ื ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ืŸ telnetd ืขืจืœื•ื™ื‘ื˜ ืจื•ื˜ ืงืื ืขืงืฉืื ืก ืืŸ ืื•ื™ื˜ืขื ื˜ื™ืคื™ืงืืฆื™ืข.

ื ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ื– ืื ื˜ื“ืขืงื˜ ื’ืขื•ื•ืืจืŸ ืื™ืŸ ื“ืขื telnetd ืกืขืจื•ื•ืขืจ ืคื•ืŸ ื“ืขืจ GNU InetUtils ืกื•ื•ื™ื˜. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืขืจืœื•ื™ื‘ื˜ ืคืืจื‘ื™ื ื“ื•ื ื’ ื•ื•ื™ ื™ืขื“ืขืจ ื‘ืื ื™ืฆืขืจ, ืืจื™ื™ื ื’ืขืจืขื›ื ื˜ ืจื•ื˜, ืืŸ ืงื™ื™ืŸ ืคืืกื•ื•ืืจื˜ ื•ื•ืขืจื™ืคื™ืงืืฆื™ืข. ื CVE ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ ืื™ื– ื ืืš ื ื™ืฉื˜ ืฆื•ื’ืขื˜ื™ื™ืœื˜ ื’ืขื•ื•ืืจืŸ. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ื– ืคืืจืืŸ ื–ื™ื ื˜ InetUtils ื•ื•ืขืจืกื™ืข 1.9.3 (2015) ืื•ืŸ ื‘ืœื™ื™ื‘ื˜ ืื•ืžื’ืขืคืขื˜ืฉื˜ ืื™ืŸ ื“ืขืจ ื™ืขืฆื˜ื™ื’ืขืจ ืื•ื™ืกื’ืื‘ืข 2.7.0. ื ืคืืจืจืขื›ื˜ื•ื ื’ ืื™ื– ืคืืจืืŸ ืื™ืŸ ืคืขื˜ืฉืขืก (1, 2).

ื“ื™ ืคืจืื‘ืœืขื ื•ื•ืขืจื˜ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ืขื ืคืึทืงื˜ ืึทื– ื›ึผื“ื™ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ืึธืก ืคึผืึทืจืึธืœ, ืจื•ืคึฟื˜ ื“ืขืจ telnetd ืคึผืจืึธืฆืขืก ืึธืŸ ื“ืขื "/usr/bin/login" ื ื•ืฆืคึผืจืึธื’ืจืึทื, ืื•ืŸ ื’ื™ื˜ ืื™ื‘ืขืจ ื•ื•ื™ ืึทืŸ ืึทืจื’ื•ืžืขื ื˜ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ื•ื•ืึธืก ื“ืขืจ ืงืœื™ืขื ื˜ ื”ืึธื˜ ืกืคึผืขืฆื™ืคึฟื™ืฆื™ืจื˜ ื•ื•ืขืŸ ืขืจ ื”ืึธื˜ ื–ื™ืš ืคึฟืึทืจื‘ื•ื ื“ืŸ ืฆื•... ืกืขืจื•ื•ืขืจื“ื™ "ืœืึธื’ื™ืŸ" ื ื•ืฆืคึผืจืึธื’ืจืึทื ืฉื˜ื™ืฆื˜ ื“ื™ "-f" ืึธืคึผืฆื™ืข, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืœืึธื’ื™ืŸ ืึธืŸ ืื•ื™ื˜ืขื ื˜ื™ืคึฟื™ืงืึทืฆื™ืข (ื“ื™ ืึธืคึผืฆื™ืข ืื™ื– ื’ืขืžื™ื™ื ื˜ ืฆื• ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ื•ื•ืขืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ื– ืฉื•ื™ืŸ ืื•ื™ื˜ืขื ื˜ื™ืคึฟื™ืฆื™ืจื˜). ื“ืขืจื™ื‘ืขืจ, ื“ื•ืจืš ืึทืจื™ื™ื ืฉื˜ืขืœืŸ ื“ื™ "-f" ืึธืคึผืฆื™ืข ืื™ืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ, ืงืขื ื˜ ืื™ืจ ื–ื™ืš ืคึฟืึทืจื‘ื™ื ื“ืŸ ืึธืŸ ืคึผืึทืจืึธืœ ื•ื•ืขืจื™ืคึฟื™ืงืึทืฆื™ืข.

ืžื™ื˜ ื ื ืืจืžืืœืขืจ ืคืืจื‘ื™ื ื“ื•ื ื’, ืงืขื ื˜ ืื™ืจ ื ื™ืฉื˜ ื ื™ืฆืŸ ื ื‘ืื ื™ืฆืขืจ ื ืืžืขืŸ ื•ื•ื™ "-f root," ืื‘ืขืจ ื˜ืขืœื ืขื˜ ื”ืื˜ ืืŸ ืื•ื™ื˜ืืžืื˜ื™ืฉืŸ ืคืืจื‘ื™ื ื“ื•ื ื’ ืžืึธื“ื•ืก ืึทืงื˜ื™ื•ื•ื™ื–ื™ืจื˜ ื“ื•ืจืš ื“ืขืจ "-a" ืึธืคึผืฆื™ืข. ืื™ืŸ ื“ืขื ืžืึธื“ื•ืก, ื•ื•ืขืจื˜ ื“ืขืจ ื‘ืื ื™ืฆืขืจ ื ืืžืขืŸ ื ื™ืฉื˜ ื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ืขืจ ืงืึธืžืึทื ื“ ืœื™ื ื™ืข, ื ืึธืจ ื•ื•ืขืจื˜ ื“ื•ืจื›ื’ืขื’ืขื‘ืŸ ื“ื•ืจืš ื“ืขืจ USER ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืึทื‘ืœ. ื•ื•ืขืŸ ื“ื™ ืœืึธื’ื™ืŸ ื™ื•ื˜ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืจื•ืคืŸ ื’ืขื•ื•ืึธืจืŸ, ืื™ื– ื“ืขืจ ื•ื•ืขืจื˜ ืคื•ืŸ ื“ืขืจ ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืึทื‘ืœ ื’ืขื•ื•ืึธืจืŸ ืกืึทื‘ืกื˜ื™ื˜ื•ื˜ื™ืจื˜ ืึธืŸ ื ืึธืš ืงืึธื ื˜ืจืึธืœ ืื•ืŸ ืึธืŸ ืขืงืกืงื™ืคึผื™ื ื’ ืกืคึผืขืฆื™ืขืœืข ืื•ืชื™ื•ืช. ื“ืขืจื™ื‘ืขืจ, ืฆื• ืคืืจื‘ื™ื ื“ืŸ ื–ื™ืš ื•ื•ื™ ื“ืขืจ ื•ื•ืึธืจืฆืœ ื‘ืื ื™ืฆืขืจ, ืฉื˜ืขืœื˜ ืคืฉื•ื˜ ื“ื™ USER ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืึทื‘ืœ ืฆื• "-f root" ืื•ืŸ ืคืืจื‘ื™ื ื“ื˜ ื–ื™ืš ืฆื•ื ื˜ืขืœื ืขื˜ ืกืขืจื•ื•ืขืจ ื ื™ืฆื ื“ื™ืง ื“ืขืจ "-a" ืึธืคึผืฆื™ืข: $ USER='-f root' telnet -a ืกืขืจื•ื•ืขืจ_ื ืึธืžืขืŸ

ื“ื™ ืขื ื“ืขืจื•ื ื’ ื•ื•ืึธืก ื”ืึธื˜ ืืฒึทื ื’ืขืคึฟื™ืจื˜ ื“ื™ ืฉื•ื•ืึทื›ืงืฒึทื˜ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื•ื telnetd ืงืึธื“ ืื™ืŸ ืžืขืจืฅ 2015 ืื•ืŸ ื”ืึธื˜ ืึทื“ืจืขืกื™ืจื˜ ืึท ืคึผืจืึธื‘ืœืขื ื•ื•ืึธืก ื”ืึธื˜ ืคึฟืึทืจื”ื™ื˜ืŸ ืึทื– ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ื–ืึธืœ ื ื™ืฉื˜ ื‘ืึทืฉื˜ื™ืžื˜ ื•ื•ืขืจืŸ ืื™ืŸ ืื•ื™ื˜ืึธืœืึธื’ื™ืŸ ืžืึธื“ืข ืึธืŸ ืงืขืจื‘ืขืจืึธืก ืื•ื™ื˜ืขื ื˜ื™ืคึฟื™ืงืึทืฆื™ืข. ืึทืœืก ืึท ืœื™ื™ื–ื•ื ื’, ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฉื˜ื™ืฆืข ืคึฟืึทืจ ืื™ื‘ืขืจื’ืขื‘ืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืคึฟืึทืจ ืื•ื™ื˜ืึธืœืึธื’ื™ืŸ ืžืึธื“ืข ื“ื•ืจืš ืึทืŸ ืขื ื•ื•ื™ื™ืจืึธืžืขื ื˜ ื•ื•ืขืจื™ืึทื‘ืœ, ืึธื‘ืขืจ ืึท ื•ื•ืึทืœื™ื“ืึทืฆื™ืข ืงืึธื ื˜ืจืึธืœ ืคึฟืึทืจ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืคึฟื•ืŸ ื“ืขืจ ืขื ื•ื•ื™ื™ืจืึธืžืขื ื˜ ื•ื•ืขืจื™ืึทื‘ืœ ืื™ื– ืคึฟืึทืจื’ืขืกืŸ ื’ืขื•ื•ืึธืจืŸ.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster