Fw: [情报]中国利用iphone 漏洞监控维吾尔族

楼主: kyle5241 (kyle)   2019-09-02 03:16:20
※ [本文转录自 iOS 看板 #1TR1Z1Fv ]
作者: kyle5241 (Kyle Korver) 看板: iOS
标题: [情报]中国利用iphone 漏洞监控维吾尔族
时间: Mon Sep 2 03:15:10 2019
iPhone 最安全?Google:iPhone 早已被恶意网站入侵多年
以为拿 iPhone 就不用担心资安吗?Google 资安研究员发现,有不少恶意网站透过尚未
公开的软件漏洞悄悄入侵 iPhone,目前已有不知情受害者造访这些恶意网站数千次,时
根据 TechCrunch 报导,Google 资安团队 Project Zero 日前发布一篇文章,指出骇客
先入侵这些网站,之后当 iPhone 使用者造访这些网站时,就会发送恶意软件,甚至在手
研究人员发现 5 个不同的漏洞利用链(exploit chain),从 iOS 10 到 iOS 12 版本都
有,这些利用链涉及了 12 种不同的安全漏洞。其中,有 7 个安全漏洞与 iPhone 内建
的网页浏览器 Safari 有关。
这 5 个攻击链让骇客拥有 iPhone 设备最高等级的“Root”权限,代表骇客可以在使用

Report: China used iPhone website exploit attacks to target Uyghur Muslims
A few days ago, Google Project Zero security researchers detailed a chain of
malicious website exploits targeting iPhone users. Now, TechCrunch reports
that the Chinese government used these attacks to target Uyghur Muslims.
之前google 发现了iphone史上最大的漏洞,现在发生这是被中国用来锁定维吾尔族
Citing sources familiar with the matter, TechCrunch says that the malicious
websites used to hack into iPhones, first detailed by Google, were part of a
“state-backed attack,” likely from China, designed to “target the Uyghur
community in the country’s Xinjiang state.”
The report goes on to detail that according to United Nations data, Beijing
has detained “more than 1 million Uyghurs in internment camps” over the
last year.
Google researchers first explained that the victims were tricked into opening
a link which would direct them to an infected webpage. On that webpage, the
malware was deployed. The implant “primarily focused on stealing files and
uploading live location data,” as often as every 60 seconds. Because the end
device itself had been compromised, services like iMessage were also
affected, researchers said.
When Google security researchers first detailed this attack, it was unclear
who it was specifically targeting. TechCrunch’s report now provides more
detail on that.
The websites were part of a campaign to target the religious group by
infecting an iPhone with malicious code simply by visiting a booby-trapped
web page. In gaining unfettered access to the iPhone’s software, an attacker
could read a victim’s messages, passwords, and track their location in
near-real time.
The report adds that the websites in question would also infect non-Uyghurs
who happened to visit the infected website. The domains were indexed in
Google search results, which made it relatively easy for anyone to stumble
upon them.
作者: Hohenzollern   2019-09-02 03:49:00
作者: AJizzInPants (阿基师在裤子里)   2019-09-02 08:55:00
没做坏事干嘛怕监控? 湾湾去过新疆吗?
作者: sunskist0831 (好男不当兵)   2019-09-02 11:02:00
假的 让我们来继续检讨卓卓
作者: princeguitar (王早)   2019-09-02 15:37:00

Links booklink

Contact Us: admin [ a t ] ucptt.com