Abaduni basebenzise amaseva weGitHub ezimayini ze-cryptocurrency

Ilogo yeGitHub

I-Los abaphathi be ipulatifomu yokubamba ikhodi IGitHub, baphenya ngenkuthalo uchungechunge lokuhlaselwa kwingqalasizinda yabo yamafu, ngoba lolu hlobo lokuhlaselwa lwaluvumela abaduni ukuba basebenzise amaseva enkampani ukwenza imisebenzi yezimayini ngokungemthetho yama-cryptocurrensets. 

Futhi kungukuthi ngekota yesithathu ka-2020, lezi ukuhlaselwa kwakususelwa ekusebenziseni isici seGitHub esibizwa ngeGitHub Actions evumela abasebenzisi ukuthi baqale imisebenzi ngokuzenzakalela ngemuva komcimbi othile kusuka ezinqolobaneni zabo zeGitHub.

Ukufeza lokhu kuxhashazwa, kubaduni bathathe indawo yokugcina esemthethweni ngokufaka ikhodi enonya kwikhodi yoqobo kuzenzo zeGitHub bese wenza isicelo sokudonsa ngokumelene nokugcina kwasekuqaleni ukuhlanganisa ikhodi eguquliwe nekhodi esemthethweni.

Njengengxenye yokuhlaselwa kweGitHub, Abaphenyi bezokuphepha babike ukuthi abaduni bangagijima kuze kube yikhulu labavukuzi be-cryptocurrency ngokuhlasela okukodwa, kwakha imithwalo emikhulu yamakhompiyutha kwingqalasizinda yeGitHub. Kuze kube manje, laba baduni babonakala besebenza ngokungahleliwe futhi ngezinga elikhulu.

Ucwaningo luveze ukuthi okungenani i-akhawunti eyodwa yenza amakhulu ezicelo zokuvuselela eziqukethe ikhodi enonya. Njengamanje, abahlaseli ababonakali beqonde ngqo kubasebenzisi be-GitHub, kunalokho bagxile ekusebenziseni ingqalasizinda yamafu yeGitHub ukusingatha umsebenzi wezimayini ze-crypto.

Unjiniyela wezokuphepha waseDashi uJustin Perdok utshele iThe Record ukuthi okungenani isigebengu esisodwa sibhekise kwizinqolobane zeGitHub lapho kungavunyelwa khona izenzo zeGitHub.

Lokhu kuhlasela kufaka phakathi ukufuna indawo yokugcina esemthethweni, ukungeza izenzo ezinonya ze-GitHub kukhodi yangempela, bese uthumela isicelo sokudonswa kanye nendawo yokugcina yangempela yokuhlanganisa ikhodi neyokuqala.

Icala lokuqala lalokhu kuhlasela labikwa ngunjiniyela we-software eFrance ngoNovemba 2020. Njengokusabela kwalo esigamekweni sokuqala, iGitHub yathi iphenya ngenkuthalo ngokuhlaselwa kwakamuva. Kodwa-ke, i-GitHub ibonakala ifika futhi ihlasele, njengoba abaduni bevele benze ama-akhawunti amasha uma ama-akhawunti athelelekile etholakele futhi ekhutshazwa yinkampani.

NgoNovemba nyakenye, iqembu labachwepheshe bezokuphepha be-Google IT elijutshwe ukuthola ubungozi bezinsuku ezi-0 liveze iphutha lokuvikela endaweni yesikhulumi seGitHub. Ngokusho kukaFelix Wilhelm, oyilungu leqembu leProject Zero olitholile, leli phutha liphinde lathinta nokusebenza kweGitHub Actions, ithuluzi lokwenza umsebenzi wonjiniyela. Lokhu kungenxa yokuthi imiyalo yokuhamba komsebenzi ye-Actions "isengozini yokuhlaselwa umjovo":

Izenzo zeGithub zisekela isici esibizwa ngemiyalo yokuhamba komsebenzi njengesiteshi sokuxhumana phakathi kwe-Action broker kanye nesenzo esenziwayo. Imiyalo ye-Workflow isetshenziswa ku-runner / src / Runner.Worker / ActionCommandManager.cs futhi isebenze ngokuhlaziya i-STDOUT yazo zonke izenzo ezenziwe ngomunye wemaki yomyalo emibili.

I-GitHub Actions iyatholakala kuma-GitHub Free, GitHub Pro, GitHub Free for Organisations, GitHub Team, GitHub Enterprise Cloud, GitHub Enterprise Server, GitHub One, kanye ne-GitHub AE akhawunti. Izenzo ze-GitHub azitholakali kumakhosombe azimele aphethwe ama-akhawunti kusetshenziswa amapulani amadala.

Umsebenzi wezimayini ze-Cryptocurrency uvame ukufihlwa noma usebenze ngemuva ngaphandle komlawuli noma kwemvume yomsebenzisi. Kunezinhlobo ezimbili zezimayini ze-crypto ezinonya:

  • Imodi kanambambili: yizinhlelo zokusebenza ezinonya ezilandiwe futhi zafakwa kudivayisi ekhonjiwe ngenhloso yokumba izimali zeDijithali. Ezinye izixazululo zokuphepha zikhomba iningi lalezi zinhlelo zokusebenza njengeTrojans.
  • Imodi yesiphequluli - Le yikhodi enonya yeJavaScript eshumekwe ekhasini lewebhu (noma ezinye zezinto zalo noma izinto), elenzelwe ukukhipha imali eyi-cryptocurrency kwiziphequluli zabavakashi besayithi. Le ndlela ebizwa nge-cryptojacking ibilokhu ithandwa kakhulu ngabenzi be-cybercriminals kusukela maphakathi no-2017. Ezinye izixazululo zokuphepha zithola iningi lalezi zikripthi ze-cryptojacking njengezicelo ezingafuneki.

 

 


Okuqukethwe yi-athikili kunamathela ezimisweni zethu ze izimiso zokuhlelela. Ukubika iphutha chofoza lapha.

Yiba ngowokuqala ukuphawula

Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.