Chii Chaunoda Kuziva Nezveiyo Log4j Kusagadzikana Muna 2023?

Log4j Vulnerability

Nhanganyaya: Chii chinonzi Log4j kusagadzikana?

Kusagadzikana kweLog4j imhosva yekuchengetedza yakawanikwa muraibhurari yakakurumbira yakavhurika-sosi yekutema matanda, Log4j. Inobvumira vanorwisa kuti vaite zvekupokana kodhi pane masisitimu anoshandisa asina njodzi vhezheni yeLog4j, zvinogona kutungamira mukuputswa kwedata uye mamwe marudzi e cyber kurwiswa.

 

Chii chinonzi Log4j uye chinoshandiswa sei?

Log4j iJava-yakavakirwa matanda raibhurari iyo inoshandiswa zvakanyanya nevagadziri kunyora mameseji egi mumashandisirwo. Iyo inobvumira vanogadzira kuburitsa zvinyorwa zvegi kubva kumashandisirwo kuenda kunzvimbo dzakasiyana siyana, senge faira, dhatabhesi, kana koni. Log4j inoshandiswa mumhando dzakasiyana dzekushandisa, kusanganisira webhu maseva, nharembozha, uye bhizinesi Software.

 

Chii chinonzi Log4j kusagadzikana uye chinoshanda sei?

Kusagadzikana kweLog4j, inozivikanwawo seCVE-2017-5645, isimba rekuchengetedza rinobvumira vanorwisa kuti vaite zvekupokana kodhi pane masisitimu anoshandisa shanduro dzisina njodzi dzeLog4j. Izvo zvinokonzerwa nekusagadzikana kwekusagadzikana muLog4j raibhurari iyo inobvumira vanorwisa kutumira zvine hutsinye mameseji elogi kune application, iyo inozobviswa uye kuurayiwa neapp. Izvi zvinogona kubvumira vanorwisa kuti vawane ruzivo rwe data rakavanzika, kuba zvitupa zvekupinda, kana kutora kutonga kweiyo system.

 

Iwe unogona sei kudzivirira kubva kune iyo Log4j kusagadzikana?

Kuti udzivirire pakusagadzikana kweLog4j, zvakakosha kuve nechokwadi kuti uri kushandisa vhezheni yeLog4j isingakanganisike nekusagadzikana. Chikwata cheLog4j chakaburitsa zvigamba zvinyorwa zveraibhurari zvinogadzirisa kusagadzikana, uye zvinokurudzirwa kukwidziridza kune imwe yeidzi shanduro nekukurumidza. Pamusoro pezvo, iwe unofanirwa zvakare kuona kuti uri kushandisa yakachengeteka deerialization raibhurari uye kuita kwakaringana kuisirwa kwekuisa kuti udzivise vanokurwisa kubva kutumira mameseji ane hutsinye kune yako application.

 

Chii chaunofanira kuita kana iwe wakakanganisika nekusagadzikana kweLog4j?

Kana iwe uchitenda kuti system yako yakakanganiswa nekusagadzikana kweLog4j, zvakakosha kuti utore matanho nekukurumidza kuchengetedza system yako uye kudzivirira imwe kukuvara. Izvi zvinogona kusanganisira kubata njodzi, kusetazve mapassword, uye kuita mamwe matanho ekuchengetedza kudzivirira kubva mukurwiswa mune ramangwana. Iwe unofanirwawo kufunga kuudza nyaya kuLog4j timu uye chero zviremera zvine chekuita, senge Cybersecurity uye Infrastructure Security Agency (CISA) muUnited States.

 

Mhedziso: Kudzivirira kubva pakusagadzikana kweLog4j

Mukupedzisa, kusagadzikana kweLog4j idambudziko rakakura rekuchengetedza iro rinogona kubvumira vanorwisa kuti vatore kodhi isina kufanira pamasisitimu anoshandisa shanduro dzisina njodzi dzeraibhurari. Izvo zvakakosha kuve nechokwadi chekuti uri kushandisa yakavharwa vhezheni yeLog4j uye kuita kwakaringana matanho ekuchengetedza kudzivirira kubva panjodzi iyi uye kudzivirira kutyora kwedata uye mamwe marudzi ekurwiswa kwecyber.