{"id":200801,"date":"2022-12-28T13:38:00","date_gmt":"2022-12-28T10:38:00","guid":{"rendered":"https:\/\/howtogeek.inform.com.de\/?p=200801"},"modified":"2022-04-04T02:51:16","modified_gmt":"2022-04-03T23:51:16","slug":"kriitiliste-haavatavuste-vaeltimiseks-desinstallige-shareit-androidi-rakendus-kohe","status":"publish","type":"post","link":"https:\/\/howtogeek.inform.com.de\/et\/kriitiliste-haavatavuste-vaeltimiseks-desinstallige-shareit-androidi-rakendus-kohe\/","title":{"rendered":"Kriitiliste haavatavuste v\u00e4ltimiseks desinstallige ShareIt Androidi rakendus kohe"},"content":{"rendered":"\n<p>Jaga seda<\/p>\n<p>Kas teie telefoni on installitud populaarne Androidi rakendus <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.lenovo.anyshare.gps&#038;hl=en_US&#038;gl=US\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">ShareIt ?<\/a> Peaksite selle v\u00f5imalikult kiiresti desinstallima. V\u00f5imaluse korral varem. <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/b\/shareit-flaw-could-lead-to-remote-code-execution.html?PID=100017430&#038;SID=100098X1555750X8ba3a51ee587c02b971909e9cfc15936&#038;cjevent=bb4a3528714511eb815c00aa0a240611\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Trend Micro<\/a> teadlaste s\u00f5nul on ShareItil palju saatuslikke vigu, mis v\u00f5ivad lubada h\u00e4kkeritel teie seadmes koodi k\u00e4ivitada, pahatahtlikke rakendusi installida ja palju muud. Ja kolme kuu p\u00e4rast otsustas ShareIt probleemiga mitte midagi ette v\u00f5tta.<\/p>\n<p>Trend Micro s\u00f5nul v\u00f5imaldavad haavatavused halbadel osalejatel &quot;lekitada kasutaja tundlikke andmeid ja k\u00e4ivitada suvalise koodi ShareIt lubadega.&quot; ShareIt&#8217;iga kaasnevad ulatuslikud lubade n\u00f5uded, kuna see on &quot;k\u00f5ik \u00fches&quot; rakendus.<\/p>\n<p>Nagu nimigi \u00fctleb, alustas see elu jagamisrakendusena, mis n\u00f5uab juba palju lubasid. Kuid rakendus l\u00e4ks \u00f5hku ja n\u00fc\u00fcd on see gif-rakendus, videopleier, lauluotsija, m\u00e4ngupood, filmipood ja palju muud.\u00a0<\/p>\n<p>ShareIt saab taotleda juurdep\u00e4\u00e4su kaamerale, mikrofonile, asukohale, kogu kasutaja salvestusruumile ja kogu meediale. Kuid kuigi see taotleb k\u00f5iki neid \u00f5igusi, ei suuda see kehtestada \u00f5igeid piiranguid, mida Android n\u00f5uab kuritarvitamise v\u00e4ltimiseks.<\/p>\n<p>Probleem tuleneb sellest, kuidas arendajad lubasid v\u00e4lise salvestusruumi load. Kui arendajad j\u00e4rgivad \u00f5igeid juhiseid, on k\u00f5ik h\u00e4sti. <a href=\"https:\/\/blog.checkpoint.com\/2018\/08\/12\/man-in-the-disk-a-new-attack-surface-for-android-apps\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Kuid ignoreerige neid, nagu tegid<\/a> ShareIt arendajad, ja j\u00e4tate oma kasutajad haavatavaks kettamehe r\u00fcnnaku suhtes.<\/p>\n<p>Rakenduste installifailid tuleks saata kaitstud salvestusruumi, et hoida need kriitilise installiperioodi ajal turvalisena. Kui arendaja salvestab need failid selle asemel avalikku salvestusruumi, v\u00f5ib halb tegutseja installifailid kinni pidada, asendada need uute versioonidega ja sisuliselt uuendada rakenduse pahatahtlikuks rakenduseks. Sama juhtus Epici Fortnite&#8217;i installijaga 2018. aastal.<\/p>\n<p>Kui see pole piisavalt halb, laadib ShareIt m\u00e4ngupood alla rakenduste andmed turvamata v\u00f5rgu\u00fchenduste (HTTP) kaudu, mis j\u00e4tab rakenduse avatuks <a href=\"https:\/\/www.howtogeek.com\/668989\/what-is-a-man-in-the-middle-attack\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">r\u00fcnnakute jaoks<\/a>. \u00d5ige oskusteabega saab halb tegutseja ShareIt&#8217;i pahatahtlikuks versiooniks v\u00e4rskendada, teie kasutajaandmeid varastada v\u00f5i m\u00f5lemat.<\/p>\n<p>Trend Micro teatas, et teavitas ShareIt&#8217;i arendajaid probleemidest kolm kuud tagasi ja pole kunagi kuulnud. Loodetavasti aitab kogu halb reklaam kurssi muuta, kuid seni on parem ShareIt v\u00e4hemalt praegu desinstallida.<\/p>\n<p>Allikas: <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/b\/shareit-flaw-could-lead-to-remote-code-execution.html?PID=100017430&#038;SID=100098X1555750X8ba3a51ee587c02b971909e9cfc15936&#038;cjevent=bb4a3528714511eb815c00aa0a240611\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Trend Micro<\/a> <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/02\/shareit-android-app-with-over-a-billion-downloads-is-a-security-nightmare\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Ars Technica<\/a> kaudu<a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/02\/shareit-android-app-with-over-a-billion-downloads-is-a-security-nightmare\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external\"><\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kas teie telefoni on installitud populaarne Androidi rakendus ShareIt? Peaksite selle v\u00f5imalikult kiiresti desinstallima. V\u00f5imalusel varem. Trend Micro teadlaste s\u00f5nul on ShareItil palju saatuslikke vigu, mis v\u00f5ivad lasta h\u00e4kkeritel teie seadmes koodi k\u00e4ivitada, pahatahtlikke rakendusi installida ja palju muud. Ja kolme kuu p\u00e4rast otsustas ShareIt probleemiga mitte midagi ette v\u00f5tta.<\/p>\n","protected":false},"author":1,"featured_media":153107,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[],"tags":[],"class_list":["post-200801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/posts\/200801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/comments?post=200801"}],"version-history":[{"count":0,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/posts\/200801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/media\/153107"}],"wp:attachment":[{"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/media?parent=200801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/categories?post=200801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/howtogeek.inform.com.de\/et\/wp-json\/wp\/v2\/tags?post=200801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}