ืคื’ื™ืขื•ื™ื•ืช ื‘-FreeBSD, IPnet ื•-Nucleus NET ื”ืงืฉื•ืจื•ืช ืœืฉื’ื™ืื•ืช ื‘ื™ื™ืฉื•ื ื“ื—ื™ืกืช DNS

ืงื‘ื•ืฆื•ืช ื”ืžื—ืงืจ Forescout Research Labs ื•-JSOF Research ืคืจืกืžื• ืชื•ืฆืื•ืช ืฉืœ ืžื—ืงืจ ืžืฉื•ืชืฃ ืขืœ ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืฉื•ื ื™ื ืฉืœ ืขืจื›ืช ื”ื“ื—ื™ืกื” ื”ืžืฉืžืฉืช ืœืืจื™ื–ืช ืฉืžื•ืช ื›ืคื•ืœื™ื ื‘ื”ื•ื“ืขื•ืช DNS, mDNS, DHCP ื•-IPv6 RA (ืืจื™ื–ื” ืฉืœ ื—ืœืงื™ ื“ื•ืžื™ื™ืŸ ื›ืคื•ืœื™ื ื‘ื”ื•ื“ืขื•ืช ื”ื›ื•ืœืœื™ื ืžืกืคืจ ืฉืžื•ืช). ื‘ืžื”ืœืš ื”ืขื‘ื•ื“ื” ื–ื•ื”ื• 9 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืกื•ื›ืžื•ืช ืชื—ืช ืฉื ื”ืงื•ื“ NAME:WRECK.

ื‘ืขื™ื•ืช ื–ื•ื”ื• ื‘-FreeBSD, ื›ืžื• ื’ื ื‘ืชืชื™-ืžืขืจื›ื•ืช ื”ืจืฉืช IPnet, Nucleus NET ื•-NetX, ืฉื”ืคื›ื• ื ืคื•ืฆื•ืช ื‘ืžืขืจื›ื•ืช ื”ื”ืคืขืœื” ื‘ื–ืžืŸ ืืžืช VxWorks, Nucleus ื•-ThreadX ื”ืžืฉืžืฉื•ืช ื‘ื”ืชืงื ื™ ืื•ื˜ื•ืžืฆื™ื”, ืื—ืกื•ืŸ, ืžื›ืฉื™ืจื™ื ืจืคื•ืื™ื™ื, ืื•ื•ื™ื•ื ื™ืงื”, ืžื“ืคืกื•ืช ื•ืžื•ืฆืจื™ ืืœืงื˜ืจื•ื ื™ืงื”. ื”ื”ืขืจื›ื” ื”ื™ื ืฉืœืคื—ื•ืช 100 ืžื™ืœื™ื•ืŸ ืžื›ืฉื™ืจื™ื ืžื•ืฉืคืขื™ื ืžื”ื—ื•ืœืฉื•ืช.

  • ืคื’ื™ืขื•ืช ื‘-FreeBSD (CVE-2020-7461) ืืคืฉืจื” ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœื• ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœืช DHCP ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“ ืœืชื•ืงืคื™ื ื”ืžืžื•ืงืžื™ื ื‘ืื•ืชื” ืจืฉืช ืžืงื•ืžื™ืช ื›ืžื• ื”ืงื•ืจื‘ืŸ, ืฉืขื™ื‘ื•ื“ื” ืขืœ ื™ื“ื™ ืœืงื•ื— DHCP ืคื’ื™ืข ื”ื•ื‘ื™ืœ ืœื’ืœื™ืฉืช ื—ื™ืฅ. ื”ื‘ืขื™ื” ื”ื•ืคื—ืชื” ืขืœ ื™ื“ื™ ื”ืขื•ื‘ื“ื” ืฉืชื”ืœื™ืš ื”-dhclient ืฉื‘ื• ื”ื™ื™ืชื” ืงื™ื™ืžืช ื”ืคื’ื™ืขื•ืช ืคืขืœ ืขื ื”ืจืฉืื•ืช ืื™ืคื•ืก ื‘ืืจื’ื– ื—ื•ืœ ืฉืœ Capsicum, ืžื” ืฉื“ืจืฉ ืœื–ื”ื•ืช ืคื’ื™ืขื•ืช ื ื•ืกืคืช ื›ื“ื™ ืœืฆืืช.

    ืžื”ื•ืช ื”ืฉื’ื™ืื” ื”ื™ื ื‘ื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ืคืจืžื˜ืจื™ื, ื‘ื—ื‘ื™ืœื” ื”ืžื•ื—ื–ืจืช ืขืœ ื™ื“ื™ ืฉืจืช DHCP ืขื ืืคืฉืจื•ืช DHCP 119, ื”ืžืืคืฉืจืช ืœื”ืขื‘ื™ืจ ืืช ืจืฉื™ืžืช "ื—ื™ืคื•ืฉ ื”ื“ื•ืžื™ื™ืŸ" ืœืคื•ืชืจ. ื—ื™ืฉื•ื‘ ืฉื’ื•ื™ ืฉืœ ื’ื•ื“ืœ ื”ืžืื’ืจ ื”ื ื“ืจืฉ ื›ื“ื™ ืœื”ื›ื™ืœ ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ืœื ืืจื•ื–ื™ื ื”ื•ื‘ื™ืœ ืœื›ืš ืฉืžื™ื“ืข ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ ื ื›ืชื‘ ืžืขื‘ืจ ืœืžืื’ืจ ืฉื”ื•ืงืฆื”. ื‘- FreeBSD, ื”ื‘ืขื™ื” ืชื•ืงื ื” ืขื•ื“ ื‘ืกืคื˜ืžื‘ืจ ื‘ืฉื ื” ืฉืขื‘ืจื”. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ื‘ืขื™ื” ืจืง โ€‹โ€‹ืื ื™ืฉ ืœืš ื’ื™ืฉื” ืœืจืฉืช ื”ืžืงื•ืžื™ืช.

  • ืคื’ื™ืขื•ืช ื‘ืขืจื™ืžืช ืจืฉืช ื”-IPnet ื”ืžืฉื•ื‘ืฆืช ื”ืžืฉืžืฉืช ื‘-RTOS VxWorks ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืคื•ื˜ื ืฆื™ืืœื™ ื‘ืฆื“ ืœืงื•ื— ื”-DNS ืขืงื‘ ื˜ื™ืคื•ืœ ืœื ื ื›ื•ืŸ ื‘ื“ื—ื™ืกืช ื”ื•ื“ืขื•ืช DNS. ื›ืคื™ ืฉื”ืชื‘ืจืจ, ืคื’ื™ืขื•ืช ื–ื• ื–ื•ื”ืชื” ืœืจืืฉื•ื ื” ืขืœ ื™ื“ื™ ืืงืกื•ื“ื•ืก ื‘ืฉื ืช 2016, ืืš ืžืขื•ืœื ืœื ืชื•ืงื ื”. ื’ื ื‘ืงืฉื” ื—ื“ืฉื” ืœื•ื•ื™ื ื“ ืจื™ื‘ืจ ืœื ื ืขื ืชื” ื•ืžื›ืฉื™ืจื™ IPnet ื ื•ืชืจื• ืคื’ื™ืขื™ื.
  • ืฉืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื–ื•ื”ื• ื‘ืขืจื™ืžืช Nucleus NET TCP/IP, ื”ื ืชืžื›ืช ืขืœ ื™ื“ื™ ืกื™ืžื ืก, ืžืชื•ื›ืŸ ืฉืชื™ื™ื ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง, ื•ืืจื‘ืข ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœืžื ื™ืขืช ืฉื™ืจื•ืช. ื”ื‘ืขื™ื” ื”ืžืกื•ื›ื ืช ื”ืจืืฉื•ื ื” ืงืฉื•ืจื” ืœืฉื’ื™ืื” ื‘ืขืช ื‘ื™ื˜ื•ืœ ื“ื—ื™ืกื” ืฉืœ ื”ื•ื“ืขื•ืช DNS ื“ื—ื•ืกื•ืช, ื•ื”ืฉื ื™ื™ื” ืงืฉื•ืจื” ืœื ื™ืชื•ื— ืฉื’ื•ื™ ืฉืœ ืชื•ื•ื™ื•ืช ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ. ืฉืชื™ ื”ื‘ืขื™ื•ืช ื’ื•ืจืžื•ืช ืœื”ืฆืคืช ืžืื’ืจ ื‘ืขืช ืขื™ื‘ื•ื“ ืชื’ื•ื‘ื•ืช DNS ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“.

    ื›ื“ื™ ืœื ืฆืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืชื•ืงืฃ ืคืฉื•ื˜ ืฆืจื™ืš ืœืฉืœื•ื— ืชื’ื•ื‘ื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“ ืœื›ืœ ื‘ืงืฉื” ืœื’ื™ื˜ื™ืžื™ืช ืฉื ืฉืœื—ืช ืžืžื›ืฉื™ืจ ืคื’ื™ืข, ืœืžืฉืœ, ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข ื”ืชืงืคืช MTIM ื•ื”ืคืจืขื” ืœืชืขื‘ื•ืจื” ื‘ื™ืŸ ืฉืจืช ื”-DNS ืœืงื•ืจื‘ืŸ. ืื ืœืชื•ืงืฃ ื™ืฉ ื’ื™ืฉื” ืœืจืฉืช ื”ืžืงื•ืžื™ืช, ืื– ื”ื•ื ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืฉืจืช DNS ืฉืžื ืกื” ืœืชืงื•ืฃ ืžื›ืฉื™ืจื™ื ื‘ืขื™ื™ืชื™ื™ื ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช mDNS ื‘ืžืฆื‘ ืฉื™ื“ื•ืจ.

  • ื”ืคื’ื™ืขื•ืช ื‘ืขืจื™ืžืช ื”ืจืฉืช ืฉืœ NetX (Azure RTOS NetX), ืฉืคื•ืชื—ื” ืขื‘ื•ืจ ThreadX RTOS ื•ื ืคืชื—ื” ื‘-2019 ืœืื—ืจ ืฉื”ืฉืชืœื˜ื” ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜, ื”ื•ื’ื‘ืœื” ืœืžื ื™ืขืช ืฉื™ืจื•ืช. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžืฉื’ื™ืื” ื‘ื ื™ืชื•ื— ื”ื•ื“ืขื•ืช DNS ื“ื—ื•ืกื•ืช ื‘ื™ื™ืฉื•ื ื”ืคื•ืชืจ.

ืžื‘ื™ืŸ ืขืจื™ืžื•ืช ื”ืจืฉืช ืฉื ื‘ื“ืงื• ื‘ื”ืŸ ืœื ื ืžืฆืื• ืคื’ื™ืขื•ื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœื“ื—ื™ืกืช ื ืชื•ื ื™ื ื—ื•ื–ืจื™ื ื‘ื”ื•ื“ืขื•ืช DNS, ื”ืคืจื•ื™ืงื˜ื™ื ื”ื‘ืื™ื ื ืงืจืื•: lwIP, Nut/Net, Zephyr, uC/TCP-IP, uC/TCP-IP, FreeRTOS+TCP , OpenThread ื•-FNET. ื™ืชืจื” ืžื›ืš, ื”ืฉื ื™ื™ื ื”ืจืืฉื•ื ื™ื (Nut/Net ื•-lwIP) ืื™ื ื ืชื•ืžื›ื™ื ื›ืœืœ ื‘ื“ื—ื™ืกื” ื‘ื”ื•ื“ืขื•ืช DNS, ื‘ืขื•ื“ ืฉื”ืื—ืจื™ื ืžื™ื™ืฉืžื™ื ืคืขื•ืœื” ื–ื• ืœืœื ืฉื’ื™ืื•ืช. ื‘ื ื•ืกืฃ, ื™ืฉ ืœืฆื™ื™ืŸ ื›ื™ ื‘ืขื‘ืจ ืื•ืชื ื—ื•ืงืจื™ื ื›ื‘ืจ ื–ื™ื”ื• ืคื’ื™ืขื•ื™ื•ืช ื“ื•ืžื•ืช ื‘ืขืจื™ืžื•ืช Treck, uIP ื•-PicoTCP.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”