{"id":112094,"date":"2023-12-09T21:10:14","date_gmt":"2023-12-09T19:10:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish"},"modified":"2023-12-09T21:10:14","modified_gmt":"2023-12-09T19:10:14","slug":"uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish","title":{"rendered":"Dob\u00ebsi n\u00eb stack-et Bluetooth t\u00eb Linux, macOS, Android dhe iOS, q\u00eb lejon injektimin e shtypjeve t\u00eb tasteve","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Marc Newlin, i cili zbuloi nj\u00eb cenueshm\u00ebri t\u00eb quajtur MouseJack shtat\u00eb vjet m\u00eb par\u00eb, zbuloi detaje rreth nj\u00eb cenueshm\u00ebrie t\u00eb ngjashme (CVE-2023-45866), e cila preku steka Bluetooth t\u00eb Android, Linux, macOS dhe iOS, dhe lejon z\u00ebvend\u00ebsimin e shtypjeve t\u00eb \u00e7el\u00ebsave p\u00ebrmes simulimit t\u00eb aktiviteteve t\u00eb nj\u00eb pajisjeje hyr\u00ebse t\u00eb lidhur p\u00ebrmes Bluetooth. Duke pasur qasje n\u00eb hyrjen e tastier\u00ebs, nj\u00eb sulmues mund t\u00eb kryej\u00eb veprime si\u00e7 jan\u00eb ekzekutimi i komandave n\u00eb sistem, instalimi i aplikacioneve dhe ridrejtimi i mesazheve.     <\/p>\n<p>Cenueshm\u00ebria shkaktohet nga fakti se drejtuesit HID (Human Interface Device) p\u00ebr pajisjet Bluetooth kan\u00eb nj\u00eb mod t\u00eb mund\u00ebsuar, q\u00eb i lejon pajisjeve periferike t\u00eb larg\u00ebta t\u00eb krijojn\u00eb dhe vendosin lidhje t\u00eb kriptuara pa autentifikim. Nd\u00ebr t\u00eb tjera, pajisjet q\u00eb lidhen n\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb mund t\u00eb transmetojn\u00eb mesazhe t\u00eb shtypjes dhe steku HID do t'i p\u00ebrpunoj\u00eb ato, duke mund\u00ebsuar organizimin e nj\u00eb sulmi t\u00eb larg\u00ebt t\u00eb z\u00ebvend\u00ebsimit t\u00eb mesazheve HID, q\u00eb realizohet pa ndihm\u00ebn e p\u00ebrdoruesit. Sulmi mund t\u00eb zbatohet edhe kur agresori ndodhet deri n\u00eb 100 metra larg viktim\u00ebs.    <\/p>\n<p>Mekanizmi i \u00e7iftimit t\u00eb pajisjeve pa autentifikim \u00ebsht\u00eb p\u00ebrcaktuar n\u00eb specifikimin Bluetooth dhe, n\u00eb var\u00ebsi t\u00eb cil\u00ebsimeve t\u00eb stekave Bluetooth, lejon lidhjen e pajisjes pa miratimin e p\u00ebrdoruesit. N\u00eb Linux, kur p\u00ebrdoret steka Bluetooth BlueZ p\u00ebr \u00e7iftim t\u00eb fsheht\u00eb, adaptori Bluetooth duhet t\u00eb jet\u00eb n\u00eb modin e zbuluar dhe lidhjes. N\u00eb Android mjafton thjesht t\u00eb aktivizohet mb\u00ebshtetja p\u00ebr Bluetooth. N\u00eb iOS dhe macOS, p\u00ebr t\u00eb realizuar sulmin duhet t\u00eb jet\u00eb aktivizuar Bluetooth dhe t\u00eb jet\u00eb lidhur nj\u00eb tastier\u00eb pa tel.        <\/p>\n<p>Mund\u00ebsia e z\u00ebvend\u00ebsimit t\u00eb hyrjes \u00ebsht\u00eb demonstruar n\u00eb Ubuntu 18.04, 20.04, 22.04 dhe 23.10 me stek Bluetooth t\u00eb bazuar n\u00eb paket\u00ebn Bluez. ChromeOS nuk \u00ebsht\u00eb i prirur ndaj cenueshm\u00ebris\u00eb, pasi cil\u00ebsimet e stekave Bluetooth n\u00eb t\u00eb nuk lejojn\u00eb lidhje pa autentifikim. N\u00eb Android, cenueshm\u00ebria prek pajisjet me versione t\u00eb platform\u00ebs nga 4.2.2 deri n\u00eb 14. N\u00eb macOS, cenueshm\u00ebria \u00ebsht\u00eb demonstruar n\u00eb MacBook Pro 2022 me CPU Apple M2 dhe macOS 13.3.3 dhe MacBook Air 2017 me CPU Intel dhe macOS 12.6.7. N\u00eb iOS, cenueshm\u00ebria \u00ebsht\u00eb demonstruar n\u00eb iPhone SE me iOS 16.6. Aktivizimi i modit Lockdown nuk mbron nga sulmi n\u00eb macOS dhe iOS.      <\/p>\n<p>N\u00eb Linux, nj\u00eb dob\u00ebsi \u00ebsht\u00eb eliminuar n\u00eb baz\u00ebn e kodit Bluez duke vendosur cil\u00ebsimin \u00abClassicBondedOnly\u00bb n\u00eb vler\u00ebn \u00abtrue\u00bb, q\u00eb aktivizon modalitetin e siguris\u00eb dhe lejon lidhjet vet\u00ebm pas \u00e7iftimit. M\u00eb par\u00eb, vlera ishte vendosur n\u00eb \u00abfalse\u00bb, e cila, me koston e uljes s\u00eb siguris\u00eb, zgjidhte probleme me p\u00ebrputhshm\u00ebrin\u00eb me disa pajisje hyr\u00ebse.     <\/p>\n<p>N\u00eb stekun Bluetooth Fluoride, i p\u00ebrdorur n\u00eb versionet e fundit t\u00eb Android, vulnerabiliteti \u00ebsht\u00eb eliminuar p\u00ebrmes aplikimit t\u00eb detyruesh\u00ebm t\u00eb autentifikimit p\u00ebr t\u00eb gjitha lidhjet e enkriptuara. Rregullimet p\u00ebr Android jan\u00eb formuar vet\u00ebm p\u00ebr deg\u00ebt 11-14. P\u00ebr pajisjet Pixel, vulnerabiliteti \u00ebsht\u00eb fiksuar n\u00eb p\u00ebrdit\u00ebsimin e firmware-it t\u00eb dhjetorit. P\u00ebr versionet e Android nga 4.2.2 deri n\u00eb 10, vulnerabiliteti mbetet i pazgjidhur.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60260\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043f\u043e\u0445\u043e\u0436\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45866), \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 Bluetooth-\u0441\u0442\u0435\u043a\u0438 Android, Linux, macOS \u0438 iOS, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u0439 \u043a\u043b\u0430\u0432\u0438\u0448 \u0447\u0435\u0440\u0435\u0437 \u0441\u0438\u043c\u0443\u043b\u044f\u0446\u0438\u044e \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0432\u0432\u043e\u0434\u0430, \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u043e\u0433\u043e \u0447\u0435\u0440\u0435\u0437 Bluetooth. \u0418\u043c\u0435\u044f \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043b\u0430\u0432\u0438\u0430\u0442\u0443\u0440\u043d\u043e\u043c\u0443 \u0432\u0432\u043e\u0434\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0442\u0430\u043a\u0438\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u043a \u043a\u043e\u043c\u0430\u043d\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112094","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043f\u043e\u0445\u043e\u0436\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45866), \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 Bluetooth-\u0441\u0442\u0435\u043a\u0438 Android, Linux, macOS \u0438 iOS, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0430\u0445 Linux, macOS, Android \u0438 iOS, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u0439 \u043a\u043b\u0430\u0432\u0438\u0448 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043f\u043e\u0445\u043e\u0436\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45866), \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 Bluetooth-\u0441\u0442\u0435\u043a\u0438 Android, Linux, macOS \u0438 iOS, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-12-09T19:10:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-12-09T19:10:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabiliteti n\u00eb stekat Bluetooth t\u00eb Linux, macOS, Android dhe iOS, q\u00eb lejon z\u00ebvend\u00ebsimin e shtypjeve t\u00eb \u00e7el\u00ebsit | ProHoster","description":"Marc Newlin, i cili zbuloi vulnerabilitetin MouseJack shtat\u00eb vjet m\u00eb par\u00eb, ka zbuluar detaje p\u00ebr nj\u00eb vulnerabilitet t\u00eb ngjash\u00ebm (CVE-2023-45866), q\u00eb ndikon n\u00eb stekat e Bluetooth t\u00eb Android, Linux, macOS dhe iOS, dhe lejon veprime t\u00eb pad\u00ebshiruara.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0430\u0445 Linux, macOS, Android \u0438 iOS, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u0439 \u043a\u043b\u0430\u0432\u0438\u0448 | ProHoster","og:description":"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043f\u043e\u0445\u043e\u0436\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45866), \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 Bluetooth-\u0441\u0442\u0435\u043a\u0438 Android, Linux, macOS \u0438 iOS, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios-dopuskayushhaya-podstanovku-nazhatij-klavish","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-12-09T19:10:14+00:00","article:modified_time":"2023-12-09T19:10:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/112094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=112094"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/112094\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=112094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=112094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=112094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}