I-UBlock Origin manje inokwesekwa kokuvinjelwa kwe-port port scan

Muva nje, imininingwane ikhishwe mayelana namawebhusayithi athile enza ukuskenwa kwetheku lasekhaya lendawo ngokumelene nezivakashi, lokhu "kucatshangwa" njengengxenye yezigxivizo zeminwe nokulandela ngomsebenzisi noma ukutholwa kwe-bot.

Ngaphakathi kwalawo mawebhusayithi, kuphela ukusho enye yezinto ezidume kakhulu ezenza ukuskena kwetheku lasendaweni isayithi le-Bay.com.

Ngaphezu kwalokho, kwavela ukuthi lo mkhuba awukhawulelwe ku-eBay nakwamanye amasayithi amaningi (ICitibank, i-TD Bank, i-Sky, i-GumTree, i-WePay, njll.) sebenzisa ukuskena kwembobos kusuka kusistimu yendawo yomsebenzisi lapho kuvulwa amakhasi ayo, kusetshenziswa ikhodi ukuthola ukufinyelela okuzama ukungena kumakhompyutha agqekeziwe, ahlinzekwa yiThreatMetrix.

Esimweni se-eBay, amachweba enethiwekhi ayi-14 aqinisekisiwe ehlotshaniswa namaseva okufinyelela akude njenge-VNC, i-TeamViewer, i-Anyplace Control, i-Aeroadmin, i-Ammy Admin, ne-RDP.

Kungenzeka kakhulu, ukuqinisekiswa kuzokwenziwa ukunquma ukuthi ngabe zikhona yini izimpawu ze-malware ezithintekayo ohlelweni ukugwema ukuthenga okukhohlisayo usebenzisa ama-botnets. Ukuskena kungasetshenziselwa ukuthola idatha yokuhlonza okungaqondile komsebenzisi.

Ngaphambi kwalokhu Umakhi weBlock Origin uthathe isinqumo sokuthatha isinyathelo kulolu dabafuthi naku-EasyPrivacy kungezwe imithetho yokuvimba imibhalo ejwayelekile eskena amachweba enethiwekhi kusistimu yomsebenzisi wendawo.

Ukuskena kusetshenziswa inqubo ngokususelwa kumzamo ukusungula ukuxhumana kumachweba wenethiwekhi ahlukahlukene we-Host 127.0.0.1 (localhost) ngeWebSocket.

Ukuskenwa kwembobo kuyindlela yokuphikisana evame ukusetshenziswa ngabadayisi noma kubaduni ukuskena imishini enoxhumano lwe-Inthanethi nokunquma ukuthi iziphi izinhlelo noma izinsiza ezilalele kunethiwekhi, imvamisa ukuze kuhlaselwe okuthile. Kuvamile ukuthi isoftware yezokuphepha ithole ukuskena kwetheku okusebenzayo bese ikumaka njengokuhlukumeza okungenzeka.

Ukuthi unembobo yenethiwekhi evulekile kunqunywa ngokungaqondile ngomehluko ekusetshenzisweni kwephutha lapho uxhuma kumachweba wenethiwekhi asebenzayo nasingasetshenziswanga.

I-WebSocket ivumela ukuthumela kuphela izicelo ze-HTTP, kepha isicelo esifanayo sethebhu yenethiwekhi engenzi lutho sihluleka ngokushesha futhi ngetheku elisebenzayo kuphela ngemuva kwesikhashana kuthatha umzamo wokuxoxisana ngokuxhumeka. Futhi, esimweni setheku elingasebenzi, I-WebSocket ikhiqiza ikhodi iphutha lokuxhumeka (ERR_CONNECTION_REFUSED), futhi esimweni setheku elisebenzayo, ikhodi yephutha lokuxoxisana lokuxhuma.

Lapho ulungiselela isokhethi yewebhu, ucacise indawo yokusingathwa netheku, Akudingeki ukuthi kube yisizinda esifanayo iskripthi esinikezwa kusuka kuso. 

Ukwenza ukuskena kwetheku, iskripthi kufanele sisho kuphela ikheli le-IP eliyimfihlo (njenge-localhost) kanye nechweba ofuna ukuskena.

Ukuskenwa kwetheku kunganikeza imininingwane kuwebhusayithi mayelana nokuthi usebenzisa yiphi isoftware. Amachweba amaningi anesethi yezinsizakalo ezichazwe kahle ezisebenzisayo, ngakho-ke uhlu lwamachweba avulekile lunikeza umbono omuhle wokusebenzisa izinhlelo. 

Isibonelo, iSteam (isitolo sokudlala nepulatifomu) yaziwa ukuthi isebenza ku-port 27036, ngakho-ke isithwebuli lapho sibona lelo port livulekile singaqiniseka ngokusobala ukuthi umsebenzisi ubenomusi ovulekile ngenkathi evakashela iwebhusayithi.

Ngaphezu kokuskena kwetheku, I-WebSocket nayo ingasetshenziselwa ukuhlasela amasistimu wonjiniyela wewebhu esebenzisa amashayeli weWebSocket wezicelo zeReact ohlelweni lwasendaweni.

Isiza sangaphandle singakhula ngamachweba enethiwekhi, sinqume ubukhona besilawuli esinjalo, bese sixhuma kuso.

Phakathi kokungena kwemilayezo yephutha nokuhlaselwa kwesikhathi, isayithi lingathola umbono omuhle wokuthi ngabe itheku elithile livulekile.

Uma unjiniyela enza iphutha, i- umhlaseli uzokwazi ukuthola okuqukethwe kwedatha yokulungisa iphutha, okungafaka imininingwane eyimfihlo eyizingcezu.

Uma ufuna ukwazi kabanzi ngayo, ungabheka kokuthunyelwe okulandelayo.

Umthombo: https://nullsweep.com/


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Unomthwalo wemfanelo ngedatha: AB Internet Networks 2008 SL
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.

  1.   Patrick kusho

    Ungakhombisa ukuthi ungawenza kanjani lo msebenzi, noma wenziwe usebenze ngokuzenzakalela?

    Ngiyabonga imikhonzo.

    1.    Jaramillo kusho

      Masithi iza ngokuzenzakalela ngoba uma ungalungiselelanga iBlock izokuzivuselela njengohlu lwayo lokuhlunga. Kepha uma ufuna ukuqiniseka ukuthi kufanele uvuselele uhlu lwe-EasyPrivacy. Iya kokuncamelayo kwe-plugin, bese 'Uhlu Lokuhlunga', sesha i-EasyPrivacy, chofoza iwashi, bese ekugcineni kunkinobho ethi 'Vuselela manje'.