืื‘ื˜ื—ื” ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื”-DNS ื”ืžืงื•ืจื™. ืžื ื’ื ื•ื ื™ื ืืœื” ื›ื•ืœืœื™ื HTTPS, HSTS, DNSSEC ื•ื™ื•ื–ืžื•ืช ืื—ืจื•ืช. ืขื ื–ืืช, ืืคื™ืœื• ืขื ื›ืœ ื”ืžื ื’ื ื•ื ื™ื ื”ืœืœื•, ื—ื˜ื™ืคืช DNS ื”ื™ื ืขื“ื™ื™ืŸ ืžืชืงืคื” ืžืกื•ื›ื ืช ื‘ืฉื ืช 2021. ื—ืœืง ื’ื“ื•ืœ ืžื”ืื™ื ื˜ืจื ื˜ ืขื“ื™ื™ืŸ ืžืกืชืžืš ืขืœ DNS ื‘ืื•ืชื• ืื•ืคืŸ ืฉื‘ื• ืขืฉื” ื–ืืช ื‘-2008, ื•ื”ื•ื ืจื’ื™ืฉ ืœืื•ืชื ืกื•ื’ื™ ื”ืชืงืคื•ืช.

ืคื’ื™ืขื•ื™ื•ืช ืฉืœ ื”ืจืขืœืช ืžื˜ืžื•ืŸ DNSpooq:
CVE-2020-25686, CVE-2020-25684, CVE-2020-25685. ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืืœื• ื“ื•ืžื•ืช ืœื”ืชืงืคื•ืช DNS SAD ืฉื“ื•ื•ื—ื• ืœืื—ืจื•ื ื” ืขืœ ื™ื“ื™ ื—ื•ืงืจื™ื ืžืื•ื ื™ื‘ืจืกื™ื˜ืช ืงืœื™ืคื•ืจื ื™ื” ื•ืžืื•ื ื™ื‘ืจืกื™ื˜ืช Tsinghua. ื ื™ืชืŸ ืœืฉืœื‘ ื’ื ืคื’ื™ืขื•ื™ื•ืช DNS ื•-DNSpooq SAD ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ื”ืชืงืคื•ืช. ื”ืชืงืคื•ืช ื ื•ืกืคื•ืช ืขื ื”ืฉืœื›ื•ืช ืœื ื‘ืจื•ืจื•ืช ื“ื•ื•ื—ื• ื’ื ืขืœ ื™ื“ื™ ืžืืžืฆื™ื ืžืฉื•ืชืคื™ื ืฉืœ ืื•ื ื™ื‘ืจืกื™ื˜ืื•ืช (Poison Over Troubled Forwarders ื•ื›ื•').
ืคื’ื™ืขื•ื™ื•ืช ืคื•ืขืœื•ืช ืขืœ ื™ื“ื™ ื”ืคื—ืชืช ืื ื˜ืจื•ืคื™ื”. ืขืงื‘ ื”ืฉื™ืžื•ืฉ ื‘-hash ื—ืœืฉ ืœื–ื™ื”ื•ื™ ื‘ืงืฉื•ืช DNS ื•ื”ื”ืชืืžื” ื”ืœื ืžื“ื•ื™ืงืช ืฉืœ ื”ื‘ืงืฉื” ืœืชื’ื•ื‘ื”, ื ื™ืชืŸ ืœื”ืคื—ื™ืช ืžืื•ื“ ืืช ื”ืื ื˜ืจื•ืคื™ื” ื•ื™ืฉ ืœื ื—ืฉ ืจืง ~19 ืกื™ื‘ื™ื•ืช, ืžื” ืฉืžืืคืฉืจ ื”ืจืขืœืช ืžื˜ืžื•ืŸ. ื”ื“ืจืš ืฉื‘ื” dnsmasq ืžืขื‘ื“ ืจืฉื•ืžื•ืช CNAME ืžืืคืฉืจืช ืœื• ืœื–ื™ื™ืฃ ืฉืจืฉืจืช ืฉืœ ืจืฉื•ืžื•ืช CNAME ื•ืœืžืขืฉื” ืœื”ืจืขื™ืœ ืขื“ 9 ืจืฉื•ืžื•ืช DNS ื‘ื›ืœ ืคืขื.

ืคืจืฆื•ืช ื”ืฆืคืช ืžืื’ืจ: CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, CVE-2020-25681. ื›ืœ 4 ื”ืคื’ื™ืขื•ื™ื•ืช ืฉืฆื•ื™ื ื• ืงื™ื™ืžื•ืช ื‘ืงื•ื“ ืขื ื™ื™ืฉื•ื DNSSEC ื•ืžื•ืคื™ืขื•ืช ืจืง ื›ืืฉืจ ื‘ื“ื™ืงื” ื‘ืืžืฆืขื•ืช DNSSEC ืžื•ืคืขืœืช ื‘ื”ื’ื“ืจื•ืช.

ืžืงื•ืจ: linux.org.ru