Ubuntu, Chrome, Safari, Parallels kanye nemikhiqizo ye-Microsoft yagqekezwa emqhudelwaneni we-Pwn2Own 2021

Imiphumela yezinsuku ezintathu zomncintiswano we-Pwn2Own 2021, obanjwa minyaka yonke njengengxenye yengqungquthela yeCanSecWest, isifingqwe. Njengonyaka odlule, umncintiswano wabanjwa cishe futhi ukuhlaselwa kwaboniswa ku-inthanethi. Kulokho okuhlosiwe okungu-23, amasu okusebenza okuxhaphaza ubungozi obungaziwa ngaphambili aboniswe ku-Ubuntu Desktop, Windows 10, Chrome, Safari, Parallels Desktop, Microsoft Exchange, Microsoft Teams kanye ne-Zoom. Kuzo zonke izimo, izinguqulo zakamuva zezinhlelo zahlolwa, kuhlanganise nazo zonke izibuyekezo ezitholakalayo. Isamba semali yezinkokhelo kwakuyisigidi esisodwa namakhulu amabili ezinkulungwane zamadola ase-US (isamba sesikhwama somklomelo sasiyisigidi nesigamu samadola).

Emncintiswaneni, kwenziwa imizamo emithathu yokusebenzisa ubungozi ku-Ubuntu Desktop. Umzamo wokuqala nowesibili ubuvumelekile futhi abahlaseli bakwazile ukukhombisa ukukhushulwa kwendawo kwamalungelo ngokusebenzisa ubungozi obungaziwa ngaphambilini obuhlobene nokuchichima kwebhafa kanye nenkumbulo ekhululekile ephindwe kabili (iziphi izingxenye zenkinga ezingakabikwa; onjiniyela banikezwa izinsuku ezingama-90 ukuthi balungise amaphutha ngaphambi kokudalula idatha). Amabhonasi angu-$30 akhokhelwe lobu buthakathaka.

Umzamo wesithathu, owenziwe elinye ithimba esigabeni sokuhlukumeza amalungelo endawo, uphumelele kancane - ukuxhaphaza kwasebenza futhi kwenza kwaba nokwenzeka ukuthola ukufinyelela kwezimpande, kodwa ukuhlasela akuzange kunikezwe udumo ngokugcwele, njengoba iphutha elihlobene nokuba sengozini lase laziwa kakade. kubathuthukisi be-Ubuntu futhi ukubuyekezwa okunokulungiswa kwakuphezu kwenqubo yokulungiselela.

Kuphinde kwaboniswa ukuhlasela okuyimpumelelo kuziphequluli ezisekelwe enjinini yeChromium - iGoogle Chrome neMicrosoft Edge. Ngokwenza inzuzo ekuvumela ukuthi wenze ikhodi yakho lapho uvula ikhasi eliklanywe ngokukhethekile ku-Chrome ne-Edge (ukuxhaphaza okukodwa kwendawo yonke kwadalelwa iziphequluli ezimbili), kukhokhiwe umklomelo wamadola ayizinkulungwane eziyi-100. Ukulungiswa kuhlelwe ukuthi kushicilelwe emahoreni azayo, kuze kube manje konke okwaziwayo ukuthi ubungozi bukhona enqubweni enesibopho sokucubungula okuqukethwe kwewebhu (umnikezeli).

Okunye ukuhlasela okuyimpumelelo:

  • AmaRandi ayizinkulungwane ezingu-200 ngokugebenga uhlelo lwe-Zoom (ukwazile ukwenza ikhodi yakhe ngokuthumela umlayezo komunye umsebenzisi, ngaphandle kwesidingo sanoma yisiphi isenzo ngasohlangothini lomamukeli). Ukuhlasela kusebenzise ubungozi obuthathu ku-Zoom kanye nokukodwa ohlelweni olusebenzayo lweWindows.
  • AmaRandi ayizinkulungwane ezingu-200 ngokugebenga iMicrosoft Exchange (ukweqa ubuqiniso kanye namalungelo akhulayo endaweni kuseva ukuze athole amalungelo omlawuli). Okunye ukusebenza ngempumelelo kwaboniswa kwelinye iqembu, kodwa umklomelo wesibili awuzange ukhokhelwe, njengoba amaphutha afanayo ayesesetshenziswe iqembu lokuqala.
  • AmaRandi ayizinkulungwane ezingama-200 ngokugebenga Amaqembu e-Microsoft (ukusebenzisa ikhodi kuseva).
  • U-$100 XNUMX ngokusebenzisa i-Apple Safari (ukuchichima okuphelele ku-Safari kanye nokuchichima kwe-buffer ku-kernel ye-macOS ukuze udlule i-sandbox futhi ukhiphe ikhodi ezingeni le-kernel).
  • AmaRandi ayizinkulungwane ezingu-140 ngokugebenga i-Parallels Desktop (ukuphuma emshinini obonakalayo kanye nokukhipha ikhodi ohlelweni oluyinhloko). Ukuhlasela kwenziwe ngokuxhashazwa kobungozi obuthathu obuhlukene - ukuvuza kwenkumbulo okungagunyaziwe, ukuchichima kwesitaki kanye nokuchichima okuphelele.
  • Imiklomelo emibili yamadola ayizinkulungwane ezingu-40 ngayinye ngokugebenga i-Parallels Desktop (iphutha eliphusile kanye nokuchichima kwebhafa okuvumele ikhodi ukuthi isetshenziswe ku-OS yangaphandle ngezenzo ngaphakathi komshini obonakalayo).
  • Imiklomelo emithathu yamadola ayizinkulungwane ezingama-40 ngokuxhashazwa okuphumelele okuthathu kwe-Windows 10 (ukuchichima okuphelele, ukufinyelela kwinkumbulo ekhululiwe kakade kanye nesimo somjaho esivumele ukuthi kutholwe amalungelo e-SYSTEM).

Imizamo yenziwe, kodwa ayiphumelelanga, ukugebenga i-Oracle VirtualBox. Ukuqokwa kokugebenga iFirefox, i-VMware ESXi, iklayenti le-Hyper-V, i-MS Office 365, i-MS SharePoint, i-MS RDP ne-Adobe Reader kuhlale kungafunwanga. Kwakungekho noyedwa owayezimisele ukukhombisa ukugetshengwa kohlelo lolwazi lwemoto yakwaTesla, naphezu komklomelo wamadola ayizinkulungwane ezingama-600 kanye nemoto yeTesla Model 3.

Source: opennet.ru

Engeza amazwana