ืคื’ื™ืขื•ืช ื‘ื˜ืœื•ื•ื™ื–ื™ื•ืช ื—ื›ืžื•ืช Supra ื”ืžืืคืฉืจืช ืœื”ืฆื™ื’ ื•ื™ื“ืื• ืคื™ืงื˜ื™ื‘ื™

ื‘ื˜ืœื•ื•ื™ื–ื™ื•ืช Supra Smart Cloud ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช (CVE-2019-12477) ื”ืžืืคืฉืจืช ืœืš ืœื”ื—ืœื™ืฃ ืืช ื”ืชื•ื›ื ื™ืช ื”ื ืฆืคื™ืช ื›ืขืช ื‘ืชื•ื›ืŸ ืฉืœ ื”ืชื•ืงืฃ. ื›ื“ื•ื’ืžื”, ืžื•ื“ื’ื ื”ืคืœื˜ ืฉืœ ืื–ื”ืจื” ืคื™ืงื˜ื™ื‘ื™ืช ืขืœ ืžืฆื‘ ื—ื™ืจื•ื.


ืœื”ืชืงืคื”, ืžืกืคื™ืง ืœืฉืœื•ื— ื‘ืงืฉืช ืจืฉืช ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ ืฉืื™ื ื” ื“ื•ืจืฉืช ืื™ืžื•ืช. ื‘ืคืจื˜, ืชื•ื›ืœ ืœื’ืฉืช ืœืžื˜ืคืœ "/remote/media_control?action=setUri&uri=" ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื›ืชื•ื‘ืช ื”ืืชืจ ืฉืœ ืงื•ื‘ืฅ m3u8 ืขื ืคืจืžื˜ืจื™ ื•ื™ื“ืื•, ืœื“ื•ื’ืžื” "http://192.168.1.155/remote/media_control?action=setUri&uri= http://attacker .com/fake_broadcast_message.m3u8."

ื‘ืจื•ื‘ ื”ืžืงืจื™ื, ื”ื’ื™ืฉื” ืœื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ื˜ืœื•ื•ื™ื–ื™ื” ืžื•ื’ื‘ืœืช ืœืจืฉืช ื”ืคื ื™ืžื™ืช, ืืš ืžื›ื™ื•ื•ืŸ ืฉื”ื‘ืงืฉื” ื ืฉืœื—ืช ื‘ืืžืฆืขื•ืช HTTP, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ื•ืช ืœื’ื™ืฉื” ืœืžืฉืื‘ื™ื ืคื ื™ืžื™ื™ื ื›ืืฉืจ ื”ืžืฉืชืžืฉ ืคื•ืชื— ื“ืฃ ื—ื™ืฆื•ื ื™ ืฉืขื•ืฆื‘ ื‘ืžื™ื•ื—ื“ (ืœื“ื•ื’ืžื”, ืชื—ืช ื‘ืžืกื•ื•ื” ืฉืœ ื‘ืงืฉืช ืชืžื•ื ื” ืื• ืฉื™ืžื•ืฉ ื‘- ืงื™ืฉื•ืจ DNS ืžื—ื“ืฉ).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”