Dropbear SSH Server Kuburitswa 2020.79

Introduced nyaya itsva Dropbear 2020.79, compact MIT-ine rezinesi SSH server uye mutengi anoshandiswa zvakanyanya pane akamisikidzwa masisitimu akadai seasina waya ma router. Dropbear inoratidzirwa nekushomeka kwendangariro kushandiswa (kana statically yakabatana neClibc inotora chete 110kB), kugona kudzima basa risingakoshe padanho rekuvaka, uye tsigiro yekuvaka mutengi uye sevha mune imwe faira faira, yakafanana nebhokisi rakabatikana. Dropbear inotsigira X11 kutumira mberi, inofambirana neOpenSSH kiyi faira (~/.ssh/authorized_keys) uye inogona kugadzira akawanda-makonekisheni nekutumira mberi kuburikidza neanotambira.

Π’ kuburitswa kutsva:

  • Yakawedzerwa rutsigiro rweEd25519 dhijitari siginecha algorithm mune hostkeys uye authorized_keys.
  • Yakawedzera tsigiro yeprotocol yekusimbisa yakavakirwa paChaCha20 stream cipher uye Poly1305 meseji yekusimbisa algorithms yakagadzirwa naDaniel Bernstein.
  • Yakawedzerwa rutsigiro rweiyo rsa-sha2 dijitari siginecha fomati, iyo, nekuda kwekupera kwesha-1 rutsigiro, ichakurumidza kuve inosungirwa kuOpenSSH (iripo RSA makiyi achakwanisa kushanda neiyo fomati itsva pasina kushandura hostkeys/authorized_keys).
  • Kuitwa kwe curve25519 kwakatsiviwa neimwe compact shanduro kubva kuTweetNaCl chirongwa.
  • Yakawedzerwa rutsigiro rweAES GCM (yakaremara neyakagadzika).
  • Yakavharwa nekusarudzika ndeye CBC ciphers, 3DES, hmac-sha1-96, uye x11 kutumira.
  • Yakagadziriswa nyaya dzekuenderana neIRIX OS.
  • Yakawedzera API kutsanangura makiyi eruzhinji zvakananga pane kushandisa authorized_keys.
  • Kusagadzikana kwakagadziriswa muSCP CVE-2018-20685, iyo inobvumira kushandura kodzero dzekuwana kune inotarirwa dhairekitori kana sevha inodzosa dhairekitori ine zita risina chinhu kana nguva. Pakugamuchira murairo "D0777 0 \n" kana "D0777 0 .\n" kubva kuseva, mutengi akashandisa shanduko yekodzero dzekuwana kudhairekitori razvino.

Source: opennet.ru

Voeg