ืฉื—ืจื•ืจ ืฉืจืช ื”-proxy Squid 4.8 ืขื ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช

ื™ืฆื ืœืื•ืจ ืฉื—ืจื•ืจ ืคืจื•ืงืกื™ ืžืชืงืŸ ื“ื™ื•ื ื•ืŸ 4.8, ืฉืชื™ืงืŸ 5 ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ืคื’ื™ืขื•ืช ืื—ืช (CVE-2019-12527) ื”ื™ื ืžืืคืฉืจืช ืขืฉื•ื™ ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื”ื–ื›ื•ื™ื•ืช ืฉืœ ืชื”ืœื™ืš ื”ืฉืจืช.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ื‘ืžื˜ืคืœ ื”ืื™ืžื•ืช HTTP Basic ื•ืžืืคืฉืจืช ื”ืคืขืœืช ื”ืฆืคืช ืžืื’ืจ ื‘ืขืช ื”ืขื‘ืจืช ืื™ืฉื•ืจื™ื ื‘ืขืœื™ ืžื‘ื ื” ืžื™ื•ื—ื“ ื‘ืขืช ื’ื™ืฉื” ืœ- Squid Cache
ืžื ื”ืœ ืื• ืฉืขืจ FTP ืžื•ื‘ื ื”. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื”ื—ืœ ืžื”ืฉื—ืจื•ืจ ืฉืœ Squid 4.0.23. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช, ืืชื” ื™ื›ื•ืœ ืœื‘ื ื•ืช ืžื—ื“ืฉ ื“ื™ื•ื ื•ืŸ ืขื ื”ืืคืฉืจื•ืช "--disable-auth-basic" ืื• ืœื”ืฉื‘ื™ืช ื’ื™ืฉื” ืœืฉื™ืจื•ืชื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืื™ืžื•ืช HTTP ื‘ืชืฆื•ืจื”:

acl FTP ืคืจื•ื˜ื• FTP
http_access ื“ื—ื™ื™ืช FTP
http_access ื“ื—ื™ื™ืช ืžื ื”ืœ

ืฉืœื•ืฉืช ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืื—ืจื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืขืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ cachemgr.cgi, HTTP Digest ืื• ืื™ืžื•ืช HTTP Basic. ื”ืคื’ื™ืขื•ืช ื”ื ื•ืชืจืช ืžืืคืฉืจืช ืกืงืจื™ืคื˜ื™ื ื‘ื™ืŸ ืืชืจื™ื ื‘ืืžืฆืขื•ืช cachemgr.cgi.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”