I-OpenBSD isebenzisa ukuxhuma kabusha kwesikhathi sokuqalisa kwe-sshd

I-OpenBSD isebenzisa indlela emelene nokuxhashazwa encike ekuxhumeni kabusha okungahleliwe kwefayela elisebenzisekayo le-sshd njalo uma uhlelo luqala. Le ndlela yokuxhuma kabusha ibisetshenziswa ngaphambilini ku-kernel namalabhulali i-libc.so, libcrypto.so kanye ne-ld.so, futhi manje izosetshenziselwa okunye okusebenzisekayo. Esikhathini esizayo esiseduze, indlela nayo ihlelelwe ukuthi isetshenziswe ku-ntpd nezinye izinhlelo zokusebenza zeseva. Ushintsho seluvele lufakiwe egatsheni CURRENT futhi luzonikezwa ekukhishweni kwe-OpenBSD 7.3.

Ukuxhuma kabusha kwenza kube nokwenzeka ukwenza ukugudluzwa kwemisebenzi emitapweni yolwazi kungabikezeleki, okwenza kube nzima ukudala ukuxhashazwa kusetshenziswa izindlela ze-return-oriented programming (ROP). Uma usebenzisa indlela ye-ROP, umhlaseli akazami ukubeka ikhodi yakhe enkumbulweni, kodwa usebenza ngezingcezu zemiyalelo yomshini kakade etholakala emitapo yolwazi elayishiwe, ephetha ngomyalelo wokubuyisela ukulawula (njengomthetho, lezi iziphetho zemisebenzi yelabhulali) . Umsebenzi wokuxhaphaza wehlela ekwakheni uchungechunge lwezingcingo kumabhulokhi afanayo (β€œamagajethi”) ukuze kutholwe ukusebenza okufunayo.

Source: opennet.ru

Engeza amazwana