{"id":87197,"date":"2020-07-05T07:42:02","date_gmt":"2020-07-05T05:42:02","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-ssh-klientah-openssh-i-putty"},"modified":"2020-07-05T07:42:02","modified_gmt":"2020-07-05T05:42:02","slug":"uyazvimost-v-ssh-klientah-openssh-i-putty","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","title":{"rendered":"Vulnerabilitet n\u00eb klient\u00ebt SSH OpenSSH dhe PuTTY","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb klient\u00ebt SSH OpenSSH dhe PuTTY <noindex><a rel=\"nofollow\" href=\"https:\/\/www.fzi.de\/en\/news\/news\/detail-en\/artikel\/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients\/\">u zbulua<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.fzi.de\/fileadmin\/user_upload\/2020-06-26-FSA-2020-2.pdf\">vulnerabiliteti<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-14002\">CVE-2020-14002<\/a><\/noindex> n\u00eb PuTTY dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-14145\">CVE-2020-14145<\/a><\/noindex> n\u00eb OpenSSH), e cila \u00e7on n\u00eb rrjedhjen e informacionit n\u00eb algoritmin e negociat\u00ebs s\u00eb lidhjes. Vulnerabiliteti lejon nj\u00eb sulmues, n\u00eb gjendje t\u00eb kap\u00eb trafikun e klientit (p\u00ebr shembull, kur p\u00ebrdoruesi lidhet p\u00ebrmes nj\u00eb pike t\u00eb kontrolluar nga sulmuesi p\u00ebrkat\u00ebse), t\u00eb p\u00ebrcaktoj\u00eb p\u00ebrpjekjen fillestare t\u00eb lidhjes nga klienti me hostin, kur klienti ende nuk ka ruajtur \u00e7el\u00ebsin e hostit n\u00eb cache. <\/p>\n<p>Duke e ditur se klienti po p\u00ebrpiqet t\u00eb lidhet p\u00ebr her\u00eb t\u00eb par\u00eb dhe ende nuk ka \u00e7el\u00ebsin e hostit n\u00eb an\u00ebn e tij, sulmuesi mund t\u00eb transmetoj\u00eb lidhjen p\u00ebrmes vetes (MITM) dhe t'i jap\u00eb klientit \u00e7el\u00ebsin e tij t\u00eb hostit, i cili klienti SSH do ta mendoj\u00eb si \u00e7el\u00ebsin e hostit t\u00eb synuar, n\u00ebse nuk kryen verifikimin e gjurm\u00ebs s\u00eb \u00e7el\u00ebsit. K\u00ebshtu, sulmuesi mund t\u00eb organizoj\u00eb nj\u00eb MITM pa i ngjallur dyshime p\u00ebrdoruesit dhe t\u00eb injoroj\u00eb seancat ku n\u00eb an\u00ebn e klientit tashm\u00eb ka \u00e7el\u00ebsa t\u00eb host\u00ebve t\u00eb ruajtur, p\u00ebrpjekja p\u00ebr t\u00eb z\u00ebvend\u00ebsuar t\u00eb cilat do t\u00eb \u00e7onte n\u00eb nxjerrjen e nj\u00eb paralajm\u00ebrimi p\u00ebr ndryshimin e \u00e7el\u00ebsit t\u00eb hostit. Sulmi bazohet n\u00eb pakujdesin\u00eb e p\u00ebrdoruesve, t\u00eb cil\u00ebt nuk kryejn\u00eb verifikimin manual t\u00eb gjurm\u00ebs s\u00eb \u00e7el\u00ebsit t\u00eb hostit gjat\u00eb lidhjes s\u00eb par\u00eb. Ata q\u00eb kontrollojn\u00eb gjurm\u00ebt e \u00e7el\u00ebsave jan\u00eb t\u00eb mbrojtur nga sulme t\u00eb tilla.<\/p>\n<p>Si nj\u00eb tregues p\u00ebr t\u00eb p\u00ebrcaktuar p\u00ebrpjekjen e par\u00eb t\u00eb lidhjes, p\u00ebrdoret ndryshimi i rendit t\u00eb algoritm\u00ebve t\u00eb mb\u00ebshtetur p\u00ebr \u00e7el\u00ebsat e hostit. N\u00eb rastin kur ndodh lidhja e par\u00eb, klienti kalon nj\u00eb list\u00eb algoritmesh t\u00eb paracaktuar, dhe n\u00ebse \u00e7el\u00ebsi i hostit tashm\u00eb \u00ebsht\u00eb n\u00eb cache, at\u00ebher\u00eb algoritmi i lidhur me t\u00eb vendoset n\u00eb vendin e par\u00eb (algoritmet renditen sipas preferenc\u00ebs). <\/p>\n<p>Problemi shfaqet n\u00eb l\u00ebshimet e OpenSSH nga 5.7 deri n\u00eb 8.3 dhe n\u00eb PuTTY nga 0.68 deri n\u00eb 0.73. Problemi <noindex><a rel=\"nofollow\" href=\"https:\/\/git.tartarus.org\/?p=simon\/putty.git;a=commit;h=08f1e2a5066ea95559945af339a60ca14560d764\">\u00ebsht\u00eb eliminuar<\/a><\/noindex> n\u00eb versionin <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.tartarus.org\/pipermail\/putty-announce\/2020\/000030.html\">PuTTY 0.74<\/a><\/noindex> n\u00ebp\u00ebrmjet shtimit t\u00eb nj\u00eb opsioni p\u00ebr t\u00eb \u00e7aktivizuar nd\u00ebrtimin dinamik t\u00eb list\u00ebs s\u00eb algoritm\u00ebve p\u00ebr p\u00ebrpunimin e \u00e7el\u00ebsave t\u00eb hostit n\u00eb favor t\u00eb rendit t\u00eb algoritm\u00ebve n\u00eb nj\u00eb m\u00ebnyr\u00eb t\u00eb q\u00ebndrueshme.<\/p>\n<p>Projekti OpenSSH nuk planifikon t\u00eb ndryshoj\u00eb sjelljen e klientit SSH, pasi n\u00ebse algoritmi i \u00e7el\u00ebsit ekzistues nuk \u00ebsht\u00eb specifikuar n\u00eb vendin e par\u00eb, do t\u00eb b\u00ebhet nj\u00eb p\u00ebrpjekje p\u00ebr t\u00eb aplikuar nj\u00eb algorit\u00ebm q\u00eb nuk p\u00ebrputhet me \u00e7el\u00ebsin e ruajtur, duke dh\u00ebn\u00eb nj\u00eb paralajm\u00ebrim p\u00ebr nj\u00eb \u00e7el\u00ebs t\u00eb panjohur. Pra, lind nj\u00eb zgjedhje \u2014 ose rrjedhje informacioni (OpenSSH dhe PuTTY), ose dh\u00ebnia e paralajm\u00ebrimeve p\u00ebr ndryshimin e \u00e7el\u00ebsit (Dropbear SSH) n\u00eb rast se \u00e7el\u00ebsi i ruajtur nuk p\u00ebrputhet me algoritmin e par\u00eb n\u00eb list\u00ebn e parazgjedhur.<\/p>\n<p>P\u00ebr t\u00eb siguruar mbrojtjen n\u00eb OpenSSH, rekomandohet p\u00ebrdorimi i m\u00ebnyrave alternative p\u00ebr verifikimin e \u00e7el\u00ebsit t\u00eb hostit p\u00ebrmes regjistrimeve SSHFP n\u00eb DNSSEC dhe certifikatave t\u00eb hostit (PKI). Po ashtu, mund t\u00eb \u00e7aktivizohet zgjedhja adaptuese e algoritmeve t\u00eb \u00e7el\u00ebsit t\u00eb hostit p\u00ebrmes opsionit HostKeyAlgorithms dhe t\u00eb p\u00ebrdoret opsioni UpdateHostKeys p\u00ebr t\u00eb marr\u00eb \u00e7el\u00ebsa t\u00eb tjer\u00eb nga hosti pas autentifikimit.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53286\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-14002 \u0432 PuTTY \u0438 CVE-2020-14145 \u0432 OpenSSH), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u0432 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443, \u0441\u043f\u043e\u0441\u043e\u0431\u043d\u043e\u043c\u0443 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043b\u0438\u0435\u043d\u0442\u0430 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0442\u043e\u0447\u043a\u0443 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430), \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u043f\u043e\u043f\u044b\u0442\u043a\u0443 \u043f\u0435\u0440\u0432\u043e\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043a \u0445\u043e\u0441\u0442\u0443, \u043a\u043e\u0433\u0434\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u043c \u0435\u0449\u0451 \u043d\u0435 \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043b\u044e\u0447 \u0445\u043e\u0441\u0442\u0430. \u0417\u043d\u0430\u044f, \u0447\u0442\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-87197","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-05T05:42:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-07-05T05:42:02+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitet n\u00eb klient\u00ebt SSH OpenSSH dhe PuTTY | ProHoster","description":"N\u00eb klient\u00ebt SSH OpenSSH dhe PuTTY","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY | ProHoster","og:description":"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-05T05:42:02+00:00","article:modified_time":"2020-07-05T05:42:02+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"87197","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:56:23","updated":"2022-10-07 22:11:57","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/87197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=87197"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/87197\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=87197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=87197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=87197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}