{"id":169083,"date":"2013-02-11T23:38:02","date_gmt":"2013-02-11T19:38:02","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=169083"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=169083","title":{"rendered":"<span class=\"post_title\">\u0424\u0430\u0439\u043b\u043e\u043e\u0431\u043c\u0435\u043d\u043d\u0438\u043a Mega \u043d\u0430\u0447\u0430\u043b \u0432\u044b\u043f\u043b\u0430\u0447\u0438\u0432\u0430\u0442\u044c \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0435 \u0437\u0430 \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438<\/span>"},"content":{"rendered":"<div class=\"content html_format\">   \t<img decoding=\"async\" src=\"http:\/\/habrastorage.org\/storage2\/d26\/799\/0be\/d267990be1a61b93fcb2872125f70038.jpg\"\/><\/p>\n<p>  \u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0435\u0434\u0435\u043b\u044e \u043d\u0430\u0437\u0430\u0434 \u043d\u0430 \u0425\u0430\u0431\u0440\u0435 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c <a href=\"http:\/\/habrahabr.ru\/post\/168025\/\">\u043d\u043e\u0432\u043e\u0441\u0442\u044c<\/a> \u043e \u0442\u043e\u043c, \u0447\u0442\u043e \u0444\u0430\u0439\u043b\u043e\u043e\u0431\u043c\u0435\u043d\u043d\u0438\u043a Mega, \u0432\u0435\u0440\u043d\u0435\u0435, \u0435\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c, \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0437\u0430 \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u0421\u0443\u043c\u043c\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0441\u0442\u0438\u0433\u0430\u0442\u044c 10 \u0442\u044b\u0441\u044f\u0447 \u0435\u0432\u0440\u043e. \u041f\u0435\u0440\u0432\u044b\u0435 \u043d\u0430\u0433\u0440\u0430\u0434\u044b \u0443\u0436\u0435 \u043d\u0430\u0448\u043b\u0438 \u0441\u0432\u043e\u0438\u0445 \u0432\u043b\u0430\u0434\u0435\u043b\u044c\u0446\u0435\u0432. <\/p>\n<p>  <a name=\"habracut\"><\/a>\u0412\u0441\u0435\u0433\u043e \u043d\u0430\u0433\u0440\u0430\u0434\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u043e \u0441\u0435\u0439\u0447\u0430\u0441 \u0441\u0435\u043c\u044c \u0447\u0435\u043b\u043e\u0432\u0435\u043a, \u0447\u044c\u0438 \u043b\u0438\u0447\u043d\u043e\u0441\u0442\u0438, \u0447\u0442\u043e \u0440\u0430\u0437\u0443\u043c\u043d\u043e, \u043d\u0435 \u0440\u0430\u0441\u043a\u0440\u044b\u0432\u0430\u044e\u0442\u0441\u044f. \u0421\u0430\u043c\u043e \u0441\u043e\u0431\u043e\u0439, \u0444\u0430\u0439\u043b\u043e\u043e\u0431\u043c\u0435\u043d\u043d\u0438\u043a \u0448\u0443\u0441\u0442\u0440\u043e \u0437\u0430\u043a\u0440\u044b\u043b \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0435 \u0434\u044b\u0440\u044b\/\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0442\u0430\u043a \u0447\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430 Mega \u0441\u0442\u0430\u043b\u0430 \u043d\u0430\u0434\u0435\u0436\u043d\u0435\u0439 (\u0445\u043e\u0442\u0435\u043b\u043e\u0441\u044c \u0431\u044b \u043d\u0430\u0434\u0435\u044f\u0442\u044c\u0441\u044f \u043d\u0430 \u044d\u0442\u043e). <\/p>\n<p>  \u0412\u0441\u0435\u0433\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Mega \u0440\u0430\u0437\u0434\u0435\u043b\u0435\u043d\u044b \u043d\u0430 \u0448\u0435\u0441\u0442\u044c \u0443\u0440\u043e\u0432\u043d\u0435\u0439, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u00ab\u0444\u0443\u043d\u0434\u0430\u043c\u0435\u043d\u0442\u0430\u043b\u044c\u043d\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b\u00bb \u0438 \u00ab\u0442\u0435\u043e\u0440\u0435\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0438\u00bb. \u0412\u043e\u0442 \u0441\u043f\u0438\u0441\u043e\u043a \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0445 \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0435\u0441\u043b\u0438 \u043a\u043e\u043c\u0443 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e:<\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0421\u043f\u0438\u0441\u043e\u043a<\/b><\/p>\n<div class=\"spoiler_text\"><b>\u0421\u043f\u0438\u0441\u043e\u043a<\/b>:<\/p>\n<p>  Class IV vulnerabilities<\/p>\n<p>  [\u00abCryptographic design flaws that can be exploited only after compromising server infrastructure (live or post-mortem)\u00bb]<\/p>\n<p>  Invalid application of CBC-MAC as a secure hash to integrity-check active content loaded from the distributed static content cluster. Mitigating factors: No static content servers had been operating in untrusted data centers at that time, thus no elevated exploitability relative to the root servers, apart from a man-in-the-middle risk due to the use of a 1024 bit SSL key on the static content servers. Fixed within hours.<\/p>\n<p>  Class III vulnerabilities <\/p>\n<p>  [\u00abGenerally exploitable remote code execution on client browsers (cross-site scripting)\u00bb]<\/p>\n<p>  XSS through file and folder names. Mitigating factors: None. Fixed within hours.<br \/>   XSS on the file download page. Mitigating factors: Chrome not vulnerable. Fixed within hours.<br \/>   XSS in a third-party component (ZeroClipboard.swf). Mitigating factors: None. Fixed within hours.<\/p>\n<p>  Class II vulnerabilities<\/p>\n<p>  [\u00abCross-site scripting that can be exploited only after compromising the API server cluster or successfully mounting a man-in-the-middle attack (e.g. by issuing a fake SSL certificate + DNS\/BGP manipulation)\u00bb]<\/p>\n<p>  XSS through strings passed from the API server to the download page (through three different vectors), the account page and the link export functionality. Mitigating factors\u2014apart from the need to control an API server or successfully mounting a man-in-the-middle attack: None. Fixed within hours.<\/p>\n<p>  Class I vulnerabilities<\/p>\n<p>  [\u00abAll lower-impact or purely theoretical scenarios\u00bb]<\/p>\n<p>  HTTP Strict Transport Security header was missing. Fixed. Also, mega.co.nz and *.api.mega.co.nz will be HSTS-preloaded in Chrome.<br \/>   X-Frame-Options header was missing, causing a clickjacking\/UI redressing risk. Fixed.<\/div>\n<\/div>\n<p>  \u0412\u043f\u043e\u043b\u043d\u0435 \u0432\u0435\u0440\u043e\u044f\u0442\u043d\u043e, \u0447\u0442\u043e \u0432 \u0431\u043b\u0438\u0436\u0430\u0439\u0448\u0435\u0435 \u0432\u0440\u0435\u043c\u044f Mega \u0432\u044b\u043f\u043b\u0430\u0442\u0438\u0442 \u0435\u0449\u0435 \u0440\u044f\u0434 \u043d\u0430\u0433\u0440\u0430\u0434, \u043f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u044f \u043e \u0440\u0430\u0437\u043d\u043e\u0433\u043e \u0440\u043e\u0434\u0430 \u043e\u0448\u0438\u0431\u043a\u0430\u0445\/\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u0430 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044e\u0442 \u043f\u043e\u044f\u0432\u043b\u044f\u0442\u044c\u0441\u044f.<\/p>\n<p>  Via <a href=\"http:\/\/thenextweb.com\/insider\/2013\/02\/10\/as-promised-kim-dotcom-starts-payouts-for-mega-vulnerability-reward-program-seven-bugs-fixed-in-first-week\/\">thenextweb<\/a>    \t \t\t   \t<\/p>\n<div class=\"clear\"><\/div>\n<\/p><\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"http:\/\/habrahabr.ru\/post\/169083\/\"> http:\/\/habrahabr.ru\/post\/169083\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"content html_format\">   \t<img decoding=\"async\" src=\"http:\/\/habrastorage.org\/storage2\/d26\/799\/0be\/d267990be1a61b93fcb2872125f70038.jpg\"\/><\/p>\n<p>  \u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0435\u0434\u0435\u043b\u044e \u043d\u0430\u0437\u0430\u0434 \u043d\u0430 \u0425\u0430\u0431\u0440\u0435 \u043f\u043e\u044f\u0432\u0438\u043b\u0430\u0441\u044c <a href=\"http:\/\/habrahabr.ru\/post\/168025\/\">\u043d\u043e\u0432\u043e\u0441\u0442\u044c<\/a> \u043e \u0442\u043e\u043c, \u0447\u0442\u043e \u0444\u0430\u0439\u043b\u043e\u043e\u0431\u043c\u0435\u043d\u043d\u0438\u043a Mega, \u0432\u0435\u0440\u043d\u0435\u0435, \u0435\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c, \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0437\u0430 \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u0421\u0443\u043c\u043c\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0441\u0442\u0438\u0433\u0430\u0442\u044c 10 \u0442\u044b\u0441\u044f\u0447 \u0435\u0432\u0440\u043e. \u041f\u0435\u0440\u0432\u044b\u0435 \u043d\u0430\u0433\u0440\u0430\u0434\u044b \u0443\u0436\u0435 \u043d\u0430\u0448\u043b\u0438 \u0441\u0432\u043e\u0438\u0445 \u0432\u043b\u0430\u0434\u0435\u043b\u044c\u0446\u0435\u0432. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-169083","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/169083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=169083"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/169083\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=169083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=169083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=169083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}