µÚÈý·½¿Í»§¶Ë¿ª·¢ÏÝÚåÈ«½ÒÃØ
ÍÆÌØÀ¶Äñ°æÏÂÔØ18rÐû³Æ¼¯³ÉÄÚÈݹýÂËɨ³ý¡¢¶àýÌåÔöÇ¿µÈ½ø½×¹¦Ð§£¬ÕâÕýÊÇÎüÒýÓû§Ã°ÏÕʹÓ÷ǹٷ½°æ±¾µÄ½¹µãÓÕÒò¡£Ç徲ʵÑéÊÒ²ð½â·¢Ã÷£¬Áè¼Ý83%µÄÐ޸İæÓ¦Óñ£´æÎ´¹ûÕæµÄRootkit£¨Äں˼¶¶ñÒâÈí¼þ£©£¬ÄÜʵʱ¼à¿ØÓû§ÊäÈëµÄËùÓÐÕ˺ÅÃÜÂë¡£ÖµµÃСÐĵÄÊÇ£¬ÕâÀà¸ßΣº¦¿Í»§¶ËÍùÍùαװ³ÉͨË×ϵͳ¸üÐÂÎļþÈö²¥£¬ÔÚ¶«ÄÏÑǵØÇøÒÑÔì³ÉÊýǧÆðÊý×ÖÇ®±Ò±»µÁ°¸¼þ¡£
Óû§Òþ˽й¶¶àά¹¥»÷·¾¶
µ±Óû§×°ÖÃÍÆÌØÀ¶Äñ°æÏÂÔØ18rʱ£¬ºǫ́ЧÀÍ»áͬ²½¼¤»îÈý×é×ÔÁ¦µÄÊý¾ÝÍøÂçÄ£¿é¡£µÚһģ¿éͨ¹ýAPI HookÊÖÒÕ½ØÈ¡Ë½ÐÅÄÚÈÝ£¬µÚ¶þÄ£¿é½¨ÉèÐéαµÄOAuthÈÏÖ¤Ò³ÃæÆÈ¡¶þ²½ÑéÖ¤Â룬µÚÈýÄ£¿éÔòʹÓð²×¿ÏµÍ³ÊðÃûÎó²îÖ²Èë¹ã¸æSDK¡£Ç徲ר¼Ò֤ʵ£¬Ä³ÏÂÔØÁ¿³¬50ÍòµÄÐ޸İæ¿Í»§¶Ë£¬ÆäÊý¾Ý¿âÿ·ÖÖÓ¶¼ÔÚÏò¾³ÍâЧÀÍÆ÷´«ÊäÓû§GPS¶¨Î»ÐÅÏ¢¡£
¶ñÒâ´úÂëÈö²¥µÄÊÖÒռܹ¹ÆÊÎö
ͨ¹ýÄæÏò¹¤³Ì»¹ÔÍÆÌØÀ¶Äñ°æÏÂÔØ18rµÄÊÖÒÕʵÏÖ£¬·¢Ã÷¿ª·¢ÕßʹÓÃMetasploit¿ò¼Ü¹¹½¨¹¥»÷ÔØºÉ¡£ÌØÊâÉè¼ÆµÄ¶¯Ì¬¼ÓÔØ»úÖÆÊ¹µÃɱ¶¾Èí¼þÄÑÒÔ¼ì²â£¬Ã¿µ±Óû§µã¿ªË½ÐÅͼƬʱ¾Í»á´¥·¢ÇéÐθÐ֪ģ¿é¡£¸Ã°æ±¾»¹²»·¨¼¯³ÉGoogle Play Protect¼ì²â¹æ±ÜÊÖÒÕ£¬ÀÖ³ÉÈÆ¹ýÁè¼Ý20ÖÖÖ÷Á÷Çå¾²Èí¼þµÄ·À»¤»úÖÆ¡£
¸ßΣº¦¿Í»§¶ËµÄÆßÏîʶ±ðÌØÕ÷
񻂿·ÖÍÆÌØÀ¶Äñ°æÏÂÔØ18rµÄÕæÊµÎ£º¦£¬Óû§ÐèÖØµã¹Ø×¢×°ÖðüµÄÆßÏîÊý×ÖÖ¸ÎÆ¡£ÊÇAPKÎļþ¾ÞϸÒì³££¬¹Ù·½°æÔ¼Îª67MB£¬Ð޸İæÆÕ±é¿ØÖÆÔÚ72-75MBÒÔÒþ²Ø¸½¼ÓÄ£¿é¡£ÊÇÊðÃûÖ¤ÊéÐÅÏ¢ÖеĿ¯ÐÐÉÌ×ֶΣ¬ËùÓзǹٷ½°æ±¾¾ùʹÓÃδÂÄÀúÖ¤µÄµ÷ÊÔÖ¤Êé¡£ÔËÐÐʱÄÚ´æÕ¼ÓÃÈôÁè¼Ý320MB£¬¼«¿ÉÄÜÕýÔÚÖ´ÐмÓÃÜÇ®±ÒÍÚ¿ó³ÌÐò¡£
ÓÅÂúÇ徲ƽ̨µÄËÄά·À»¤ÏµÍ³
Õë¶ÔµÚÈý·½¿Í»§¶ËµÄ¸ßΣΣº¦£¬ÓÅÂúƽ̨¿ª·¢³öÁ¢ÒìµÄÓ¦ÓÃɳÏä¼ì²âÊÖÒÕ¡£¸Ã¼Æ»®½ÓÄÉʵʱÐÐΪÆÊÎöÒýÇæ£¬ÄÜ׼ȷʶ±ðÍÆÌØÀ¶Äñ°æÏÂÔØ18rÌØÓеÄ18ÏîΣÏÕAPIŲÓá£Çå¾²ÑéÖ¤Àú³Ì°üÀ¨×°Öðü¹þϣУÑé¡¢¶¯Ì¬ÐÐΪ¼à¿Ø¡¢Òþ˽ȨÏÞÆÀ¹ÀºÍÊý×ÖÊðÃûÈÏÖ¤Ëĸöά¶È£¬¼ì²â׼ȷÂÊ´ï99.3%¡£Æ½Ì¨ÄÚÖõÄÓ¦¼±ÏìӦģ¿é£¬¿ÉÔÚ30ÃëÄÚ¸ôÀëÒÑ×°ÖõĶñÒâ¿Í»§¶Ë¡£
Óû§Êý¾Ý±£»¤µÄ½ø½×²Ù×÷Ö¸ÄÏ
¹ØÓÚÒѾװÖÃÍÆÌØÀ¶Äñ°æÏÂÔØ18rµÄÓû§£¬Ó¦Á¬Ã¦Ö´ÐÐÈý½×¶ÎÓ¦¼±´¦Öóͷ££ºÇжÏ×°±¸µÄÍøÂçÅþÁ¬£¬±ÜÃâÃô¸ÐÊý¾ÝÒ»Á¬Íâй£»Ê¹ÓÃרҵ¹¤¾ßɨ³ýÒþ²ØµÄAndroid×é¼þЧÀÍ£»ÐèÖÜÈ«¸üÐÂËùÓйØÁªÕ˺ŵÄÈÏ֤ƾ֤¡£ÓÅÂúÇå¾²ÖÐÐÄÌṩµÄ×°±¸Éî¶ÈɨÃ蹦Ч£¬½ÓÄÉ»úеѧϰËã·¨¿É»¹Ô93%µÄDZÔÚÊý¾Ýй¶·¾¶¡£
ÐÅÏ¢Ç徲ר¼ÒÔÙ´ÎÌáÐÑ£¬ÍÆÌØÀ¶Äñ°æÏÂÔØ18rµÈ·Ç¹Ù·½¿Í»§¶ËµÄÍþвƷ¼¶ÒÑ´ïCritical£¨ÑÏÖØ£©¼¶±ð¡£Óû§Ó¦µ±Í¨¹ýÓÅÂúƽ̨µÈ¿ÉÐÅÇþµÀ»ñȡӦÓ㬲¢°´ÆÚ¾ÙÐÐ×°±¸Çå¾²Ìå¼ì¡£½¨Ò鿪ÆôÓ²¼þ¼¶µÄÇå¾²·ÉµØ·À»¤¹¦Ð§£¬½«Õ˺ű»µÁΣº¦½µµÍ78%ÒÔÉÏ¡£¼Ç×Å£¬ÍøÂçÒþ˽±£»¤Ã»Óнݾ¶£¬Ç徲ʹÓù淶²ÅÊÇ·ÀÓùÍøÂçÍþвµÄ×îÖÕ½â¾ö¼Æ»®¡£µÚÒ»Õ£ºµÚÈý·½¹¤¾ßΪºÎ³ÉÎªÍÆÌØÇå¾²ÖØÔÖÇø
ÍÆÌØÆ½Ì¨ÈÕ¾ù»îÔ¾Óû§´ï2.3ÒÚ£¬ÆäÖÐ31%µÄÕ˺ÅÇå¾²ÊÂÎñÓë²»·¨µÚÈý·½¹¤¾ßÏà¹Ø¡£ÒÔ91Ãâ·Ñ°æÎª´ú±íµÄÒ»¼üÖÎÀí¹¤¾ß³£Î±×°Ð§¹ûÂÊÖúÊÖ£¬ÊµÔòͨ¹ý×¢Èë¾ç±¾£¨script injection£©»ñÈ¡Óû§Ãô¸ÐÊý¾Ý¡£Ñо¿ÏÔʾ£¬Ä³°æ±¾91¹¤¾ß×°ÖðüÄÚǶµÄÒþ²ØÊ½´úÂ루covert code£©¿Éʵʱ¼à¿ØÓû§Ë½ÐÅ¡¢×·×ÙµØÀíλÖò¢ÍøÂçÁªÏµÈËÐÅÏ¢¡£
µÚ¶þÕ£º91Ãâ·Ñ°æÔËÐлúÖÆµÄÊÖÒÕÆÊ½â
ÄæÏò¹¤³Ì£¨reverse engineering£©ÆÊÎöÅú×¢£¬¸Ã¹¤¾ß½ÓÄÉÆæÒìµÄȨÏÞÀ¦°óÕ½ÂÔ¡£×°ÖÃÀú³ÌÖлáÇ¿ÖÆÒªÇó¿ªÆô11ÏîϵͳȨÏÞ£¬°üÀ¨¶ÁȡͨѶ¼¡¢»á¼ûÉãÏñÍ·µÈ½¹µãÒþ˽¹¦Ð§¡£¸üΣÏÕµÄÊÇÆäʹÓõĶ¯Ì¬Ö¤Êé¸üУ¨Dynamically Updating Certificate£©ÊÖÒÕ£¬¿ÉÈÆ¹ýGoogle PlayÊÐËÁµÄÇå¾²¼ì²â¡£µ±Óû§Ö´ÐÐÍÆÌØ·¢Ìû²Ù×÷ʱ£¬¿Í»§¶Ë»á½«ÐÅϢͬʱ´«Ê䵽δ֪IPµØµã¡£
µÚÈýÕ£º¸ßΣȨÏÞ±³ºóµÄÊý¾ÝºÚ²úÁ´Ìõ
ÍøÂçÇ徲ר¼Òͨ¹ýÁ÷Á¿¼à¿Ø·¢Ã÷£¬Ê¹ÓÃ91Ãâ·Ñ°æµÄÕË»§Ã¿24Сʱ¾Í»á±¬·¢Ô¼340KBµÄÒì³£Êý¾Ý´«Êä¡£ÕâЩÊý¾Ý¾ÓÉAES-256¼ÓÃܺóÁ÷Ïò¾³ÍâЧÀÍÆ÷£¬½âÂëºó°üÀ¨ÍêÕûµÄÓû§»ÏñÊý¾Ý¡£Æ¾Ö¤ÍøÂç·¸·¨Ñо¿ÖÐÐĵı¨¸æ£¬ÕâЩÐÅÏ¢ÔÚºÚÊпÉÂôµ½Ã¿Ìõ0.3-1.5ÃÀÔª£¬Ö÷Òª±»ÓÃÓÚ¾«×¼¹ã¸æÍ¶·ÅºÍ´¹ÂÚ¹¥»÷£¨phishing attacks£©¡£
µÚËÄÕ£º¹Ù·½APIÓë²»·¨¹¤¾ßµÄȨÏÞ±ÈÕÕ
ÍÆÌØ¹Ù·½ÌṩµÄ±ê×¼API£¨Application Programming Interface£©½ö¿ª·Å38Ïî»ù´¡¹¦Ð§£¬ÑÏ¿á×ñÕÕOAuth 2.0ÊÚȨÐÒé¡£Ïà±È֮ϣ¬²»·¨¹¤¾ßͨ¹ýÄæÏò¹¤³ÌÊֶλñÈ¡µÄ˽ÓÐAPI½Ó¿ÚµÖ´ï79ÏÆäÖаüÀ¨ÅÌÎÊÓû§Òþ˽״̬µÄÄÚ²¿½Ó¿Ú¡£Êý¾ÝÏÔʾ£¬Ê¹Óò»·¨¹¤¾ßµÄÕË»§±»ºÚ¿ÍÈëÇֵĸÅÂÊÊÇͨË×ÕË»§µÄ7.3±¶¡£
µÚÎåÕ£º×¨Òµ¼¶ÍÆÌØÇå¾²·À»¤¼Æ»®
½¨ÒéÓû§½ÓÄÉÁãÐÅÈΣ¨Zero Trust£©Ç徲ģ×Ó¾ÙÐзÀ»¤¡£ÆôÓÃÓ²¼þÇå¾²ÃÜÔ¿£¨ÈçYubiKey£©¾ÙÐÐË«ÒòËØÈÏÖ¤£¬Æä·À´¹ÂÚÀÖ³ÉÂʿɴï99.9%¡£Ê¹Óùٷ½Ðû²¼µÄTwitter Advanced Protection³ÌÐò£¬¸Ã³ÌÐòʵʱ¼à¿ØAPIŲÓ㬿ÉÒÉÇëÇó×èµ²ÏìӦʱ¼ä½öΪ0.08Ãë¡£Õë¶ÔÒÆ¶¯¶ËÓû§£¬½¨Òé×°ÖÃGoogle Play ProtectʵʱɨÃèDZÔÚÍþв¡£
µÚÁùÕ£ºÕ˺ÅÒì³£µÄÌØÕ÷ʶ±ðÓë´¦Öóͷ£
µ±ÕË»§·ºÆðÒÔÏÂ3¸öÕ÷Õ×ʱӦÁ¬Ã¦ÅŲ飺1£©¹Ø×¢ÁÐ±í·ºÆðδ¹Ø×¢Õ˺ţ»2£©Ë½ÐżÍ¼Öб£´æÎ´·¢ËÍÐÅÏ¢£»3£©µÇ¼ËùÔÚÏÔʾºÜÊÇÓÃÇøÓò¡£×¨ÒµÈ¡Ö¤¹¤¾ßÏÔʾ£¬±»Ö²Èë¶ñÒâ´úÂëµÄÕË»§»áÔÚÿ120Ãë·¢ËÍÐÄÌø°ü£¨heartbeat packet£©ÖÁC&CЧÀÍÆ÷¡£·ºÆðÒ쳣ʱ¿ÉʹÓÃTwitter Safety DashboardÌìÉúÍêÕûµÄÇå¾²É󼯱¨¸æ¡£
ͨ¹ý±¾ÎĵÄÊÖÒÕÆÊÎö¿ÉÒÔ¿´µ½£¬ÍÆÌظßΣΣº¦91Ãâ·Ñ°æ×°ÖðüʵÔòÊÇÈ«ÐÄÉè¼ÆµÄÊý×ÖÏÝÚå¡£Çå¾²Ñо¿Êý¾ÝÅú×¢£¬×èֹʹÓò»·¨µÚÈý·½¹¤¾ß¿É½«ÕË»§Ç徲Ʒ¼¶ÌáÉý89%¡£½¨ÒéÓû§°´ÆÚ¼ì²éÒÑÊÚȨµÄÓ¦ÓóÌÐò£¬½«OAuthÁîÅÆÓÐÓÃÆÚÉèÖÃΪ×î´óÖµ£¨¼´12¸öÔ£©£¬²¢¿ªÆôµÇ¼ÑéÖ¤ÂëË«ÖØ±£»¤¹¦Ð§¡£¼Çס£ºÕæÕýµÄÇå¾²À´×ÔÓÚ¶ÔϵͳȨÏÞµÄÑÏ¿á¹Ü¿ØºÍ¶Ô¹Ù·½¹¤¾ßµÄºÏÀíʹÓá£