{"id":197588,"date":"2022-05-18T19:48:00","date_gmt":"2022-05-18T16:48:00","guid":{"rendered":"https:\/\/howtogeek.inform.click\/?p=197588"},"modified":"2022-05-18T19:49:06","modified_gmt":"2022-05-18T16:49:06","slug":"haekkerid-on-applei-erakorralisest-macos-i-turvaparandusest-juba-moeoeda-laeinud","status":"publish","type":"post","link":"https:\/\/howtogeek.inform.click\/et\/haekkerid-on-applei-erakorralisest-macos-i-turvaparandusest-juba-moeoeda-laeinud\/","title":{"rendered":"H\u00e4kkerid on Apple&#8217;i erakorralisest macOS-i turvaparandusest juba m\u00f6\u00f6da l\u00e4inud"},"content":{"rendered":"<p>Apple<\/p>\n<p>Apple parandas hiljuti kriitilise MacOS-i haavatavuse, mis v\u00f5imaldab h\u00e4kkeritel meilimanuste kaudu suvalist koodi k\u00e4ivitada. Kahjuks on see plaaster lohakas ja sellest on \u00e4\u00e4rmiselt lihtne m\u00f6\u00f6da minna. Maci omanikud peaksid v\u00e4ltima meilimanuste avamist inetloc-laiendiga, kuni Apple v\u00e4ljastab \u00f5ige paranduse.<\/p>\n<p>Interneti-otseteefailid, mida macOS-is nimetatakse inetloc-failideks, on m\u00f5eldud kasutajate veebilehtedele suunamiseks. Saate luua inetloc-faili, lohistades n\u00e4iteks URL-i oma t\u00f6\u00f6lauale. Kuid macOS-i vea t\u00f5ttu saavad h\u00e4kkerid manustada kasutatava koodi inetloc-failidesse. See kood t\u00f6\u00f6tab m\u00f5jutatud faili avamisel hoiatuseta, pakkudes lihtsat viisi MacOS-i kasutajate r\u00fcnnamiseks e-posti teel.<\/p>\n<p>Kasutamise programmeerimine n\u00f5uab v\u00e4hest arvutuskogemust. Vaadake, inetloc-failid sisaldavad URL-e, mis algavad tavaliselt t\u00e4hega http:\/\/ v\u00f5i https:\/\/. Kuid Apple&#8217;i j\u00e4relevalve v\u00f5imaldab inetloc-failidel osutada file:\/\/ asukohtadele teie arvutis\u00fcsteemis. V\u00e4ike koodirida inetloc-failis v\u00f5ib lasta h\u00e4kkeril k\u00e4ivitada teie s\u00fcsteemis tarkvara v\u00f5i pahatahtlikku laadi.<\/p>\n<p>Teadlane Park Minchan avastas \u00e4rakasutamise selle n\u00e4dala alguses. <a href=\"https:\/\/ssd-disclosure.com\/ssd-advisory-macos-finder-rce\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Apple andis kiiresti v\u00e4lja plaastri p\u00e4rast seda, kui SSD Secure Disclosure<\/a> teatas haavatavusest, kuigi mitmed tehnikav\u00e4ljaanded ja turvaeksperdid leiavad, et sellest paigast ei piisa.<\/p>\n<p>Nagu teatas <a href=\"https:\/\/arstechnica.com\/information-technology\/2021\/09\/unpatched-macos-vulnerability-lets-remote-attackers-execute-code\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Ars Technica<\/a>, takistab Apple&#8217;i v\u00e4ljastatud h\u00e4daabiplaaster MacOS-il k\u00e4ivitamast inetloc-faile, mis algavad eesliitega file:\/\/. Kuid plaaster on t\u00f5stutundlik. Faili file:\/\/ mis tahes osa asendamine suure t\u00e4hega j\u00e4tab paranduse t\u00e4ielikult m\u00f6\u00f6da.<\/p>\n<p>See on Apple&#8217;i amat\u00f6\u00f6rlik t\u00f6\u00f6. See on selline lahendus, mida ootate v\u00e4ikese ettev\u00f5tte praktikantidelt. Ja ausalt \u00f6eldes on see murettekitav m\u00e4rk sellest, et Apple ei v\u00f5ta turvalisust nii t\u00f5siselt, kui v\u00e4idab. See on vist p\u00f5hjus, miks me pole m\u00f5nda aega n\u00e4inud reklaamtahvlit &quot;mis juhtub teie iPhone&#8217;is j\u00e4\u00e4b teie iPhone&#8217;i&quot;.<\/p>\n<p>Allikas: <a href=\"https:\/\/arstechnica.com\/information-technology\/2021\/09\/unpatched-macos-vulnerability-lets-remote-attackers-execute-code\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Ars Technica<\/a>, <a href=\"https:\/\/appleinsider.com\/articles\/21\/09\/22\/apple-partially-patches-new-macos-finder-zero-day-vulnerability\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Apple Insider<\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple parandas hiljuti kriitilise MacOS-i haavatavuse, mis v\u00f5imaldab h\u00e4kkeritel meilimanuste kaudu suvalist koodi k\u00e4ivitada. Kahjuks on see plaaster lohakas ja sellest on \u00e4\u00e4rmiselt lihtne m\u00f6\u00f6da minna. Maci omanikud peaksid v\u00e4ltima meilimanuste avamist inetloc-laiendiga, kuni Apple v\u00e4ljastab \u00f5ige paranduse.<\/p>\n","protected":false},"author":1,"featured_media":184930,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[],"tags":[],"class_list":["post-197588","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/posts\/197588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/comments?post=197588"}],"version-history":[{"count":0,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/posts\/197588\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/media\/184930"}],"wp:attachment":[{"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/media?parent=197588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/categories?post=197588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/howtogeek.inform.click\/et\/wp-json\/wp\/v2\/tags?post=197588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}