ืคื’ื™ืขื•ืช ืœื™ื‘ื” Linux, ื”ืžืืคืฉืจ ืœืš ืœืขืงื•ืฃ ืืช ื”ืžื’ื‘ืœื•ืช ืฉืœ ืžืฆื‘ ื ืขื™ืœื”

ื‘ืœื™ื‘ืช Linux ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2022-21505) ื”ืžืืคืฉืจืช ืขืงื™ืคื” ืงืœื” ืฉืœ ืžื ื’ื ื•ืŸ ื”ื”ื’ื ื” Lockdown, ืืฉืจ ืžื’ื‘ื™ืœ ืืช ื’ื™ืฉืช ืžืฉืชืžืฉื™ root ืœืœื™ื‘ื” ื•ื—ื•ืกื ืขืงื™ืคื•ืช ืฉืœ UEFI Secure Boot. ื”ืขืงื™ืคื” ื”ืžื•ืฆืขืช ื›ื•ืœืœืช ืฉื™ืžื•ืฉ ื‘ืชืช-ืžืขืจื›ืช ื”ืœื™ื‘ื” IMA (Integrity Measurement Architecture), ืืฉืจ ื ื•ืขื“ื” ืœืืžืช ืืช ืฉืœืžื•ืช ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื•-hashes.

ืžืฆื‘ ื ืขื™ืœื” ืžื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœ-/dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes mode debug, mmiotrace, tracefs, BPF, PCMCIA CIS (ืžื‘ื ื” ืžื™ื“ืข ื›ืจื˜ื™ืก), ื›ืžื” ืžืžืฉืงื™ ACPI ื•-CPU ืื•ื’ืจื™ MSR, ืฉื™ื—ื•ืช kexec_file ื•-kexec_load ื—ืกื•ืžื•ืช, ืžืฆื‘ ืฉื™ื ื” ืืกื•ืจ, ื”ืฉื™ืžื•ืฉ ื‘-DMA ืขื‘ื•ืจ ื”ืชืงื ื™ PCI ืžื•ื’ื‘ืœ, ื™ื‘ื•ื ืงื•ื“ ACPI ืžืžืฉืชื ื™ EFI ืืกื•ืจ, ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื™ืฆื™ืื•ืช I/O ืื™ื ืŸ ืžื•ืชืจื•ืช, ื›ื•ืœืœ ืฉื™ื ื•ื™ ืžืกืคืจ ื”ืคืกื™ืงื” ื•ื™ืฆื™ืื” I /O ืขื‘ื•ืจ ื™ืฆื™ืื” ื˜ื•ืจื™ืช.

ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ืคืจืžื˜ืจ ื”ืืชื—ื•ืœ "ima_appraise=log", ืืคืฉืจ ืœืงืจื•ื ืœ-kexec ื›ื“ื™ ืœื˜ืขื•ืŸ ืขื•ืชืง ื—ื“ืฉ ืฉืœ ื”ืœื™ื‘ื” ืื ืžืฆื‘ ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื— ืื™ื ื• ืคืขื™ืœ ื‘ืžืขืจื›ืช ื•ืžืฆื‘ ื”ื ืขื™ืœื” ืžืฉืžืฉ ื‘ื ืคืจื“ ืžื–ื”. IMA ืื™ื ื” ืžืืคืฉืจืช ืืช ื”ืคืขืœืช ืžืฆื‘ "ima_appraise" ื›ืืฉืจ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืคืขื™ืœ, ืืš ืื™ื ื” ืœื•ืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืืคืฉืจื•ืช ืฉืœ ืฉื™ืžื•ืฉ ื‘ื ืขื™ืœื” ื‘ื ืคืจื“ ืžืืชื—ื•ืœ ืžืื•ื‘ื˜ื—.

ืžืงื•ืจ: OpenNet.ru

ืงื ื” ืื™ืจื•ื— ืืžื™ืŸ ืœืืชืจื™ื ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS ๐Ÿ”ฅ ืงื ื” ืื—ืกื•ืŸ ืืชืจื™ื ืืžื™ืŸ ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS | ProHoster