{"id":221359,"date":"2022-11-24T17:33:00","date_gmt":"2022-11-24T14:33:00","guid":{"rendered":"https:\/\/geek.mediadoma.com\/?p=221359"},"modified":"2022-12-04T14:59:16","modified_gmt":"2022-12-04T11:59:16","slug":"teadlased-leiavad-uue-windowsi-aerakasutamise-ja-raeaegivad-haekkeritele-kogemata-kuidas-seda-kasutada","status":"publish","type":"post","link":"https:\/\/geek.mediadoma.com\/et\/teadlased-leiavad-uue-windowsi-aerakasutamise-ja-raeaegivad-haekkeritele-kogemata-kuidas-seda-kasutada\/","title":{"rendered":"Teadlased leiavad uue Windowsi \u00e4rakasutamise ja r\u00e4\u00e4givad h\u00e4kkeritele kogemata, kuidas seda kasutada"},"content":{"rendered":"<p>Microsoft<\/p>\n<p>Juunis parandas Microsoft kriitilise tasemega haavatavuse nimega CVE-2021-1675. See haavatavus v\u00f5imaldas h\u00e4kkeritel prindispuuleri s\u00fcsteemi kaudu arvutite kaugjuhtimist \u00fcle v\u00f5tta \u2013 p\u00e4ris hirmutav v\u00e4rk! Kahjuks on Hiina tehnoloogiaettev\u00f5tte Sangfor teadlased sarnase \u00e4rakasutamise nimega <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">PrintNightmare vabastanud<\/a> p\u00e4rast seda, kui olid h\u00e4kkeritele \u00f6elnud, kuidas kasutada \u00e4ra varem avastamata viga.<\/p>\n<blockquote>\n<p><strong>V\u00e4rskendus, 7\/7\/21 11:29 Ida:<\/strong> Microsoft <a href=\"https:\/\/geek.mediadoma.com\/et\/vaerskendus-see-ei-toeoeta-printnightmarei-haavatavuse-parandamiseks-vaerskendage-oma-windowsi-arvutit-kohe\/\" title=\"avaldab n\u00fc\u00fcd erakorralist v\u00e4rskendust\">avaldab n\u00fc\u00fcd erakorralist v\u00e4rskendust<\/a>, et parandada PrintNightmare&#8217;i haavatavust. See v\u00e4rskendus laieneb enamikule Windowsi operatsioonis\u00fcsteemi versioonidele, sealhulgas Windows 7-le.<\/p>\n<\/blockquote>\n<p>Kuidas see juhtus? Noh, Sangfor valmistub korraldama konverentsi Windowsi printeris\u00fcsteemi \u00fcle, mis on alati olnud h\u00e4kkerite suhtes haavatav. Inimeste ettevalmistamiseks selleks konverentsiks otsustas Sangfor avaldada <a href=\"https:\/\/doublepulsar.com\/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">kontseptsiooni<\/a> t\u00f5endi (POC), milles selgitatakse, kuidas hiljuti paigatud CVE-2021-1675 t\u00f6\u00f6tab ja k\u00f5iki ohtlikke asju, mida saate sellega teha.<\/p>\n<p>Kuid need teadlased ei m\u00e4nginud CVE-2021-1675-ga. Selgub, et nad olid avastanud sarnase haavatavuse Windowsi prindispuuleris nimega <a href=\"https:\/\/doublepulsar.com\/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">PrintNightmare<\/a> \u2013 mis kannab n\u00fc\u00fcd meelitavat nime CVE-2021-34527. PrintNightmare&#8217;is POC-i avaldamisega \u00f5petas Sangfor h\u00e4kkeritele t\u00f5husalt kasutama Windowsi s\u00fcsteemi ohtlikku nullp\u00e4evaviga.<\/p>\n<p><a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsofti<\/a> andmetel m\u00f5jutab PrintNightmare k\u00f5iki Windowsi versioone. See on viga Windowsi prindispuuleris \u2013 keerulises t\u00f6\u00f6riistas, mida Windows kasutab muu hulgas printimisgraafikutega \u017eongleerimiseks. H\u00e4kkerid, kes seda haavatavust \u00e4ra kasutavad, saavad s\u00fcsteemi \u00fcle t\u00e4ieliku kontrolli ning neil on \u00f5igus k\u00e4ivitada suvalist koodi, installida tarkvara ja hallata faile.<\/p>\n<p>1 juuni <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsoft Security Response Centeri<\/a> postituses v\u00e4idab ettev\u00f5te, et h\u00e4kkerid peavad enne PrintNightmare&#8217;i \u00e4rakasutamist arvutisse sisse logima (see t\u00e4hendab, et ettev\u00f5tted, raamatukogud ja muud suurte v\u00f5rkudega organisatsioonid v\u00f5ivad olla k\u00f5ige haavatavamad). Microsoft \u00fctleb, et h\u00e4kkerid kasutavad aktiivselt PrintNightmare&#8217;i s\u00fcsteemide kompromiteerimiseks, seega peaksid asjaomased osapooled v\u00f5tma meetmeid <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">probleemi leevendamiseks<\/a>.<\/p>\n<p>Praegu on aga ainus viis arvuti kaitsmiseks PrintNightmare&#8217;i eest keelata sellised printimisfunktsioonid nagu Print Spooler. See ettevaatusabin\u00f5u v\u00f5ib osutuda v\u00f5imatuks organisatsioonides, kus printimisv\u00f5rgud on h\u00e4davajalikud, kuid saate teada, kuidas neid samme teha <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsofti turvalisuse reageerimiskeskusest<\/a>.<\/p>\n<p>Allikas: <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsoft<\/a> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-shares-mitigations-for-windows-printnightmare-zero-day-bug\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Bleeping Computeri<\/a> kaudu, <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2021\/07\/02\/new-critical-security-warning-issued-for-all-windows-versions-as-printnightmare-confirmed\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Forbes<\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Juunis parandas Microsoft kriitilise tasemega haavatavuse nimega CVE-2021-1675. See haavatavus v\u00f5imaldas h\u00e4kkeritel prindispuuleri s\u00fcsteemi kaudu arvutite kaugjuhtimist \u00fcle v\u00f5tta \u2013 p\u00e4ris hirmutav v\u00e4rk! Kahjuks on Hiina tehnoloogiaettev\u00f5tte Sangfor teadlased sarnase \u00e4rakasutamise nimega PrintNightmare vabastanud p\u00e4rast seda, kui olid h\u00e4kkeritele \u00f6elnud, kuidas kasutada \u00e4ra varem avastamata viga.<\/p>\n","protected":false},"author":1,"featured_media":230601,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[735,754,724],"tags":[],"class_list":["post-221359","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mitmesugused","category-turvalisus","category-uudis"],"_links":{"self":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts\/221359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/comments?post=221359"}],"version-history":[{"count":0,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/posts\/221359\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/media\/230601"}],"wp:attachment":[{"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/media?parent=221359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/categories?post=221359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/et\/wp-json\/wp\/v2\/tags?post=221359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}