ืคื’ื™ืขื•ื™ื•ืช ื‘-OpenSMTPD ื”ืžืืคืฉืจื•ืช ื’ื™ืฉื” ืœืฉื•ืจืฉ ืžืจื—ื•ืง ื•ืžืงื•ืžื™

ื—ื‘ืจืช Qualys ื’ื™ืœื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื ื•ืกืคืช ืžืจื—ื•ืง (CVE-2020-8794) ื‘ืฉืจืช ื”ื“ื•ืืจ OpenSMTPD, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืคืจื•ื™ืงื˜ OpenBSD. ื›ืžื• ื–ื” ืฉื–ื•ื”ื” ื‘ืกื•ืฃ ื™ื ื•ืืจ ืคื’ื™ืขื•ืช, ื‘ืขื™ื” ื—ื“ืฉื” ืžืืคืฉืจืช ืœื‘ืฆืข ืžืจื—ื•ืง ืคืงื•ื“ื•ืช ืžืขื˜ืคืช ืฉืจื™ืจื•ืชื™ื•ืช ื‘ืฉืจืช ืขื ื–ื›ื•ื™ื•ืช ืžืฉืชืžืฉ ืฉื•ืจืฉ. ืคื’ื™ืขื•ืช ื—ื•ืกืœื• ื‘ืกื•ื’ื™ื” OpenSMTPD 6.6.4p1.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ื‘ืงื•ื“ ืฉืžืขื‘ื™ืจ ื“ื•ืืจ ืœืฉืจืช ื”ื“ื•ืืจ ื”ืžืจื•ื—ืง (ืœื ื‘ืงื•ื“ ืฉืžื˜ืคืœ ื‘ื—ื™ื‘ื•ืจื™ื ื ื›ื ืกื™ื). ื”ื”ืชืงืคื” ืืคืฉืจื™ืช ื”ืŸ ื‘ืฆื“ ื”ืœืงื•ื— ื•ื”ืŸ ื‘ืฆื“ ื”ืฉืจืช. ื‘ืฆื“ ื”ืœืงื•ื—, ื”ืžืชืงืคื” ืืคืฉืจื™ืช ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ OpenSMTPD, ืฉื‘ื” OpenSMTPD ืžืงื‘ืœ ื‘ืงืฉื•ืช ืจืง ื‘ืžืžืฉืง ื”ืจืฉืช ื”ืคื ื™ืžื™ (localhost) ื•ืฉื•ืœื— ื”ื•ื“ืขื•ืช ื“ื•ืืจ ืœืฉืจืชื™ื ื—ื™ืฆื•ื ื™ื™ื. ื›ื“ื™ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช, ืžืกืคื™ืง ืฉื‘ืžื”ืœืš ืžืกื™ืจืช ื”ืžื›ืชื‘, OpenSMTPD ื™ื™ืฆื•ืจ ื”ืคืขืœื” ืขื ืฉืจืช ื“ื•ืืจ ืฉื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ, ืื• ืฉื”ืชื•ืงืฃ ื™ื•ื›ืœ ืœื”ืชืงืข ื‘ื—ื™ื‘ื•ืจ ื”ืœืงื•ื— (MITM ืื• ื ื™ืชื•ื‘ ืžื—ื“ืฉ ื‘ืžื”ืœืš ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช DNS ืื• BGP ).

ืขื‘ื•ืจ ื”ืชืงืคื” ื‘ืฆื“ ื”ืฉืจืช, ื™ืฉ ืœื”ื’ื“ื™ืจ ืืช OpenSMTPD ืœืงื‘ืœ ื‘ืงืฉื•ืช ืจืฉืช ื—ื™ืฆื•ื ื™ื•ืช ืžืฉืจืชื™ ื“ื•ืืจ ืื—ืจื™ื ืื• ืœืฉืจืช ืฉื™ืจื•ืชื™ ืฆื“ ืฉืœื™ืฉื™ ื”ืžืืคืฉืจื™ื ืœืฉืœื•ื— ื‘ืงืฉื” ืœืžื™ื™ืœ ืฉืจื™ืจื•ืชื™ (ืœื“ื•ื’ืžื”, ื˜ืคืกื™ ืื™ืฉื•ืจ ื›ืชื•ื‘ืช ื‘ืืชืจื™ ืื™ื ื˜ืจื ื˜). ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืฉืจืช OpenSMTPD ื•ืœืฉืœื•ื— ืžื›ืชื‘ ืฉื’ื•ื™ (ืœืžืฉืชืžืฉ ืœื ืงื™ื™ื), ืžื” ืฉื™ื•ื‘ื™ืœ ืœืชื’ื•ื‘ื” ืฉืœื™ื—ืช ืžื›ืชื‘ ืขื ืงื•ื“ ืฉื’ื™ืื” (ืงืคื™ืฆื”) ืœืฉืจืช ืฉืœ ื”ืชื•ืงืฃ. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื›ืืฉืจ OpenSMTPD ืžืชื—ื‘ืจ ื›ื“ื™ ืœื”ืขื‘ื™ืจ ื”ื•ื“ืขื” ืœืฉืจืช ืฉืœ ื”ืชื•ืงืฃ. ืคืงื•ื“ื•ืช ื”ืžืขื˜ืคืช ืฉื”ื•ื–ืจืงื• ื‘ืžื”ืœืš ื”ืžืชืงืคื” ืžืžื•ืงืžื•ืช ื‘ืงื•ื‘ืฅ ืฉืžืชื‘ืฆืข ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื›ืืฉืจ OpenSMTPD ืžื•ืคืขืœ ืžื—ื“ืฉ, ื›ืš ืฉื”ืชื•ืงืฃ ื—ื™ื™ื‘ ืœื—ื›ื•ืช ืœ-OpenSMTPD ื›ื“ื™ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืื• ืœื™ื–ื•ื ืงืจื™ืกื” ืฉืœ OpenSMTPD ื›ื“ื™ ืœื”ืฉืœื™ื ืืช ื”ืžืชืงืคื”.

ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ืคื•ื ืงืฆื™ื” mta_io() ื‘ืงื•ื“ ืœื ื™ืชื•ื— ื”ืชื’ื•ื‘ื” ื”ืจื‘-ืฉื•ืจื™ืช ื”ืžื•ื—ื–ืจืช ืขืœ ื™ื“ื™ ื”ืฉืจืช ื”ืžืจื•ื—ืง ืœืื—ืจ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ (ืœื“ื•ื’ืžื”, "250-ENHANCEDSTATUSCODES" ื•-"250 HELP"). OpenSMTPD ืžื—ืฉื‘ืช ืฉื”ืฉื•ืจื” ื”ืจืืฉื•ื ื” ื›ื•ืœืœืช ืžืกืคืจ ืชืœืช ืกืคืจืชื™ ื•ื˜ืงืกื˜ ืžื•ืคืจื“ื™ื ื‘ืืžืฆืขื•ืช ืชื• "-", ื•ื”ืฉื•ืจื” ื”ืฉื ื™ื™ื” ืžื›ื™ืœื” ืžืกืคืจ ืชืœืช ืกืคืจืชื™ ื•ื˜ืงืกื˜ ืžื•ืคืจื“ื™ื ื‘ืจื•ื•ื—. ืื ืžืกืคืจ ืชืœืช ืกืคืจืชื™ ืื™ื ื• ืžืœื•ื•ื” ื‘ืจื•ื•ื— ื•ื˜ืงืกื˜ ื‘ืฉื•ืจื” ื”ืฉื ื™ื™ื”, ื”ืžืฆื‘ื™ืข ื”ืžืฉืžืฉ ืœื”ื’ื“ืจืช ื”ื˜ืงืกื˜ ืžื•ื’ื“ืจ ืœื‘ื™ื™ื˜ ืฉืœืื—ืจ ื”ืชื• '\0' ื•ื ืขืฉื” ื ื™ืกื™ื•ืŸ ืœื”ืขืชื™ืง ืืช ื”ื ืชื•ื ื™ื ืœืื—ืจ ื”ืกื•ืฃ ืฉืœ ื”ืงื• ืœืชื•ืš ื”ืžืื’ืจ.

ืœื‘ืงืฉืช ืคืจื•ื™ืงื˜ OpenBSD, ืคืจืกื•ื ื”ืคืจื˜ื™ื ืขืœ ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื ื“ื—ื” ืขื“ ื”-26 ื‘ืคื‘ืจื•ืืจ ื›ื“ื™ ืœืืคืฉืจ ืœืžืฉืชืžืฉื™ื ืœืขื“ื›ืŸ ืืช ื”ืžืขืจื›ื•ืช ืฉืœื”ื. ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ื‘ืกื™ืก ื”ืงื•ื“ ืžืื– ื“ืฆืžื‘ืจ 2015, ืืš ื ื™ืฆื•ืœ ืœืคื ื™ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ื‘ืกื™ืก ืืคืฉืจื™ ืžืื– ืžืื™ 2018. ื”ื—ื•ืงืจื™ื ื”ื›ื™ื ื• ืื‘ ื˜ื™ืคื•ืก ืขื•ื‘ื“ ืฉืœ ื”ื ื™ืฆื•ืœ, ืฉื ื‘ื“ืง ื‘ื”ืฆืœื—ื” ื‘-OpenSMTPD build ืขื‘ื•ืจ OpenBSD 6.6, OpenBSD 5.9, Debian 10, Debian 11 (ื‘ื“ื™ืงื”) ื•-Fedora 31.

ื’ื ื‘-OpenSMPD ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช ื ื•ืกืคืช (CVE-2020-8793) ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืงืจื•ื ืืช ื”ืฉื•ืจื” ื”ืจืืฉื•ื ื” ืฉืœ ื›ืœ ืงื•ื‘ืฅ ื‘ืžืขืจื›ืช. ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืงืจื•ื ืืช ื”ืฉื•ืจื” ื”ืจืืฉื•ื ื” ืฉืœ /etc/master.passwd, ื”ืžื›ื™ืœื” ืืช ื”-hash ืฉืœ ื”ืกื™ืกืžื” ืฉืœ ืžืฉืชืžืฉ ื”ืฉื•ืจืฉ. ื”ืคื’ื™ืขื•ืช ื’ื ืžืืคืฉืจืช ืœืš ืœืงืจื•ื ืืช ื›ืœ ื”ืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ื‘ื‘ืขืœื•ืช ืžืฉืชืžืฉ ืื—ืจ ืื ืงื•ื‘ืฅ ื–ื” ืžืžื•ืงื ื‘ืื•ืชื” ืžืขืจื›ืช ืงื‘ืฆื™ื ื›ืžื• ืกืคืจื™ื™ืช /var/spool/smtpd/. ื”ื‘ืขื™ื” ืื™ื ื” ื ื™ืชื ืช ืœื ื™ืฆื•ืœ ื‘ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ืจื‘ื•ืช ืฉื‘ื”ืŸ ื”ืขืจืš ืฉืœ /proc/sys/fs/protected_hardlinks ืžื•ื’ื“ืจ ืœ-1.

ื”ื‘ืขื™ื” ื”ื™ื ืชื•ืฆืื” ืฉืœ ื—ื™ืกื•ืœ ืœื ืฉืœื ะฟั€ะพะฑะปะตะผ, ืฉื”ื•ืฉืžืข ื‘ืžื”ืœืš ื”ื‘ื™ืงื•ืจืช ืฉืขืจื›ื” Qualys ื‘-2015. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื• ืขื ื”ื–ื›ื•ื™ื•ืช ืฉืœ ืงื‘ื•ืฆืช "_smtpq" ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ื”ืžืฉืชื ื” "PATH=.". ื•ื”ืฆื‘ืช ืกืงืจื™ืคื˜ ื‘ืฉื makemap ื‘ืกืคืจื™ื™ื” ื”ื ื•ื›ื—ื™ืช (ื”ื›ืœื™ smtpctl ืžืจื™ืฅ makemap ืžื‘ืœื™ ืœืฆื™ื™ืŸ ื‘ืžืคื•ืจืฉ ืืช ื”ื ืชื™ื‘). ืขืœ ื™ื“ื™ ื”ืฉื’ืช ื’ื™ืฉื” ืœืงื‘ื•ืฆืช "_smtpq", ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื’ืจื•ื ืœืžืฆื‘ ืžืจื•ืฅ (ืœื™ืฆื•ืจ ืงื•ื‘ืฅ ื’ื“ื•ืœ ื‘ืกืคืจื™ื™ื” ื”ืœื ืžืงื•ื•ื ืช ื•ืœืฉืœื•ื— ืื•ืช SIGSTOP), ื•ืœืคื ื™ ื”ืฉืœืžืช ื”ืขื™ื‘ื•ื“, ืœื”ื—ืœื™ืฃ ืืช ื”ืงื•ื‘ืฅ ื‘ืกืคืจื™ื™ื” ื”ืœื ืžืงื•ื•ื ืช ื‘ืงื•ื‘ืฅ ืงืฉื™ื—. ืงื™ืฉื•ืจ ืกื™ืžืœื™ ื”ืžืฆื‘ื™ืข ืขืœ ืงื•ื‘ืฅ ื”ื™ืขื“ ืฉื™ืฉ ืœืงืจื•ื ืืช ืชื•ื›ื ื•.

ืจืื•ื™ ืœืฆื™ื™ืŸ ืฉื‘-Fedora 31 ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืš ืœืงื‘ืœ ืžื™ื“ ืืช ื”ื”ืจืฉืื•ืช ืฉืœ ืงื‘ื•ืฆืช ื”ืฉื•ืจืฉ, ืžื›ื™ื•ื•ืŸ ืฉืชื”ืœื™ืš smtpctl ืžืฆื•ื™ื“ ื‘ื“ื’ืœ setgid root, ื‘ืžืงื•ื ื‘ื“ื’ืœ setgid smtpq. ืขืœ ื™ื“ื™ ืงื‘ืœืช ื’ื™ืฉื” ืœืงื‘ื•ืฆืช ื”ืฉื•ืจืฉ, ืืชื” ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ ืืช ื”ืชื•ื›ืŸ ืฉืœ /var/lib/sss/mc/passwd ื•ืœืงื‘ืœ ื’ื™ืฉืช ืฉื•ืจืฉ ืžืœืื” ืœืžืขืจื›ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”