I-Docker Hub yaqhekezwa kwaye iiakhawunti ezili-190,000 zavezwa, iithokheni, ukufikelela nokunye

Igqekeziwe

Kutshanje iqela le UDocker ukhuphe iingcebiso kwezokhuseleko ukwazisa ukufikelela okungagunyaziswanga kwindawo yogcino lwedatha yeDocker Hub ngumntu ongaziwayo. Iqela le-Docker laqonda ngokungenelela okwathatha ixesha elifutshane ngo-Epreli 25, 2019.

Isiseko sedatha yeDocker Hub kutyhilwa ulwazi olubuthathaka kubasebenzisi abamalunga ne-190,000, kubandakanya amagama abasebenzisi kunye neepassword, kunye neethokheni zeGitHub kunye neBitbucket zokugcina ezingasetyenziswanga ngumntu wesithathu ezinokuthi zonakalise ukuthembeka kweekhowudi zokugcina.

Ngokombono kaDocker, ulwazi olukwiziko ledatha lubandakanya iithokheni zokufikelela zeGitHub kunye neBitbucket zokugcina ezisetyenziselwa ukudityaniswa kwekhowudi ezenzekelayo kwiDocker Hub, kunye namagama abasebenzisi kunye neepassword zabasebenzisi abancinci beepesenti: iakhawunti yomsebenzisi eyi-190,000. Bamele ngaphantsi kwe-5% yabasebenzisi beDocker Hub.

Enyanisweni, Izitshixo zokufikelela zeGitHub kunye neBitbucket ezigcinwe kwiDocker Hub zivumela abaphuhlisi ukuba baguqule ikhowudi yeprojekthi kwaye ngokuzenzekelayo uqokelele umfanekiso uye kwiDocker Hub.

Ukusetyenziswa kwabo bachaphazelekayo kunokulungiswa

Umngcipheko onokubakho Abasebenzisi be-190,000 iiakhawunti zabo zavezwa kukuba ukuba umhlaseli ufumana ukufikelela kwiithokheni zabo zokufikelela, unokufumana ukufikelela kwikhowudi yabo yabucala abanokuthi bayiguqule ngokusekwe kwiimvume ezigcinwe kwithokheni.

Nangona kunjalo, ukuba ikhowudi itshintshiwe ngenxa yezizathu ezingalunganga kunye nemifanekiso eyonakalisiweyo yenziwe, oku kungakhokelela kuhlaselo olunzima lokubonelelanjengemifanekiso yeDocker Hub iqhele ukusetyenziswa kwizicelo zeseva nakwinkqubo.

Kwingcebiso yakho yezokhuseleko eposwe ngoLwesihlanu ebusuku, UDocker uthe sele ezirhoxisile zonke iithokheni kunye nezitshixo zokufikelela kwiscreen.

UDocker ukwathe uphucula iinkqubo zawo zokhuseleko kunye nokuphononongwa kwemigaqo-nkqubo. Ukwazise ukuba izixhobo ezitsha zokubeka iliso sele zikhona.

I-Docker-Hub-Hacked1

Nangona kunjalo, Kubalulekile ukuba abaphuhlisi, basebenzise ulwakhiwo oluzenzekelayo lweDocker Hub, jonga iipositi zakho zeprojekhthi ukufikelela ngokungekho mthethweni.

Nalu ingcebiso kwezokhuseleko eposwe nguDocker ngolwesiHlanu ebusuku:

NgoLwesine, nge-25 ka-Epreli 2019, sifumene ukufikelela okungagunyaziswanga kwindawo enye yokugcina iziko ledatha eligcina iseti yedatha engengomsebenzisi. ezezimali Emva kokufumanisa, senza ngokukhawuleza ukungenelela kwaye sikhusele indawo.

Sifuna ukukwazisa esikufundileyo kuphando lwethu oluqhubekayo, kubandakanya ukuba zeziphi iiakhawunti zeDocker Hub ezichaphazelekayo kunye nokuba zeziphi iintshukumo ezenziwa ngabasebenzisi.

Yile nto siyifundileyo:

Ngexesha elifutshane lokufikelela okungagunyaziswanga kwindawo yogcino lwedatha yeDocker Hub, idatha ebuthathaka evela malunga neakhawunti ezili-190,000 (ngaphantsi kwe-5% yabasebenzisi beHub) inokuvezwa.

Idatha ibandakanya amagama abasebenzisi kunye negama eligqithisiweyo lwepesenti encinci yalaba basebenzisi, kunye neethokheni zeGithub kunye neBitbucket zokwakha okuzenzekelayo kweDocker.

Inyathelo lokuthabatha:

Sicela abasebenzisi ukuba batshintshe iphasiwedi kwi-Docker Hub nayo nayiphi na enye iakhawunti ekwabelana ngale password.

Kubasebenzisi abaneseva ezakha ngokuzenzekelayo ezinokuthi zichaphazeleke, sizirhoxisile izitshixo zokufikelela kunye neethokheni kwiGitHub kwaye uyacelwa ukuba uphinde unxibelelane noovimba bakho kwaye ujonge iilog zokhuseleko ukubona ukuba akukho nasiphi na isenzo. Iziganeko ezingalindelekanga zenzekile.

Ungajonga iintshukumo zokhuselo kwiiakhawunti zakho zeGitHub okanye zeBitBucket ukubona ukuba ngaba kukho ukufikelela okungalindelekanga kwiiyure ezingama-24 ezidlulileyo.

Oku kunokuchaphazela ulwakhiwo lwakho lwangoku kwinkonzo yethu ezenzekelayo. Kuya kufuneka unqamle kwaye uqhagamshele kwakhona umboneleli wakho wemithombo uGithub kunye neBitbucket njenge ichazwe kwikhonkco elingezantsi.


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.