{"id":25540,"date":"2022-05-12T13:36:03","date_gmt":"2022-05-12T10:36:03","guid":{"rendered":"https:\/\/kutaybilen.com.tr\/?p=25540"},"modified":"2022-05-12T13:36:03","modified_gmt":"2022-05-12T10:36:03","slug":"macos-guvenligini-atlatan-bir-ziyanli-yazilim-kesfedildi","status":"publish","type":"post","link":"https:\/\/kutaybilen.com.tr\/?p=25540","title":{"rendered":"macOS G\u00fcvenli\u011fini Atlatan Bir Ziyanl\u0131 Yaz\u0131l\u0131m Ke\u015ffedildi"},"content":{"rendered":"<p>Antivir\u00fcs firmas\u0131\u00a0Intego&#39;daki ara\u015ft\u0131rmac\u0131lar, <strong>macOS<\/strong> kullan\u0131c\u0131lar\u0131n\u0131 aldatarak ayg\u0131ta s\u0131zan yeni t\u0131p bir ziyanl\u0131 yaz\u0131l\u0131m ke\u015ffetti. macOS Catalina&#39;da, Apple yeni uygulama onay ihtiya\u00e7lar\u0131 getirmi\u015fti. Apple&#39;\u0131n <strong>Gatekeeper<\/strong> teknolojisinin belirledi\u011fi \u00f6zellikler; kullan\u0131c\u0131lar\u0131,\u00a0do\u011frulanmayan uygulamalar\u0131 a\u00e7maktan vazge\u00e7iriyor. Bu nedenle de ziyanl\u0131 yaz\u0131l\u0131m \u00fcretenler, taktiklerini daha yarat\u0131c\u0131 h\u00e2le getirmi\u015f \u00fczere g\u00f6r\u00fcn\u00fcyor.<\/p>\n<p>Intego ara\u015ft\u0131rmac\u0131lar\u0131, yeni bir <em>trojan <\/em>ziyanl\u0131 yaz\u0131l\u0131m\u0131n\u0131 faal olarak yay\u0131l\u0131rken ke\u015ffettiler. Bu yaz\u0131l\u0131m, bozulmu\u015f Google arama sonu\u00e7lar\u0131 vas\u0131tas\u0131yla kullan\u0131c\u0131lar\u0131 aldatarak Apple muhafazalar\u0131n\u0131 atlat\u0131yor ve sisteme giriyor. Ziyanl\u0131 yaz\u0131l\u0131m, <strong>Adobe<\/strong> <strong>Flash<\/strong> <strong>Installer<\/strong> \u00fczere g\u00f6r\u00fcnen bir <em>.dmg<\/em> disk uzant\u0131s\u0131 halinde geliyor. Bir sefer kullan\u0131c\u0131n\u0131n bilgisayar\u0131nda a\u00e7\u0131ld\u0131\u011f\u0131 zamansa\u00a0kullan\u0131c\u0131y\u0131 y\u00fckleme s\u00fcreciyle y\u00f6nlendiriyor ve talimatlar g\u00f6steriyor.<\/p>\n<p><b>Yeni bir taktik olarak bedellendiriliyor:<\/b><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.webtekno.com\/images\/editor\/default\/0002\/70\/77cdb72cbe5e4e1de6df14f9d31b7fe6119b7564.jpeg\"\/><\/p>\n<p>Intego taraf\u0131ndan \u00f6zg\u00fcn bir taktik olarak nitelendirilen bu yolda;\u00a0zararl\u0131 yaz\u0131l\u0131m, kullan\u0131c\u0131lardan yaz\u0131l\u0131m\u0131n \u00fcst\u00fcne <strong>\u00e7ift<\/strong> <strong>t\u0131klamak<\/strong> yerine <strong>sa\u011f<\/strong> <strong>t\u0131klayarak<\/strong> a\u00e7malar\u0131n\u0131 istiyor. macOS Catalina Gatekeeper ayarlar\u0131nda, bu durumda bir diyalog penceresi a\u00e7\u0131l\u0131yor ve burada bir &#39;A\u00e7&#39; (Open) d\u00fc\u011fmesi de bulunuyor. Ola\u011fan \u015fartlarda\u00a0do\u011frulanmam\u0131\u015f bir evraka t\u0131klad\u0131\u011f\u0131n\u0131zda\u00a0Apple bunlar\u0131 a\u00e7man\u0131za m\u00fcsaade vermiyor.<\/p>\n<p>Tekrar ola\u011fan \u015fartlarda\u00a0macOS; kullan\u0131c\u0131lar\u0131n do\u011frulanmam\u0131\u015f evraklar\u0131 a\u00e7mas\u0131n\u0131, bu s\u00fcreci zorla\u015ft\u0131rarak <strong>engellemeye<\/strong> \u00e7al\u0131\u015f\u0131yor. Sistem; \u00f6zel olarak\u00a0kullan\u0131c\u0131lar\u0131 Sistem Tercihleri&#39;ne y\u00f6nlendirerek Gatekeeper&#39;\u0131 ge\u00e7ersiz k\u0131lmaya zorluyor. Bu strateji birebir vakitte makus niyetli bireyleri bir <strong>Apple<\/strong> <strong>Developer<\/strong> hesab\u0131na giri\u015f yapmaktan ya da haz\u0131rda var olan birinin \u00e7al\u0131nmas\u0131ndan da koruyor.\u00a0<\/p>\n<p>Kullan\u0131c\u0131lar y\u00fckleme uygulamas\u0131n\u0131 a\u00e7t\u0131klar\u0131nda, <em>&#39;bash shell script&#39; <\/em>denilen bir komut \u00e7al\u0131\u015f\u0131yor ve \u015fifre muhafazal\u0131 bir<em> .zip<\/em> evrak\u0131 ortaya \u00e7\u0131k\u0131yor. Bu <em>.zip<\/em> evrak\u0131 daha klasik bir ziyanl\u0131 yaz\u0131l\u0131m uygulama paketini b\u00fcnyesinde bar\u0131nd\u0131r\u0131yor. Ba\u015flang\u0131\u00e7 olarak Flash&#39;\u0131n ge\u00e7erli bir s\u00fcr\u00fcm\u00fcn\u00fc y\u00fcklemesine ra\u011fmen\u00a0Intego&#39;nun belirtti\u011fine nazaran \u00f6b\u00fcr Mac ziyanl\u0131 yaz\u0131l\u0131mlar\u0131 ya da reklam yaz\u0131l\u0131m\u0131 paketleri indirmek i\u00e7in de kullan\u0131labiliyor.\u00a0<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.webtekno.com\/images\/editor\/default\/0002\/70\/0c7f797d6e08ffb556730e89bcea082d2d85b802.png\"\/><\/p>\n<p>De\u011fi\u015fik olansa\u00a0zararl\u0131 yaz\u0131l\u0131m\u0131n <strong>Google<\/strong> <strong>arama<\/strong> <strong>sonu\u00e7lar\u0131<\/strong> arac\u0131l\u0131\u011f\u0131yla yay\u0131lmas\u0131. Bu sonu\u00e7lar, kullan\u0131c\u0131lar\u0131 ziyanl\u0131 internet sitelerine y\u00f6nlendiriyor ve bu siteler de kullan\u0131c\u0131lara, taray\u0131c\u0131lar\u0131ndaki Flash Player&#39;\u0131n yenili\u011fini yitirmi\u015f oldu\u011funu s\u00f6yl\u00fcyor. Intego&#39;nun belirtti\u011fine nazaran bu ziyanl\u0131 yaz\u0131l\u0131m, bir\u00e7ok antivir\u00fcs yaz\u0131l\u0131m\u0131n\u0131n taramas\u0131ndan <strong>s\u0131yr\u0131lm\u0131\u015f<\/strong>.<\/p>\n<p>Adobe Flash Player, 31 Aral\u0131k 2020&#39;de nihayete erecek olsa da yenili\u011fini yitirmi\u015f Flash Player aldatmacas\u0131n\u0131n ba\u015far\u0131l\u0131 oldu\u011funa dikkat \u00e7ekiliyor. Kullan\u0131c\u0131lara, <strong>b\u00fcsb\u00fct\u00fcn<\/strong> <strong>emin<\/strong> <strong>olduklar\u0131<\/strong> ili\u015fkilere t\u0131klamalar\u0131 tavsiye ediliyor. Bir internet sitesi, size istemedi\u011fiminiz bir \u015feyi indirtmek istiyorsa\u00a0o siteden \u00e7abucak \u00e7\u0131kman\u0131z \u00f6neriliyor.\u00a0<\/p>\n<div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Antivir\u00fcs firmas\u0131\u00a0Intego&#39;daki ara\u015ft\u0131rmac\u0131lar, macOS kullan\u0131c\u0131lar\u0131n\u0131 aldatarak ayg\u0131ta s\u0131zan yeni t\u0131p bir ziyanl\u0131 yaz\u0131l\u0131m ke\u015ffetti. macOS &#8230;<\/p>\n","protected":false},"author":1,"featured_media":25541,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[854],"tags":[2037,2886,1237,3787],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/25540"}],"collection":[{"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=25540"}],"version-history":[{"count":1,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/25540\/revisions"}],"predecessor-version":[{"id":25542,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/25540\/revisions\/25542"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=\/wp\/v2\/media\/25541"}],"wp:attachment":[{"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=25540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=25540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kutaybilen.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=25540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}