DNspooq - ื–ื™ื‘ืŸ ื ื™ื™ึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ dnsmasq

ืกืคึผืขืกื™ืึทืœื™ืกืฅ ืคื•ืŸ JSOF ืคืึธืจืฉื•ื ื’ ืœืึทื‘ื– ื’ืขืžืืœื“ืŸ ื–ื™ื‘ืŸ ื ื™ื™ึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ื“ื ืก / DHCP ืกืขืจื•ื•ืขืจ ื“ื ืกืžืึทืกืง. ื“ื™ ื“ื ืกืžืึทืกืง ืกืขืจื•ื•ืขืจ ืื™ื– ื–ื™ื™ืขืจ ืคืึธืœืงืก ืื•ืŸ ืื™ื– ื’ืขื ื•ืฆื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ ืคื™ืœืข ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืื™ืŸ ื ืขืฅ ื•ื™ืกืจื™ื›ื˜ ืคื•ืŸ Cisco, Ubiquiti ืื•ืŸ ืื ื“ืขืจืข. Dnspooq ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืึทืจื™ื™ึทื ื ืขืžืขืŸ DNS ืงืึทืฉ ืคืึทืจืกืึทืžื•ื ื’ ืื•ืŸ ื•ื•ื™ื™ึทื˜ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ dnsmasq 2.83.

ืื™ืŸ 2008, ื“ืขืจ ื‘ืึทืจื™ืžื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคืึธืจืฉืขืจ ื“ืŸ ืงืึทืžื™ื ืกืงื™ ื“ื™ืกืงืึทื•ื•ืขืจื“ ืื•ืŸ ื™ืงืกืคึผืึธื•ื–ื“ ืึท ืคื•ื ื“ืึทืžืขื ื˜ืึทืœ ื—ืกืจื•ืŸ ืื™ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ืก ื“ื ืก ืžืขืงืึทื ื™ื–ืึทื. ืงืึทืžื™ื ืกืงื™ ืคึผืจื•ื•ื•ื“ ืึทื– ืึทื˜ืึทืงืขืจื– ืงืขื ืขืŸ ืฉื•ื•ื™ื ื“ืœ ืคืขืœื“ ืึทื“ืจืขืกืขืก ืื•ืŸ ื’ืึทื ื•ื•ืขื ืขืŸ ื“ืึทื˜ืŸ. ื“ื ืก ืื™ ื– ืฉื•ื™ ืŸ ื’ืขืฐืข ืŸ ื‘ืืงืื  ื˜ ืืœ ื ืดืงืืžื™ื ืกืงื™ึพืื˜ืืงืด .

ื“ื ืก ืื™ื– ื’ืขื”ืืœื˜ืŸ ืึท ื™ื ืกืึทืงื™ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ ื“ืขืงืึทื“ืขืก, ื›ืึธื˜ืฉ ืขืก ืื™ื– ื’ืขืžื™ื™ื ื˜ ืฆื• ื’ืึทืจืึทื ื˜ื™ืจืŸ ืึท ื–ื™ื›ืขืจ ืžื“ืจื’ื” ืคื•ืŸ ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜. ืขืก ืื™ื– ืคึฟืึทืจ ื“ืขื ืกื™ื‘ื” ืึทื– ืขืก ืื™ื– ื ืึธืš ืฉื•ื•ืขืจ ืคืึทืจืœืึธื–ื  ืื•ื™ืฃ. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืžืขืงืึทื ื™ื–ืึทืžื– ื–ืขื ืขืŸ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ืฆื• ืคึฟืึทืจื‘ืขืกืขืจืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคื•ืŸ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ื“ื ืก ืคึผืจืึธื˜ืึธืงืึธืœ. ื“ื™ ืžืขืงืึทื ื™ื–ืึทืžื– ืึทืจื™ื™ึทื ื ืขืžืขืŸ HTTPS, HSTS, DNSSEC ืื•ืŸ ืื ื“ืขืจืข ื™ื ื™ืฉืึทื˜ื™ื•ื•ื–. ืึธื‘ืขืจ, ืืคื™ืœื• ืžื™ื˜ ืึทืœืข ื“ื™ ืžืขืงืึทื ื™ื–ืึทืžื– ืื™ืŸ ืคึผืœืึทืฅ, ื“ื ืก ื›ื™ื™ื“ื–ืฉืึทืงื™ื ื’ ืื™ื– ื ืึธืš ืึท ื’ืขืคืขืจืœืขืš ื‘ืึทืคืึทืœืŸ ืื™ืŸ 2021. ืคื™ืœ ืคื•ืŸ ื“ืขืจ ืื™ื ื˜ืขืจื ืขืฅ ืจื™ืœื™ื™ื– ื ืึธืš ืื•ื™ืฃ ื“ื ืก ืื™ืŸ ื“ื™ ื–ืขืœื‘ืข ื•ื•ืขื’ ืขืก ื”ืื˜ ืื™ืŸ 2008, ืื•ืŸ ืื™ื– ืกืึทืกืขืคึผื˜ืึทื‘ืึทืœ ืฆื• ื“ื™ ื–ืขืœื‘ืข ื˜ื™ื™ืคึผืก ืคื•ืŸ ืื ืคืืœืŸ.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคื•ืŸ DNspooq ืงืึทืฉ ืคืึทืจืกืึทืžื•ื ื’:
CVE-2020-25686, CVE-2020-25684, CVE-2020-25685. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืขื ืœืขืš ืฆื• SAD DNS ืื ืคืืœืŸ ืœืขืฆื˜ื ืก ื’ืขืžืืœื“ืŸ ื“ื•ืจืš ืจื™ืกืขืจื˜ืฉืขืจื– ืคื•ืŸ ื“ื™ ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜ ืคื•ืŸ ืงืึทืœื™ืคืึธืจื ื™ืึท ืื•ืŸ ืฆื™ื ื’ื”ื•ืึท ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜. SAD DNS ืื•ืŸ DNSpooq ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ืงืึทืžื‘ื™ื™ื ื“ ืฆื• ืžืึทื›ืŸ ืื ืคืืœืŸ ืืคื™ืœื• ื’ืจื™ื ื’ืขืจ. ื ืึธืš ืึทื˜ืึทืงืขืก ืžื™ื˜ ื•ืžืงืœืึธืจ ืงืึทื ืกืึทืงื•ื•ืขื ืกืึทื– ื–ืขื ืขืŸ ืื•ื™ืš ืจืขืคึผืึธืจื˜ืขื“ ื“ื•ืจืš ืฉืœืึธืก ื”ืฉืชื“ืœื•ืช ืคื•ืŸ ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜ืŸ (ืกื ืื™ื‘ืขืจ ื•ืžืจื•ื™ืง ืคืึธืจื•ื•ืขืจื“ืขืจื–, ืืื–"ื• ื•).
ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืึทืจื‘ืขื˜ ื“ื•ืจืš ืจื™ื“ื•ืกื™ื ื’ ืขื ื˜ืจืึธืคึผื™ืข. ืจืขื›ื˜ ืฆื• ื“ืขืจ ื ื•ืฆืŸ ืคื•ืŸ ืึท ืฉื•ื•ืึทืš ื”ืึทืฉ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ DNS ืจื™ืงื•ื•ืขืก ืื•ืŸ ื“ื™ ื•ืžืคึผื™ื ืงื˜ืœืขืš ื’ืœื™ื™ึทื›ืŸ ืคื•ืŸ ื“ื™ ื‘ืขื˜ืŸ ืฆื• ื“ืขืจ ืขื ื˜ืคืขืจ, ืขื ื˜ืจืึธืคึผื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื–ื™ื™ืขืจ ืจื™ื“ื•ืกื˜ ืื•ืŸ ื‘ืœื•ื™ื– ~ 19 ื‘ื™ื˜ืŸ ื“ืึทืจืคึฟืŸ ืฆื• ื–ื™ื™ืŸ ื’ืขืกื˜, ื•ื•ืึธืก ืžืื›ื˜ ืงืึทืฉ ืคืึทืจืกืึทืžื•ื ื’ ืžืขื’ืœืขืš. ื“ื™ ื•ื•ืขื’ ื“ื ืกืžืึทืกืง ืคึผืจืึทืกืขืกืึทื– CNAME ืจืขืงืึธืจื“ืก ืึทืœืึทื•ื– ืขืก ืฆื• ืฉื•ื•ื™ื ื“ืœ ืึท ืงื™ื™ื˜ ืคื•ืŸ CNAME ืจืขืงืึธืจื“ืก ืื•ืŸ ื™ืคืขืงื˜ื™ื•ื•ืœื™ ื’ื™ืคื˜ ืึทืจื•ื™ืฃ ืฆื• 9 ื“ื ืก ืจืขืงืึธืจื“ืก ืื™ืŸ ืึท ืฆื™ื™ื˜.

ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–: CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, CVE-2020-25681. ืึทืœืข 4 ื‘ืืžืขืจืงื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ืงืึธื“ ืžื™ื˜ DNSSEC ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืื•ืŸ ื“ืขืจืฉื™ื™ึทื ืขืŸ ื‘ืœื•ื™ื– ื•ื•ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื•ืจืš DNSSEC ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก.

ืžืงื•ืจ: linux.org.ru