Ithuluzi elisha le-Hacker likuvumela ukuthi udale amakhasi wobugebengu bokweba imininingwane ebucayi ngesikhathi sangempela

Anonim
Ithuluzi elisha le-Hacker likuvumela ukuthi udale amakhasi wobugebengu bokweba imininingwane ebucayi ngesikhathi sangempela 12802_1

Ochwepheshe ekuvuthweni kwe-cybersecurity kusuka eReviqt bathola isethi entsha ye-Hacker yamathuluzi wobugebengu bokweba imininingwane ebucayi, ukusebenza okuyinhloko kwalokho okuwukushintsha ilogo nombhalo ekhasini lobugebengu ngesikhathi sangempela sokuzidela okuthile.

I-Toolkit yeLogoKit, ngokusho kwengozi, sekuyisikhathi eside isetshenziswe ngama-cybercriminals ngesikhathi sokuhlaselwa kobugebengu bokweba imininingwane ebucayi. Kufakwe izizinda ezingaphezu kuka-300 ngesonto eledlule, futhi ezingaphezu kuka-700 kulo nyaka. Ochwepheshe baphawula ukuthi i-lookit ithumela izixhumanisi zokweba imininingwane ebucayi kubasebenzisi abaqukethe amakheli e-imeyili ahlukunyezwa.

"Lapho nje umuntu eqhubeka nesixhumanisi, ithuluzi lokuphumula lithola ilogo yenkampani lapho isebenza khona ngokuyilayisha kwisevisi yeqembu lesithathu. Ikheli le-imeyili lomsebenzisi linamathiselwa ngokuzenzakalela enkundleni ehambisanayo, ngenxa yokuthi isisulu sicabanga ukuthi selivele ligunyaziwe kuleli sayithi. Ngemuva kokuthi isisulu singene iphasiwedi, i-lookit ifaka isicelo se-AJAX, ithumele iziqinisekiso ezitholakele kuseva yangaphandle, ngemuva kwalokho iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iphinde iqondise umsebenzisi kusayithi langempela lenhlangano yalo, "usho engcupheni:

Ithuluzi elisha le-Hacker likuvumela ukuthi udale amakhasi wobugebengu bokweba imininingwane ebucayi ngesikhathi sangempela 12802_2

Ochwepheshe baphawula ukuthi ithuluzi lokungena linokusebenza okufanayo ngenxa yesethi eshumekiwe yemisebenzi ye-JavaScript, "engezelelwa kunoma yisiphi isimo esijwayelekile sokugunyazwa noma kumadokhumenti ayinkimbinkimbi we-HTML." Indlela enjalo ihluke kakhulu emabekweni ajwayelekile amathuluzi wobugebengu bokweba imininingwane ebucayi, iningi lawo adinga amaphethini anembile ukuze ulingise ikhasi lokugunyazwa ikhasi.

Isimo sesethi ye-Lookit sivumela ama-cybercriminals ukuthi ahlasele cishe kunoma iyiphi inkampani abayifunayo, izindleko zokusetha okuncane.

I-RisetiQ ibike ukuthi ngoJanuwari 2021 kwaphawulwa ukuthi ithuluzi lokungena lalisetshenziselwa ukulingisa futhi lisungule amakhasi okugunyazwa ngezinsizakalo ezihlukile zeWebhu (i-Adobe Doused Cloud, i-Office 365), Isitoli se-Cryptocurrency shintshisana

"Kubalulekile ukuqaphela ukuthi i-Lookit ifayela le-Javascript elisethiwe, ngakho-ke izinsizakusebenza zalo zingathunyelwa ezinsizakalweni ezithembekile ezitholakala emphakathini - ama-Firebase, i-GitHub, i-Oracle Cloud nabanye, iningi lazo libhalwe kuhlu olumhlophe lwemidiya yenhlangano, ngakho-ke Abasebenzisi ngeke bathole izexwayiso ", - efingqiwe e-Riskiq.

Indwangu ethokozisayo ku-CisoClub.ru. Bhalisela: Facebook | I-VK | I-Twitter | I-Instagram | I-Telegraph | Zen | Isithunywa | I-ICQ New | I-YouTube | Pulse.

Funda kabanzi