{"id":37054,"date":"2019-10-31T22:15:30","date_gmt":"2019-10-31T19:15:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\/"},"modified":"2019-10-31T22:15:30","modified_gmt":"2019-10-31T19:15:30","slug":"pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","title":{"rendered":"Pwnie Awards 2019: vulnerabilitetet m\u00eb t\u00eb r\u00ebnd\u00ebsishme dhe d\u00ebshtimet n\u00eb siguri","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb konferenc\u00ebn e mbajtur n\u00eb Las Vegas, Black Hat USA <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/\">u mbajt<\/a><\/noindex> ceremonia e ndarjes s\u00eb \u00e7mimeve <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\">Pwnie Awards 2019<\/a><\/noindex>, ku u ndan\u00eb vler\u00ebsime p\u00ebr dob\u00ebsit\u00eb m\u00eb t\u00eb r\u00ebnd\u00ebsishme dhe d\u00ebshtimet absurde n\u00eb fush\u00ebn e siguris\u00eb kompjuterike. Pwnie Awards konsiderohet ekuivalenti i Oscar-it dhe Golden Raspberry n\u00eb fush\u00ebn e siguris\u00eb kompjuterike dhe zhvillohet \u00e7do vit q\u00eb nga viti 2007. <\/p>\n<p>Main <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/winners\/\">fituesit<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/nominations\">nominimet<\/a><\/noindex>: <\/p>\n<ul>\n<li class=\"l\"> <b>Gabimi m\u00eb i mir\u00eb i serverit<\/b>. Jepet p\u00ebr identifikimin dhe shfryt\u00ebzimin e gabimit m\u00eb t\u00eb nd\u00ebrlikuar dhe interesant teknik n\u00eb nj\u00eb sh\u00ebrbim rrjeti. Fituesit u shpall\u00ebn studiuesit,  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blackhat.com\/us-19\/briefings\/schedule\/#infiltrating-corporate-intranet-like-nsa---pre-auth-rce-on-leading-ssl-vpns-15545\">t\u00eb cil\u00ebt identifikuan<\/a><\/noindex> dob\u00ebsin\u00eb te ofruesi i VPN Pulse Secure, sh\u00ebrbimi i VPN q\u00eb p\u00ebrdoret nga Twitter, Uber, Microsoft, sla, SpaceX, Akamai, Intel, IBM, VMware, Forcat Detar\u00eb t\u00eb SHBA-s\u00eb, Ministria e Siguris\u00eb Komb\u00ebtare t\u00eb SHBA-s\u00eb dhe ndoshta n\u00eb gjysm\u00ebn e kompanive t\u00eb List\u00ebs Fortune 500. Studiuesit gjet\u00ebn nj\u00eb backdoor q\u00eb lejon nj\u00eb sulmues pa autentifikim t\u00eb ndryshoj\u00eb fjal\u00ebkalimin e \u00e7do p\u00ebrdoruesi. U demonstruar mund\u00ebsia e shfryt\u00ebzimit t\u00eb problemit p\u00ebr t\u00eb marr\u00eb qasje root n\u00eb serverin VPN, n\u00eb t\u00eb cilin \u00ebsht\u00eb hapur vet\u00ebm porta HTTPS;\n<p>Nga kandidat\u00ebt q\u00eb nuk mor\u00ebn \u00e7mim, mund t\u00eb p\u00ebrmenden: <\/p>\n<ul>\n<li class=\"l\"> E shfryt\u00ebzuar n\u00eb faz\u00ebn para kalimit n\u00eb autentifikim <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/orangetw\/awesome-jenkins-rce-2019\">vulnerabiliteti<\/a><\/noindex> n\u00eb sistemin e integrimit t\u00eb vazhduesh\u00ebm Jenkins, duke lejuar ekzekutimin e kodit n\u00eb server. Dob\u00ebsia aktivisht p\u00ebrdoret nga bot\u00ebt p\u00ebr t\u00eb organizuar minimin e kriptovalutave n\u00eb server\u00eb;\n<li class=\"l\"> Kritike <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">vulnerabiliteti<\/a><\/noindex> n\u00eb serverin e post\u00ebs Exim, duke lejuar ekzekutimin e kodit n\u00eb server me t\u00eb drejta root;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2018\/10\/millions-of-xiongmai-video-surveillance-devices-can-be-hacked-via-cloud-feature-xmeye-p2p-cloud\/\">Dob\u00ebsit\u00eb<\/a><\/noindex> n\u00eb kamerat IP Xiongmai XMeye P2P, duke lejuar kapjen e kontrollit mbi pajisjen. Kamerat u dor\u00ebzuan me nj\u00eb fjal\u00ebkalim inxhinierik dhe nuk p\u00ebrdor\u00ebn verifikimin me n\u00ebnshkrim digjital gjat\u00eb p\u00ebrdit\u00ebsimit t\u00eb firmware;\n<li class=\"l\"> Kritike <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0708\">vulnerabiliteti<\/a><\/noindex> n\u00eb zbatimin e protokollit RDP n\u00eb Windows, duke lejuar ekzekutimin e kodit tuaj nga distanca;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50177\">Vulnerabiliteti<\/a><\/noindex> n\u00eb WordPress, e lidhur me ngarkimin e kodit PHP n\u00ebn guise t\u00eb imazhit. Problemi lejon ekzekutimin e kodit t\u00eb rast\u00ebsish\u00ebm n\u00eb server, duke pasur privilegje si autor publikimesh (Author) n\u00eb faqe;\n<\/ul>\n<li class=\"l\"> <b>Gabimi m\u00eb i mir\u00eb n\u00eb softuerin klient<\/b>. Fituesi u shpall leht\u00ebsisht i shfryt\u00ebzuesh\u00ebm <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-6223\">vulnerabiliteti<\/a><\/noindex> n\u00eb sistemin e thirrjeve grupore Apple FaceTime, duke lejuar iniciuesin e thirrjes grupore t\u00eb iniciroj\u00eb nj\u00eb p\u00ebrgjigje t\u00eb detyrueshme n\u00eb an\u00ebn e personit t\u00eb thirur (p\u00ebr shembull, p\u00ebr t\u00eb p\u00ebrgjuar dhe shikuar).\n<p>Gjithashtu, p\u00ebr \u00e7mimin garuan: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50679\">Vulnerabiliteti<\/a><\/noindex> n\u00eb WhatsApp, q\u00eb lejon arritjen e ekzekutimit t\u00eb kodit tuaj p\u00ebrmes d\u00ebrgimit t\u00eb nj\u00eb thirrjeje t\u00eb formatuar n\u00eb m\u00ebnyr\u00eb speciale;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=899689\">Vulnerabiliteti<\/a><\/noindex> n\u00eb bibliotek\u00ebn grafike Skia, e p\u00ebrdorur n\u00eb shfletuesin Chrome, e cila mund t\u00eb \u00e7oj\u00eb n\u00eb d\u00ebm t\u00eb memories p\u00ebr shkak t\u00eb sakt\u00ebsis\u00eb n\u00eb operacionet me numra t\u00eb l\u00ebvizsh\u00ebm gjat\u00eb disa transformimeve gjeometrike;\n<\/ul>\n<li class=\"l\"> <b>Dob\u00ebsia m\u00eb e mir\u00eb q\u00eb \u00e7on n\u00eb rritjen e privilegjeve<\/b>. Fitorja i \u00ebsht\u00eb dh\u00ebn\u00eb p\u00ebr zbardhjen e <noindex><a rel=\"nofollow\" href=\"https:\/\/googleprojectzero.blogspot.com\/2019\/01\/voucherswap-exploiting-mig-reference.html\">mang\u00ebsive<\/a><\/noindex> n\u00eb b\u00ebrtham\u00ebn iOS, e cila mund t\u00eb shfryt\u00ebzohet p\u00ebrmes ipc_voucher, e cila \u00ebsht\u00eb e aksesueshme p\u00ebr t'u thirrur p\u00ebrmes shfletuesit Safari.\n<p>Gjithashtu, p\u00ebr \u00e7mimin garuan: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0859\">Vulnerabiliteti<\/a><\/noindex> n\u00eb Windows, q\u00eb lejon marrjen e kontrollit t\u00eb plot\u00eb mbi sistemin p\u00ebrmes manipulimeve me funksionin CreateWindowEx (win32k.sys). Problemi u identifikua gjat\u00eb analiz\u00ebs s\u00eb malware q\u00eb shfryt\u00ebzonte dob\u00ebsin\u00eb para se t\u00eb korrigjohej;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50130\">Vulnerabiliteti<\/a><\/noindex> n\u00eb runc dhe LXC, q\u00eb ndikon n\u00eb Docker dhe sisteme t\u00eb tjera t\u00eb izolimit t\u00eb konteiner\u00ebve, e cila lejon q\u00eb nj\u00eb konteiner i izoluar n\u00ebn kontrollin e sulmuesit t\u00eb ndryshoj\u00eb skedarin ekzekutiv t\u00eb runc dhe t\u00eb fitoj\u00eb privilegje root n\u00eb an\u00ebn e sistemit host;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.zecops.com\/vulnerabilities\/exploit-of-cve-2019-7286\/\">Vulnerabiliteti<\/a><\/noindex> n\u00eb iOS (CFPrefsDaemon), q\u00eb lejon kalimin e m\u00ebnyrave t\u00eb izolimit dhe ekzekutimin e kodit me privilegje root;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-9568\">Vulnerabiliteti<\/a><\/noindex> n\u00eb redaktimin e TCP-stack t\u00eb Linux, e p\u00ebrdorur n\u00eb Android, q\u00eb lejon nj\u00eb p\u00ebrdorues lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb pajisje;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49931\">Dob\u00ebsit\u00eb<\/a><\/noindex> n\u00eb systemd-journald, q\u00eb lejon marrjen e privilegjeve root;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4077-1\/\">Vulnerabiliteti<\/a><\/noindex> n\u00eb utilitarin tmpreaper p\u00ebr pastrimin e \/tmp, q\u00eb lejon ruajtjen e skedarit tuaj n\u00eb \u00e7do pjes\u00eb t\u00eb FSH;\n<\/ul>\n<li class=\"l\"> <b>Sulmi m\u00eb i mir\u00eb kriptografik<\/b>. I jepet p\u00ebr identifikimin e dob\u00ebsive m\u00eb dometh\u00ebn\u00ebse n\u00eb sistemet reale, protokollet dhe algoritmet e enkriptimit. \u00c7mimi u dha p\u00ebr zbardhjen e <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">dob\u00ebsive<\/a><\/noindex> n\u00eb teknologjin\u00eb e mbrojtjes s\u00eb rrjeteve pa tel WPA3 dhe n\u00eb EAP-pwd, q\u00eb lejojn\u00eb riprodhimin e fjal\u00ebkalimit t\u00eb lidhjes dhe qasjen n\u00eb rrjetin pa tel pa pasur njohuri p\u00ebr fjal\u00ebkalimin.\n<p>Konkurrent\u00ebt p\u00ebr \u00e7mimin gjithashtu ishin: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48597\">Sanitizer.replaceElementWithChildren()<\/a><\/noindex> sulmet ndaj enkriptimit PGP dhe S\/MIME n\u00eb klient\u00ebt e post\u00ebs;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.f-secure.com\/cold-boot-attacks\/\">P\u00ebrdorimi<\/a><\/noindex> metod\u00ebn e ri-ngrohjes p\u00ebr t\u00eb fituar qasje n\u00eb p\u00ebrmbajtjen e Ndjeshm\u00ebrive t\u00eb koduara Bitlocker;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50213\">Vulnerabiliteti<\/a><\/noindex> n\u00eb OpenSSL, q\u00eb lejon ndarjen e situatave p\u00ebr marrjen e mbushjes s\u00eb pasakt\u00eb dhe MAC t\u00eb pasakt\u00eb. Problemi \u00ebsht\u00eb shkaktuar nga trajtimi i pasakt\u00eb i byte-ve zero n\u00eb mbushjen shtes\u00eb (padding oracle);\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2018\/11\/my-name-is-johann-wolfgang-von-goethe-i-can-prove-it\/\">Problemet<\/a><\/noindex> me kartat identifikuese t\u00eb p\u00ebrdorura n\u00eb Gjermani, q\u00eb p\u00ebrdorin SAML;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.chromium.org\/chromium-os\/u2f-ecdsa-vulnerability\">Problemi<\/a><\/noindex> me entropin\u00eb e numrave rastor\u00eb n\u00eb zbatimin e mb\u00ebshtetjes p\u00ebr tokenet U2F n\u00eb ChromeOS;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/monocypher.org\/quality-assurance\/disclosures\">Vulnerabiliteti<\/a><\/noindex> n\u00eb Monocypher, p\u00ebr shkak t\u00eb s\u00eb cil\u00ebs njihej si t\u00eb sakt\u00eb n\u00ebnshkrimet zero EdDSA.\n<\/ul>\n<li class=\"l\"> <b>Studimi m\u00eb inovativ.<\/b>  \u00c7mimi \u00ebsht\u00eb dh\u00ebn\u00eb zhvilluesit t\u00eb teknologjis\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/gamozolabs.github.io\/fuzzing\/2018\/10\/14\/vectorized_emulation.html\">Emulimi i Vektorizuar<\/a><\/noindex>, i cili p\u00ebrdor instrukcione vektoriale AVX-512 p\u00ebr t\u00eb emuluar ekzekutimin e programeve, duke lejuar nj\u00eb rritje t\u00eb r\u00ebnd\u00ebsishme t\u00eb shpejt\u00ebsis\u00eb s\u00eb testimit fuzz (deri n\u00eb 40-120 miliard instruksione n\u00eb sekond\u00eb). Kjo teknik\u00eb lejon ekzekutimin e paralelsh\u00ebm t\u00eb 8 makinave virtuale 64-bit ose 16 makinave virtuale 32-bit me instrukcione p\u00ebr testimin fuzz t\u00eb aplikacioneve n\u00eb \u00e7do b\u00ebrtham\u00eb CPU.\n<p>Kandidat\u00eb p\u00ebr \u00e7mimin ishin: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mimecast.com\/blog\/2019\/06\/exploit-using-microsoft-excel-power-query-for-remote-dde-execution-discovered\/\">Vulnerabiliteti<\/a><\/noindex> teknologjia Power Query nga MS Excel, e cila mund\u00ebson organizimin e ekzekutimit t\u00eb kodit dhe kalimin e metodave t\u00eb izolimit t\u00eb aplikacioneve kur hapin tabela elektronike t\u00eb formuara n\u00eb m\u00ebnyr\u00eb specifike;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50446\">Sanitizer.replaceElementWithChildren()<\/a><\/noindex> manipulimi i autoveturave Tesla p\u00ebr t\u00eb shkaktuar daljen n\u00eb korsin\u00eb e kund\u00ebrt t\u00eb qarkullimit;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2019\/02\/reverse-engineering-architecture-pinout-plc\/\">Puna<\/a><\/noindex> n\u00eb inxhinierin\u00eb e reverz p\u00ebr \u00e7ipin ASICS Siemens S7-1200;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/arxiv.org\/abs\/1808.10250\">SonarSnoop<\/a><\/noindex> \u2014 teknologji e ndjekjes s\u00eb l\u00ebvizjes s\u00eb gisht\u00ebrinjve p\u00ebr t\u00eb identifikuar kodin e \u00e7el\u00ebsit t\u00eb telefonit, e bazuar n\u00eb parimin e funksionimit t\u00eb sonar\u00ebve \u2014 dinamikat e sip\u00ebrme dhe t\u00eb poshtme t\u00eb smartfonit krijojn\u00eb vibracione t\u00eb pad\u00ebgjuara, nd\u00ebrsa mikrofon\u00ebt e integruar i kapin ato p\u00ebr analizimin e pranis\u00eb s\u00eb reflektimeve t\u00eb l\u00ebvizjeve nga dora;\n<li class=\"l\"> \t<noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50260\">Zhvillimi<\/a><\/noindex> n\u00eb mjetin e NSA-s\u00eb p\u00ebr inxhinierin\u00eb e reverz Ghidra;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@massarelli\/safe-self-attentive-function-embedding-d80abbfea794\">SAFE<\/a><\/noindex> \u2014 teknologji p\u00ebr p\u00ebrcaktimin e p\u00ebrdorimit t\u00eb kodit t\u00eb funksioneve t\u00eb nj\u00ebjta n\u00eb disa skedare ekzekutues duke u bazuar n\u00eb analiz\u00ebn e kompilimeve binar;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/vulmon.com\/vulnerabilitydetails?qid=CVE-2019-11098&#038;scoretype=cvssv2\">Krijimi<\/a><\/noindex> metoda e kalimit t\u00eb mekanizmit Intel Boot Guard p\u00ebr t\u00eb ngarkuar UEFI firmware t\u00eb modifikuar pa verifikim me n\u00ebnshkrimin digjital.\n<\/ul>\n<li class=\"l\"> <b>Reagimi m\u00eb i dob\u00ebt nga shit\u00ebsi<\/b> (Lamest Vendor Response). Nominimi p\u00ebr reagimin m\u00eb t\u00eb paekuilibruar ndaj njoftimit p\u00ebr nj\u00eb cenueshm\u00ebri n\u00eb produktin e tij. Fituesit ishin zhvilluesit e portofolit digjital BitFi, q\u00eb k\u00ebrkonin p\u00ebr sigurin\u00eb maksimale t\u00eb produktit t\u00eb tyre, e cila n\u00eb t\u00eb v\u00ebrtet\u00eb rezultoi e rreme, duke organizuar nj\u00eb gjueti ndaj k\u00ebrkuesve q\u00eb zbulonin cenueshm\u00ebri dhe duke mos paguar \u00e7mimet e premtuara p\u00ebr zbulimin e problemeve;\n<p>Nd\u00ebr kandidat\u00ebt p\u00ebr k\u00ebt\u00eb \u00e7mim u shqyrtuan gjithashtu: <\/p>\n<ul>\n<li class=\"l\"> Nj\u00eb k\u00ebrkues sigurie akuzoi drejtorin e Atrient p\u00ebr sulm p\u00ebr t\u00eb detyruar fshirjen e raportit t\u00eb zbulimit t\u00eb cenueshm\u00ebris\u00eb, por drejtori mohon incidentin dhe kamerat e mbik\u00ebqyrjes nuk e kan\u00eb regjistruar k\u00ebt\u00eb sulm;\n<li class=\"l\"> Kompania Zoom po shtynte korrigjimin e nj\u00eb cenueshm\u00ebrie kritike <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/bugbountywriteup\/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5\">mang\u00ebsive<\/a><\/noindex> n\u00eb sistemin e saj t\u00eb konferencave dhe e zgjidhi problemin vet\u00ebm pas publikimit t\u00eb tij. Vulnerabiliteti lejonte nj\u00eb sulmues t\u00eb jasht\u00ebm t\u00eb merrte t\u00eb dh\u00ebna nga kamerat web t\u00eb p\u00ebrdoruesve macOS kur hapte nj\u00eb faqe t\u00eb ve\u00e7ant\u00eb n\u00eb shfletues (zoom aktivizonte n\u00eb an\u00ebn e klientit nj\u00eb server http q\u00eb merrte komandat nga aplikacioni lokal).\n<li class=\"l\"> Pamund\u00ebsia p\u00ebr t\u00eb korrigjuar p\u00ebr m\u00eb shum\u00eb se 10 vjet <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51006\">problemit<\/a><\/noindex> me server\u00ebt e \u00e7el\u00ebsave kriptografik\u00eb OpenPGP, duke argumentuar se kodi \u00ebsht\u00eb shkruar n\u00eb nj\u00eb gjuh\u00eb specifike OCaml dhe mbetet pa mb\u00ebshtetje.\n<\/ul>\n<p><b>Njoftimi m\u00eb i tepruar p\u00ebr nj\u00eb vulnerabilitet<\/b>. Ajo jepet p\u00ebr trajtimin m\u00eb t\u00eb sajuar dhe m\u00eb t\u00eb shkall\u00ebzuar t\u00eb problemeve n\u00eb internet dhe media, sidomos n\u00ebse vulnerabiliteti rezulton t\u00eb jet\u00eb i paeksploruesh\u00ebm n\u00eb praktik\u00eb. \u00c7mimi iu dha botimit Bloomberg p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49393\">nj\u00eb deklarat\u00eb<\/a><\/noindex> identifikimin e \u00e7ipave spiun n\u00eb tabelat Super Micro, q\u00eb nuk u konfirmua, nd\u00ebrsa burimi tregoi nj\u00eb informacion krejt\u00ebsisht <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49417\">tjet\u00ebr.<\/a><\/noindex>.<\/p>\n<p>N\u00eb nominimin p\u00ebrmenden: <\/p>\n<ul>\n<li class=\"l\"> Vulnerabiliteti n\u00eb libssh, i cili <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49453\">prekte<\/a><\/noindex> aplikacione serveri t\u00eb izoluara (libssh p\u00ebrdoret pak p\u00ebr server\u00ebt), por u paraqit nga NCC Group si nj\u00eb vulnerabilitet q\u00eb lejon sulmimin e \u00e7do serveri OpenSSH.\n<li class=\"l\"> Sulmi me p\u00ebrdorimin e imazheve n\u00eb format DICOM. Thelbi \u00ebsht\u00eb se mund t\u00eb p\u00ebrgatitet nj\u00eb skedar ekzekutiv p\u00ebr Windows q\u00eb do t\u00eb dukej si nj\u00eb imazh i vlefsh\u00ebm n\u00eb format DICOM. Ky skedar mund t\u00eb ngarkohet n\u00eb nj\u00eb pajisje mjek\u00ebsore dhe t\u00eb ekzekutohet.\n<li class=\"l\"> Vulnerabiliteti <noindex><a rel=\"nofollow\" href=\"https:\/\/thrangrycat.com\/\">Thrangrycat<\/a><\/noindex>, i cili lejon p\u00ebr t\u00eb anashkaluar mekanizmin e ngarkes\u00ebs s\u00eb siguris\u00eb n\u00eb pajisjet Cisco. Vulnerabiliteti u rendit n\u00eb kategorin\u00eb e problemeve t\u00eb tepruara pasi k\u00ebrkon p\u00ebr sulm akses root, por n\u00ebse nj\u00eb sulmues tashm\u00eb ka arritur t\u00eb siguroj\u00eb akses root, at\u00ebher\u00eb p\u00ebr \u00e7far\u00eb sigurie mund t\u00eb flitet. Vulnerabiliteti fitoi gjithashtu n\u00eb kategorin\u00eb e problemeve m\u00eb t\u00eb n\u00ebnvler\u00ebsuara, pasi lejon t\u00eb injorohet nj\u00eb backdoor i p\u00ebrhersh\u00ebm n\u00eb Flash;\n<\/ul>\n<li class=\"l\"> <b>D\u00ebshtimi m\u00eb i madh<\/b> (Most Epic FAIL). Fitorja iu dha publikimit Bloomberg p\u00ebr nj\u00eb s\u00ebr\u00eb artikujsh sensacional me tituj t\u00eb bujsh\u00ebm, por me fakte t\u00eb shpikura, fshehje t\u00eb burimeve, kalim n\u00eb teori konspirative, p\u00ebrdorim t\u00eb terma si \u00abarm\u00eb kibernetike\u00bb, dhe generalizime t\u00eb papranueshme. Mes nominuesve t\u00eb tjer\u00eb:\n<ul>\n<li class=\"l\"> Sulmi Shadowhammer n\u00eb sh\u00ebrbimin e p\u00ebrdit\u00ebsimeve t\u00eb Asus;\n<li class=\"l\"> Thyerja e magazin\u00ebs BitFi, e reklamuar si \u00abe pamundur p\u00ebr t'u thyer\u00bb;\n<li class=\"l\"> Shkarkimet e t\u00eb dh\u00ebnave personale dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49366\">harduerik\u00eb<\/a><\/noindex> aksesin n\u00eb Facebook.\n<\/ul>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51267\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie Awards 2019, \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u044b \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u0430\u0431\u0441\u0443\u0440\u0434\u043d\u044b\u0435 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. Pwnie Awards \u0441\u0447\u0438\u0442\u0430\u0435\u0442\u0441\u044f \u0430\u043d\u0430\u043b\u043e\u0433\u043e\u043c \u041e\u0441\u043a\u0430\u0440\u0430 \u0438 \u0417\u043e\u043b\u043e\u0442\u043e\u0439 \u043c\u0430\u043b\u0438\u043d\u044b \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u0435\u0436\u0435\u0433\u043e\u0434\u043d\u043e, \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 2007 \u0433\u043e\u0434\u0430. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u043f\u043e\u0431\u0435\u0434\u0438\u0442\u0435\u043b\u0438 \u0438 \u043d\u043e\u043c\u0438\u043d\u0430\u0446\u0438\u0438: \u041b\u0443\u0447\u0448\u0430\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37054","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Pwnie Awards 2019: \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:15:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:15:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c7mimet Pwnie 2019: vulnerabilitetet m\u00eb t\u00eb r\u00ebnd\u00ebsishme dhe d\u00ebshtimet n\u00eb siguri | ProHoster","description":"N\u00eb konferenc\u00ebn e mbajtur n\u00eb Las Vegas, Black Hat USA u zhvillua ceremonia e ndarjes s\u00eb \u00e7mimeve Pwnie.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Pwnie Awards 2019: \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 | ProHoster","og:description":"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:15:30+00:00","article:modified_time":"2019-10-31T19:15:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37054","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:53:22","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:34:24","updated":"2026-01-22 05:53:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/37054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=37054"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/37054\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=37054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=37054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=37054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}