{"id":1412,"date":"2024-08-09T07:34:00","date_gmt":"2024-08-09T05:34:00","guid":{"rendered":"https:\/\/techlance.ddns.net\/?p=1412"},"modified":"2024-08-09T07:34:47","modified_gmt":"2024-08-09T05:34:47","slug":"0-0-0-0-day-haavoittuvuuden-hyvaksikaytto-paikallisverkon-api-rajapintojen-kautta-selaimesta-kasin","status":"publish","type":"post","link":"https:\/\/techlance.ddns.net\/en\/0-0-0-0-day-haavoittuvuuden-hyvaksikaytto-paikallisverkon-api-rajapintojen-kautta-selaimesta-kasin\/","title":{"rendered":"0.0.0.0 Day: Haavoittuvuuden hyv\u00e4ksik\u00e4ytt\u00f6 paikallisverkon API-rajapintojen kautta selaimesta k\u00e4sin"},"content":{"rendered":"<p>Oligo Securityn tutkimustiimi on \u00e4skett\u00e4in paljastanut uuden &#8221;0.0.0.0 Day&#8221; -haavoittuvuuden. T\u00e4m\u00e4 haavoittuvuus mahdollistaa haitallisille verkkosivustoille selaimen tietoturvamekanismien ohittamisen ja yhteydenoton organisaation paikallisverkon palveluihin. T\u00e4m\u00e4n seurauksena hy\u00f6kk\u00e4\u00e4j\u00e4t voivat saada luvattoman p\u00e4\u00e4syn ja suorittaa et\u00e4koodia paikallisissa palveluissa, vaikka he toimivat verkon ulkopuolelta.<\/p>\n\n\n\n<p><strong>Haavoittuvuuden tausta:<\/strong><br>Ongelma johtuu tietoturvamekanismien ep\u00e4johdonmukaisesta toteutuksesta eri selaimissa sek\u00e4 standardoinnin puutteesta selainalalla. T\u00e4m\u00e4n seurauksena IP-osoite 0.0.0.0, joka normaalisti vaikuttaa harmittomalta, voi muuttua hy\u00f6kk\u00e4\u00e4jien tehokkaaksi ty\u00f6kaluksi paikallisten palvelujen, kuten kehitysymp\u00e4rist\u00f6jen, k\u00e4ytt\u00f6j\u00e4rjestelmien ja jopa sis\u00e4isten verkkojen hyv\u00e4ksik\u00e4ytt\u00f6\u00f6n.<\/p>\n\n\n\n<p><strong>Haavoittuvuuden vaikutukset:<\/strong><br>0.0.0.0 Day -haavoittuvuuden vaikutukset ovat laaja-alaisia, ja ne voivat kohdistua niin yksil\u00f6ihin kuin organisaatioihin. Aktiivisesti hy\u00f6dynnettyjen kampanjoiden, kuten ShadowRayn, l\u00f6ytyminen korostaa entisest\u00e4\u00e4n t\u00e4m\u00e4n haavoittuvuuden kiireellist\u00e4 korjaustarvetta.<\/p>\n\n\n\n<p><strong>Suositus:<\/strong><br>On t\u00e4rke\u00e4\u00e4, ett\u00e4 sek\u00e4 selainten kehitt\u00e4j\u00e4t ett\u00e4 organisaatiot ottavat huomioon t\u00e4m\u00e4n haavoittuvuuden ja ryhtyv\u00e4t tarvittaviin toimenpiteisiin est\u00e4\u00e4kseen sen hyv\u00e4ksik\u00e4yt\u00f6n, kuten varmistamalla selainten ja paikallisten palveluiden asianmukaisen tietoturvan ja p\u00e4ivitt\u00e4m\u00e4ll\u00e4 ohjelmistot mahdollisimman pian.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.oligo.security\/blog\/0-0-0-0-day-exploiting-localhost-apis-from-the-browser\">https:\/\/www.oligo.security\/blog\/0-0-0-0-day-exploiting-localhost-apis-from-the-browser<\/a><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techlance wp-block-embed-techlance\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"w032p56Ggl\"><a href=\"https:\/\/techlance.ddns.net\/en\/\">Etusivu<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8221;Etusivu&#8221; &#8212; Techlance\" src=\"https:\/\/techlance.ddns.net\/embed\/#?secret=g45E51pucG#?secret=w032p56Ggl\" data-secret=\"w032p56Ggl\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>","protected":false},"excerpt":{"rendered":"<p>Oligo Securityn tutkimustiimi on \u00e4skett\u00e4in paljastanut uuden &#8221;0.0.0.0 Day&#8221; -haavoittuvuuden. T\u00e4m\u00e4 haavoittuvuus mahdollistaa haitallisille verkkosivustoille selaimen tietoturvamekanismien ohittamisen ja yhteydenoton [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[21,9],"tags":[22,15],"class_list":["post-1412","post","type-post","status-publish","format-standard","hentry","category-data-protection","category-security","tag-data-protection","tag-tietoturva"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/comments?post=1412"}],"version-history":[{"count":0,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1412\/revisions"}],"wp:attachment":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/media?parent=1412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/categories?post=1412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/tags?post=1412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}