ื”ืฆืคืช ืžืื’ืจ ื‘-Toxcore ืžื ื•ืฆืœืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœืช UDP

ืœ-Toxcore, ื™ื™ืฉื•ื ื”ื™ื™ื—ื•ืก ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื”ื”ื•ื“ืขื•ืช Tox P2P, ื™ืฉ ืคื’ื™ืขื•ืช (CVE-2021-44847) ืฉืขืœื•ืœื” ืœื”ืคืขื™ืœ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื—ื‘ื™ืœืช UDP ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ื›ืœ ื”ืžืฉืชืžืฉื™ื ืฉืœ ื™ื™ืฉื•ืžื™ื ืžื‘ื•ืกืกื™ Toxcore ืฉืœื ืžื•ืฉื‘ืชื™ื ื‘ื”ื ืชื—ื‘ื•ืจื” UDP ืžื•ืฉืคืขื™ื ืžื”ืคื’ื™ืขื•ืช. ื›ื“ื™ ืœืชืงื•ืฃ, ืžืกืคื™ืง ืœืฉืœื•ื— ื—ื‘ื™ืœืช UDP ืœื“ืขืช ืืช ื›ืชื•ื‘ืช ื”-IP, ื™ืฆื™ืืช ื”ืจืฉืช ื•ืžืคืชื— ื”-DHT ื”ืฆื™ื‘ื•ืจื™ ืฉืœ ื”ืงื•ืจื‘ืŸ (ืžื™ื“ืข ื–ื” ื–ืžื™ืŸ ืœืฆื™ื‘ื•ืจ ื‘-DHT, ื›ืœื•ืžืจ, ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืขืœ ื›ืœ ืžืฉืชืžืฉ ืื• ืฆื•ืžืช DHT).

ื”ื‘ืขื™ื” ื”ื™ื™ืชื” ืงื™ื™ืžืช ื‘ืžื”ื“ื•ืจื•ืช toxcore 0.1.9 ืขื“ 0.2.12 ื•ืชื•ืงื ื” ื‘ื’ืจืกื” 0.2.13. ื‘ื™ืŸ ื™ื™ืฉื•ืžื™ ื”ืœืงื•ื—, ืจืง ืคืจื•ื™ืงื˜ qTox ืคืจืกื ืขื“ ื›ื” ืขื“ื›ื•ืŸ ืฉืžื‘ื˜ืœ ืืช ื”ืคื’ื™ืขื•ืช. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช UDP ืชื•ืš ืฉืžื™ืจื” ืขืœ ืชืžื™ื›ืช TCP.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” handle_request() ื”ืžืชืจื—ืฉืช ืขืงื‘ ื—ื™ืฉื•ื‘ ืฉื’ื•ื™ ืฉืœ ื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื‘ื—ื‘ื™ืœืช ืจืฉืช. ื‘ืื•ืคืŸ ืกืคืฆื™ืคื™, ืื•ืจืš ื”ื ืชื•ื ื™ื ื”ืžื•ืฆืคื ื™ื ื ืงื‘ืข ื‘ืžืืงืจื• CRYPTO_SIZE, ื”ืžื•ื’ื“ืจ ื›"1 + CRYPTO_PUBLIC_KEY_SIZE * 2 + CRYPTO_NONCE_SIZE", ืืฉืจ ืฉื™ืžืฉ ืœืื—ืจ ืžื›ืŸ ื‘ืคืขื•ืœืช ื”ื—ื™ืกื•ืจ "ืื•ืจืš - CRYPTO_SIZE". ื‘ื’ืœืœ ื”ื™ืขื“ืจ ืกื•ื’ืจื™ื™ื ื‘ืžืืงืจื•, ื‘ืžืงื•ื ืœื’ืจื•ืข ืืช ืกื›ื•ื ื›ืœ ื”ืขืจื›ื™ื, ื”ื•ื ื”ืคื—ื™ืช 1 ื•ื”ื•ืกื™ืฃ ืืช ื”ื—ืœืงื™ื ื”ื ื•ืชืจื™ื. ืœื“ื•ื’ืžื”, ื‘ืžืงื•ื "ืื•ืจืš - (1 + 32 * 2 + 24)", ื’ื•ื“ืœ ื”ืžืื’ืจ ื—ื•ืฉื‘ ื›"ืื•ืจืš - 1 + 32 * 2 + 24", ืžื” ืฉื”ื‘ื™ื ืœื”ื—ืœืคืช ื ืชื•ื ื™ื ืขืœ ื”ืžื—ืกื ื™ืช ืžืขื‘ืจ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”