Ukwazi i-Port Knock eyimfihlo ingavulela inkqubo yakho

Abafana abalungileyo kunye nabaGad bad usebenzisa le ndlela yokuvula iichwep

Ngokufanelekileyo ufuna ukukhawulela nokulawula i-traffic evunyelwe kwinethiwekhi yakho okanye ikhompyutha. Oku kuya kwenziwa ngeendlela ezahlukeneyo. Iinkqubo ezimbini ezibalulekileyo zokuqinisekisa ukuba iifayili ezingadingekanga kwikhompyutheni yakho ayivuli okanye ilalele ukudibanisa kwaye isebenzise i-firewall-nokuba yikhompyutheni ngokwayo okanye kwi-network perimeter- ukuvimba i-traffic engagunyazisiweyo.

Ngokubeka iliso kwendlela kunye nokulawula imigaqo yomlilo ngokusekelwe kwiimeko ezenzekayo ukudala uhlobo "lokungqongqoza ngasese" oluya kuvula isango kwaye likuvumeleke kwi-firewall. Nangona akukho machweba angase avule ngelo xesha, uchungechunge oluthile lwemizamo yokuxhuma kwiichweba ezivaliweyo kunokubonelela ukuvula ichweba lokunxibelelana.

Ngokucacileyo, uya kuba nenkonzo eqhubayo kwisixhobo esicacileyo esiza kuwujonga umsebenzi wenethiwekhi-ngokuqhelekileyo ngokubeka iliso kwimilo yomlilo . Le nkonzo iya kufuneka ikwazi "ukukhonkqoza" -mzekelo umzekelo wehlulekile ukuzama ukuxhamla ukukhupha i-103, 102, 108, 102, 102. Ukuba inkonzo yadibana ne "imfihlo yongqongqo" ngendlela echanekileyo iya kutshintsha ngokuzenzekelayo i-firewall ukuvula i-port ekhethiweyo ukuvumela ukufikelela okude.

Ngelishwa ngelinye ilanga ababhali be-malware behlabathi (okanye ngethamsanqa-niya kubona ukuba yintoni emininzi) baqala ukusebenzisa le ndlela yokuvula ama-backdoors kwiinkqubo ezixhatshaziweyo. Ngokuqhelekileyo, kunokuvula iichwep zokuxhunywa okude ezibonakalayo kwaye zibonakala, iTrojan isitsalwe ebeka esweni intengiso yenethiwekhi. Emva kokuba "inkonkqozo yangasese" ifunyenwe i-malware iya kuvuselela kwaye ivule i-port yangaphambili yangaphambili, ivumela umhlaseli ukuba afikelele kwinkqubo.

Ndithe ngasentla ukuba oku kunokuba yinto enhle. Ewe, ukusuleleka nge-malware nayiphi na into ayisoze into enhle. Kodwa, njengoko limi ngoku kanye neyintsholongwane okanye iimbungu ziqala ukuvula izibuko kwaye ezo manani ezibuko ziba nolwazi oluntu ukuba iinkqubo ezikhuselekileyo zivulekele ukuhlaselwa ngumntu-kungekhona nje umbhali we-malware ovule i-backdoor. Oku kukhulisa kakhulu iimeko zokungatshatyalaliswa kwintsholongwane okanye kwintsholongwane elandelayo emva kokuba i-malware.

Ngokudala i-backdoor ekhuselekileyo efuna ukuba "unqamle umnqweno" ukuyivula umlobi we-malware ugcina imfihlo yangasemva. Kwakhona, okulungileyo nokubi. Kulungile kuba wonke uTom, uDick noHarry abangcolileyo wannabe abayi kukhangela i-port scanning ukuze bafumane iinkqubo ezisengozini esekelwe kwichweba evuliwe yi-malware. Okubi kuba ukuba sele ilala, awuyi kuba uyazi nokuba kukho na indlela elula yokufumanisa ukuba unesimo sangasemva esingasemva kwenkqubo yakho elindele ukuvuswa yi-port.

Eli qhinga lingasetyenziswe ngabafana abalungileyo njengoko kuboniswe kwiphepha leNkcazelo yeCripto-Gram evela eBruce Schneier. Ngokukodwa umlawuli angacima ngokupheleleyo inkqubo-engavumelekanga ngaphandle kwezithuthi zangaphandle kodwa aphumeze icebo lokungqongqo. Ukusebenzisa "inkonkqozo yangasese" umlawuli uza kuba nako ukuvula ichwep xa kuyimfuneko ukuseka uxhumano olude.

Kubonakala ukuba kubalulekile ukuba kugcinwe imfihlo yekhowudi "yebhonkco". Ngokuyinene, "ukugodla" kuyakuba "iphasiwedi" yeentlobo ezingavumela ukufikelela okungapheliyo kumntu owaziyo.

Kukho iindlela ezininzi zokumisela ukukhutshwa kwefowuni kunye nokuqinisekisa ubungqina besikhokelo sokungena kwichweba- kodwa kusekho ubuchule kunye nokuqhafaza ekusebenziseni ichweba ukubetha ithuluzi lokukhusela kwinethiwekhi yakho. Ukuze uthole iinkcukacha ezingaphezulu funda Njani: Ukukhunjulwa kwePort kwiLinuxJournal.com okanye ezinye zezinye izixhumanisi ukuya ngasekunene kweli nqaku.

Inqaku lomhleli: Eli nqaku liyimvelaphi yelifa kwaye yahlaziywa nguAndy O'Donnell ngo-8/28/2016.