{"id":9512,"date":"2021-04-13T17:43:18","date_gmt":"2021-04-13T14:43:18","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9512"},"modified":"2021-04-13T17:43:18","modified_gmt":"2021-04-13T14:43:18","slug":"is-txt-file-safe","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/is-txt-file-safe\/9512\/","title":{"rendered":"Metin dosyalar\u0131 g\u00fcvenli midir?"},"content":{"rendered":"<p>Harici e-postalar alan \u00e7al\u0131\u015fanlar genellikle hangi dosyalar\u0131n potansiyel olarak tehlikeli oldu\u011fu hakk\u0131nda bilgilendirilir. \u00d6rne\u011fin EXE dosyalar\u0131 da, k\u00f6t\u00fc ama\u00e7l\u0131 makrolar i\u00e7erebilen DOCX ve XLSX dosyalar\u0131 gibi varsay\u0131lan olarak tehlikeli kabul edilir. \u00d6te yandan metin dosyalar\u0131, d\u00fcz metinden ba\u015fka bir \u015fey i\u00e7eremedikleri i\u00e7in genellikle kas\u0131tl\u0131 olarak zarars\u0131z kabul edilir. Ancak durum her zaman b\u00f6yle de\u011fildir.<\/p>\n<p>Ara\u015ft\u0131rmac\u0131lar, dosya bi\u00e7imindeki (\u015fu an yamalanm\u0131\u015f olan) bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan yararlanman\u0131n bir yolunu buldular ve daha da fazlas\u0131n\u0131 bulabilirlerdi. Asl\u0131nda sorun dosya bi\u00e7iminden de\u011fil; programlar\u0131n TXT\u2019leri i\u015fleme \u015feklinden kaynaklan\u0131yor.<\/p>\n<h2>macOS\u2019un CVE-2019-8761 g\u00fcvenlik a\u00e7\u0131\u011f\u0131<\/h2>\n<p>Ara\u015ft\u0131rmac\u0131 Paulos Yibelo, ilgin\u00e7 bir yol ile metin dosyalar\u0131 \u00fczerinden macOS bilgisayarlara sald\u0131rma konusuna <a href=\"https:\/\/www.paulosyibelo.com\/2021\/04\/this-man-thought-opening-txt-file-is.html\" target=\"_blank\" rel=\"noopener nofollow\">\u0131\u015f\u0131k tuttu<\/a>. Di\u011fer bir\u00e7ok koruyucu \u00e7\u00f6z\u00fcm gibi, macOS\u2019un yerle\u015fik g\u00fcvenlik sistemi Gatekeeper da metin dosyalar\u0131n\u0131 tamamen g\u00fcvenilir olarak g\u00f6r\u00fcr. Kullan\u0131c\u0131lar ek kontroller olmadan metin belgelerini indirebilir ve i\u015fletim sisteminde yerle\u015fik metin d\u00fczenleyicisi TextEdit ile a\u00e7abilir.<\/p>\n<p>Ancak TextEdit, Microsoft Windows\u2019un Not Defteri uygulamas\u0131ndan biraz daha karma\u015f\u0131kt\u0131r. Metnin kal\u0131n g\u00f6r\u00fcnt\u00fclenmesi gibi daha fazla \u015fey yapabilir, kullan\u0131c\u0131lar\u0131n yaz\u0131 tipi rengini de\u011fi\u015ftirmesi ve daha ba\u015fka bir \u00e7ok \u015feye izin verir. TXT dosya bi\u00e7imi metnin stil bilgilerini saklamak \u00fczere tasarlanmad\u0131\u011f\u0131ndan, bu g\u00f6revi yerine getirebilmek i\u00e7in gereken ek teknik bilgileri TextEdit al\u0131r. \u00d6rne\u011fin bir dosya, &lt;!DOCTYPE HTML&gt; &lt;html&gt; &lt;head&gt; &lt;\/head&gt; &lt;body&gt; sat\u0131r\u0131yla ba\u015fl\u0131yorsa TextEdit, .txt uzant\u0131l\u0131 bir dosyada bile HTML etiketlerini i\u015flemeye ba\u015flar.<\/p>\n<p>Asl\u0131nda bir metin dosyas\u0131na bu sat\u0131rla ba\u015flayan HTML kodunun yaz\u0131lmas\u0131, TextEdit\u2019i kodu veya en az\u0131ndan kodun baz\u0131 \u00f6\u011felerini i\u015flemeye zorlar.<\/p>\n<h2>Metin dosyalar\u0131 arac\u0131l\u0131\u011f\u0131yla ger\u00e7ekle\u015febilecek olas\u0131 sald\u0131r\u0131lar<\/h2>\n<p>Bu y\u00f6ntemi kullanacak olan potansiyel bir sald\u0131rgan\u0131n yararlanabilece\u011fi t\u00fcm olas\u0131l\u0131klar\u0131 dikkatlice inceledikten sonra Yibelo, bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131n \u015funlara imkan sa\u011flad\u0131\u011f\u0131n\u0131 buldu:<\/p>\n<ul>\n<li>DoS sald\u0131r\u0131lar\u0131. Gatekeeper, TXT uzant\u0131s\u0131na sahip bir nesneden yerel dosyalar\u0131n a\u00e7\u0131lmas\u0131n\u0131 engellemez. Bu nedenle k\u00f6t\u00fc ama\u00e7l\u0131 bir metin dosyas\u0131n\u0131 a\u00e7mak, \u00f6rne\u011fin HTML kodu sonsuz say\u0131da bo\u015f karakter yarat\u0131lan <a href=\"https:\/\/tr.wikipedia.org\/wiki\/\/dev\/zero\" target=\"_blank\" rel=\"noopener nofollow\">\/dev\/zero <\/a>dosyas\u0131na eri\u015ferek bir bilgisayar\u0131 a\u015f\u0131r\u0131 y\u00fckleyebilir.<\/li>\n<li>Bir kullan\u0131c\u0131n\u0131n ger\u00e7ek IP adresini tan\u0131mlama. Metin dosyas\u0131ndaki kod, dosya sistemlerini ba\u011flamak i\u00e7in standart bir program olan ve harici bir s\u00fcr\u00fcc\u00fcye eri\u015fim sa\u011flayabilen AutoFS\u2019yi \u00e7a\u011f\u0131rabilir. Bu eylem kendi ba\u015f\u0131na zarars\u0131z olsa da, otomatik ba\u011flama i\u015flemi sistem \u00e7ekirde\u011fini bir TCP iste\u011fi g\u00f6ndermeye zorlad\u0131\u011f\u0131ndan, kullan\u0131c\u0131 bir proxy sunucusunun arkas\u0131nda olsa bile, k\u00f6t\u00fc ama\u00e7l\u0131 metin dosyas\u0131n\u0131 haz\u0131rlayan ki\u015fi dosyan\u0131n tam olarak ne zaman a\u00e7\u0131ld\u0131\u011f\u0131n\u0131 bulabilir ve ger\u00e7ek IP adresini kaydeder.<\/li>\n<li>Dosya h\u0131rs\u0131zl\u0131\u011f\u0131. T\u00fcm dosyalar, &lt;iframedoc&gt; \u00f6zniteli\u011fi i\u00e7eren bir metin belgesine eklenebilir. Bu sayede k\u00f6t\u00fc ama\u00e7l\u0131 metin dosyas\u0131 kurban\u0131n bilgisayar\u0131ndaki herhangi bir dosyaya eri\u015febilir ve ard\u0131ndan bir bi\u00e7imlendirme sald\u0131r\u0131s\u0131 kullanarak i\u00e7eri\u011fini aktarabilir. Kullan\u0131c\u0131n\u0131n sadece dosyay\u0131 a\u00e7mas\u0131 yeterlidir.<\/li>\n<\/ul>\n<p>G\u00fcvenlik a\u00e7\u0131\u011f\u0131, Aral\u0131k 2019\u2019da Apple\u2019a bildirildi ve <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-8761\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2019-8761<\/a> ile numaraland\u0131r\u0131ld\u0131. <a href=\"https:\/\/www.paulosyibelo.com\/2021\/04\/this-man-thought-opening-txt-file-is.html\" target=\"_blank\" rel=\"noopener nofollow\">Paulos Yibello\u2019nun g\u00f6nderisinde<\/a>, g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan yararlan\u0131lmas\u0131na ili\u015fkin daha fazla bilgi mevcut.<\/p>\n<h2>G\u00fcvenli\u011finizi nas\u0131l sa\u011flayabilirsiniz?<\/h2>\n<p>Yay\u0131nlanan bir 2020 g\u00fcncellemesi, <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-8761\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2019-8761<\/a> g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 kapatt\u0131 ancak bu, yaz\u0131l\u0131mda TXT ile ilgili gizli kalm\u0131\u015f hatalar\u0131n olmad\u0131\u011f\u0131n\u0131 garanti etmez. Hen\u00fcz kimsenin nas\u0131l yararlan\u0131laca\u011f\u0131n\u0131 \u00e7\u00f6zemedi\u011fi ba\u015fka a\u00e7\u0131klar da olabilir. O y\u00fczden, \u201cBu metin dosyas\u0131 g\u00fcvenli mi?\u201d sorusunun do\u011fru cevab\u0131 \u015f\u00f6yle bir \u015feydir: \u201cEvet, \u015fimdilik g\u00fcvenli. Ama yine de tetikte olun.\u201d<\/p>\n<p>Bu nedenle, zarars\u0131z bir metin dosyas\u0131 gibi g\u00f6r\u00fcnse bile her bir dosyay\u0131 potansiyel bir tehdit olarak ele almalar\u0131 i\u00e7in <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">t\u00fcm \u00e7al\u0131\u015fanlar\u0131 e\u011fitmenizi<\/a> \u00f6neriyoruz.<\/p>\n<p>Her \u015feye ra\u011fmen, \u015firketin t\u00fcm d\u0131\u015far\u0131 giden bilgi ak\u0131\u015f\u0131n\u0131n kontrol\u00fcn\u00fc dahili veya <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/managed-detection-and-response?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener nofollow\">harici SOC<\/a>\u2018ye vermek mant\u0131kl\u0131d\u0131r.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kasap\">\n","protected":false},"excerpt":{"rendered":"<p>Genellikle TXT uzant\u0131s\u0131na sahip dosyalar\u0131n g\u00fcvenli oldu\u011fu d\u00fc\u015f\u00fcn\u00fcl\u00fcr. Ama ger\u00e7ekten \u00f6yle mi? <\/p>\n","protected":false},"author":2581,"featured_media":9513,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[790,1170,2400,2399],"class_list":{"0":"post-9512","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-guvenlik-aciklari","10":"tag-macos","11":"tag-metin","12":"tag-txt"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/is-txt-file-safe\/9512\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/is-txt-file-safe\/22708\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/is-txt-file-safe\/18189\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/is-txt-file-safe\/24519\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/is-txt-file-safe\/22557\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/is-txt-file-safe\/21597\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/is-txt-file-safe\/25049\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/is-txt-file-safe\/24330\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/is-txt-file-safe\/30455\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/is-txt-file-safe\/39256\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/is-txt-file-safe\/16727\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/is-txt-file-safe\/17296\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/is-txt-file-safe\/14662\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/is-txt-file-safe\/26504\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/is-txt-file-safe\/30449\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/is-txt-file-safe\/26893\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/is-txt-file-safe\/23735\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/is-txt-file-safe\/29081\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/is-txt-file-safe\/28879\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/guvenlik-aciklari\/","name":"g\u00fcvenlik a\u00e7\u0131klar\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9512"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9512\/revisions"}],"predecessor-version":[{"id":9514,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9512\/revisions\/9514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9513"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}