{"id":9991,"date":"2021-09-07T11:48:53","date_gmt":"2021-09-07T08:48:53","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9991"},"modified":"2021-09-08T12:23:56","modified_gmt":"2021-09-08T09:23:56","slug":"power-apps-exposure","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/power-apps-exposure\/9991\/","title":{"rendered":"Microsoft Power Apps ile olu\u015fturulan uygulamalar, kullan\u0131c\u0131lara ait ki\u015fisel bilgileri s\u0131zd\u0131r\u0131yor olabilir"},"content":{"rendered":"<p>\u015eirketlerin toplad\u0131\u011f\u0131 bilgiler nas\u0131l yanl\u0131\u015f ellere ge\u00e7er? Bu bilgiler bazen \u015firket i\u00e7inden birileri taraf\u0131ndan sat\u0131l\u0131r, bazen hedefli bir hackleme s\u0131z\u0131nt\u0131n\u0131n yay\u0131lmas\u0131n\u0131 sa\u011flar, ancak \u00e7o\u011fu zaman ki\u015fileri tan\u0131mlay\u0131c\u0131 bilgiler yanl\u0131\u015f yap\u0131land\u0131r\u0131lm\u0131\u015f hizmetler veya programlar arac\u0131l\u0131\u011f\u0131yla a\u00e7\u0131\u011fa \u00e7\u0131kar. Buna \u00f6rnek bir \u00e7ok kan\u0131ta ek olarak UpGuard\u2019dan ara\u015ft\u0131rmac\u0131lar, 38 milyon ki\u015fiye ait ki\u015fileri tan\u0131mlay\u0131c\u0131 bilginin <a href=\"https:\/\/www.theverge.com\/2021\/8\/24\/22639106\/microsoft-power-apps-default-permissions-settings-user-records-exposed-38-million-upgard\" target=\"_blank\" rel=\"noopener nofollow\">if\u015fa oldu\u011funu<\/a> ke\u015ffetti. S\u0131z\u0131nt\u0131n\u0131n kayna\u011f\u0131 ise Microsoft Power Apps platformuyla olu\u015fturulan, k\u00f6t\u00fc yap\u0131land\u0131r\u0131lm\u0131\u015f baz\u0131 Web uygulamalar\u0131. Neyse ki, k\u00f6t\u00fc niyetli ki\u015filer bilgiye eri\u015fim sa\u011flayamam\u0131\u015f gibi g\u00f6r\u00fcn\u00fcyor.<\/p>\n<h2>Power Apps\u2019in yanl\u0131\u015f yap\u0131land\u0131rmas\u0131<\/h2>\n<p>\u015eirketlerin b\u00fcy\u00fck yaz\u0131l\u0131m geli\u015ftirme yat\u0131r\u0131mlar\u0131na ihtiya\u00e7 duymadan uygulamalar ve Web portallar\u0131 olu\u015fturmas\u0131na yard\u0131mc\u0131 olan bir ara\u00e7 olan Microsoft\u2019un Power Apps, az kod (low-code) ilkesinden yararlan\u0131yor (yani, \u00e7ok fazla kod yazmay\u0131 gerektirmiyor). Uygulama hakk\u0131ndaki <a href=\"https:\/\/powerapps.microsoft.com\/tr-tr\/\" target=\"_blank\" rel=\"noopener nofollow\">kullan\u0131c\u0131 incelemeleri<\/a>, BT ve programlama konusunda deneyim sahibi olmadan herhangi bir fikri ger\u00e7e\u011fe d\u00f6n\u00fc\u015ft\u00fcrme becerisini abart\u0131yor.<\/p>\n<p>Sorunun alt\u0131nda yatan neden ise bu basitlik. Yaln\u0131zca BT deneyiminden yoksun olmakla kalmay\u0131p ayn\u0131 zamanda bilgi g\u00fcvenli\u011fini de g\u00f6z ard\u0131 eden ki\u015filer, Power Apps\u2019i kullanarak hi\u00e7 de s\u00fcrpriz olmayan bir \u015fekilde, g\u00fcvenli olmayan ara\u00e7lar yaratt\u0131lar. Ara\u015ft\u0131rmac\u0131lar, ki\u015fisel verileri toplayan ancak bu verilerin g\u00fcvenli\u011fini sa\u011flamayan ara\u00e7lar olu\u015fturmak i\u00e7in Power Apps kullanan 47 \u015firket ve devlet kurumu ke\u015ffetti.<\/p>\n<p>Uzun ve olduk\u00e7a teknik bir a\u00e7\u0131klamay\u0131 \u00f6zetlemek gerekirse, Power Apps, kullan\u0131c\u0131lar\u0131n hem veri payla\u015fmak hem de veri toplamak i\u00e7in ara\u00e7lar olu\u015fturmas\u0131na olanak tan\u0131r. Her iki durumda da veriler tablolarda tutulur ve uygulaman\u0131n yarat\u0131c\u0131s\u0131 bunlara eri\u015fim izinleri verebilir. Varsay\u0131lan olarak, bu izinler devre d\u0131\u015f\u0131 b\u0131rak\u0131lm\u0131\u015ft\u0131. Bir taraftan, i\u00e7erik olu\u015fturucular\u0131n payla\u015f\u0131m\u0131 kolayca etkinle\u015ftirmesi olanak tan\u0131n\u0131rken di\u011fer taraftan bunu yapmak asl\u0131nda tablolar\u0131 herkesin eri\u015fimine a\u00e7\u0131k hale getiriyordu. Bu nedenle toplanan veriler \u015firket d\u0131\u015f\u0131ndan eri\u015fime a\u00e7\u0131k hale geldi.<\/p>\n<h2>\u015eirketinizin ve m\u00fc\u015fterilerinizin verilerini s\u0131z\u0131nt\u0131lardan nas\u0131l korursunuz?<\/h2>\n<p>Ara\u015ft\u0131rmac\u0131lar s\u0131z\u0131nt\u0131y\u0131 bildirdikten sonra Microsoft, platformun varsay\u0131lan ayarlar\u0131nda de\u011fi\u015fikli\u011fe gitti. Art\u0131k birisi ki\u015fisel verileri toplayan yeni bir proje olu\u015fturdu\u011funda, toplad\u0131\u011f\u0131 t\u00fcm bilgiler, d\u0131\u015far\u0131dan eri\u015filemeyecek \u015fekilde tutuluyor. Ancak, Microsoft\u2019un g\u00fcncellemesinden \u00f6nce olu\u015fturulan uygulamalar ve Web hizmetleri hala savunmas\u0131z olabilir. \u015eirketiniz Microsoft Power Apps kullan\u0131yorsa, \u00f6zellikle de uygulamalar\u0131n\u0131z ki\u015fileri tan\u0131mlay\u0131c\u0131 bilgiler toplay\u0131p sakl\u0131yorsa, bu t\u00fcr s\u0131z\u0131nt\u0131lar\u0131 \u00f6nlemek i\u00e7in t\u00fcm yap\u0131land\u0131rma se\u00e7eneklerini ba\u015ftan sona kontrol etmelisiniz.<\/p>\n<p>Ancak, asl\u0131nda sorun \u00e7ok daha geni\u015f kapsaml\u0131. BT uzmanl\u0131\u011f\u0131na sahip olmayan ki\u015filerin hizmetler, uygulamalar ve internet siteleri olu\u015fturmak i\u00e7in kulland\u0131\u011f\u0131 tek az kod (low-code) ilkesine sahip platform Power Apps de\u011fil. \u015eirketlerin daha \u00e7ok yaln\u0131zca \u015firket i\u00e7i g\u00f6revler i\u00e7in kulland\u0131\u011f\u0131 bu ara\u00e7lardan, g\u00fcvenlik departmanlar\u0131n\u0131n hi\u00e7 haberi olmayabilir. Ayn\u0131 zamanda kaynak kodunda g\u00fcvenlik a\u00e7\u0131klar\u0131, di\u011fer i\u015f s\u00fcre\u00e7leriyle entegrasyon s\u0131ras\u0131nda olu\u015fan hatalar veya ya\u015fanan bu \u00f6rnekte oldu\u011fu gibi yanl\u0131\u015f yap\u0131land\u0131rmalar s\u00f6z konusu olabilir.<\/p>\n<p>Bu nedenle, az kod ilkesi ile \u00e7al\u0131\u015fan platformlar\u0131 kullanan \u015firketlerin a\u015fa\u011f\u0131dakileri yapmas\u0131n\u0131 \u00f6neriyoruz:<\/p>\n<ul>\n<li>Hem yay\u0131nlanan hem de hen\u00fcz yay\u0131nlanmayan uygulamalar\u0131n g\u00fcvenlik ve gizlilik ayarlar\u0131n\u0131 dikkatlice kontrol edin,<\/li>\n<li>Bilgi g\u00fcvenli\u011fi departmanlar\u0131na, bu t\u00fcr platformlar\u0131n i\u015f s\u00fcre\u00e7lerinde kullan\u0131m\u0131 konusunda e\u011fitim vermek;<\/li>\n<li>G\u00fcvenlik de\u011ferlendirmesi i\u00e7in (\u015firket i\u00e7i uzman bulunmuyorsa) <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/cybersecurity-services?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">\u015firket d\u0131\u015f\u0131ndan uzmanlar<\/a> istihdam etmek.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-b2b\">\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Power Apps ile olu\u015fturulan yanl\u0131\u015f yap\u0131land\u0131r\u0131lm\u0131\u015f uygulamalar, milyonlarca ki\u015fileri tan\u0131mlay\u0131c\u0131 bilgi kayd\u0131n\u0131 korunmas\u0131z hale getiriyor.<\/p>\n","protected":false},"author":2581,"featured_media":9992,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[881,38,2007,2465,2464],"class_list":{"0":"post-9991","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-ayarlar","10":"tag-microsoft","11":"tag-sizintilar","12":"tag-web-hizmetleri","13":"tag-yanlis-yapilandirma"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/power-apps-exposure\/9991\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/power-apps-exposure\/23234\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/power-apps-exposure\/18721\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/power-apps-exposure\/25286\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/power-apps-exposure\/23356\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/power-apps-exposure\/22781\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/power-apps-exposure\/25926\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/power-apps-exposure\/25417\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/power-apps-exposure\/31406\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/power-apps-exposure\/41523\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/power-apps-exposure\/17547\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/power-apps-exposure\/18038\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/power-apps-exposure\/15192\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/power-apps-exposure\/27259\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/power-apps-exposure\/31521\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/power-apps-exposure\/27471\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/power-apps-exposure\/24283\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/power-apps-exposure\/29608\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/power-apps-exposure\/29413\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/yanlis-yapilandirma\/","name":"yanl\u0131\u015f yap\u0131land\u0131rma"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9991"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9991\/revisions"}],"predecessor-version":[{"id":10007,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9991\/revisions\/10007"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9992"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}