OpenSSH 9.3 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืžื™ื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคื™ืงืกื™ื–

ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 9.3 ืื™ื– ืืจื•ื™ืก, ืึทืŸ ืึธืคึฟืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื“ื™ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืก. ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืคื™ืงืกื™ื– ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก:

  • ื ืœืึทื“ื–ืฉื™ืงืึทืœ ื˜ืขื•ืช ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื™ื˜ืขืงื˜ืึทื“ ืื™ืŸ ื“ื™ ssh-add ื ื•ืฆืŸ, ื•ื•ื™ื™ึทืœ ื•ื•ืขืŸ ืึทื“ื™ื ื’ ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ ืกืžืึทืจื˜ ืงืึทืจื“ืก ืฆื• ssh-agent, ื“ื™ ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ืกืคึผืขืกื™ืคื™ืขื“ ืžื™ื˜ ื“ื™ "ssh-add -h" ืึธืคึผืฆื™ืข ื–ืขื ืขืŸ ื ื™ืฉื˜ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื• ื“ืขืจ ืึทื’ืขื ื˜. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืึท ืฉืœื™ืกืœ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ ืึทื’ืขื ื˜, ืคึฟืึทืจ ื•ื•ืึธืก ืงื™ื™ืŸ ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขื•ื•ืขื ื“ื˜, ืึทืœืึทื•ื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ื‘ืœื•ื™ื– ืคื•ืŸ ื–ื™ื›ืขืจ ืžื—ื ื•ืช.
  • ื ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ssh ื ื•ืฆืŸ ื•ื•ืึธืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืึทื˜ืŸ ืคื•ืŸ ื“ื™ ืึธื ืœื™ื™ื’ืŸ ื’ืขื’ื ื˜ ืึทืจื•ื™ืก ื“ื™ ืึทืœืึทืงื™ื™ื˜ื™ื“ ื‘ืึทืคืขืจ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืกืคึผืขืฆื™ืขืœ ืคืึธืจืžืึทื˜ื˜ืขื“ ื“ื ืก ืจืขืกืคึผืึธื ืกืขืก, ืื•ื™ื‘ ื“ื™ VerifyHostKeyDNS ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืื™ืŸ ื“ื™ ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ getrrsetbyname () ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ืื™ื– ื’ืขื ื•ืฆื˜ ืื™ืŸ ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ OpenSSH ืฆื•ื ื•ื™ืคื’ืขืฉื˜ืขืœื˜ ืึธืŸ ื ื™ืฆืŸ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ldns ื‘ื™ื‘ืœื™ืึธื˜ืขืง (-with-ldns) ืื•ืŸ ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ ื ืึธืจืžืึทืœ ืœื™ื™ื‘ืจืขืจื™ื– ื•ื•ืึธืก ืฉื˜ื™ืฆืŸ ื ื™ืฉื˜ ื“ื™ getrrsetbyname ( ) ืจื•ืคืŸ. ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืื ื“ืขืจืข ื•ื•ื™ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืฆื• ื“ื™ ssh ืงืœื™ืขื ื˜, ืื™ื– ืึทืกืกืขืกืกืขื“ ื•ื•ื™ ืึทื ืœื™ื™ืงืœื™.

ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ืœื™ื‘ืกืงื™ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ OpenBSD, ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ OpenSSH. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ื–ื™ื ื˜ 1997 ืื•ืŸ ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ืกื˜ืึทืง ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืกืคึผืขืฆื™ืขืœ ืคืึธืจืžืึทื˜ื˜ืขื“ ื”ืึธืกื˜ื ืึทืžืขืก. ืขืก ืื™ื– ื‘ืืžืขืจืงื˜ ืึทื– ื˜ืจืึธืฅ ื“ืขืจ ืคืึทืงื˜ ืึทื– ื“ื™ ืžืึทื ืึทืคืขืกื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื™ื ื™ืฉื™ื™ื™ื˜ื™ื“ ืจื™ืžืึธื•ื˜ืœื™ ื“ื•ืจืš OpenSSH, ืื™ืŸ ืคื™ืจ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทืจื•ื™ืกื’ืขื•ื•ืึธืจืคืŸ, ื•ื•ื™ื™ึทืœ ืคึฟืึทืจ ืขืก ืฆื• ื‘ืึทืฉื™ื™ึทืžืคึผืขืจืœืขืš ื–ื™ืš, ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ืึทื˜ืึทืงื™ืจื˜ ื‘ืึทืœืขื‘ืึธืก (/etc/hostname) ืžื•ื–ืŸ ืึทื ื˜ื”ืึทืœื˜ืŸ ืžืขืจ ื•ื•ื™ 126 ืื•ืชื™ื•ืช, ืื•ืŸ ื“ืขืจ ื‘ืึทืคืขืจ ืงืขื ืขืŸ ื‘ืœื•ื™ื– ื–ื™ื™ืŸ ืึธื•ื•ื•ืขืจืคืœืึธื•ื™ื ื’ ืžื™ื˜ ืื•ืชื™ื•ืช ืžื™ื˜ ื ื•ืœ ืงืึธื“ ('\0').

ื ื™ื˜-ื–ื™ื›ืขืจื”ื™ื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ:

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ "-Ohashalg=sha1|sha256" ืคึผืึทืจืึทืžืขื˜ืขืจ ืฆื• ssh-keygen ืื•ืŸ ssh-keyscan ืฆื• ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื SSHFP ื ืึทื’ืขื˜ ื•ื•ื™ื™ึทื– ืึทืœื’ืขืจื™ื“ืึทื.
  • sshd ื”ืื˜ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืึท "-G" ืึธืคึผืฆื™ืข ืฆื• ืคึผืึทืจืก ืื•ืŸ ืึทืจื•ื™ืกื•ื•ื™ื™ึทื–ืŸ ื“ื™ ืึทืงื˜ื™ื•ื• ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืŸ ืคึผืจื•ื•ื•ืŸ ืฆื• ืœืึธื“ืŸ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ืื•ืŸ ืึธืŸ ื“ื•ืจื›ืคื™ืจืŸ ื ืึธืš ื˜ืฉืขืงืก, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ืื™ื™ื“ืขืจ ื“ื™ ื“ื–ืฉืขื ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ืฉืœื™ืกืœืขืŸ ืื•ืŸ ืœื•ื™ืคืŸ ื“ื™ ื˜ืฉืขืง ื“ื•ืจืš ืึทื ืคึผืจื™ื•ื•ื™ืœื™ื“ื–ืฉื“ ื™ื•ื–ืขืจื–.
  • sshd ื”ืื˜ ืคึฟืึทืจื‘ืขืกืขืจื˜ ืคึผืœืึทื˜ืคืึธืจืžืข ืื™ื–ืึธืœืึทืฆื™ืข Linux, ื•ื•ืึธืก ื ื™ืฆื˜ ื“ื™ seccomp ืื•ืŸ seccomp-bpf ืกื™ืกื˜ืขื ืจื•ืฃ ืคื™ืœื˜ืขืจื™ื ื’ ืžืขืงืึทื ื™ื–ืžืขืŸ. ืคืึธืŸ ืคึฟืึทืจ mmap, madvise, ืื•ืŸ futex ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื• ื“ืขืจ ืจืฉื™ืžื” ืคื•ืŸ ืขืจืœื•ื™ื‘ื˜ืข ืกื™ืกื˜ืขื ืจื•ืคืŸ.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster