Kwiintsuku ezidlulileyo bebaleka ngomnatha iingxelo zokuhlaselwa Baxhaphaza ukuba semngciphekweni kwi-PHP, evumela ezinye iisayithi ezisemthethweni ukuba zisebenzise amaphepha ewebhu obuqhetseba kunye neentengiso, ziveze iindwendwe kufakelo lwe-malware kwiikhompyuter zazo. Olu hlaselo luthatha ithuba umngcipheko obaluleke kakhulu we-PHP kutyhilwe esidlangalaleni iinyanga ezingama-22 ezidlulileyo nalapho kukhutshwe uhlaziyo oluhambelanayo.
Abanye baqalisile ukunyanzelisa ukuba icandelo elilungileyo leeseva ezonakaliswe kolu hlaselo ziqhuba iinguqulelo ze-GNU / Linux, bezenza ngathi babuza ukhuseleko lwale nkqubo yokusebenza, kodwa ngaphandle kokuya kwiinkcukacha malunga nobume bokuba sesichengeni okanye izizathu kutheni le yenzekileyo.
Iinkqubo ezine-GNU / Linux ezosulelekileyo, kuzo zonke iimeko, baqhuba i Inguqulelo yeLinux kernel 2.6, ekhutshwe ngo-2007 okanye ngaphambili. Akukho naphi na apho kukhankanywayo usulelo lweenkqubo ezisebenzisa iinkozo eziphezulu okanye ezihlaziywe ngokufanelekileyo; Kodwa kunjalo, kusekho abalawuli abacinga ukuba "... ukuba ayophukanga, ayifuni kulungiswa" emva koko ezi zinto ziyenzeka.
Ngakolunye uhlangothi, uphononongo lwakutsha nje lwenkampani yezokhuseleko ESET, ityhila umnxeba ngokweenkcukacha "Umsebenzi weWindigo", apho ngokusebenzisa iikiti ezininzi zokuhlaselwa, kubandakanya enye ebizwa Umsebenzi okhethiweyo eyenzelwe ngokukodwa i-Apache kunye nezinye iiseva zomthombo ezivulekileyo zomthombo wewebhu, kunye nenye ebizwa I-SSH, ibe ngaphezulu kweenkqubo ezingama-26,000 ze-GNU / Linux ezonakalisiweyo ukusukela ngoMeyi kunyaka ophelileyo, ngaba oku kuthetha ukuba i-GNU / Linux ayisakhuselekanga?
Okokuqala ukubeka izinto emxholweni, ukuba sithelekisa amanani angaphambili kunye nezigidi ezi-2 zeekhompyuter zeWindows ezonakaliswe yi-bootnet ZeroAccess Phambi kokuba ivalwe ngoDisemba 2013, kulula ukugqiba ukuba, ngokubhekiselele kukhuseleko, Iinkqubo ze-GNU / Linux zisakhuseleke ngakumbi Ngaphezu kwabo basebenzisa iNkqubo yokuSebenza yeMicrosoft, kodwa ngaba sisiphoso se-GNU / Linux ukuba iinkqubo ezingama-26,000 ezine-OS zonakaliswe?
Njengakwimeko yokuba sesichengeni kokubaluleka kwe-PHP ekuxoxwe ngayo ngasentla, echaphazela iinkqubo ngaphandle kohlaziyo lwe-kernel, olu hlaselo lubandakanya iinkqubo apho igama lomsebenzisi elingagqibekanga kunye / okanye ipassword ingatshintshwanga kwaye igcina Izibuko lama-23 nelama-80 zivulwe ngokungeyomfuneko; Ngaba ngenene yimpazamo ye-GNU / Linux?
Ngokucacileyo, impendulo ngu-HAYI, ingxaki ayisiyiyo i-OS esetyenzisiweyo kodwa kukungakhathali kunye nokungahoywa kwabalawuli bezo nkqubo abangaqondi kakuhle ubuninzi obuchazwe yingcali yezokhuseleko. UBruce Schneier Oko kuya kutshiswa kwiingqondo zethu: Ukhuseleko YINKQUBO AYIKHO imveliso.
Akuncedi nganto ukuba sifaka inkqubo ekhuselekileyo eqinisekisiweyo ukuba siyishiya ishiywe kwaye singafaki uhlaziyo oluhambelanayo ngokukhawuleza ukuba zikhutshwe. Ngokufanayo, akunamsebenzi ukugcina inkqubo yethu ihlaziywa ukuba iziqinisekiso zokungqinisisa ezibonakala ngokungagqibekanga ngexesha lofakelo ziyaqhubeka nokusetyenziswa. Kuzo zombini iimeko, kunjalo iinkqubo zokhuselo lokuqala, ezingadingi ukuphindwaphindwa, zisetyenziswe ngokufanelekileyo.
Ukuba unokhathalelo lwenkqubo ye-GNU / Linux ene-Apache okanye enye indawo evulekileyo yomthombo wewebhu kwaye ufuna ukukhangela ukuba ngaba yonakalisiwe, inkqubo ilula. Kwindaba ye ukungcwaba, Kuya kufuneka uvule i-terminal kwaye uchwetheze lo myalelo ulandelayo:
ssh -G
Ukuba impendulo yahlukile ku:
ssh: illegal option – G
kwaye ke uluhlu lwezinto ezichanekileyo zokwenza loo myalelo, emva koko inkqubo yakho iyancitshiswa.
Kwimeko ye Umsebenzi okhethiweyo, inkqubo inzima ngakumbi. Kuya kufuneka uvule i-terminal kwaye ubhale:
curl -i http://myserver/favicon.iso | grep "Location:"
Ukuba inkqubo yakho yonakalisiwe, ngoko Umsebenzi okhethiweyo uya kusihambisa kwakhona isicelo kwaye akunike iziphumo:
Location: http://google.com
Ngaphandle koko, ayizukubuyisa nantoni na okanye enye indawo eyahlukileyo.
Ifom yokubulala iintsholongwane inokubonakala ngathi krwada, kodwa kuphela kwento eqinisekisiweyo esebenzayo: inkqubo epheleleyo yokusula, ukuphinda ufake kwakhona ukuqala kwaye setha kwakhona zonke iziqinisekiso umsebenzisi kunye nomphathi ukusuka kwisiphelo esingaqinisekiswanga. Ukuba kubonakala kunzima kuwe, qaphela ukuba, ukuba ubunokutshintsha iziqinisekiso ngokukhawuleza, ngekhe uyonakalise inkqubo.
Ukufumana uhlalutyo olunzulu ngakumbi lweendlela ezi zifo ezisebenza ngayo, kunye neendlela ezithile ezisetyenzisiweyo ukusasaza kunye namanyathelo ahambelanayo ekufuneka ethathiwe, sicebisa ukukhuphela kunye nokufunda uhlalutyo olupheleleyo "Umsebenzi weWindigo" iyafumaneka kule khonkco ilandelayo:
Okokugqibela, a Isiphelo esisisiseko: Akukho ndlela yokusebenza eqinisekisiweyo ngokuchasene nabaphathi abangenankathalo okanye abangakhathaliyo; Ngokuphathelele ukhuseleko, kuhlala kukho into ekufuneka yenziwe, kuba eyona mpazamo yokuqala kunye neyona inkulu kukucinga ukuba sele siphumelele, okanye awucingi njalo?
Kuyinyani, abantu "bayenzeka", emva koko kwenzeka ntoni. Ndiyibona yonke imihla ngomcimbi wohlaziyo, nokuba yeyiphi na inkqubo (iLinux, Windows, Mac, Android ...) ukuba abantu abenzi uhlaziyo, bayonqena, abanalo ixesha, andidlali xa kunokwenzeka ...
Kwaye ayisiyiyo loo nto kuphela, kodwa bayahamba ukusuka ekutshintsheni iziqinisekiso ezingagqibekanga okanye baqhubeke besebenzisa iipassword ezinje ngo "1234" nokunye okunje emva koko bakhalaze; Ewe ulungile, nokuba yeyiphi na i-OS abayisebenzisayo, iimpazamo ziyafana.
Ndiyabulela kakhulu ngokuma uze ubeke izimvo ...
Ogqwesileyo! yinyani kuyo yonke into!
Enkosi ngengcaciso yakho nangokuma ngu ...
Umyalelo ogcwele ngakumbi endiwufumene kwinethiwekhi yomsebenzisi @Matt:
ssh -G 2> & 1 | grep -e ngokungekho mthethweni -ingaziwa> / dev / null && echo "Inkqubo ecocekileyo" || "Inkqubo yosulelekileyo"
Waoh! ... Ngcono kakhulu, umyalelo sele ukuxelele ngqo.
Enkosi ngegalelo nangokuma kwakho.
Ndivumelana ngokupheleleyo nawe, ukhuseleko luphuculo oluqhubekayo!
Inqaku elihle!
Enkosi kakhulu malunga nenkcazo kunye nokuma ngu ...
Kuyinyani kakhulu, ngumsebenzi wembovane apho uhlala uhlala ujonga kwaye ukhathalela ukhuseleko.
Inqaku elilungileyo, phezolo nje iqabane lam belindixelela ngomsebenzi weWindigo awafunde ezindabeni: "ayisiyiyo iLinux engenakosuleleka kusulelo", kwaye wayesithi ixhomekeke kwizinto ezininzi, hayi kuphela ukuba iLinux ayiqinisekanga .
Ndizokucebisa ukuba ufunde eli nqaku, nokuba awuqondi nto malunga nobuchwephesha be-XD
Ngelishwa lo ngumbono oshiywe zezi ntlobo zeendaba, ngokoluvo lwam zichazwe ngabom, ngethamsanqa iqabane lakho ubuncinci liphawule kuwe, kodwa ngoku lungiselela umjikelo wemibuzo emva kokuba inqaku lifundiwe.
Enkosi kakhulu malunga nenkcazo kunye nokuma ngu ...
Inqaku elilunge kakhulu, uCharlie. Enkosi ngokuthatha ixesha lakho.
Enkosi ngokuma kwaye uphawule ...
Inqaku elilunge kakhulu!
hug, pablo.
Enkosi kakhulu uPablo, ukwanga ...
Ndiyayibulela ingcaciso oyipapashayo, kwaye ngokuvumelana ngokupheleleyo neenqobo ezichaziweyo, ngendlela efanelekileyo kakhulu ukubhekisa kwinqaku likaSchneier "Ukhuseleko YINKQUBO ASIYIMveliso".
Imibuliso evela eVenezuela. 😀
Enkosi kuwe ngokuphawula nangokudlula.
Kulungile!
Okokuqala, igalelo elihle !! Ndiyifundile kwaye ibinomdla ngokwenene, ndivuma ngokupheleleyo uluvo lwakho lokuba ukhuseleko yinkqubo, hayi imveliso, ixhomekeke kumlawuli weNkqubo, ukuba kufanelekile ukuba ube nenkqubo ekhuselekileyo ukuba uyishiya apho ngaphandle Ukuyihlaziya ngaphandle kokutshintsha iziqinisekiso ezizenzekelayo?
Ndithatha eli thuba ukukubuza umbuzo ukuba awunangxaki, ndiyathemba ukuba awukhathazeki ukuphendula.
Jonga ndivuya kakhulu ngesi sihloko sokhuseleko kwaye ndingathanda ukufunda ngakumbi ngokhuseleko kwi-GNU / Linux, SSH kunye ne-GNU / Linux ngokubanzi, yiza, ukuba ayisiyongxaki, ungandicebisa? kuqala? I-PDF, "isalathiso", nantoni na enokuthi ikhokele i-newbie inokunceda.
Imibuliso kwaye ndiyabulela kakhulu kwangaphambili!
Umsebenzi weWindigo ... Kude kube kutshanje ndiyifumene le meko, sonke siyazi ukuba ukhuseleko kwi-GNU / Linux lungaphezulu kwalo lonke uxanduva lomlawuli. Ewe, andikaqondi ukuba inkqubo yam yonakaliswe njani, oko kukuthi, "Inkqubo echaphazelekayo" ukuba akukho nto ndiyifakileyo kwinkqubo engekho ngqo kwinkxaso, kwaye okunene ukuba ibiyiveki endiyifakileyo I-Linux Mint, kwaye kuphela ndifake i-lm-sensors, Gparted kunye nezixhobo zendlela yeelaptop, ke kubonakala kuyinto engaqhelekanga kum ukuba le nkqubo inentsholongwane, ngoku kufuneka ndiyisuse ngokupheleleyo kwaye ndiyibuyisele kwakhona. Ngoku ndinombuzo omkhulu malunga nendlela yokukhusela le nkqubo ukusukela oko yayinosulelo kwaye andazi nokuba u-haha… Enkosi
Enkosi ngolwazi.
Kuhlala kubalulekile ukuba neendlela zokhuseleko ezinje ngale ichazwe kwinqaku nangakumbi xa kufikwa kumba wokukhathalela usapho, kodwa ukuba ufuna ukubona zonke iindlela ezinikezelwa yimarike malunga noku, ndiyakumema ukuba undwendwele http://www.portaldeseguridad.es/