{"id":32603,"date":"2019-10-31T21:47:55","date_gmt":"2019-10-31T18:47:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\/"},"modified":"2019-10-31T21:47:55","modified_gmt":"2019-10-31T18:47:55","slug":"potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","title":{"rendered":"Sulmet potenciale ndaj HTTPS dhe si t\u00eb mbrohesh prej tyre","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Gjashtu e faqeve <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/services\/ssl\/dv?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">p\u00ebrdorin HTTPS<\/a><\/noindex>, dhe numri i tyre po rritet n\u00eb m\u00ebnyr\u00eb t\u00eb q\u00ebndrueshme. Protokolli zvog\u00eblon rrezikun e kapjes s\u00eb trafikut, por nuk p\u00ebrjashton p\u00ebrpjekjet p\u00ebr sulme si t\u00eb tilla. Rreth disa prej tyre \u2014 POODLE, BEAST, DROWN dhe t\u00eb tjer\u00ebve \u2014 dhe m\u00ebnyrat e mbrojtjes, do t\u00eb flasim n\u00eb materialin ton\u00eb.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/449866\/\"><img decoding=\"async\" alt=\"Sulmet potenciale ndaj HTTPS dhe si t\u00eb mbrohesh prej tyre\" src=\"\/wp-content\/uploads\/2019\/04\/305d426243ec7e580b5dd14de36eaed0.jpeg\" style=\"display:block;margin: 0 auto;\" \/> <\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/2011101\/23434336563\/\">Sven Graeme<\/a><\/noindex> \/ CC BY-SA<\/i><\/p>\n<h2>POODLE<\/h2>\n<p>\nS\u00eb pari u b\u00eb e njohur p\u00ebr sulmin <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-3566\">POODLE<\/a><\/noindex> n\u00eb vitin 2014. Vulnerabiliteti n\u00eb protokollin SSL 3.0 u zbulua nga specialisti i siguris\u00eb Bodo M\u00f6ller me koleg\u00ebt e tij nga Google.<\/p>\n<p>Thelbi i saj q\u00ebndron n\u00eb k\u00ebt\u00eb: nj\u00eb haker e detyron klientin t\u00eb lidhet p\u00ebrmes SSL 3.0, duke imituar nd\u00ebrprerjet e lidhjes. Pastaj ai k\u00ebrkon n\u00eb trafikun e koduar n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%A0%D0%B5%D0%B6%D0%B8%D0%BC_%D1%81%D1%86%D0%B5%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D1%8F_%D0%B1%D0%BB%D0%BE%D0%BA%D0%BE%D0%B2_%D1%88%D0%B8%D1%84%D1%80%D0%BE%D1%82%D0%B5%D0%BA%D1%81%D1%82%D0%B0\">CBC<\/a><\/noindex>-modin mesazhe t\u00eb ve\u00e7anta-sh\u00ebnjues. Me an\u00eb t\u00eb nj\u00eb s\u00ebr\u00eb k\u00ebrkesash t\u00eb manipuluara, sulmuesit fitojn\u00eb mund\u00ebsin\u00eb p\u00ebr t\u00eb rikonstruktuar p\u00ebrmbajtjen e t\u00eb dh\u00ebnave q\u00eb i interesojn\u00eb, p\u00ebr shembull cookies.<\/p>\n<p>SSL 3.0 \u00ebsht\u00eb nj\u00eb protokoll i vjet\u00ebruar. Por \u00e7\u00ebshtja e siguris\u00eb s\u00eb tij \u00ebsht\u00eb ende aktuale. Klient\u00ebt e p\u00ebrdorin at\u00eb p\u00ebr t\u00eb shmangur problemet e pajtueshm\u00ebris\u00eb me server\u00ebt. Sipas disa t\u00eb dh\u00ebnave, pothuajse 7% e 100 mij\u00eb faqeve m\u00eb t\u00eb njohura <noindex><a rel=\"nofollow\" href=\"https:\/\/www.thesslstore.com\/blog\/nearly-21-of-the-worlds-top-100000-websites-still-arent-using-https\/\">ende mb\u00ebshtesin SSL 3.0<\/a><\/noindex>. Gjithashtu <noindex><a rel=\"nofollow\" href=\"https:\/\/www.globalsign.com\/en\/blog\/poodle-vulnerability-expands-beyond-sslv3-to-tls\/\">ekzistojn\u00eb<\/a><\/noindex> modifikime t\u00eb POODLE, q\u00eb fokusohet n\u00eb TLS 1.0 dhe TLS 1.1. N\u00eb k\u00ebt\u00eb vit <noindex><a rel=\"nofollow\" href=\"https:\/\/www.tripwire.com\/state-of-security\/vulnerability-management\/zombie-poodle-goldendoodle\/\">shfaqen<\/a><\/noindex> sulmet e reja Zombie POODLE dhe GOLDENDOODLE, t\u00eb cilat kalojn\u00eb mbrojtjen e TLS 1.2 (ato ende lidhen me enkriptimin CBC).<\/p>\n<p><b>Si t\u00eb mbrohemi.<\/b> N\u00eb rastin e POODLE origjinal duhet t\u00eb deaktivizohet mb\u00ebshtetje p\u00ebr SSL 3.0. Megjithat\u00eb, n\u00eb k\u00ebt\u00eb rast ka rrezik t\u00eb krijohen probleme me pajtueshm\u00ebrin\u00eb. Nj\u00eb zgjidhje alternative mund t\u00eb jet\u00eb mekanizmi TLS_FALLBACK_SCSV \u2014 ai garanton q\u00eb shk\u00ebmbimi i t\u00eb dh\u00ebnave p\u00ebrmes SSL 3.0 do t\u00eb realizohet vet\u00ebm me sisteme t\u00eb vjetra. Sulmuesit nuk do t\u00eb mund t\u00eb nisin m\u00eb uljen e versionit t\u00eb protokollit. M\u00ebnyra e mbrojtjes nga Zombie POODLE dhe GOLDENDOODLE \u00ebsht\u00eb \u00e7aktivizimi i mb\u00ebshtetjes p\u00ebr CBC n\u00eb aplikacionet mbi baz\u00ebn TLS 1.2. Nj\u00eb zgjidhje radikale do t\u00eb jet\u00eb kalimi n\u00eb TLS 1.3 \u2014 n\u00eb versionin e ri t\u00eb protokollit nuk p\u00ebrdoret enkriptimi CBC. N\u00eb vend t\u00eb tij, p\u00ebrdoren AES dhe ChaCha20 m\u00eb t\u00eb q\u00ebndruesh\u00ebm.<\/p>\n<h2>BEAST<\/h2>\n<p>\nNj\u00eb nga sulmet e para ndaj SSL dhe TLS 1.0, e zbuluar n\u00eb vitin 2011. Ashtu si POODLE, BEAST <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acunetix.com\/blog\/articles\/tls-vulnerabilities-attacks-final-part\/\">p\u00ebrdor<\/a><\/noindex> karakteristikat e enkriptimit CBC. Sulmuesit futin n\u00eb makin\u00ebn e klientit nj\u00eb agjent JavaScript ose nj\u00eb applet Java, e cila z\u00ebvend\u00ebson mesazhet gjat\u00eb transmetimit t\u00eb t\u00eb dh\u00ebnave p\u00ebrmes TLS ose SSL. Duke qen\u00eb se sulmuesit jan\u00eb t\u00eb njohur me p\u00ebrmbajtjen e paketave \"t\u00eb rreme\", ata mund t'i p\u00ebrdorin ato p\u00ebr t\u00eb dekoduar vektorin e inicializimit dhe p\u00ebr t\u00eb lexuar mesazhet e tjera d\u00ebrguar serverit, si\u00e7 jan\u00eb cookie-t p\u00ebr autentifikim.<\/p>\n<p>P\u00ebr momentin, vulnerabilitetet BEAST ende <noindex><a rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/its-2018-and-network-middleware-still-cant-handle-tls-without-breaking-encryption\/\">i ekspozojn\u00eb nj\u00eb num\u00ebr mjetesh rrjetesh<\/a><\/noindex>: server\u00ebt proxy dhe aplikacionet p\u00ebr mbrojtjen e portave lokale t\u00eb internetit.<\/p>\n<p><b>Si t\u00eb mbrohemi.<\/b> Sulmuesi duhet t\u00eb d\u00ebrgoj\u00eb rregullisht k\u00ebrkesa p\u00ebr t\u00eb dekoduar t\u00eb dh\u00ebnat. N\u00eb VMware <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.vmware.com\/s\/article\/2008784\">rekomandojn\u00eb<\/a><\/noindex> duhet t\u00eb shkurtosh koh\u00ebn e SSLSessionCacheTimeout \u2014 nga pes\u00eb minuta (rekomandimi standard) n\u00eb 30 sekonda. Ky qasje do ta b\u00ebj\u00eb m\u00eb t\u00eb komplikuar zbatimin e planeve p\u00ebr sulmuesit, megjith\u00ebse do t\u00eb ket\u00eb nj\u00eb efekt t\u00eb vog\u00ebl negativ n\u00eb performanc\u00eb. P\u00ebrve\u00e7 k\u00ebsaj, \u00ebsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb kuptohet se s\u00eb shpejti vulnerabiliteti BEAST mund t\u00eb shp\u00ebtoj\u00eb vet\u00eb \u2014 q\u00eb nga viti 2020 shfletuesit kryesor\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/tls-10-and-tls-11-being-retired-in-2020-by-all-major-browsers\/\">ndalojn\u00eb<\/a><\/noindex> mb\u00ebshtetjes s\u00eb TLS 1.0 dhe 1.1. N\u00eb \u00e7do rast, me k\u00ebto protokolle punon m\u00eb pak se 1,5% e t\u00eb gjith\u00eb p\u00ebrdoruesve t\u00eb shfletuesve.<\/p>\n<h2>DROWN<\/h2>\n<p>\nKjo \u00ebsht\u00eb nj\u00eb sulm nd\u00ebr-protokollor, q\u00eb p\u00ebrdor gabimet n\u00eb realizimin e SSLv2 me \u00e7el\u00ebsa RSA 40-bit. Sulmuesi d\u00ebgjon qindra lidhje TLS t\u00eb objektivit dhe d\u00ebrgon paketa speciale n\u00eb serverin me SSLv2, i cili p\u00ebrdor t\u00eb nj\u00ebjtin \u00e7el\u00ebs privat. Duke p\u00ebrdorur <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Adaptive_chosen-ciphertext_attack\">sulmin Bleichenbacher<\/a><\/noindex>, hakeri mund t\u00eb dekodoj\u00eb nj\u00eb nga af\u00ebrsisht nj\u00eb mij\u00eb seancat TLS t\u00eb klientit.<\/p>\n<p>O DROWN u b\u00eb e njohur p\u00ebr her\u00eb t\u00eb par\u00eb n\u00eb vitin 2016 \u2014 at\u00ebher\u00eb ajo ishte <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acunetix.com\/blog\/articles\/tls-vulnerabilities-attacks-final-part\/\">e ekspozuar p\u00ebr nj\u00eb t\u00eb tret\u00ebn e server\u00ebve<\/a><\/noindex> n\u00eb bot\u00eb. Aktualisht ajo nuk ka humbur relevanc\u00ebn e saj. Nga 150 mij\u00eb sitet m\u00eb t\u00eb njohura, 2% ende <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ssllabs.com\/ssl-pulse\/\">mb\u00ebshtesin<\/a><\/noindex> SSLv2 dhe mekanizmat e enkriptimit t\u00eb vulneruesh\u00ebm.<\/p>\n<p><b>Si t\u00eb mbrohemi.<\/b> Duhet t\u00eb instalosh patch-et e propozuara nga zhvilluesit e bibliotekave kriptografike, t\u00eb cilat \u00e7aktivizojn\u00eb mb\u00ebshtetje p\u00ebr SSLv2. P\u00ebr shembull, dy t\u00eb tilla patch-e u ofruan p\u00ebr OpenSSL (n\u00eb vitin 2016 <noindex><a rel=\"nofollow\" href=\"https:\/\/drownattack.com\/#mitigation\">ato ishin p\u00ebrdit\u00ebsimet<\/a><\/noindex> 1.0.1s dhe 1.0.2g). Gjithashtu, azhurnime dhe udh\u00ebzime p\u00ebr \u00e7aktivizimin e protokollit vulnerues u publikuan n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/drown\">Red Hat<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/httpd.apache.org\/docs\/2.2\/mod\/mod_ssl.html#sslprotocol\">Apache<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2016-0800\">Debian<\/a><\/noindex>.<\/p>\n<blockquote><p><i>\"Burimi mund t\u00eb jet\u00eb i vulneruesh\u00ebm ndaj DROWN, n\u00ebse \u00e7el\u00ebsat e tij p\u00ebrdoren nga nj\u00eb server i jasht\u00ebm me SSLv2, p\u00ebr shembull nj\u00eb email, \" v\u00ebren drejtori i zhvillimit <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">i ofruesit IaaS 1cloud.ru<\/a><\/noindex> Sergej Belkin. \u2014 Kjo situat\u00eb ndodh kur disa server\u00eb p\u00ebrdorin nj\u00eb certifikat\u00eb SSL t\u00eb zakonshme. N\u00eb k\u00ebt\u00eb rast, mb\u00ebshtetja p\u00ebr SSLv2 duhet \u00e7aktivizuar n\u00eb t\u00eb gjitha makinat.<\/i><\/p><\/blockquote>\n<p>\nMund t\u00eb kontrolloni n\u00ebse duhet t\u00eb azhurnoni sistemin tuaj duke p\u00ebrdorur nj\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nimia\/public_drown_scanner\">utilitare<\/a><\/noindex> \u2014 e zhvilluar nga specialist\u00ebt e siguris\u00eb informacionit, t\u00eb cil\u00ebt zbuluan DROWN. M\u00eb shum\u00eb rreth rekomandimeve lidhur me mbrojtjen nga k\u00ebt\u00eb lloj sulmi mund t\u00eb lexoni n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openssl.org\/blog\/blog\/2016\/03\/01\/an-openssl-users-guide-to-drown\/\">postimin n\u00eb faqen e OpenSSL<\/a><\/noindex>.<\/p>\n<h2>Heartbleed<\/h2>\n<p>\nNj\u00eb nga vulnerabilitetet m\u00eb t\u00eb m\u00ebdha n\u00eb softuer \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Heartbleed\">Heartbleed<\/a><\/noindex>. Ai u zbulua n\u00eb vitin 2014 n\u00eb bibliotek\u00ebn OpenSSL. N\u00eb momentin e shpalljes s\u00eb gabimit, numri i faqeve t\u00eb prekura <noindex><a rel=\"nofollow\" href=\"https:\/\/news.netcraft.com\/archives\/2014\/04\/08\/half-a-million-widely-trusted-websites-vulnerable-to-heartbleed-bug.html\">u vler\u00ebsua n\u00eb gjysm\u00eb milioni<\/a><\/noindex> \u2014 kjo \u00ebsht\u00eb rreth 17% e burimeve t\u00eb mbrojtura n\u00eb mreht.<\/p>\n<p>Sulmi realizohet p\u00ebrmes nj\u00eb moduli t\u00eb vog\u00ebl Heartbeat t\u00eb zgjerimit TLS. Protokolli TLS k\u00ebrkon q\u00eb t\u00eb dh\u00ebnat t\u00eb transfertohen vazhdimisht. N\u00eb rast t\u00eb nj\u00eb periudhe t\u00eb gjat\u00eb qet\u00ebsie, ndodhin nd\u00ebrprerje dhe e gjith\u00eb procedura duhet t\u00eb rivendoset. P\u00ebr t\u00eb p\u00ebrballuar k\u00ebt\u00eb problem, server\u00ebt dhe klient\u00ebt artificialisht \"bukur\" kanalin (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc6520\">RFC 6520, fq.5<\/a><\/noindex>), duke transferuar nj\u00eb paket\u00eb me gjat\u00ebsi t\u00eb rast\u00ebsishme. N\u00ebse ajo ishte m\u00eb e madhe se paketa, versionet vulnerabile t\u00eb OpenSSL lexonin memorjen p\u00ebrtej kufijve t\u00eb caktuar. N\u00eb k\u00ebt\u00eb zon\u00eb mund t\u00eb ndodhen \u00e7do lloj t\u00eb dh\u00ebne, p\u00ebrfshir\u00eb \u00e7el\u00ebsat e mbyllur t\u00eb enkriptimit dhe informacionin p\u00ebr lidhje t\u00eb tjera.<\/p>\n<p>Vulnerabiliteti ishte i pranish\u00ebm n\u00eb t\u00eb gjitha versionet e bibliotek\u00ebs midis 1.0.1 dhe 1.0.1f p\u00ebrfshir\u00eb, si dhe n\u00eb disa OS \u2014 Ubuntu deri n\u00eb 12.04.4, CentOS m\u00eb t\u00eb vjet\u00ebr se 6.5, OpenBSD 5.3 dhe t\u00eb tjera. Lista e plot\u00eb \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"http:\/\/heartbleed.com\/\">n\u00eb faqen e dedikuar Heartbleed<\/a><\/noindex>. Edhe pse patch-et kund\u00ebr k\u00ebtij vulnerabiliteti u l\u00ebshuan praktikisht menj\u00ebher\u00eb pas zbulimit t\u00eb tij, problemi mbetet aktual deri tani. Edhe n\u00eb vitin 2017 <noindex><a rel=\"nofollow\" href=\"https:\/\/thehackernews.com\/2017\/01\/heartbleed-openssl-vulnerability.html\">ishin pothuajse 200 mij\u00eb faqe<\/a><\/noindex>, t\u00eb prekura nga Heartbleed.<\/p>\n<p><b>Si t\u00eb mbrohemi.<\/b> Duhet <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openssl.org\/source\/\">t\u00eb azhurnoni OpenSSL<\/a><\/noindex> n\u00eb versionin 1.0.1g ose m\u00eb t\u00eb lart\u00eb. Mund t\u00eb \u00e7aktivizoni gjithashtu k\u00ebrkesat Heartbeat manualisht duke p\u00ebrdorur opsionin DOPENSSL_NO_HEARTBEATS. Pas azhurnimit, specialist\u00ebt e siguris\u00eb informacionit <noindex><a rel=\"nofollow\" href=\"https:\/\/thehackernews.com\/2017\/01\/heartbleed-openssl-vulnerability.html\">rekomandojn\u00eb<\/a><\/noindex> duhet ta ri-l\u00ebshojn\u00eb certifikat\u00ebn SSL. Z\u00ebvend\u00ebsimi \u00ebsht\u00eb i nevojsh\u00ebm p\u00ebr rastin n\u00ebse t\u00eb dh\u00ebnat mbi \u00e7el\u00ebsat e enkriptimit ndonj\u00ebher\u00eb arrijn\u00eb n\u00eb duar t\u00eb haker\u00ebve.<\/p>\n<h2>Z\u00ebvend\u00ebsimi i certifikat\u00ebs<\/h2>\n<p>\nNj\u00eb nyj\u00eb e menaxhuar vendoset midis p\u00ebrdoruesit dhe serverit me nj\u00eb certifikat\u00eb SSL legjitime, e cila aktivisht kap trafikun. Kjo nyj\u00eb paraqet veten si server legjitim duke paraqitur nj\u00eb certifikat\u00eb t\u00eb vlefshme, dhe krijohet mund\u00ebsia p\u00ebr nj\u00eb sulm MITM.<\/p>\n<p>Sipas <noindex><a rel=\"nofollow\" href=\"https:\/\/jhalderm.com\/pub\/papers\/interception-ndss17.pdf\">hulumtimi<\/a><\/noindex> Sipas nj\u00eb hulumtimi nga Mozilla, Google dhe disa universitete, rreth 11% e lidhjeve t\u00eb mbrojtura n\u00eb internet \"ndjeken\". Kjo \u00ebsht\u00eb rezultat i instalimit t\u00eb certifikatave t\u00eb dyshimta t\u00eb rr\u00ebnj\u00ebs n\u00eb kompjuter\u00ebt e p\u00ebrdoruesve.<\/p>\n<p><b>Si t\u00eb mbrohemi.<\/b> T\u00eb p\u00ebrdorni sh\u00ebrbimet e <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/services\/ssl?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">ofruesve t\u00eb SSL<\/a><\/noindex>. Mund t\u00eb kontrolloni \"cil\u00ebsin\u00eb\" e certifikatave me ndihm\u00ebn e sh\u00ebrbimit <noindex><a rel=\"nofollow\" href=\"https:\/\/www.certificate-transparency.org\/\">Certificate Transparency<\/a><\/noindex> (CT). Ofruesit e cloud gjithashtu mund t\u00eb ndihmojn\u00eb n\u00eb zbulimin e \"ndjekjes\" \u2014 disa kompani t\u00eb m\u00ebdha tashm\u00eb ofrojn\u00eb mjete specializuara p\u00ebr monitorimin e lidhjeve p\u00ebrmes TLS.<\/p>\n<p>Nj\u00eb tjet\u00ebr m\u00ebnyr\u00eb mbrojtjeje do t\u00eb jet\u00eb standardi i ri <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\">ACME, i cili automatizon marrjen e certifikatave SSL. Ai do t\u00eb shtoj\u00eb mekanizma t\u00eb tjer\u00eb p\u00ebr verifikimin e pronarit t\u00eb sitit. M\u00eb shum\u00eb n\u00eb lidhje me t\u00eb<\/a><\/noindex> ne kemi shkruar n\u00eb nj\u00eb nga materialet tona t\u00eb m\u00ebparshme <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\">Yuri Samoilov<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Sulmet potenciale ndaj HTTPS dhe si t\u00eb mbrohesh prej tyre\" src=\"\/wp-content\/uploads\/2019\/04\/0ce792d1ebce9077460ebd02518e01ac.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/yusamoilov\/13334048894\/\">Perspektivat e HTTPS<\/a><\/noindex> \/ CC BY<\/i><\/p>\n<h2>Pavar\u00ebsisht disa dob\u00ebsive, gjigant\u00ebt IT dhe ekspert\u00ebt e siguris\u00eb jan\u00eb t\u00eb sigurt p\u00ebr t\u00eb ardhmen e protokollit. Aktivisht po promovon aplikimin e HTTPS<\/h2>\n<p>\nkrijuesi i WWW Tim Berners-Lee. Sipas tij, me kalimin e koh\u00ebs, TLS do t\u00eb b\u00ebhet m\u00eb i mbrojtur, duke rritur ndjesh\u00ebm sigurin\u00eb e lidhjeve. Berners-Lee madje sugjeroi se n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.w3.org\/DesignIssues\/Security-NotTheS.html\">t\u00eb ardhmen do t\u00eb dalin<\/a><\/noindex> certifikata klienti p\u00ebr autentikimin e identitetit. Ato do t\u00eb ndihmojn\u00eb n\u00eb p\u00ebrmir\u00ebsimin e mbrojtjes s\u00eb server\u00ebve nga sulmuesit. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.w3.org\/DesignIssues\/Security-ClientCerts.html\">T\u00eb zhvillohen teknologjit\u00eb SSL\/TLS gjithashtu planifikohet p\u00ebrmes m\u00ebsimit t\u00eb makinerive \u2014 algoritmet inteligjente do t\u00eb jen\u00eb p\u00ebrgjegj\u00ebse p\u00ebr filtrimin e trafikut t\u00eb d\u00ebmsh\u00ebm. N\u00eb lidhjet HTTPS, administrator\u00ebt nuk kan\u00eb mund\u00ebsi t\u00eb din\u00eb p\u00ebrmbajtjen e mesazheve t\u00eb enkriptuara \u2014 p\u00ebrfshir\u00eb zbules\u00ebn e k\u00ebrkesave nga softueri d\u00ebmsh\u00ebm. Tashm\u00eb, rrjetet neurale jan\u00eb n\u00eb gjendje t\u00eb filtrojn\u00eb paketat potencialisht t\u00eb rrezikshme me sakt\u00ebsi 90%. (<\/a><\/noindex> slajdi 23 i prezantimit<\/p>\n<p>Sulmet ndaj HTTPS jan\u00eb kryesisht t\u00eb lidhura jo me problemet n\u00eb protokollin vet\u00eb, por me mb\u00ebshtetje t\u00eb mekanizmave t\u00eb enkriptimeve t\u00eb vjetra. Industria IT po fillon t\u00eb heq\u00eb gradualisht dor\u00eb nga protokollet e brezit t\u00eb kaluar dhe ofron mjete t\u00eb reja p\u00ebr gjetjen e dob\u00ebsive. N\u00eb t\u00eb ardhmen, k\u00ebto mjete do t\u00eb b\u00ebhen gjithnj\u00eb e m\u00eb inteligjente.<noindex><a rel=\"nofollow\" href=\"https:\/\/2018.bsidesbud.com\/wp-content\/uploads\/2018\/03\/seba_garcia_frantisek_strasak.pdf?forcedefault=true\">Linket shtes\u00eb p\u00ebr tem\u00ebn:<\/a><\/noindex>).<\/p>\n<h2>P\u00ebrfundimet<\/h2>\n<p>\nZhvillimi n\u00eb cloud, siguria dhe t\u00eb dh\u00ebnat personale: p\u00ebrmbledhje nga 1cloud<\/p>\n<h5>SSL-rrjedha: Materialet m\u00eb t\u00eb mira praktike n\u00eb Habr dhe jo vet\u00ebm<\/h5>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/448760\/\"> VPN-rrjedha: Artikuj njoh\u00ebs n\u00eb Habr dhe jo vet\u00ebm<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habrahabr.ru\/company\/1cloud\/blog\/315758\/\">SSL-\u0434\u0430\u0439\u0434\u0436\u0435\u0441\u0442: \u041b\u0443\u0447\u0448\u0438\u0435 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0438 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habrahabr.ru\/company\/1cloud\/blog\/316266\/\">VPN-\u0434\u0430\u0439\u0434\u0436\u0435\u0441\u0442: \u041e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u043d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0438 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e<\/a><\/noindex><\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/449866\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f. \u041f\u0440\u043e\u0442\u043e\u043a\u043e\u043b \u0441\u043e\u043a\u0440\u0430\u0449\u0430\u0435\u0442 \u0440\u0438\u0441\u043a \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043d\u043e \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u0430\u0442\u0430\u043a \u043a\u0430\u043a \u0442\u0430\u043a\u043e\u0432\u044b\u0435. \u041e \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0445 \u043d\u0438\u0445 \u2014 POODLE, BEAST, DROWN \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u2014 \u0438 \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u0437\u0430\u0449\u0438\u0442\u044b, \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0435\u043c \u0432 \u043d\u0430\u0448\u0435\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435. \/ Flickr \/ Sven Graeme \/ CC BY-SA POODLE \u0412\u043f\u0435\u0440\u0432\u044b\u0435 \u043e\u0431 \u0430\u0442\u0430\u043a\u0435 POODLE \u0441\u0442\u0430\u043b\u043e \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":24394,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32603","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 HTTPS \u0438 \u043a\u0430\u043a \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:47:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:47:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sulmet potenciale ndaj HTTPS dhe si t\u00eb mbrohemi nga to | ProHoster","description":"Gjasht p\u00ebr qind e faqeve p\u00ebrdorin HTTPS, dhe numri i tyre \u00ebsht\u00eb n\u00eb rritje.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 HTTPS \u0438 \u043a\u0430\u043a \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f | ProHoster","og:description":"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:47:55+00:00","article:modified_time":"2019-10-31T18:47:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32603","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 11:43:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:55:24","updated":"2026-01-21 11:43:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32603"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32603\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/24394"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}