µ½90°×¶ÈÊ×Ò³

Äú²éѯµÄ¹Ø¼ü´Ê½öÔÚÍøÒ³±êÌâ»òÖ¸Ïò´ËÍøÒ³µÄÁ´½ÓÖгöÏÖ¡£

(90°×¶ÈºÍÍøÒ³https://www.leiphone.com/category/gbsecurity/JHyStw97xoSZ3NlM.htmlµÄ×÷ÕßÎ޹أ¬²»¶ÔÆäÄÚÈݸºÔð¡£90°×¶È¿ìÕÕ½÷ÎªÍøÂç¹ÊÕÏʱ֮Ë÷Òý£¬²»´ú±í±»ËÑË÷ÍøÕ¾µÄ¼´Ê±Ò³Ãæ¡£)


UTF-8 iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ | À×·åÍø
ÄúÕýÔÚʹÓÃIEµÍ°æä¯ÀÀÆ÷£¬ÎªÁËÄúµÄÀ×·åÍøÕ˺Ű²È«ºÍ¸üºÃµÄ²úÆ·ÌåÑ飬ǿÁÒ½¨ÒéʹÓøü¿ì¸ü°²È«µÄä¯ÀÀÆ÷
´ËΪÁÙʱÁ´½Ó£¬½öÓÃÓÚÎÄÕÂÔ¤ÀÀ£¬½«ÔÚʱʧЧ
·¢Ë½ÐŸøÁõÁÕ

0

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

±¾ÎÄ×÷Õߣº ÁõÁÕ 2020-04-23 15:38
µ¼ÓÇë×¢Ò⣬ÄãµÄiPhone¡¢iPad»ò±»ºÚ¿ÍÀûÓÃÁ˰ËÄê¡£

Ò»Ö±ÒÔÀ´£¬Æ»¹ûµÄ°²È«ÐÔ¶¼ÊDZ»Óû§ÍƳçµÄ£¬µ«×î½ü£¬Æ»¹ûÈ´±»½ÓÁ¬ÆØ³öÖØ´ó°²È«Â©¶´¡£

À×·æÍø 4Ô 23ÈÕÏûÏ¢£¬¾ÝÍâý±¨µÀ£¬¾É½ðɽµÄÍøÂ簲ȫ¹«Ë¾ ZecOps ·¢ÏÖÁËÒ»¸ö´æÔÚÓÚ iOS É豸ÉϵÄ©¶´£¬¶øÇÒÓÐÖ¤¾Ý±íÃ÷£¬ÖÁÉÙÓÐ 6 ´ÎÍøÂ簲ȫÈëÇֻÀûÓÃÁËÕâ¸ö©¶´¡£

¿ÉŵÄÊÇ£¬¸Ã©¶´»òÓ°Ïì iOS6 ÒÔÉÏËùÓа汾£¬³¬¹ý 5 ÒÚµÄÓû§ÃæÁÙ±»¹¥»÷µÄ·çÏÕ£¬¶øÕâһ©¶´¿ÉÄܱ»ºÚ¿ÍÀûÓÃÁ˰ËÄê¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

²¢ÇÒÕâ¸ö©¶´²»ÐèÒªÓû§Èκεã»÷£¬Ö»Òª¸øÓû§·¢ËÍÒ»·âµç×ÓÓʼþ£¬ÉõÖÁÓʼþ»¹ÔÚÏÂÔØ¹ý³ÌÖУ¬¾ÍÄÜ´¥·¢Â©¶´¹¥»÷¡£

Ŀǰƻ¹ûÒѾ­³ÐÈÏÁËÕâһ©¶´µÄ´æÔÚ£¬²¢±íʾÕýÔÚŬÁ¦ÐÞ¸´Ïà¹ØµÄ©¶´¡£Æ»¹ûÒѾ­ÔÚ×îÐ嵀 iOS 13.4.5 ²âÊÔ°æÖÐÐÞ¸´Á˰²È«Â©¶´¡£iOS 13.4.5 Õýʽ°æÓ¦¸Ã»áÔÚδÀ´¼¸ÖÜÄÚ¹«¿ª·¢²¼¡£

©¶´ÒÑDZ·ü°ËÄ꣬5ÒÚÓû§¿ÉÄܱ»¹¥»÷

ÄÇô£¬Õâ¸ö©¶´»áÈçºÎ·¢Æð¹¥»÷ÄØ£¿

¾ÝÍâý£¬ÕâÏîÑо¿±íÃ÷¸Ã©¶´¿É±»Ô¶³Ì´¥·¢£¬¶øÇÒÒѱ»ºÚ¿ÍÓÃÀ´¹¥»÷һЩ֪ÃûÓû§¡£

Õâһ©¶´ÔÊÐí¹¥»÷Õßͨ¹ý·ÃÎÊ iOS 12 ºÍ iOS 13 ÖÐµÄ MobileMail ºÍ Mailid ½ø³Ì¿ªÊ¹ÓÃÌØÊâµÄÓʼþÀ´ÔËÐÐÔ¶³Ì´úÂë¡£¶øÒ»¸ö©¶´¿ÉÒÔÈù¥»÷Õßͨ¹ý·¢ËÍÏûºÄ´óÁ¿ÄÚ´æµÄÓʼþÀ´Ô¶³Ì¸ÐȾ iOS É豸¡£

Ò²¾ÍÊÇ˵£¬ÀûÓÃÕâЩ©¶´£¬¹¥»÷Õß¿ÉÒÔй¶¡¢Ð޸ĺÍɾ³ýÓû§µÄµç×ÓÓʼþ¡£

ZecOps ÔÚÖÜÈýµÄ±¨¸æÖбíʾ£¬ËûÃÇ"¸ß¶ÈÏàÐÅ"ÕâЩ©¶´ÒѾ­±»¸ßˮƽºÚ¿ÍÀûÓ᣶øÕâÁ½¸ö©¶´µÄ±äÌåÉõÖÁ¿ÉÒÔ×·Ëݵ½ 2012 Äê·¢²¼µÄ iOS 6 ÉíÉÏ£¬ÕâÒâζןڿÍÒѾ­ÀûÓÃËüÃÇ¶Ô iPhone ºÍ iPad Óû§½øÐÐÁ˳¤´ï°ËÄêµÄ¹¥»÷¡£Èç¹ûÉ豸±»¸ÐȾ£¬Óû§ÉõÖÁ²»ÖªµÀËûÃÇÕýÔÚ±»ºÚ¿Í¹¥»÷¡£

¾ßÌå¹¥»÷;¾¶ÊÇ£ººÚ¿Íͨ¹ý Mail Ó¦ÓÃÏòÊܺ¦Õß·¢³öÒ»·Ý¿Õ°×µçÓÊ£¬µ¼ÖºóÕßµÄϵͳ±ÀÀ£²¢ÖØÖ㬶øÏµÍ³±ÀÀ£ÁîºÚ¿ÍµÃÒÔÇÔÈ¡ÕÕÆ¬ºÍÁªÏµÈËÐÅÏ¢µÈÆäËûÊý¾Ý¡£

ZecOps Éù³Æ£¬¼´Ê¹ÊÇ»ùÓÚ×îа汾 iOS ϵͳÔËÐÐµÄ iPhone£¬ºÚ¿ÍÒ²ÄÜÀûÓÃÕâ¸ö©¶´Ô¶³ÌÇÔÈ¡ÆäÊý¾Ý¡£¸Ã©¶´¿ÉÁîºÚ¿Í»ñÈ¡ Mail Ó¦ÓÃÓÐȨ·ÃÎʵÄÈκÎÐÅÏ¢£¬°üÀ¨Ë½ÃÜÏûÏ¢¡£

ZecOps ·¢ÏÖµ¼ÖÂÕâÒ»¹¥»÷µÄÔ­ÒòÊÇ£ºMFMutableDataÔÚ MIME ¿âÖУ¬È±ÉÙϵͳµ÷ÓõĴíÎó¼ì²é¡£ftruncate()»áµ¼ÖÂÔ½½çд×÷¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

³ý´ËÖ®Í⣬ËûÃÇ»¹·¢ÏÖÁËÒ»ÖÖÔÚ²»µÈ´ýϵͳµ÷ÓÃʧ°ÜµÄÇé¿öÏ´¥·¢OOB-дµÄ·½·¨ÒÔ¼°Ò»¸ö¿ÉÒÔÔ¶³Ì´¥·¢µÄ¶ÑÒç³ö¡£

¶ø OOB-д´íÎóºÍ¶ÑÒç³ö´íÎó¶¼ÊÇÓÉÓÚÏàͬµÄÎÊÌâ¶ø·¢ÉúµÄ£ºÃ»ÓÐÕýÈ·´¦Àíϵͳµ÷Óõķµ»ØÖµ¡£

Ò²¾ÍÊÇ˵£¬¸Ã©¶´¿ÉÒÔÔÚÏÂÔØÕû·âµç×ÓÓʼþ֮ǰ¾Í´¥·¢£¬¼´Ê¹ÄãûÓн«ÓʼþÄÚÈÝÏÂÔØµ½±¾µØ¡£

©¶´±»ÀûÓÃÁËÖ®ºó»á³öÏÖÄÄЩÒì³££¿

¿´µ½ÕâÀÓÐÍøÓÑ˵£¬ÎÒ¶¼²»ÓÃÓʼþ£¬ÓêÎÒÎ޹ϰ¡¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

¿ÉÊÇ£¬Õâ¸ö©¶´µÄ¿ÉÅÂÖ®´¦»òÐí²»ÔÚÓÚÓû§ÊÇ·ñʹÓã¬Ö»ÒªËüÔÚÄãµÄÓ¦ÓÃÁбíÀÄÇôÄãÓпÉÄܾÍÊDZ»¹¥»÷µÄ¶ÔÏó¡£

¸ù¾Ý ZecOpsµÄÑо¿£¬ËûÃÇ·¢ÏÖµ±ÄãµÄ iPhone ºÍ iPad±»¹¥»÷ºó»á£¬³ýÁËÒÆ¶¯ÓʼþÓ¦ÓóÌÐòÔÝʱ·Å»ºÖ®Í⣬Óû§²»Ó¦¹Û²ìµ½ÈÎºÎÆäËûÒì³£ÐÐΪ¡£

ÔÚ IOS 12 ÖУ¬¸üÈÝÒ×´¥·¢¸Ã©¶´£¬ÒòΪÊý¾ÝÁ÷ÊÇÔÚͬһ½ø³ÌÄÚÍê³ÉµÄ£¬×÷ΪĬÈÏÓʼþÓ¦ÓóÌÐò(MobileMail)£¬Ëü´¦ÀíµÄ×ÊÔ´Òª¶àµÃ¶à£¬Õâ»áÕ¼ÓÃÐéÄâÄÚ´æ¿Õ¼äµÄ·ÖÅä£¬ÌØ±ðÊÇ UI ³ÊÏÖ£¬¶øÔÚ IOS 13 ÖУ¬MobileMail ½«Êý¾ÝÁ÷´«µÝµ½ºǫ́½ø³Ì£¬¼´ maild¡£Ëü½«Æä×ÊÔ´¼¯ÖÐÔÚ·ÖÎöµç×ÓÓʼþÉÏ£¬´Ó¶ø½µµÍÁËÐéÄâÄÚ´æ¿Õ¼äÒâÍâºÄ¾¡µÄ·çÏÕ¡£

¾ßÌå·´Ó¦ÈçÏ£º

ºÚ¿ÍÔÚ iOS 12ÉϵĹ¥»÷³¢ÊÔ(³É¹¦»òʧ°Ü)Ö®ºó£¬Óû§¿ÉÄÜ»á×¢Òâµ½ Mail Ó¦ÓóÌÐòͻȻ±ÀÀ£¡£

ÔÚ iOS 13 ÉÏ£¬ÕâÒ»¹¥»÷Ôò±íÏֵIJ»ÄÇôÃ÷ÏÔ¡£³ýÁËÔÝʱµÄ·Å»º£¬ÆäËûÒì³£¶¼²»»á±»×¢Òâµ½¡£

ÔÚʧ°ÜµÄ¹¥»÷ÖУ¬¹¥»÷Õß·¢Ë͵ĵç×ÓÓʼþ½«ÏÔʾÏûÏ¢£º¡°´ËÏûϢûÓÐÄÚÈÝ¡±¡£ÈçÏÂͼËùʾ£º

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

ÔÚ iOS 13ÉÏ£¬¹¥»÷Õß¿ÉÄÜ»á¶à´Î³¢ÊÔÔÚûÓÐÓû§½»»¥µÄÇé¿öÏÂÇÄÇĵظÐȾÉ豸¡£ÔÚ iOS 12ÉÏ£¬ÔòÒªÇóÓû§µã»÷¹¥»÷ÕßÐÂÊÕµ½µÄµç×ÓÓʼþ´¥·¢¹¥»÷¡£²»¹ý£¬ZecOpsÒ²±íʾ£¬ÏÖÔÚ¿ÉÒÔÈ·¶¨µÄÊÇ MacOS ²»ÈÝÒ×Êܵ½ÕâÁ½ÖÖ©¶´µÄ¹¥»÷¡£

¾ÍÆä±¾Éí¶øÑÔ£¬ÕâЩ©¶´²¢²»»á¶ÔÓû§Ôì³ÉÌ«´óµÄ·çÏÕ--ËüÃÇÖ»ÔÊÐí¹¥»÷ÕßÔĶÁ¡¢Ð޸Ļòɾ³ýµç×ÓÓʼþ¡£µ«Èç¹ûÓëÁíÒ»ÖÖÄں˹¥»÷Ïà½áºÏ£¬ÀýÈçÎÞ·¨ÐÞ²¹µÄ Checkm8 ©¶´£¬ÕâЩ©¶´¿ÉÄÜ»áÈò»Á¼ÐÐΪÕß¶ÔÌØ¶¨Ä¿±êÉ豸½øÐÐ root ·ÃÎÊ¡£

ZecOps ÔÚÆä±¨¸æÖз¢ÏÖ£¬ºÚ¿Í¹¥»÷µÄÄ¿±êÖ÷Òª¼¯ÖÐÔÚÆóÒµ¸ß¹ÜºÍ¹úÍâ¼ÇÕßµÄÉ豸ÉÏ¡£ËùÒÔ£¬´ó¼ÒÔÝʱ²»±Ø¹ýÓÚµ£ÐÄ¡£

ÈçºÎ×Ծȣ¿

ÊÂʵÉÏ£¬½ñÄê2Ô£¬ZecOps ¾ÍÏòÆ»¹û¹«Ë¾±¨¸æ¿ÉÒÉ©¶´¡£

3ÔÂ31ÈÕ£¬ZecOps È·ÈÏÁ˵ڶþ¸ö©¶´´æÔÚÓÚÍ¬Ò»ÇøÓò£¬²¢ÇÒÓÐÔ¶³Ì´¥·¢µÄÄÜÁ¦¡£

4 Ô 15 ÈÕ£¬Æ»¹û¹«Ë¾·¢²¼ÁË iOS13.4.5 beta 2 °æ£¬ÆäÖаüº¬ÁËÕë¶ÔÕâЩ©¶´µÄ²¹¶¡³ÌÐò£¬ÐÞ¸´ÁËÕâÁ½¸ö©¶´¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

4Ô 20 ÈÕ£¬ZecOpsÖØÐ·ÖÎöÁËÀúÊ·Êý¾Ý£¬²¢·¢ÏÖÁ˶îÍâµÄÖ¤¾Ý£¬²¢¼°Ê±Í¨ÖªÁËÆ»¹û±ØÐëÁ¢¼´·¢²¼´ËÍþв¾¯¸æ£¬ÒÔʹ×éÖ¯Äܹ»±£»¤×Ô¼º£¬ÒòΪ¹¥»÷Õß¿ÉÄÜ»á´ó´óÔö¼ÓËûÃǵĻ£¬ÒòΪËüÒѾ­ÔÚ beta °æÖеõ½ÁËÐÞ²¹¡£

¶øÆ»¹ûÒ²´ó·½³ÐÈÏÁËÕâһ©¶´£¬ËùÒÔÔÚÆ»¹û×îеÄÐÞ¸´°æ±¾³öÏÖ֮ǰ£¬ÎÒÃÇÓ¦¸ÃÈçºÎ×èÖ¹ÕâÖÖ¹¥»÷ÄØ£¿

ZecOps ½¨ÒéÓû§Ê¹Óà Gmail »ò Outlook µÈµÚÈý·½µç×ÓÓʼþApp£¬²¢ÇÒÔÚºǫ́½ûÓÃÕâ¿îÔ­×°Èí¼þ¡£

Æ»¹ûµÄ°²È«ÐÔÊÜÖÊÒÉ£¿

Æ»¹û¹Ù·½Êý¾ÝÏÔʾ£¬2019 ÄêÔ¼ÓÐ 9 ÒÚ²¿ iPhone ´¦ÓÚ»îԾʹÓÃ״̬¡£ÍøÂ簲ȫר¼ÒÈÏΪ£¬Æä¹ã·ºÆÕ¼°³Ì¶ÈÒâζ×Å£¬ÑÏÖØ°²È«Â©¶´Ò»µ©Ôâµ½ÀÄÓ㬾ͿÉÄÜÔì³É³¬¹ýÊý°ÙÍòÃÀÔªµÄËðʧ¡£

ǰÓÐ siriÇÔÌý£¬ºóÓÐiPhoneÔ½ÓüʼþÒÔ¼°ÏÖÔÚ±»±¬µÄ°²È«Â©¶´ÎÊÌ⣬ƻ¹ûµÄ°²È«ÐÔÒ²Ôâµ½ÁËÓû§ÃǵÄÖÊÒÉ¡£

Ò»·½ÈÏΪ£¬Óû§ÈÏΪÈκÎϵͳ¶¼ÎÞ·¨±ÜÃâ©¶´£¬Æ»¹ûÔÚ¹ýÈ¥±íÏÖ³öµÄ³É¼¨×ãÒÔÖ¤Ã÷ËüµÄ°²È«ÐÔ£¬¶ÔÆ»¹ûÒÀÈ»ÓÐÆÚ´ý¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

ÁíÒ»·½ÔòÈÏΪ£¬Á¬Æ»¹û¶¼±»ÆØ³ö°²È«ÎÊÌ⣬ÊÖ»ú³§ÉÌÃÇÊÇʱºò¿¼ÂÇ·´»÷ÁË¡£

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

iPhone Óû§¿´¹ýÀ´£¡Æ»¹ûÔÙÏÖ°²È«Â©¶´£º³¬ 5 ÒÚÓû§»ò±»ºÚ¿ÍÀûÓðËÄ꣬iOS 6 ÒÔÉÏËùÓа汾¶¼ÓÐΣÏÕ

¶Ô´Ë£¬ÄãÔõô¿´ÄØ£¿Ä㻹»áÐÅÈÎÆ»¹ûµÄ²úÆ·Âð£¿

À×·æÍøÀ×·æÍøÀ×·æÍø

²Î¿¼À´Ô´£º

¡¾1¡¿https://www.vice.com/en_us/article/pken5n/iphone-email-zero-day-hack-in-the-wild

¡¾2¡¿https://www.vice.com/en_us/article/3da5qj/government-hackers-iphone-hacking-jailbreak-nso-group

¡¾3¡¿https://www.volexity.com/blog/2020/04/21/evil-eye-threat-actor-resurfaces-with-ios-exploit-and-updated-implant/

¡¾4¡¿https://blog.zecops.com/vulnerabilities/unassisted-ios-attacks-via-mobilemail-maild-in-the-wild/

À×·åÍøÔ­´´ÎÄÕ£¬Î´¾­ÊÚȨ½ûÖ¹×ªÔØ¡£ÏêÇé¼û×ªÔØÐëÖª¡£

·ÖÏí£º
Ïà¹ØÎÄÕÂ
µ±ÔÂÈÈÃÅÎÄÕÂ
×îÐÂÎÄÕÂ
ÇëÌîдÉêÇëÈË×ÊÁÏ
ÐÕÃû
µç»°
ÓÊÏä
΢ÐźÅ
×÷Æ·Á´½Ó
¸öÈ˼ò½é
ΪÁËÄúµÄÕË»§°²È«£¬ÇëÑéÖ¤ÓÊÏä
ÄúµÄÓÊÏ仹δÑéÖ¤,Íê³É¿É»ñ20»ý·ÖÓ´£¡
ÇëÑéÖ¤ÄúµÄÓÊÏä
ÍêÉÆÕ˺ÅÐÅÏ¢
ÄúµÄÕ˺ÅÒѾ­°ó¶¨£¬ÏÖÔÚÄú¿ÉÒÔÉèÖÃÃÜÂëÒÔ·½±ãÓÃÓÊÏäµÇ¼
Powered by 90°×¶È