ืคื’ื™ืขื•ืช ื‘ื›ืจื•ื ื™

ะ’ ื›ืจื•ื ื™ื”, ื™ื™ืฉื•ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ NTP ื”ืžืฉืžืฉ ืœืกื ื›ืจื•ืŸ ื–ืžืŸ ืžื“ื•ื™ืง ื‘ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ืฉื•ื ื•ืช, ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช (CVE-2020-14367), ืžื” ืฉืžืืคืฉืจ ืœืš ืœื”ื—ืœื™ืฃ ื›ืœ ืงื•ื‘ืฅ ื‘ืžืขืจื›ืช ืขื ื’ื™ืฉื” ืœื›ืจื•ื ื™ ื”ืžืฉืชืžืฉ ื”ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืจืง ื‘ืืžืฆืขื•ืช ื›ืจื•ื ื™ ื”ืžืฉืชืžืฉ, ืžื” ืฉืžืคื—ื™ืช ืืช ื”ืกื›ื ื” ืฉืœื”. ืขื ื–ืืช, ื”ื‘ืขื™ื” ืคื•ื’ืขืช ื‘ืจืžืช ื”ื‘ื™ื“ื•ื“ ื‘ื›ืจื•ื ื™ ื•ืขืœื•ืœื” ืœื”ื™ื•ืช ืžื ื•ืฆืœืช ืื ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช ืื—ืจืช ื‘ืงื•ื“ ื”ืžื•ืคืขืœ ืœืื—ืจ ืื™ืคื•ืก ื”ื”ืจืฉืื•ืช.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ื›ืชื•ืฆืื” ืžื™ืฆื™ืจื” ืœื ื‘ื˜ื•ื—ื” ืฉืœ ืงื•ื‘ืฅ pid, ืฉื ื•ืฆืจ ื‘ืฉืœื‘ ืฉื‘ื• chrony ืขื“ื™ื™ืŸ ืœื ืื™ืคืก ื”ืจืฉืื•ืช ื•ืคืขืœ ื›-root. ื‘ืžืงืจื” ื–ื”, ืกืคืจื™ื™ืช /run/chrony, ื‘ื” ื ื›ืชื‘ ืงื•ื‘ืฅ pid, ื ื•ืฆืจื” ืขื ื–ื›ื•ื™ื•ืช 0750 ื‘ืืžืฆืขื•ืช systemd-tmpfiles ืื• ื›ืืฉืจ chronyd ื”ื•ืฉืงื” ื‘ืฉื™ืชื•ืฃ ืขื ื”ืžืฉืชืžืฉ ื•ื”ืงื‘ื•ืฆื” "chrony". ืœืคื™ื›ืš, ืื ื™ืฉ ืœืš ื’ื™ืฉื” ืœ-user chrony, ืืคืฉืจ ืœื”ื—ืœื™ืฃ ืืช ืงื•ื‘ืฅ pid /run/chrony/chronyd.pid ื‘ืงื™ืฉื•ืจ ืกืžืœื™. ืงื™ืฉื•ืจ ืกืžืœื™ ื™ื›ื•ืœ ืœื”ืฆื‘ื™ืข ืขืœ ื›ืœ ืงื•ื‘ืฅ ืžืขืจื›ืช ืฉื™ื•ื—ืœืฃ ื‘ืขืช ื”ืคืขืœืช chronyd.

root# systemctl stop chronyd.service
root# sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
ื™ืฆื™ืื” chrony$

root# /usr/sbin/chronyd -n
^C
# ื‘ืžืงื•ื ื”ืชื•ื›ืŸ ืฉืœ /etc/shadow, ืžื–ื”ื” ื”ืชื”ืœื™ืš ืฉืœ chronyd ื™ื™ืฉืžืจ
root# cat /etc/shadow
15287

ืคื’ื™ืขื•ืช ื—ื•ืกืœื• ื‘ืกื•ื’ื™ื” ื›ืจื•ื ื™ 3.5.1. ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื•ืช ืฉืžืชืงื ื™ื ืืช ื”ืคื’ื™ืขื•ืช ื–ืžื™ื ื™ื ืขื‘ื•ืจ ืคื“ื•ืจื”. ื‘ืชื”ืœื™ืš ื”ื›ื ืช ืขื“ื›ื•ืŸ ืขื‘ื•ืจ ืจื”ืœ, ื“ื‘ื™ืืŸ ะธ ืื•ื‘ื•ื ื˜ื•.

ื‘ืขื™ื™ืช SUSE ื•-openSUSE ืœื ืจื’ื™ืฉื™ื, ืžื›ื™ื•ื•ืŸ ืฉื”ืงื™ืฉื•ืจ ื”ืกื™ืžื‘ื•ืœื™ ืขื‘ื•ืจ chrony ื ื•ืฆืจ ื™ืฉื™ืจื•ืช ื‘ืกืคืจื™ื™ืช /run, ืœืœื ืฉื™ืžื•ืฉ ื‘ืกืคืจื™ื•ืช ืžืฉื ื” ื ื•ืกืคื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”