OnWorks Linux ื•-Windows Online WorkStations

ืœื•ื’ื•

ืื™ืจื•ื— ืžืงื•ื•ืŸ ื‘ื—ื™ื ื ืขื‘ื•ืจ ืชื—ื ื•ืช ืขื‘ื•ื“ื”

<ื”ืงื•ื“ื | ืชื•ื›ืŸ | ื”ื‘ื>

11.2. ืกื•ื’ื™ ื”ืขืจื›ื•ืช


ื›ืขืช, ืœืื—ืจ ืฉื”ื‘ื˜ื—ืช ืฉืกื‘ื™ื‘ืช ื”ืงืืœื™ ืฉืœืš ืžื•ื›ื ื”, ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ืœื”ื’ื“ื™ืจ ื‘ื“ื™ื•ืง ืื™ื–ื” ืกื•ื’ ืฉืœ ื”ืขืจื›ื” ืืชื” ืขื•ืจืš. ื‘ืจืžื” ื”ื’ื‘ื•ื”ื” ื‘ื™ื•ืชืจ, ื ื™ืชืŸ ืœืชืืจ ืืจื‘ืขื” ืกื•ื’ื™ ื”ืขืจื›ื•ืช: ื ื”ืขืจื›ืช ืคื’ื™ืขื•ืช, ืžื‘ื—ืŸ ืชืื™ืžื•ืช, ืžื‘ื—ืŸ ื—ื“ื™ืจื” ืžืกื•ืจืชื™, ื• ื”ืขืจื›ืช ื™ื™ืฉื•ื. ื”ืชืงืฉืจื•ืช ืขืฉื•ื™ื” ืœื›ืœื•ืœ ืืœืžื ื˜ื™ื ืฉื•ื ื™ื ืฉืœ ื›ืœ ืกื•ื’ ืฉืœ ื”ืขืจื›ื”, ืืš ื›ื“ืื™ ืœืชืืจ ืื•ืชื ื‘ืคื™ืจื•ื˜ ืžืกื•ื™ื ื•ืœื”ืกื‘ื™ืจ ืืช ื”ืจืœื•ื•ื ื˜ื™ื•ืช ืฉืœื”ื ืœืžื‘ื ื” ื•ืœืกื‘ื™ื‘ื” ืฉืœ Kali Linux.

ืœืคื ื™ ืฉืžืชืขืžืงื™ื ื‘ืกื•ื’ื™ ื”ื”ืขืจื›ื•ืช ื”ืฉื•ื ื™ื, ื—ืฉื•ื‘ ืชื—ื™ืœื” ืœืฉื™ื ืœื‘ ืœื”ื‘ื“ืœ ื‘ื™ืŸ ืคื’ื™ืขื•ืช ืœื ื™ืฆื•ืœ.

A ืคื’ื™ืขื•ืช ืžื•ื’ื“ืจืช ื›ืคื’ื ืฉื›ืืฉืจ ื ื™ืฆืœื•, ื™ืคื’ืข ื‘ืกื•ื“ื™ื•ืช, ืฉืœืžื•ืช ืื• ื–ืžื™ื ื•ืช ืฉืœ ืžืขืจื›ืช ืžื™ื“ืข. ื™ืฉื ื ืกื•ื’ื™ื ืจื‘ื™ื ื•ืฉื•ื ื™ื ืฉืœ ืคื’ื™ืขื•ืช ืฉื ื™ืชืŸ ืœื”ื™ืชืงืœ ื‘ื”ืŸ, ื›ื•ืœืœ:

โ€ข ื”ื›ืœืœืช ืงื‘ืฆื™ื: ืคื’ื™ืขื•ื™ื•ืช ืฉืœ ื”ื›ืœืœืช ืงื‘ืฆื™ื1 ื‘ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ืžืืคืฉืจื™ื ืœืš ืœื›ืœื•ืœ ื”ืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ืžืงื•ืžื™ ืื• ืžืจื•ื—ืง ืœืชื•ืš ื”ื—ื™ืฉื•ื‘ ืฉืœ ืชื•ื›ื ื™ืช. ืœื“ื•ื’ืžื”, ืœืืคืœื™ืงืฆื™ื™ืช ืื™ื ื˜ืจื ื˜ ืขืฉื•ื™ื” ืœื”ื™ื•ืช ืคื•ื ืงืฆื™ื™ืช "ื”ื•ื“ืขืช ื”ื™ื•ื" ื”ืงื•ืจืืช ืืช ืชื•ื›ืŸ ื”ืงื•ื‘ืฅ ื•ื›ื•ืœืœืช ืื•ืชื• ื‘ื“ืฃ ื”ืื™ื ื˜ืจื ื˜ ื›ื“ื™ ืœื”ืฆื™ื’ ืื•ืชื• ืœืžืฉืชืžืฉ. ื›ืืฉืจ ืกื•ื’ ื–ื” ืฉืœ ืชื›ื•ื ื” ืžืชื•ื›ื ืช ื‘ืฆื•ืจื” ืฉื’ื•ื™ื”, ื–ื” ื™ื›ื•ืœ ืœืืคืฉืจ ืœืชื•ืงืฃ ืœืฉื ื•ืช ืืช ื‘ืงืฉืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœื• ื›ื“ื™ ืœืืœืฅ ืืช ื”ืืชืจ ืœื›ืœื•ืœ ืืช ื”ืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ืœื‘ื—ื™ืจืชื•.

โ€ข SQL Injection: ื”ื–ืจืงืช SQL2 ื”ืชืงืคื” ื”ื™ื ื›ื–ื• ืฉื‘ื” ืขื•ืงืคื™ื ืืช ืฉื’ืจื•ืช ืื™ืžื•ืช ื”ืงืœื˜ ืขื‘ื•ืจ ื”ืชื•ื›ื ื™ืช, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืฃ ืœืกืคืง ืคืงื•ื“ื•ืช SQL ืœื‘ื™ืฆื•ืข ื”ืชื•ื›ื ื™ืช ื”ืžืžื•ืงื“ืช. ื–ื•ื”ื™ ืฆื•ืจื” ืฉืœ ื‘ื™ืฆื•ืข ืคืงื•ื“ื” ืฉื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ืคื•ื˜ื ืฆื™ืืœื™ื•ืช.

โ€ข ื”ืฆืคืช ืžืื’ืจ: ื”ืฆืคืช ืžืื’ืจ3 ื”ื™ื ืคื’ื™ืขื•ืช ืฉืขื•ืงืคืช ืฉื’ืจื•ืช ืื™ืžื•ืช ืงืœื˜ ื›ื“ื™ ืœื›ืชื•ื‘ ื ืชื•ื ื™ื ืœืชื•ืš ื”ื–ื™ื›ืจื•ืŸ ื”ืกืžื•ืš ืฉืœ ื”ืžืื’ืจ. ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื, ืžื™ืงื•ื ื”ื–ื™ื›ืจื•ืŸ ื”ืกืžื•ืš ื”ื–ื” ืขืฉื•ื™ ืœื”ื™ื•ืช ืงืจื™ื˜ื™ ืœืคืขื•ืœืช ื”ืชื•ื›ื ื™ืช ื”ืžืžื•ืงื“ืช ื•ื ื™ืชืŸ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ื‘ื™ืฆื•ืข ื”ืงื•ื“ ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ื–ื”ื™ืจื” ืฉืœ ื ืชื•ื ื™ ื”ื–ื™ื›ืจื•ืŸ ืฉื”ื•ื—ืœืคื•.

โ€ข ืชื ืื™ ืžืจื•ืฅ: ืชื ืื™ ืžืจื•ืฅ4 ื”ื™ื ืคื’ื™ืขื•ืช ื”ืžื ืฆืœืช ืืช ื”ืชืœื•ืช ื‘ืชื–ืžื•ืŸ ื‘ืชื•ื›ื ื™ืช. ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื, ื–ืจื™ืžืช ื”ืขื‘ื•ื“ื” ืฉืœ ืชื•ื›ื ื™ืช ืชืœื•ื™ื” ื‘ืจืฆืฃ ืกืคืฆื™ืคื™ ืฉืœ ืื™ืจื•ืขื™ื ืฉื™ืชืจื—ืฉื•. ืื ืืชื” ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ืจืฆืฃ ื”ืื™ืจื•ืขื™ื ื”ื–ื”, ื–ื” ืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื•ืช.

An ืœื ืฆืœ, ืžืฆื“ ืฉื ื™, ื”ื™ื ืชื•ื›ื ื” ืฉื‘ืฉื™ืžื•ืฉ, ื”ื™ื ืžื ืฆืœืช ืคื’ื™ืขื•ืช ืกืคืฆื™ืคื™ืช, ืื ื›ื™ ืœื ื›ืœ ื”ืคื’ื™ืขื•ืช ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ. ืžื›ื™ื•ื•ืŸ ืฉื ื™ืฆื•ืœ ื—ื™ื™ื‘ ืœืฉื ื•ืช ืชื”ืœื™ืš ืคื•ืขืœ, ื•ืžืืœืฅ ืื•ืชื• ืœื‘ืฆืข ืคืขื•ืœื” ืœื ืžื›ื•ื•ื ืช, ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžื•ืจื›ื‘ืช. ื™ืชืจ ืขืœ ื›ืŸ, ืงื™ื™ืžื•ืช ืžืกืคืจ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื ื’ื“ ื ื™ืฆื•ืœ ื‘ืคืœื˜ืคื•ืจืžื•ืช ืžื—ืฉื•ื‘ ืžื•ื“ืจื ื™ื•ืช ืฉื”ื™ื•


ืชืžื•ื ื”

1https://en.wikipedia.org/wiki/File_inclusion_vulnerability 2https://en.wikipedia.org/wiki/SQL_injection 3https://en.wikipedia.org/wiki/Buffer_overflow 4https://en.wikipedia.org/wiki/Race_conditionโ€Œโ€Œโ€Œ

ื ื•ืขื“ ืœื”ืงืฉื•ืช ืขืœ ื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ื›ื’ื•ืŸ ืžื ื™ืขืช ื‘ื™ืฆื•ืข ื ืชื•ื ื™ื5 (DEP) ื•ืคืจื™ืกืช ืžืจื—ื‘ ื›ืชื•ื‘ืช ืืงืจืื™ืช6 (ASLR). ืขื ื–ืืช, ืจืง ื‘ื’ืœืœ ืฉืื™ืŸ ื ื™ืฆื•ืœ ื™ื“ื•ืข ื‘ืฆื™ื‘ื•ืจ ืขื‘ื•ืจ ืคื’ื™ืขื•ืช ืกืคืฆื™ืคื™ืช, ื–ื” ืœื ืื•ืžืจ ืฉื”ื™ื ืœื ืงื™ื™ืžืช (ืื• ืฉืื™ ืืคืฉืจ ืœื™ืฆื•ืจ ืื•ืชื”). ืœื“ื•ื’ืžื”, ืืจื’ื•ื ื™ื ืจื‘ื™ื ืžื•ื›ืจื™ื ื ื™ืฆื•ืœื™ื ืžืžื•ืกื—ืจื™ื ืฉืœืขื•ืœื ืื™ื ื ืžืคื•ืจืกืžื™ื ืœืฆื™ื‘ื•ืจ, ื•ืœื›ืŸ ื™ืฉ ืœื”ืชื™ื™ื—ืก ืœื›ืœ ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ื›ืขืœ ืคื•ื˜ื ืฆื™ืืœ ืœื ื™ืฆื•ืœ.


 

ืžื—ืฉื•ื‘ ืขื ืŸ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžื•ื‘ื™ืœ ื‘-OnWorks: