{"id":10492,"date":"2022-02-07T12:38:17","date_gmt":"2022-02-07T09:38:17","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10492"},"modified":"2022-02-07T12:38:17","modified_gmt":"2022-02-07T09:38:17","slug":"how-to-protect-from-pegasus-spyware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/how-to-protect-from-pegasus-spyware\/10492\/","title":{"rendered":"Pegasus, Chrysaor ve di\u011fer APT mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan korunma"},"content":{"rendered":"<p>2021\u2019in muhtemelen en b\u00fcy\u00fck haberi olan, Guardian ve di\u011fer 16 medya kurulu\u015fu taraf\u0131ndan Temmuz ay\u0131nda yay\u0131nlanan bir ara\u015ft\u0131rma, d\u00fcnya \u00e7ap\u0131nda 30.000\u2019den fazla insan haklar\u0131 aktivistinin, gazetecinin ve avukat\u0131n Pegasus taraf\u0131ndan hedef al\u0131nd\u0131\u011f\u0131n\u0131 \u00f6ne s\u00fcrd\u00fc. Pegasus, \u0130srailli \u015firket NSO taraf\u0131ndan geli\u015ftirilen s\u00f6zde \u201cyasal bir g\u00f6zetim yaz\u0131l\u0131m\u0131\u201d. <a href=\"https:\/\/www.amnesty.org\/en\/latest\/press-release\/2021\/07\/the-pegasus-project\/\" target=\"_blank\" rel=\"noopener nofollow\">Pegasus Projesi<\/a> adl\u0131 raporda, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 yayg\u0131n \u015fekilde da\u011f\u0131tmak i\u00e7in baz\u0131 iOS s\u0131f\u0131r t\u0131klamal\u0131 s\u0131f\u0131r g\u00fcnleri de dahil olmak \u00fczere \u00e7e\u015fitli g\u00fcvenlik a\u00e7\u0131klar\u0131ndan yararlan\u0131ld\u0131\u011f\u0131 iddia edildi.<\/p>\n<p>Uluslararas\u0131 Af \u00d6rg\u00fct\u00fc\u2019n\u00fcn G\u00fcvenlik Laboratuvar\u0131, say\u0131s\u0131z mobil cihaz\u0131n adli analizine dayanarak yaz\u0131l\u0131m\u0131n defalarca g\u00f6zetleme amac\u0131yla k\u00f6t\u00fcye kullan\u0131ld\u0131\u011f\u0131n\u0131 ortaya koydu. Hedeflenen ki\u015filerin listesi, 14 d\u00fcnya liderinin yan\u0131 s\u0131ra bir\u00e7ok aktivisti, insan haklar\u0131 savunucusunu, kar\u015f\u0131t g\u00f6r\u00fc\u015fl\u00fc ki\u015fileri ve muhalefette yer alan isimleri i\u00e7eriyor.<\/p>\n<p>Temmuz ay\u0131 i\u00e7erisinde, \u0130srail h\u00fck\u00fcmetinden temsilciler, iddialarla ilgili soru\u015fturman\u0131n bir par\u00e7as\u0131 olarak <a href=\"https:\/\/www.theguardian.com\/news\/2021\/jul\/29\/israeli-authorities-inspect-nso-group-offices-after-pegasus-revelations\" target=\"_blank\" rel=\"noopener nofollow\">NSO ofislerini ziyaret etti.<\/a> Ekim ay\u0131nda, Hindistan Y\u00fcksek Mahkemesi, vatanda\u015flar\u0131na casusluk yapmak amac\u0131yla <a href=\"https:\/\/www.theregister.com\/2021\/10\/29\/india_nso_pegasus_probe\/\" target=\"_blank\" rel=\"noopener nofollow\">Pegasus kullan\u0131m\u0131n\u0131 ara\u015ft\u0131rmak<\/a> i\u00e7in bir teknik komite g\u00f6revlendirdi. Apple, Kas\u0131m ay\u0131nda, kullan\u0131c\u0131lar\u0131n\u0131 \u201ck\u00f6t\u00fc ama\u00e7l\u0131 ve casus yaz\u0131l\u0131mlar\u201d kullanarak hedef alan yaz\u0131l\u0131mlar geli\u015ftirdi\u011fi i\u00e7in <a href=\"https:\/\/www.theguardian.com\/technology\/2021\/nov\/23\/apple-sues-israeli-cyber-firm-nso-group\" target=\"_blank\" rel=\"noopener nofollow\">NSO Group\u2019a kar\u015f\u0131 yasal i\u015flem ba\u015flatt\u0131\u011f\u0131n\u0131 duyurdu.<\/a> Son olarak, Aral\u0131k ay\u0131nda Reuters, Apple\u2019\u0131n da uyard\u0131\u011f\u0131 gibi, <a href=\"https:\/\/www.reuters.com\/technology\/exclusive-us-state-department-phones-hacked-with-israeli-company-spyware-sources-2021-12-03\/\" target=\"_blank\" rel=\"noopener nofollow\">ABD D\u0131\u015fi\u015fleri Bakanl\u0131\u011f\u0131 telefonlar\u0131n\u0131n NSO Pegasus k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131yla hacklendi\u011fini yay\u0131nlad\u0131.<\/a><\/p>\n<p>Ge\u00e7ti\u011fimiz birka\u00e7 ay boyunca, d\u00fcnyan\u0131n d\u00f6rt bir yan\u0131ndaki ilgili kullan\u0131c\u0131lardan mobil cihazlar\u0131n\u0131 Pegasus ve benzeri ara\u00e7lardan ve k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan nas\u0131l koruyabileceklerine dair \u00e7ok say\u0131da soru ald\u0131m. Bu yaz\u0131da, hi\u00e7bir savunma tekni\u011fi listesinin asla tam olarak her \u015feyi kapsayamayaca\u011f\u0131n\u0131 da not d\u00fc\u015ferek, bu sorular\u0131 yan\u0131tlamaya \u00e7al\u0131\u015f\u0131yoruz. Sald\u0131rganlar \u00e7al\u0131\u015fma \u015fekillerini de\u011fi\u015ftirdik\u00e7e, koruma tekniklerinin de yeni y\u00f6ntemlere uyarlanmas\u0131 gerekti\u011fi de unutulmamal\u0131.<\/p>\n<h2>Pegasus ve di\u011fer geli\u015fmi\u015f mobil casus yaz\u0131l\u0131mlardan nas\u0131l korunabilirsiniz?<\/h2>\n<p>Her \u015feyden \u00f6nce, <strong>Pegasus\u2019un ulus devletlere nispeten y\u00fcksek fiyatlarla sat\u0131lan bir ara\u00e7 tak\u0131m\u0131 oldu\u011funu<\/strong> s\u00f6yleyerek ba\u015flamal\u0131y\u0131z. Tam bir da\u011f\u0131t\u0131m\u0131n maliyeti kolayl\u0131kla milyonlarca USD\u2019yi bulabilir. Benzer \u015fekilde, s\u0131f\u0131r t\u0131klamal\u0131 s\u0131f\u0131r g\u00fcn a\u00e7\u0131klar\u0131ndan yararlan\u0131larak ba\u015fka k\u00f6t\u00fc ama\u00e7l\u0131 APT mobil yaz\u0131l\u0131mlar da da\u011f\u0131t\u0131labilir. Bunlar son derece pahal\u0131d\u0131r. \u00d6rne\u011fin, bir k\u00f6t\u00fcye kullan\u0131m arac\u0131 kurumu olan Zerodium, kal\u0131c\u0131 bir Android s\u0131f\u0131r t\u0131klamal\u0131 bula\u015fma zinciri i\u00e7in 2,5 milyon USD\u2019ye kadar \u00f6deme yap\u0131yor:<\/p>\n<div id=\"attachment_10494\" style=\"width: 834px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10494\" class=\"wp-image-10494 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/02\/04163136\/how-to-protect-from-pegasus-spyware-zerodium-price-list.png\" alt=\"\" width=\"824\" height=\"603\"><p id=\"caption-attachment-10494\" class=\"wp-caption-text\">Kal\u0131c\u0131 g\u00fcvenlik a\u00e7\u0131klar\u0131 Zerodium\u2019un fiyat listesinde 2,5 milyon USD\u2019ye kadar \u00e7\u0131k\u0131yor<\/p><\/div>\n<p>\u00a0<\/p>\n<p>Buradan, daha en ba\u015ftan, \u00f6nemli bir sonu\u00e7 \u00e7\u0131k\u0131yor: Ulus devlet destekli siber casusluk, istedi\u011fini alabilecek bir giri\u015fim. Bir tehdit akt\u00f6r\u00fc, sald\u0131r\u0131 programlar\u0131na milyonlarca, belki de on milyonlarca, hatta y\u00fcz milyonlarca USD harcamay\u0131 g\u00f6ze alabiliyorsa, hedefin vir\u00fcs bula\u015fmas\u0131ndan ka\u00e7\u0131nabilmesi pek de olas\u0131 de\u011fil. Daha basit ifade etmek gerekirse, e\u011fer b\u00f6yle bir akt\u00f6r taraf\u0131ndan hedef al\u0131n\u0131yorsan\u0131z esas mesele vir\u00fcs bula\u015f\u0131p bula\u015fmayaca\u011f\u0131 de\u011fil, <strong>ne kadar zamanda ve ne kadar kaynak kullan\u0131larak<\/strong> bula\u015faca\u011f\u0131.<\/p>\n<p>Gelelim iyi habere: K\u00f6t\u00fcye kullan\u0131m geli\u015ftirme ve sald\u0131r\u0131ya dayal\u0131 siber sava\u015f, genellikle kesin bir bilim olmaktan ziyade bir sanatt\u0131r. Belirli i\u015fletim sistemi s\u00fcr\u00fcmlerine ve donan\u0131mlara g\u00f6re ince ayarlamalara ihtiya\u00e7 duyan k\u00f6t\u00fcye kullan\u0131mlar; yeni i\u015fletim sistemi s\u00fcr\u00fcmleri, yeni risk azaltma teknikleri, hatta rastgele olaylar gibi ufak \u015feyler taraf\u0131ndan kolayca engellenebilir.<\/p>\n<p>Buna ek olarak, bula\u015fma ve hedefleme ayn\u0131 zamanda bir maliyet sorunudur; bu da sald\u0131rganlar i\u00e7in i\u015fleri daha da zorla\u015ft\u0131r\u0131r. Mobil cihaza vir\u00fcs bula\u015ft\u0131rma ve k\u00f6t\u00fcye kullanma giri\u015fimlerinin ba\u015far\u0131l\u0131 olmas\u0131n\u0131 her zaman engelleyemesek de, bunu sald\u0131rganlar i\u00e7in m\u00fcmk\u00fcn oldu\u011funca zorla\u015ft\u0131rmaya \u00e7al\u0131\u015fabiliriz.<\/p>\n<p>Peki, bunu pratikte nas\u0131l yapar\u0131z? \u0130\u015fte size basit bir kontrol listesi:<\/p>\n<h3>iOS\u2019ta geli\u015fmi\u015f casus yaz\u0131l\u0131mlardan nas\u0131l korunabilirsiniz?<\/h3>\n<p><strong>Her g\u00fcn yeniden ba\u015flat\u0131n.<\/strong> Uluslararas\u0131 Af \u00d6rg\u00fct\u00fc ve Citizen Lab\u2019in ara\u015ft\u0131rmas\u0131na g\u00f6re, Pegasus bula\u015fma zinciri genellikle kal\u0131c\u0131 olmayan s\u0131f\u0131r t\u0131klamal\u0131 s\u0131f\u0131r g\u00fcnlere dayan\u0131yor. Bu nedenle d\u00fczenli olarak yeniden ba\u015flatmak, cihaz\u0131 temizlemeye yard\u0131mc\u0131 olacakt\u0131r. Cihaz her g\u00fcn yeniden ba\u015flat\u0131l\u0131rsa sald\u0131rganlar\u0131n cihaza tekrar tekrar vir\u00fcs bula\u015ft\u0131rmas\u0131 gerekir. Zamanla bu tespit \u015fans\u0131n\u0131 art\u0131r\u0131r; bir \u00e7\u00f6kme meydana gelebilir veya bula\u015fman\u0131n gizli yap\u0131s\u0131n\u0131 a\u00e7\u0131\u011fa \u00e7\u0131karan kal\u0131nt\u0131lar kaydedilebilir. Bu yaln\u0131zca teoriden ibaret de\u011fil; pratikte de bir mobil cihaz\u0131n s\u0131f\u0131r t\u0131klama yoluyla hedef al\u0131nd\u0131\u011f\u0131 bir durumu analiz ettik (muhtemelen FORCEDENTRY). Cihaz sahibi, sald\u0131r\u0131y\u0131 takip eden 24 saat i\u00e7inde cihaz\u0131n\u0131 d\u00fczenli olarak yeniden ba\u015flatt\u0131. Sald\u0131rganlar bu ki\u015fiyi birka\u00e7 kez daha hedeflemeye \u00e7al\u0131\u015fsalar da, yeniden ba\u015flatmalar yoluyla birka\u00e7 kez geri p\u00fcsk\u00fcrt\u00fcld\u00fckten sonra sonunda pes ettiler.<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"F1dF18YA31\"><p><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/what-is-noreboot-attack-and-how-to-protect-your-smartphone\/10440\/\" target=\"_blank\" rel=\"noopener\">NoReboot: Sistemde yer edinmek i\u00e7in telefonun sahte \u015fekilde yeniden ba\u015flat\u0131lmas\u0131<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"\u201cNoReboot: Sistemde yer edinmek i\u00e7in telefonun sahte \u015fekilde yeniden ba\u015flat\u0131lmas\u0131\u201d \u2014 Daily - Turkish - Turkey - www.kaspersky.com.tr\/blog\" src=\"https:\/\/www.kaspersky.com.tr\/blog\/what-is-noreboot-attack-and-how-to-protect-your-smartphone\/10440\/embed\/#?secret=y9ebCz3qdI#?secret=F1dF18YA31\" data-secret=\"F1dF18YA31\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>\u00a0<\/p>\n<p><strong>iMessage\u2019\u0131 devre d\u0131\u015f\u0131 b\u0131rak\u0131n<\/strong>. iMessage, iOS\u2019ta yerle\u015fiktir ve varsay\u0131lan olarak etkindir; bu da onu \u00e7ekici bir k\u00f6t\u00fcye kullan\u0131m vekt\u00f6r\u00fc haline getirir. Varsay\u0131lan olarak etkin oldu\u011fundan, s\u0131f\u0131r t\u0131klamal\u0131 zincirler i\u00e7in en \u00e7ok tercih edilen da\u011f\u0131t\u0131m mekanizmas\u0131d\u0131r ve k\u00f6t\u00fcye kullan\u0131m arac\u0131 kurumlar\u0131 taraf\u0131ndan iMessage k\u00f6t\u00fcye kullan\u0131mlar\u0131 i\u00e7in \u00e7ok y\u00fcksek paralar \u00f6denir. Zerodium\u2019un kurucusu <a href=\"https:\/\/www.wired.com\/story\/android-zero-day-more-than-ios-zerodium\/\" target=\"_blank\" rel=\"noopener nofollow\">Chaouki Bekrar 2019\u2019da WIRED\u2019a \u015f\u00f6yle yazm\u0131\u015ft\u0131<\/a>: \u201cSon birka\u00e7 ayd\u0131r geli\u015ftirilen ve d\u00fcnya \u00e7ap\u0131nda ara\u015ft\u0131rmac\u0131lar taraf\u0131ndan sat\u0131lan iOS k\u00f6t\u00fcye kullan\u0131mlar\u0131n\u0131n, \u00e7o\u011funlukla da Safari ve iMessage zincirlerinin say\u0131s\u0131nda bir art\u0131\u015f g\u00f6zlemliyoruz. <strong>S\u0131f\u0131r g\u00fcn pazar\u0131nda o kadar fazla iOS k\u00f6t\u00fcye kullan\u0131m\u0131 var ki, son zamanlarda baz\u0131lar\u0131n\u0131 geri \u00e7evirmeye ba\u015flad\u0131k<\/strong>.\u201d iMessage\u2019s\u0131z hayat\u0131n baz\u0131lar\u0131 i\u00e7in \u00e7ok zor olabilece\u011finin fark\u0131nday\u0131z (bunun hakk\u0131nda daha fazla ayr\u0131nt\u0131ya birazdan girece\u011fiz), ancak tehdit modelinizde Pegasus ve di\u011fer \u00fcst d\u00fczey APT mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar varsa bu \u00f6d\u00fcn\u00fc vermenize de\u011fer.<\/p>\n<p><strong>Facetime\u2019\u0131 devre d\u0131\u015f\u0131 b\u0131rak\u0131n.<\/strong> Yukar\u0131dakiyle ayn\u0131 tavsiye.<\/p>\n<p><strong>Mobil cihaz\u0131 g\u00fcncel tutun; en son iOS yamalar\u0131n\u0131 \u00e7\u0131kar \u00e7\u0131kmaz y\u00fckleyin.<\/strong> Herkes s\u0131f\u0131r t\u0131klamal\u0131 s\u0131f\u0131r g\u00fcn sald\u0131r\u0131lar\u0131n\u0131n maliyetini kar\u015f\u0131layamaz. Asl\u0131na bakarsan\u0131z, kar\u015f\u0131la\u015ft\u0131\u011f\u0131m\u0131z iOS k\u00f6t\u00fcye kullan\u0131m kitlerinin bir\u00e7o\u011fu halihaz\u0131rda yamalanm\u0131\u015f olan g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 hedefliyor. Ne var ki pek \u00e7ok ki\u015fi ya eski telefon kullan\u0131yor ya da \u00e7e\u015fitli nedenlerle g\u00fcncellemeleri erteliyor. (En az\u0131ndan baz\u0131) ulus devlet hackerlar\u0131n\u0131n \u00f6n\u00fcne ge\u00e7mek istiyorsan\u0131z, g\u00fcncellemelerinizi en k\u0131sa s\u00fcrede yap\u0131n ve <a href=\"https:\/\/twitter.com\/ryanaraine\/status\/1324445133668974592\" target=\"_blank\" rel=\"noopener nofollow\">yamalar\u0131n\u0131z\u0131 y\u00fcklemek i\u00e7in yeni emojilerin \u00e7\u0131kmas\u0131n\u0131 beklemeyin<\/a>.<\/p>\n<p><strong>Mesajlardaki ba\u011flant\u0131lara asla t\u0131klamay\u0131n<\/strong>. Basit ama \u00e7ok etkili bir tavsiye. Pegasus\u2019un b\u00fct\u00fcn m\u00fc\u015fterileri milyonlarca dolara s\u0131f\u0131r t\u0131klamal\u0131 s\u0131f\u0131r g\u00fcn zincirler sat\u0131n alamad\u0131\u011f\u0131 i\u00e7in, i\u00e7lerinden baz\u0131lar\u0131 bir t\u0131klamal\u0131 k\u00f6t\u00fcye kullan\u0131mlara y\u00f6neliyor. Kimi zaman SMS mesaj\u0131 bi\u00e7iminde gelen bu sald\u0131r\u0131lar, kimi zaman da di\u011fer mesajla\u015fma programlar\u0131, hatta e-posta yoluyla da ger\u00e7ekle\u015ftirilebiliyor. Bir ba\u011flant\u0131 i\u00e7eren ilgin\u00e7 bir SMS (veya ba\u015fka bir mesajla\u015fma uygulamas\u0131ndan gelen bir mesaj) al\u0131rsan\u0131z bunu bir masa\u00fcst\u00fc bilgisayarda, tercihen TOR Taray\u0131c\u0131 kullanarak ya da daha da iyisi, Tails gibi kal\u0131c\u0131 olmayan g\u00fcvenli bir i\u015fletim sistemi kullanarak a\u00e7\u0131n.<\/p>\n<div id=\"attachment_10495\" style=\"width: 756px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10495\" class=\"wp-image-10495 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/02\/04163331\/how-to-protect-from-pegasus-spyware-malicious-sms.png\" alt=\"Bir siyasi aktivisti hedef almak amac\u0131yla kullan\u0131lan k\u00f6t\u00fc ama\u00e7l\u0131 bir ba\u011flant\u0131 i\u00e7eren SMS\" width=\"746\" height=\"568\"><p id=\"caption-attachment-10495\" class=\"wp-caption-text\">Bir siyasi aktivisti hedef almak amac\u0131yla kullan\u0131lan k\u00f6t\u00fc ama\u00e7l\u0131 bir ba\u011flant\u0131 i\u00e7eren SMS Kaynak: <a>Citizen Lab<\/a><\/p><\/div>\n<p>\u00a0<\/p>\n<p><strong>\u0130nternette Safari veya Chrome yerine Firefox Focus gibi alternatif bir taray\u0131c\u0131yla gezinin.<\/strong>\u00a0 iOS\u2019taki hemen hemen t\u00fcm taray\u0131c\u0131lar ayn\u0131 motoru, yani Webkit\u2019i kullansa da, k\u00f6t\u00fcye kullan\u0131mlar\u0131n baz\u0131lar\u0131 (<a href=\"https:\/\/securelist.com\/ios-exploit-chain-deploys-lightspy-malware\/96407\/\" target=\"_blank\" rel=\"noopener\">LightRighter \/ TwoSailJunk APT \u00f6rnekleri<\/a>) baz\u0131 alternatif taray\u0131c\u0131larda iyi \u00e7al\u0131\u015fmaz:<\/p>\n<div id=\"attachment_10496\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10496\" class=\"wp-image-10496 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/02\/04163442\/how-to-protect-from-pegasus-spyware-lightriver-exploit-1024x372.png\" alt=\"\" width=\"1024\" height=\"372\"><p id=\"caption-attachment-10496\" class=\"wp-caption-text\">LightRiver k\u00f6t\u00fcye kullan\u0131m kiti, kullan\u0131c\u0131 arac\u0131s\u0131 dizesinde \u201cSafari\u201d olup olmad\u0131\u011f\u0131n\u0131 kontrol eder<\/p><\/div>\n<p>\u00a0<\/p>\n<p>iOS\u2019ta Safari, Chrome ve Firefox Focus taray\u0131c\u0131lar\u0131ndan kullan\u0131c\u0131 arac\u0131s\u0131 dizeleri:<\/p>\n<ul>\n<li><strong>Safari: <\/strong>Mozilla\/5.0 (iPhone; CPU iPhone OS 15_1, Mac OS X gibi) AppleWebKit\/605.1.15 (KHTML, Gecko gibi) S\u00fcr\u00fcm\/15.1 Mobil\/15E148 &lt;strong style=\u201dcolor:red;\u201d&gt;<strong>Safari<\/strong>&lt;\/strong&gt;\/604.1<\/li>\n<li><strong>Chrome:<\/strong> Mozilla\/5.0 (iPhone; CPU iPhone OS 15_1, Mac OS X gibi) AppleWebKit\/605.1.15 (KHTML, Gecko gibi) CriOS\/96.0.4664.53 Mobil\/15E148 &lt;strong style=\u201dcolor:red;\u201d&gt;<strong>Safari<\/strong>&lt;\/strong&gt;\/604.1<\/li>\n<li><strong>Firefox Focus:<\/strong> Mozilla\/5.0 (iPhone; CPU iPhone OS 15_1, Mac OS X gibi) AppleWebKit\/605.1.15 (KHTML, Gecko gibi) FxiOS\/39 Mobil\/15E148 S\u00fcr\u00fcm\/15.0<\/li>\n<\/ul>\n<p><strong>Daima trafi\u011finizi maskeleyen bir VPN kullan\u0131n<\/strong>. Baz\u0131 k\u00f6t\u00fcye kullan\u0131mlar, HTTP sitelerinde gezinirken veya DNS ele ge\u00e7irme yoluyla, GSM operat\u00f6r\u00fc MitM sald\u0131r\u0131lar\u0131yla ger\u00e7ekle\u015ftirilir. Trafi\u011fi maskelemek i\u00e7in bir VPN kullanmak, GSM operat\u00f6r\u00fcn\u00fcz\u00fcn sizi do\u011frudan internet \u00fczerinden hedeflemesini zorla\u015ft\u0131r\u0131r. Sald\u0131rganlar\u0131n, \u00f6rne\u011fin dola\u015f\u0131m s\u0131ras\u0131nda, veri ak\u0131\u015f\u0131n\u0131z\u0131 kontrol etmesi durumunda da hedefleme s\u00fcrecini karma\u015f\u0131k hale getirir. L\u00fctfen t\u00fcm VPN\u2019lerin ayn\u0131 olmad\u0131\u011f\u0131n\u0131 ve hepsinin kullan\u0131ma uygun olmad\u0131\u011f\u0131n\u0131 unutmay\u0131n. Birinci \u00f6nceli\u011finiz anonimlikse, bir VPN aboneli\u011fi sat\u0131n al\u0131rken g\u00f6z \u00f6n\u00fcnde bulundurabilece\u011finiz, belirli bir VPN sa\u011flay\u0131c\u0131s\u0131n\u0131 kay\u0131rmayan \u00f6nerilerimiz \u015funlar:<\/p>\n<ul>\n<li>Sat\u0131n almak derken ger\u00e7ekten sat\u0131n almay\u0131 kastediyoruz: \u201c<strong>\u00dccretsiz\u201d VPN kullanmay\u0131n.<\/strong><\/li>\n<li><strong>Kripto para birimleriyle \u00f6deme kabul eden<\/strong> servisleri tercih edin.<\/li>\n<li><strong>Herhangi bir kay\u0131t bilgisi vermenizi gerektirmeyen<\/strong> servisleri tercih edin<strong>.<\/strong><\/li>\n<li>VPN uygulamalar\u0131ndan ka\u00e7\u0131nmaya \u00e7al\u0131\u015f\u0131n. Bunun yerine OpenVPN, WireGuard ve VPN profilleri gibi a\u00e7\u0131k kaynakl\u0131 ara\u00e7lar\u0131 kullan\u0131n.<\/li>\n<li>Yeni VPN servislerinden ka\u00e7\u0131n\u0131n ve bir s\u00fcredir var olan yerle\u015fik hizmetleri tercih edin.<\/li>\n<\/ul>\n<p><strong>Cihazda jailbreak yap\u0131l\u0131p yap\u0131lmad\u0131\u011f\u0131n\u0131 kontrol eden ve yap\u0131ld\u0131ysa uyaran bir g\u00fcvenlik uygulamas\u0131 y\u00fckleyin.<\/strong> Defalarca engellenmekten b\u0131kan sald\u0131rganlar, sonunda bir kal\u0131c\u0131l\u0131k mekanizmas\u0131 kurmak isteyecek ve bu s\u00fcre\u00e7te cihaz\u0131n\u0131za jailbreak yapacaklar. Onlar\u0131 yakalama \u015fans\u0131 bu noktada on kat artar; cihazda jailbreak yap\u0131ld\u0131\u011f\u0131n\u0131 tespit ederek bundan yararlanabiliriz.<\/p>\n<p><strong>Ayda bir iTunes yedeklemesi yap\u0131n.<\/strong> Bu sayede, <a href=\"https:\/\/github.com\/mvt-project\/mvt\" target=\"_blank\" rel=\"noopener nofollow\">Uluslararas\u0131 Af \u00d6rg\u00fct\u00fc\u2019n\u00fcn ola\u011fan\u00fcst\u00fc MVT paketini<\/a> kullanarak sonras\u0131nda bula\u015fmalar\u0131 te\u015fhis edebilir ve bulabiliriz (bu konuya birazdan daha detayl\u0131 \u015fekilde girece\u011fiz).<\/p>\n<p><strong>Sistem tan\u0131lar\u0131n\u0131 s\u0131k s\u0131k tetikleyin ve bunlar\u0131 harici yedeklemelere kaydedin.<\/strong> Adli bili\u015fim kal\u0131nt\u0131lar\u0131, hedef al\u0131n\u0131p al\u0131nmad\u0131\u011f\u0131n\u0131z\u0131 ilerleyen zamanlarda belirlemenize yard\u0131mc\u0131 olabilir. Sistem tan\u0131lar\u0131n\u0131n nas\u0131l tetiklenece\u011fi telefon modeline ba\u011fl\u0131d\u0131r: \u00d6rne\u011fin, baz\u0131 iPhone\u2019larda bu, <em>Ses A\u00e7ma + Ses K\u0131sma + A\u00e7ma Kapama<\/em> tu\u015flar\u0131na ayn\u0131 anda basarak yap\u0131l\u0131r. Telefon titreyene kadar birka\u00e7 kez denemeniz gerekebilir. Sistem tan\u0131s\u0131 olu\u015fturulduktan sonra, tan\u0131lamalar i\u00e7inde g\u00f6r\u00fcn\u00fcr:<\/p>\n<div id=\"attachment_10497\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10497\" class=\"wp-image-10497 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/02\/04163649\/how-to-protect-from-pegasus-spyware-ios-sysdiagnoses-1024x585.png\" alt=\"\" width=\"1024\" height=\"585\"><p id=\"caption-attachment-10497\" class=\"wp-caption-text\">iOS\u2019un Analiz ve \u0130yile\u015ftirmeler men\u00fcs\u00fcnde sistem tan\u0131lar\u0131<\/p><\/div>\n<p>\u00a0<\/p>\n<h3>Android\u2019de geli\u015fmi\u015f casus yaz\u0131l\u0131mlardan nas\u0131l korunabilirsiniz?<\/h3>\n<p>Android kullan\u0131c\u0131lar\u0131 i\u00e7in benzer bir liste (ayr\u0131nt\u0131lar ve gerek\u00e7elendirmeler i\u00e7in yukar\u0131daki iOS listesine bak\u0131n):<\/p>\n<ul>\n<li><strong>Her g\u00fcn yeniden ba\u015flat\u0131n.<\/strong> En son Android s\u00fcr\u00fcmlerinde kal\u0131c\u0131l\u0131k zordur, bir\u00e7ok APT ve k\u00f6t\u00fcye kullan\u0131m sat\u0131c\u0131s\u0131 kal\u0131c\u0131l\u0131ktan ka\u00e7\u0131n\u0131r!<\/li>\n<li><strong>Telefonu g\u00fcncel tutun; en son \u00e7\u0131kan yamalar\u0131 y\u00fckleyin.<\/strong><\/li>\n<li><strong>Metin mesajlar\u0131ndaki ba\u011flant\u0131lara asla t\u0131klamay\u0131n.<\/strong><\/li>\n<li><strong>\u0130nternette gezinmek i\u00e7in <\/strong>varsay\u0131lan Chrome<strong> yerine Firefox Focus gibi alternatif bir taray\u0131c\u0131 kullan\u0131n.<\/strong><\/li>\n<li><strong>Daima trafi\u011finizi maskeleyen bir VPN kullan\u0131n.<\/strong> Baz\u0131 k\u00f6t\u00fcye kullan\u0131mlar, HTTP sitelerinde gezinirken veya DNS ele ge\u00e7irme yoluyla, GSM operat\u00f6r\u00fc MitM sald\u0131r\u0131lar\u0131yla ger\u00e7ekle\u015ftirilir.<\/li>\n<li><strong>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 tarayan, cihazda root yap\u0131l\u0131p yap\u0131lmad\u0131\u011f\u0131n\u0131 kontrol eden ve yap\u0131ld\u0131ysa uyaran bir g\u00fcvenlik paketi y\u00fckleyin.<\/strong><\/li>\n<\/ul>\n<p>Hem iOS hem de Android i\u00e7in daha sofistike bir \u00f6neri vermek gerekirse, daima canl\u0131 IoC\u2019ler kullanarak a\u011f trafi\u011finizi kontrol edin. K\u00f6t\u00fc ama\u00e7l\u0131 \u015feyleri filtrelemek ve t\u00fcm trafi\u011fi sonradan incelenmek \u00fczere kay\u0131t alt\u0131na almak i\u00e7in <a href=\"https:\/\/pi-hole.net\" target=\"_blank\" rel=\"noopener nofollow\">pi-hole<\/a> kullanan, sizin kontrol\u00fcn\u00fczdeki bir sunucuya, s\u00fcrekli a\u00e7\u0131k bir Wireguard VPN y\u00fcklemek, iyi bir kurulum tercihi olabilir.<\/p>\n<h2>iMessage olmadan nas\u0131l idare edeceksiniz?<\/h2>\n<p>Ge\u00e7enlerde arkada\u015f\u0131m Ryan Naraine konu\u015fuyordum. \u201c<em>iMessage ve FaceTime, insanlar\u0131n iPhone kullanmas\u0131n\u0131n <strong>en b\u00fcy\u00fck<\/strong> nedeni!<\/em>\u201d dedi ve kesinlikle hakl\u0131yd\u0131. Ben de 2008\u2019den beri iPhone kullan\u0131c\u0131s\u0131y\u0131m ve Apple\u2019\u0131n bu ekosisteme yapt\u0131\u011f\u0131 en b\u00fcy\u00fck katk\u0131lardan ikisinin iMessage ve FaceTime oldu\u011funu d\u00fc\u015f\u00fcn\u00fcyorum. Bunlar\u0131n ayn\u0131 zamanda ulus devletlerin telefonunuzu g\u00f6zetlemek i\u00e7in en \u00e7ok k\u00f6t\u00fcye kulland\u0131\u011f\u0131 \u00f6zellikler oldu\u011funu fark edince, iMessage <a href=\"https:\/\/www.youtube.com\/watch?v=FVsbvFkhzY4\" target=\"_blank\" rel=\"noopener nofollow\">hapishanesinden<\/a> ka\u00e7maya \u00e7al\u0131\u015ft\u0131m. En zoru ne miydi? Di\u011fer aile \u00fcyelerinin de kullanmay\u0131 b\u0131rakmas\u0131n\u0131 sa\u011flamak. Kula\u011fa \u015fa\u015f\u0131rt\u0131c\u0131 gelse de, t\u00fcm bu g\u00fcvenlik maceras\u0131ndaki en zor \u015feylerden biri buydu.<\/p>\n<div id=\"attachment_10498\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10498\" class=\"wp-image-10498 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/02\/04163827\/how-to-protect-from-pegasus-spyware-imessage-disabled-1024x989.png\" alt=\"\" width=\"1024\" height=\"989\"><p id=\"caption-attachment-10498\" class=\"wp-caption-text\">iMessage\u2019s\u0131z hayat ye\u015fil ve emojisiz<\/p><\/div>\n<p>\u00a0<\/p>\n<p>\u0130lk ba\u015fta herkesi <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/telegram-privacy-security\/9221\/\" target=\"_blank\" rel=\"noopener\">Telegram\u2019a<\/a> ge\u00e7irmeye \u00e7al\u0131\u015ft\u0131m. Pek iyi gitmedi. Ard\u0131ndan, Signal giderek daha iyi hale geldi; g\u00f6r\u00fcnt\u00fcl\u00fc arama ve grup aramas\u0131 \u00f6zelliklerini ekledi. Zamanla daha fazla arkada\u015f\u0131m <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/signal-privacy-security\/9805\/\" target=\"_blank\" rel=\"noopener\">Signal<\/a> kullanmaya ba\u015flad\u0131. Bu yenilikler ailemin de ho\u015funa gitti ve i\u015fe yarad\u0131. Sizin de ayn\u0131 \u015feyi yapman\u0131z gerekti\u011fini s\u00f6ylemiyorum. Belki de iMessage kullanmaya devam ederek mutlu ve k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan ar\u0131nm\u0131\u015f bir \u015fekilde ya\u015famay\u0131 s\u00fcrd\u00fcrebilirsiniz. Asl\u0131na bak\u0131l\u0131rsa Apple, iOS 14\u2019te BlastDoor ile iMessage \u00e7evresindeki korumal\u0131 alan\u0131 <a href=\"https:\/\/googleprojectzero.blogspot.com\/2021\/01\/a-look-at-imessage-in-ios-14.html\" target=\"_blank\" rel=\"noopener nofollow\">b\u00fcy\u00fck \u00f6l\u00e7\u00fcde geli\u015ftirdi.<\/a> \u00d6te yandan, NSO\u2019nun Pegasus\u2019u yaymak i\u00e7in kulland\u0131\u011f\u0131 FORCEDENTRY k\u00f6t\u00fcye kullan\u0131m\u0131, <a href=\"https:\/\/citizenlab.ca\/2021\/09\/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild\/\" target=\"_blank\" rel=\"noopener nofollow\">BlastDoor\u2019u atlatmay\u0131 ba\u015fard\u0131<\/a>. Ayr\u0131ca, elbette hi\u00e7bir g\u00fcvenlik \u00f6zelli\u011fi asla %100 hack ge\u00e7irmez de\u011fil.<\/p>\n<p>Bu durumda her iki yakla\u015f\u0131m\u0131n da avantajlar\u0131ndan faydalanman\u0131n bir yolu olup olmad\u0131\u011f\u0131n\u0131 merak edebilirsiniz. Ben de dahil olmak \u00fczere baz\u0131 ki\u015filer birden fazla telefon kullan\u0131yor: Biri iMessage\u2019\u0131n devre d\u0131\u015f\u0131 b\u0131rak\u0131ld\u0131\u011f\u0131 bir telefon, di\u011feri ise iMessage\u2019\u0131n etkinle\u015ftirildi\u011fi bir \u201cbal k\u00fcp\u00fc\u201d (tuzak) iPhone. Her ikisi de ayn\u0131 Apple kimli\u011fi ve telefon numaras\u0131yla ili\u015fkilendiriliyor. Birileri beni bu \u015fekilde hedef almaya karar verirse bal k\u00fcp\u00fc iPhone\u2019u hacklemeleri \u00e7ok daha olas\u0131.<\/p>\n<h2>Pegasus ve di\u011fer geli\u015fmi\u015f mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar nas\u0131l tespit edilir?<\/h2>\n<p>Pegasus ve di\u011fer geli\u015fmi\u015f mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n bula\u015fma izlerini tespit etmek, iOS ve Android gibi modern i\u015fletim sistemlerinin g\u00fcvenlik \u00f6zellikleri nedeniyle \u00e7ok zor ve karma\u015f\u0131k. G\u00f6zlemlerimize dayanarak, yeniden ba\u015flatman\u0131n ard\u0131ndan neredeyse hi\u00e7 iz b\u0131rakmayan, kal\u0131c\u0131 olmayan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n kullan\u0131lmas\u0131, bu durumu daha da karma\u015f\u0131k hale getiriyor. Bir\u00e7ok adli bili\u015fim \u00e7er\u00e7evesi cihazda jailbreak yap\u0131lmas\u0131n\u0131 gerektirdi\u011fi, bunun i\u00e7in de cihaz yeniden ba\u015flat\u0131ld\u0131\u011f\u0131 i\u00e7in, yeniden ba\u015flatma s\u0131ras\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m bellekten kald\u0131r\u0131lm\u0131\u015f oluyor.<\/p>\n<p>\u015eu anda Pegasus ve di\u011fer mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n tespiti i\u00e7in kullan\u0131labilen \u00e7e\u015fitli y\u00f6ntemler var. Uluslararas\u0131 Af \u00d6rg\u00fct\u00fc\u2019n\u00fcn \u00fccretsiz, a\u00e7\u0131k kaynakl\u0131 <a href=\"https:\/\/github.com\/mvt-project\/mvt\" target=\"_blank\" rel=\"noopener nofollow\">MVT (Mobil Do\u011frulama Ara\u00e7 Seti<\/a>) program\u0131, teknoloji uzmanlar\u0131n\u0131n ve ara\u015ft\u0131rmac\u0131lar\u0131n cep telefonlar\u0131n\u0131 bula\u015fma belirtileri a\u00e7\u0131s\u0131ndan incelemesine olanak tan\u0131yor. MVT, y\u00fcksek profilli vakalardan toplanan ve Uluslararas\u0131 Af \u00d6rg\u00fct\u00fc taraf\u0131ndan kullan\u0131ma sunulan bir IoC (risk g\u00f6stergesi) listesiyle daha da g\u00fc\u00e7lendiriliyor.<\/p>\n<p><span class=\"embed-youtube\" style=\"text-align:center; display: block;\"><iframe class=\"youtube-player\" type=\"text\/html\" width=\"640\" height=\"390\" src=\"https:\/\/www.youtube.com\/embed\/1p0Xm-Opzjg?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen=\"true\"><\/iframe><\/span><\/p>\n<h2>Pegasus bula\u015f\u0131rsa ne yapmal\u0131s\u0131n\u0131z?<\/h2>\n<p>Diyelim ki t\u00fcm bu \u00f6nerileri dikkatle uygulad\u0131n\u0131z ama yine de ka\u00e7amad\u0131n\u0131z. Ne yaz\u0131k ki g\u00fcn\u00fcm\u00fczde ya\u015fad\u0131\u011f\u0131m\u0131z ger\u00e7ek bu. Ac\u0131n\u0131z\u0131 anl\u0131yorum, ger\u00e7ekten. Hi\u00e7 de k\u00f6t\u00fc biri olmayabilirsiniz; aksine, iyilerden biri oldu\u011funuza eminim. Belki g\u00fc\u00e7l\u00fc insanlar\u0131n aleyhinde konu\u015ftunuz veya belirli siyasi fig\u00fcrlerin \u015f\u00fcpheli bir karar\u0131na kar\u015f\u0131 baz\u0131 protestolara kat\u0131ld\u0131n\u0131z. Belki de sadece \u015fifreleme yaz\u0131l\u0131m\u0131 kulland\u0131n\u0131z ya da yanl\u0131\u015f zamanda yanl\u0131\u015f yerde bulundunuz. \u0130yi taraf\u0131ndan bak\u0131n: Vir\u00fcs bula\u015ft\u0131\u011f\u0131n\u0131 <em>biliyorsunuz<\/em>, \u00e7\u00fcnk\u00fc kal\u0131nt\u0131lar ve bilgiler sayesinde bunu belirleyebildiniz. \u015eunlar\u0131 d\u00fc\u015f\u00fcn\u00fcn:<\/p>\n<ul>\n<li><strong>Sizi kim, neden hedef ald\u0131?<\/strong> B\u00fcy\u00fck adamlar\u0131n dikkatini \u00e7ekmenize sebep olan \u015feyin ne oldu\u011funu bulmaya \u00e7al\u0131\u015f\u0131n. Bu, gelecekte daha gizli davranarak ka\u00e7\u0131nabilece\u011finiz bir \u015fey mi?<\/li>\n<li><strong>Bunu birilerine anlatabilir misiniz?<\/strong> Eninde sonunda bir\u00e7ok g\u00f6zetleme \u015firketini \u00e7\u00f6kerten \u015fey, haklar\u0131nda \u00e7\u0131kan olumsuz haberler oldu. K\u00f6t\u00fcye kullan\u0131mlar hakk\u0131nda haber yapan ve yaz\u0131lar yazan muhabirler ve gazeteciler, yalanlar\u0131, yanl\u0131\u015flar\u0131 ve t\u00fcm k\u00f6t\u00fcl\u00fckleri if\u015fa ediyor. Hedef al\u0131nd\u0131ysan\u0131z bir gazeteciye ba\u015f\u0131n\u0131za gelenleri anlatmay\u0131 deneyin.<\/li>\n<li><strong>Cihaz\u0131n\u0131z\u0131 de\u011fi\u015ftirin<\/strong>: iOS kullan\u0131yorsan\u0131z bir s\u00fcre Android\u2019e ge\u00e7meyi deneyin. Android kullan\u0131yorsan\u0131z iOS\u2019a ge\u00e7in. Bu, sald\u0131rganlar\u0131n kafas\u0131n\u0131 bir s\u00fcreli\u011fine kar\u0131\u015ft\u0131rabilir; \u00f6rne\u011fin, baz\u0131 tehdit akt\u00f6rlerinin yaln\u0131zca belirli bir telefon ve i\u015fletim sistemi markas\u0131 \u00fczerinde \u00e7al\u0131\u015fan k\u00f6t\u00fcye kullan\u0131m sistemleri sat\u0131n ald\u0131\u011f\u0131 biliniyor.<\/li>\n<li><strong>G\u00fcvenli ileti\u015fim i\u00e7in tercihen GrapheneOS \u00e7al\u0131\u015ft\u0131ran ikincil bir cihaz edinin<\/strong>. Bu cihazda \u00f6n \u00f6demeli bir kart kullan\u0131n veya yaln\u0131zca u\u00e7ak modundayken Wi-Fi ve TOR ile internete ba\u011flan\u0131n.<\/li>\n<li><strong>Ki\u015filerinize telefon numaran\u0131z\u0131 vermeniz gereken mesajla\u015fma programlar\u0131ndan ka\u00e7\u0131n\u0131n<\/strong>. Bir sald\u0131rgan telefon numaran\u0131z\u0131 ele ge\u00e7irdi\u011finde, sizi bu yolla bir\u00e7ok farkl\u0131 mesajla\u015fma program\u0131 \u00fczerinden kolayca hedefleyebilir. iMessage, WhatsApp, Signal, Telegram gibi programlar\u0131n hepsi telefon numaran\u0131za ba\u011fl\u0131d\u0131r. Bu noktada Session ilgin\u00e7 ve yeni bir tercih olabilir. Session, mesajlar\u0131n\u0131z\u0131 Onion tarz\u0131 bir a\u011f \u00fczerinden y\u00f6nlendirir ve telefon numaras\u0131na ihtiya\u00e7 duymaz.<\/li>\n<li>B\u00f6lgenizdeki <strong>bir g\u00fcvenlik ara\u015ft\u0131rmac\u0131s\u0131yla<\/strong> <a href=\"https:\/\/twitter.com\/craiu\" target=\"_blank\" rel=\"noopener nofollow\">ileti\u015fime ge\u00e7meye<\/a> \u00e7al\u0131\u015f\u0131n ve en iyi uygulamalar\u0131 s\u00fcrekli olarak tart\u0131\u015f\u0131n. Tuhaf bir \u015fey oldu\u011funu d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fcn\u00fczde, kal\u0131nt\u0131lar\u0131, \u015f\u00fcpheli mesajlar\u0131 veya g\u00fcnl\u00fckleri payla\u015f\u0131n. G\u00fcvenlik hi\u00e7bir zaman %100 etkili tek bir anl\u0131k \u00e7\u00f6z\u00fcmle sa\u011flanmaz. G\u00fcvenli\u011fi akan bir nehir gibi d\u00fc\u015f\u00fcn\u00fcn: H\u0131z\u0131n\u0131za, ak\u0131nt\u0131n\u0131za ve engellere g\u00f6re yelkeninizi ayarlaman\u0131z gerekiyor.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p>Yaz\u0131ya son verirken sizi biraz d\u00fc\u015f\u00fcnd\u00fcrmek istiyorum. Ulus devletler taraf\u0131ndan hedef al\u0131n\u0131yorsan\u0131z <strong>\u00f6nemlisiniz<\/strong> demektir. Unutmay\u0131n: \u00d6nemli olmak iyi olsa da, iyi olmak daha \u00f6nemlidir. Tek ba\u015f\u0131m\u0131za zay\u0131f\u0131z, birlikte g\u00fc\u00e7l\u00fcy\u00fcz. D\u00fcnya raydan \u00e7\u0131km\u0131\u015f olabilir, ama hala bir \u015feyleri de\u011fi\u015ftirebilece\u011fimize inan\u0131yorum. <a href=\"https:\/\/edition.cnn.com\/2021\/12\/09\/media\/journalists-imprisoned-cpj-census\/index.html\" target=\"_blank\" rel=\"noopener nofollow\">K\u00e2r amac\u0131 g\u00fctmeyen Gazetecileri Koruma Komitesi\u2019nin (CPJ) bir raporuna<\/a> g\u00f6re, 2021\u2019de 293 gazeteci tutukland\u0131. Bu, 1992\u2019de bu say\u0131y\u0131 takip etmeye ba\u015flayan CPJ\u2019in \u015fimdiye kadar bildirdi\u011fi en y\u00fcksek say\u0131. D\u00fcnyan\u0131n 10 y\u0131l sonra ya da \u00e7ocuklar\u0131m\u0131z i\u00e7in, hatta \u00e7ocuklar\u0131m\u0131z\u0131n \u00e7ocuklar\u0131 i\u00e7in nas\u0131l bir yer olaca\u011f\u0131n\u0131 \u015fekillendirmek bizim elimizde.<\/p>\n<p><em>G\u00fc\u00e7, siz insanlarda. Makine yaratma g\u00fcc\u00fc de. Mutluluk yaratma g\u00fcc\u00fc de! Siz, insanlar, bu hayat\u0131 \u00f6zg\u00fcr ve g\u00fczel k\u0131lacak, bu hayat\u0131 harika bir maceraya d\u00f6n\u00fc\u015ft\u00fcrecek g\u00fcce sahipsiniz.<\/em><\/p>\n<p><em>O halde, demokrasi ad\u0131na, bu g\u00fcc\u00fc kullanal\u0131m. Hepimiz birle\u015felim. Yeni bir d\u00fcnya i\u00e7in sava\u015fal\u0131m. \u0130nsanlara \u00e7al\u0131\u015fma \u015fans\u0131 verecek, gen\u00e7lere bir gelecek, ya\u015fl\u0131lara ise bir g\u00fcvence sunacak iyi bir d\u00fcnya i\u00e7in. Zalimler bunlar\u0131 vadederek iktidara geldi. Ama yalan s\u00f6yl\u00fcyorlar! Bu s\u00f6z\u00fc yerine getirmiyorlar. Hi\u00e7bir zaman da getirmeyecekler!<\/em><\/p>\n<p><em>Diktat\u00f6rler kendilerini \u00f6zg\u00fcrle\u015ftirirken halk\u0131 k\u00f6lele\u015ftiriyor! \u015eimdi bu s\u00f6z\u00fc yerine getirmek i\u00e7in sava\u015fal\u0131m! Ulusal engelleri ortadan kald\u0131rarak, a\u00e7g\u00f6zl\u00fcl\u00fc\u011f\u00fc, nefreti ve ho\u015fg\u00f6r\u00fcs\u00fczl\u00fc\u011f\u00fc ortadan kald\u0131rarak, d\u00fcnyay\u0131 \u00f6zg\u00fcrle\u015ftirmek i\u00e7in sava\u015fal\u0131m. Mant\u0131\u011f\u0131n h\u00fck\u00fcm s\u00fcrd\u00fc\u011f\u00fc bir d\u00fcnya i\u00e7in, bilim ve ilerlemenin t\u00fcm insanlara mutluluk getirdi\u011fi bir d\u00fcnya i\u00e7in sava\u015fal\u0131m. Askerler! Demokrasi ad\u0131na hepimiz birle\u015felim!<\/em><\/p>\n<p><em>B\u00fcy\u00fck Diktat\u00f6r\u2019deki final konu\u015fmas\u0131<\/em><\/p>\n<p>Bu g\u00f6nderi ilk olarak Dark Reading\u2019de bir yaz\u0131 dizisi olarak yay\u0131nland\u0131 (<a href=\"https:\/\/www.darkreading.com\/dr-tech\/how-to-protect-your-phone-from-pegasus-and-other-apts\" target=\"_blank\" rel=\"noopener nofollow\">1. B\u00f6l\u00fcm<\/a>, <a href=\"https:\/\/www.darkreading.com\/edge-articles\/fighting-back-against-pegasus-other-advanced-mobile-malware\" target=\"_blank\" rel=\"noopener nofollow\">2. B\u00f6l\u00fcm<\/a>).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>iPhone ya da Android ak\u0131ll\u0131 telefonunuzu Pegasus ve benzeri mobil APT&#8217;lerden nas\u0131l koruyabilirsiniz?<\/p>\n","protected":false},"author":378,"featured_media":10493,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[2517,105,493,1900,914,627,750,665,1190],"class_list":{"0":"post-10492","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-0days","9":"tag-android","10":"tag-apt","11":"tag-casus-yazilim","12":"tag-costin-raiu","13":"tag-great","14":"tag-ios","15":"tag-mobil-cihazlar","16":"tag-pegasus"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/how-to-protect-from-pegasus-spyware\/10492\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/how-to-protect-from-pegasus-spyware\/23861\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/how-to-protect-from-pegasus-spyware\/19358\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/how-to-protect-from-pegasus-spyware\/26103\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/how-to-protect-from-pegasus-spyware\/24071\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/how-to-protect-from-pegasus-spyware\/23841\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/how-to-protect-from-pegasus-spyware\/26812\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/how-to-protect-from-pegasus-spyware\/26405\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/how-to-protect-from-pegasus-spyware\/32942\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/how-to-protect-from-pegasus-spyware\/43453\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/how-to-protect-from-pegasus-spyware\/18515\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/how-to-protect-from-pegasus-spyware\/18973\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/how-to-protect-from-pegasus-spyware\/15741\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/how-to-protect-from-pegasus-spyware\/28055\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/how-to-protect-from-pegasus-spyware\/32437\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/how-to-protect-from-pegasus-spyware\/28069\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/how-to-protect-from-pegasus-spyware\/24866\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/how-to-protect-from-pegasus-spyware\/30207\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/how-to-protect-from-pegasus-spyware\/29996\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/casus-yazilim\/","name":"casus yaz\u0131l\u0131m"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/378"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10492"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10492\/revisions"}],"predecessor-version":[{"id":10501,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10492\/revisions\/10501"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10493"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}