I-Bloomberg yabhengeza ukuchongwa kwe-backdoor enokwenzeka kwisixhobo seHuawei kwiminyaka eyi-8 eyadlulayo

Uhlelo lweBloomberg, kunyaka ophelileyo ipapashiwe
impikiswano ubukrelekrele malunga netshiphu yentlola engaqinisekanga kwiibhodi zeSupermicro, watsho malunga nokuchonga i-backdoor kwizixhobo zeHuawei. Nangona kunjalo, iVodafone, eyafumanisa ingxaki, iyibiza ngokuba sesichengeni, kwaye iBloomberg iyayibaxa. Kuyabonakala ukuba, i-backdoor yayingeyiyo i-backdoor yangabom eyongezwe ngenjongo ekhohlakeleyo kunye neenjongo zobuntlola, kodwa yaba sisiphumo sokushiya indawo yofikelelo yobunjineli eyalityalwa ukuba ingasebenzi kuhlobo lokugqibela lwemveliso ngenxa yokongamela okanye ukwenza lula uxilongo nge inkonzo yenkxaso.

Ingxaki yachongwa yiVodafone ngo-2011 kwaye yalungiswa nguHuawei emva kokwaziswa ngobungozi. Undoqo we-backdoor kukukwazi ukufumana ukufikelela kwisixhobo ngokusebenzisa iseva ye-telnet eyakhelwe-ngaphakathi. Iinkcukacha zombutho wokungena azibonelelwanga; Kufuneka kuqatshelwe ukuba "iingcango ezingasemva" ezifanayo ezivumela ukuqhagamshelwa nge-telnet nazo zifunyenwe kwisixhobo kwiminyaka yakutshanje. ServerAdmin, UMoxa, Asus, ZTE, D-Link ΠΈ Juniper.

Emva kokulungiswa kwengxaki, iinjineli zeVodafone zaqaphela ukuba ukukwazi ukungena kude kude akuzange kususwe ngokupheleleyo kwaye iseva ye-telnet isenokuqaliswa (akucaci ukuba kuthetha ukuthini ukwala ukususa ngokupheleleyo iseva ye-telnet kwi-firmware okanye ukushiya amandla. ukuyiqala phantsi kweemeko ezithile) . UHuawei uphawule ngokufumaneka kokukwazi ukungena nge-telnet kunye neemfuno zemveliso - le nkonzo isetyenziselwa ukuvavanya kunye noqwalaselo lokuqala lwezixhobo. Ngelo xesha, iHuawei iphumeze ukukwazi ukukhubaza inkonzo emva kokugqiba eli nqanaba, kodwa ikhowudi yenkonzo ye-telnet ngokwayo ayizange isuswe kwi-firmware.

umthombo: opennet.ru

Yongeza izimvo