{"id":98911,"date":"2021-01-21T14:42:14","date_gmt":"2021-01-21T12:42:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq"},"modified":"2021-01-21T14:42:14","modified_gmt":"2021-01-21T12:42:14","slug":"dnspooq-sem-novyh-uyazvimostej-v-dnsmasq","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq","title":{"rendered":"DNSpooq - \u0219apte vulnerabilit\u0103\u021bi noi \u00een dnsmasq","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Speciali\u0219tii de la laboratoarele de cercetare JSOF au raportat \u0219apte vulnerabilit\u0103\u021bi noi \u00een serverul DNS\/DHCP dnsmasq. Serverul dnsmasq este foarte popular \u0219i este utilizat \u00een mod obi\u0219nuit \u00een multe distribu\u021bii Linux, precum \u0219i \u00een echipamentele de re\u021bea Cisco, Ubiquiti \u0219i altele. Vulnerabilit\u0103\u021bile Dnspooq includ otr\u0103virea cache-ului DNS, precum \u0219i execu\u021bia de cod de la distan\u021b\u0103. Vulnerabilit\u0103\u021bile au fost remediate \u00een dnsmasq 2.83.<\/p>\n<p>\u00cen 2008, cunoscutul cercet\u0103tor \u00een domeniul securit\u0103\u021bii, Dan Kaminsky, a descoperit \u0219i a dezv\u0103luit o deficien\u021b\u0103 fundamental\u0103 \u00een mecanismul DNS din Internet. Kaminsky a demonstrat c\u0103 atacatorii pot substitui adresele <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/domain\/\"   title=\"domenii\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3158\">domenii<\/a> \u0219i a fura date. De atunci, aceasta a devenit cunoscut\u0103 sub numele de &laquo;Atacul Kamin\u021bki&raquo;.<\/p>\n<p>DNS-ul este considerat un protocol nesigur de zeci de ani, de\u0219i se presupune c\u0103 garanteaz\u0103 un anumit nivel de integritate. Tocmai din acest motiv se bazeaz\u0103 \u00een continuare foarte mult pe el. \u00cen acela\u0219i timp, au fost dezvoltate mecanisme pentru a \u00eembun\u0103t\u0103\u021bi securitatea protocolului DNS original. Aceste mecanisme includ HTTPS, HSTS, DNSSEC \u0219i alte ini\u021biative. Totu\u0219i, chiar \u0219i cu toate aceste mecanisme, interceptarea DNS r\u0103m\u00e2ne o atac periculos \u00een 2021. O mare parte din internet se bazeaz\u0103 \u00een continuare pe DNS la fel cum o f\u0103cea \u00een 2008 \u0219i este vulnerabil la atacuri de acela\u0219i tip.<\/p>\n<p>Vulnerabilit\u0103\u021bile de otr\u0103vire a cache-ului DNSpooq:<br \/>\nCVE-2020-25686, CVE-2020-25684, CVE-2020-25685. Aceste vulnerabilit\u0103\u021bi sunt similare cu atacurile SAD DNS, despre care au raportat recent cercet\u0103torii de la Universitatea din California \u0219i Universitatea Tsinghua. Vulnerabilit\u0103\u021bile SAD DNS \u0219i DNSpooq pot fi, de asemenea, combinate pentru a facilita \u0219i mai mult atacurile. De asemenea, au fost raportate atacuri suplimentare cu consecin\u021be neclare, realizate \u00een colaborare \u00eentre universit\u0103\u021bi (Poison Over Troubled Forwarders \u0219i altele).<br \/>\nVulnerabilit\u0103\u021bile func\u021bioneaz\u0103 prin reducerea entropiei. Datorit\u0103 utiliz\u0103rii unei func\u021bii hash slabe pentru identificarea cererilor DNS \u0219i a asocierii imprecise \u00eentre cerere \u0219i r\u0103spuns, entropia poate fi semnificativ redus\u0103, fiind necesar\u0103 ghicirea a doar ~19 bi\u021bi, ceea ce face posibil\u0103 otr\u0103virea cache-ului. Modul \u00een care dnsmasq proceseaz\u0103 \u00eenregistr\u0103rile CNAME permite falsificarea lan\u021bului de \u00eenregistr\u0103ri CNAME \u0219i otr\u0103virea eficient\u0103 a p\u00e2n\u0103 la 9 \u00eenregistr\u0103ri DNS simultan.<\/p>\n<p>Vulnerabilit\u0103\u021bile de overflow de buffer: CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, CVE-2020-25681. Toate cele patru vulnerabilit\u0103\u021bi men\u021bionate sunt prezente \u00een codul pentru implementarea DNSSEC \u0219i se manifest\u0103 doar atunci c\u00e2nd verificarea prin DNSSEC este activat\u0103 \u00een set\u0103ri.<\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"http:\/\/www.linux.org.ru\/news\/security\/16121275\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u0438\u0437 JSOF research labs \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0441\u0435\u043c\u0438 \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 DNS\/DHCP \u0441\u0435\u0440\u0432\u0435\u0440\u0435 dnsmasq. \u0421\u0435\u0440\u0432\u0435\u0440 dnsmasq \u0432\u0435\u0441\u044c\u043c\u0430 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u0435\u043d \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 linux, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Cisco, Ubiquiti \u0438 \u043f\u0440\u043e\u0447\u0438\u0445. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 Dnspooq \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0442 \u0432 \u0441\u0435\u0431\u044f \u043e\u0442\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 DNS-\u043a\u044d\u0448\u0430, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u044b \u0432 dnsmasq 2.83. \u0412 2008 \u0433\u043e\u0434\u0443 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-98911","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u0438\u0437 JSOF research labs \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0441\u0435\u043c\u0438 \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 DNS\/DHCP \u0441\u0435\u0440\u0432\u0435\u0440\u0435 dnsmasq.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47DNSpooq \u2014 \u0441\u0435\u043c\u044c \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 dnsmasq | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u0438\u0437 JSOF research labs \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0441\u0435\u043c\u0438 \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 DNS\/DHCP \u0441\u0435\u0440\u0432\u0435\u0440\u0435 dnsmasq.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-01-21T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-01-21T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47DNSpooq \u2014 \u0219apte noi vulnerabilit\u0103\u021bi \u00een dnsmasq | ProHoster","description":"Speciali\u0219tii de la JSOF research labs au raportat despre \u0219apte noi vulnerabilit\u0103\u021bi \u00een serverul DNS\/DHCP dnsmasq.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47DNSpooq \u2014 \u0441\u0435\u043c\u044c \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 dnsmasq | ProHoster","og:description":"\u0421\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u0438\u0437 JSOF research labs \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0438 \u043e \u0441\u0435\u043c\u0438 \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 DNS\/DHCP \u0441\u0435\u0440\u0432\u0435\u0440\u0435 dnsmasq.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/dnspooq-sem-novyh-uyazvimostej-v-dnsmasq","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-01-21T12:42:14+00:00","article:modified_time":"2021-01-21T12:42:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"98911","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 09:57:26","updated":"2026-02-11 11:12:04","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/98911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=98911"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/98911\/revisions"}],"predecessor-version":[{"id":160551,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/98911\/revisions\/160551"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=98911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=98911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=98911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}