ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ FreeBSD ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ืึท ื‘ื™ื™ื–ืข ื•ืกื‘ ืžื™ื˜ืœ

ืื•ื™ืฃ FreeBSD ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ื•ืกื‘ ืึธื ืœื™ื™ื’ืŸ (CVE-2020-7456) ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ืงืขืจืŸ ืžื“ืจื’ื” ืึธื“ืขืจ ืื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ ื•ื•ืขืŸ ืึท ื‘ื™ื™ื–ืข ื•ืกื‘ ืžื™ื˜ืœ ืื™ื– ืงืึธื ื ืขืงื˜ืขื“ ืฆื• ื“ื™ ืกื™ืกื˜ืขื. USB HID (Human Interface Device) ืžื™ื˜ืœ ื“ื™ืกืงืจื™ืคึผื˜ืึธืจืก ืงืขื ืขืŸ ืฉื˜ืขืœืŸ ืื•ืŸ ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืงืจืึทื ื˜ ืฉื˜ืึทื˜, ืึทืœืึทื•ื™ื ื’ ื ื•ืžืขืจ ื“ื™ืกืงืจื™ืคึผืฉืึทื ื– ืฆื• ื–ื™ื™ืŸ ื’ืจื•ืคึผื˜ ืื™ืŸ ืžื•ืœื˜ื™-ืžื“ืจื’ื” ื’ืจื•ืคึผืขืก. FreeBSD ืฉื˜ื™ืฆื˜ ืึทืจื•ื™ืฃ ืฆื• 4 ืึทื–ืึท ื™ืงืกื˜ืจืึทืงืฉืึทืŸ ืœืขื•ื•ืขืœืก. ืื•ื™ื‘ ื“ื™ ืžื“ืจื’ื” ืื™ื– ื ื™ืฉื˜ ื’ืขื–ื•ื ื˜ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ HID ืขืœืขืžืขื ื˜, ืึท ืคืึทืจืงืจื™ืคึผืœื˜ ื–ื›ึผืจื•ืŸ ืึธืจื˜ ืื™ื– ืึทืงืกืขืกื˜. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ FreeBSD 11.3-RELEASE-p10 ืื•ืŸ 12.1-RELEASE-p6 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ. ื•ื•ื™ ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ืฉื˜ืขืœืŸ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ "sysctl hw.usb.disable_enumeration=1".

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื•ืจืš Andy Nguyen ืคึฟื•ืŸ Google ืื•ืŸ ืื™ื– ื ื™ืฉื˜ ืึธื•ื•ื•ืขืจืœืึทืคึผ ืžื™ื˜ ืืŸ ืื ื“ืขืจ ืคึผืจืึธื‘ืœืขื ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืœืขืฆื˜ื ืก ืžื•ื“ื™ืข ืจื™ืกืขืจื˜ืฉืขืจื– ืคื•ืŸ Purdue ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜ ืื•ืŸ ื“ื™ ร‰cole Polytechnique Fรฉdรฉrale de Lausanne. ื“ื™ ืจื™ืกืขืจื˜ืฉืขืจื– ื”ืึธื‘ืŸ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื™ USBFuzz ื˜ืึธืึธืœืงื™ื˜, ื•ื•ืึธืก ืกื™ืžื™ืึทืœื™ื™ืฅ ืึท ืคืึทืœืฉ ืคืึทื ื’ืงืฉืึทื ื™ื ื’ ื•ืกื‘ ืžื™ื˜ืœ ืคึฟืึทืจ ืคื™ื•ื–ื™ื ื’ ื˜ืขืกื˜ื™ื ื’ ืคื•ืŸ ื•ืกื‘ ื“ืจื™ื•ื•ืขืจืก. USBFuzz ืื™ื– ืคึผืœืึทื ื ืขื“ ื‘ืึทืœื“ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื•ื™ืฃ GitHub. ืžื™ื˜ ื“ื™ ื ื™ื™ึทืข ื’ืขืฆื™ื™ึทื’, 26 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“, ืคื•ืŸ ื•ื•ืึธืก 18 ืื™ืŸ ืœื™ื ื•ืงืก, 4 ืื™ืŸ Windows, 3 ืื™ืŸ ืžืึทืงืึธืก ืื•ืŸ ืื™ื™ื ืขืจ ืื™ืŸ FreeBSD. ื“ืขื˜ืึทื™ืœืก ื•ื•ืขื’ืŸ ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ื“ื™ืกืงืœืึธื•ื–ื“; ืขืก ืื™ื– ื‘ืœื•ื™ื– ื“ืขืจืžืื ื˜ ืึทื– CVE ื™ื“ืขื ื˜ื™ืคื™ืขืจืก ื–ืขื ืขืŸ ื‘ืืงื•ืžืขืŸ ืคึฟืึทืจ 10 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืื•ืŸ 11 ืคึผืจืึธื‘ืœืขืžืก ื•ื•ืึธืก ืคึผืึทืกื™ืจืŸ ืื™ืŸ ืœื™ื ื•ืงืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜. ื ืขื ืœืขืš ืคื™ื•ื–ื™ื ื’ ื˜ืขืกื˜ื™ื ื’ ื˜ืขื›ื ื™ืง ืคึผืึทืกืŸ ืึทื ื“ืจื™ื™ ืงืึธื ืึธื•ื•ืึทืœืึธื•ื• ืคื•ืŸ ื’ื•ื’ืœ, ื•ื•ืึธืก ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ื™ืึธืจืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ 44 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืœื™ื ื•ืงืก ื•ืกื‘ ืึธื ืœื™ื™ื’ืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’