Categories: esihlokweni

Isevisi ye-NotLegit Vulnerability Azure App Yenza Ikhodi Yomthombo Isesidlangalaleni

Uchwepheshe wezokuphepha u-Wiz uxwayisa ngobungozi ku-Microsoft's Azure App Service. Ukuba sengozini kuveza amakhulukhulu amaqoqo ekhodi yomthombo. IMicrosoft isikhiphe ukuvuza.

U-Wiz uthole lokho okubizwa nge-NotLegit sengozini ku-Azure App Service. Le nkonzo, eyaziwa nangokuthi i-Azure Web Apps, iyinkundla yokubamba amawebhusayithi nezinhlelo zokusebenza ezisekelwe kuwebhu. Ikhodi yomthombo nama-artifact angalayishwa ku-Azure App Service kusetshenziswa ithuluzi le-Local Git. Abasebenzisi bangakwazi ukumisa ikhosombe le-Local Git ngesiqukathi sesevisi ye-Azure App futhi baphushele ikhodi ngqo kuseva.

Ngokwabacwaningi, yilapho kanye kulele khona ukuba sengozini. Lapho usebenzisa i-Local Git ukukhipha ikhodi ku-Azure App Service, inqolobane ye-git yamiswa ngohlu lwemibhalo olufinyeleleka esidlangalaleni wonke umuntu angalufinyelela.

Izilimi zekhodi ezimbalwa zithintekile

Ikakhulukazi ikhodi yomthombo ebhalwe nge-PHP, i-Python, i-Ruby noma i-Node isengozini. Lokhu kungenxa yokuthi lezi zilimi zekhodi zivame ukusebenzisa amaseva ewebhu njenge-Apache, Nginx kanye neFlask. Lezi ziphakeli zewebhu azikwazi ukuphatha amafayela we-web.config. Lokhu kuvumela ukufinyelela komphakathi kumakhosombe amakhodi omthombo.

Kwaziwa yiMicrosoft

Ochwepheshe bezokuphepha e-Wiz sebevele bazisile i-Microsoft ngobungozi ekuqaleni kuka-Okthoba kulo nyaka. IMicrosoft isiyivalile. Kunoma yikuphi, ochwepheshe banxusa abasebenzisi ukuthi bahlole ukuthi ikhodi yabo yomthombo iyembuliwe yini futhi bathathe isinyathelo ngezicelo zabo.

UMax Reisler

Sanibonani! Ngingu-Max, ingxenye yethimba lethu lokususa uhlelo olungayilungele ikhompuyutha. Umgomo wethu ukuhlala siqaphile ukuze sigweme izinsongo zohlelo olungayilungele ikhompuyutha. Ngebhulogi yethu, sikugcina unolwazi ngezingozi zakamuva zohlelo olungayilungele ikhompuyutha kanye negciwane lekhompyutha, likuhlomisa ngamathuluzi okuvikela idivayisi yakho. Ukusekela kwakho ekusakazeni lolu lwazi olubalulekile kuyo yonke inkundla yezokuxhumana kubaluleke kakhulu emzamweni wethu ohlangene wokuvikela abanye.

Okuthunyelwe kwakamuva

Susa i-QEZA ransomware (Susa ukubethela amafayela e-QEZA)

Usuku ngalunye oludlulayo lwenza ukuhlaselwa kwe-ransomware kube yinto evamile. Badala isiphithiphithi futhi bafuna imali…

amahora 3 edlule

Susa i-Forbeautiflyr.com (inkomba yokususa igciwane)

Abantu abaningi babika ukuthi babhekene nezinkinga ngewebhusayithi ebizwa ngeForbeautiflyr.com. Le webhusayithi ikhohlisa abasebenzisi ukuthi...

1 usuku oludlule

Susa i-Myxioslive.com (inkomba yokususa igciwane)

Abantu abaningi babika ukuthi babhekene nezinkinga ngewebhusayithi ebizwa ngokuthi i-Myxioslive.com. Le webhusayithi ikhohlisa abasebenzisi ukuthi...

1 usuku oludlule

Uyikhipha kanjani i-HackTool:Win64/ExplorerPatcher!MTB

Uyikhipha kanjani i-HackTool:Win64/ExplorerPatcher!MTB? I-HackTool:Win64/ExplorerPatcher!MTB ifayela legciwane elithelela amakhompyutha. I-HackTool:Win64/ExplorerPatcher!I-MTB ithatha izintambo...

Izinsuku 2 edlule

Susa i-BAAA ransomware (Susa ukubethela amafayela e-BAAA)

Usuku ngalunye oludlulayo lwenza ukuhlaselwa kwe-ransomware kube yinto evamile. Badala isiphithiphithi futhi bafuna imali…

Izinsuku 3 edlule

Khipha Wifebaabuy.live (inkomba yokususa igciwane)

Abantu abaningi babika ukuthi babhekene nezinkinga ngewebhusayithi ebizwa ngokuthi Wifebaabuy.live. Le webhusayithi ikhohlisa abasebenzisi ukuthi...

Izinsuku 4 edlule