UCä¯ÀÀÆ÷ÖÐÑëÈ˹¥»÷(MITM)·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-28

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

ĿǰUCä¯ÀÀÆ÷Ų×ÅÊÖ»ú°æÒÔ¼°×ÀÃæ°æ¾ùÊÜÓ°Ïì¡£


·ì϶¸ÅÊö


×Ô2016ÄêÒÔÀ´£¬UCä¯ÀÀÆ÷ÖгöÏÖÁËÒ»¸öDZÔÚΣÏյĸüÐÂÖ°ÄÜ¡£Ö»¹Ü¸ÃÀûÓ÷¨Ê½»¹Ã»Óп´µ½·Ö·¢Ä¾Âí»ò²»±ØÒªµÄÈí¼þ£¬µ«Ëü¼ÓÔØºÍÆô¶¯ÐµĺÍδ¾­ÑéÖ¤µÄÄ£¿éµÄÖ°ÄÜ×é³ÉÁËDZÔÚµÄÍþв¡£


UCä¯ÀÀÆ÷µÄÒ×Êܹ¥»÷µÄÖ°ÄÜ¿ÉÓÃÓÚÖ´ÐÐÖÐÑëÈ˹¥»÷£¨MITM£©¡£ÎªÁËÏÂÔØÐ²å¼þ£¬ä¯ÀÀÆ÷ÏòºÅÁîºÍ½ÚÔì·þÎñÆ÷·¢ËÍÒªÇ󣬲¢½Ó¹ÜÏìÓ¦ÎļþµÄÁ´½Ó¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚ·¨Ê½Í¨¹ý²»°²È«µÄͨ·£¨HTTPºÍ̸¶ø²»ÊǼÓÃܵÄHTTPS£©Óë·þÎñÆ÷ͨѶ£¬Òò¶øÍøÂç·¸×ï·Ö×ÓÄܹ»hookÀ´×ÔÀûÓ÷¨Ê½µÄÒªÇó¡£ËûÃÇÄܹ»ÓÃÔ̺¬·ÖÆçµØÖ·µÄºÅÁî´úÌæºÅÁî¡£ÕâʹµÃä¯ÀÀÆ÷´Ó¶ñÒâ·þÎñÆ÷¶ø²»ÊÇ×Ô¼ºµÄºÅÁîºÍ½ÚÔì·þÎñÆ÷ÏÂÔØÐÂÄ£¿é¡£ÓÉÓÚUCä¯ÀÀÆ÷ʹÓÃδÊðÃûµÄ²å¼þ£¬Ëü½«Æô¶¯¶ñÒâÄ£¿é¶øÎÞÐèÈκÎÑéÖ¤¡£


Òò¶ø£¬MITM¹¥»÷Äܹ»Ô®ÊÖÍøÂç·¸×ï·Ö×ÓʹÓÃUCä¯ÀÀÆ÷´«²¼Ö´Ðи÷Àà²Ù×÷µÄ¶ñÒâ²å¼þ¡£ÀýÈ磬ËûÃÇÄܹ»ÏÔÊ¾ÍøÂç´¹µöÓʼþÒÔÇÔÈ¡Óû§Ãû£¬ÃÜÂë£¬ÒøÐп¨¾ßÌåÐÅÏ¢ºÍÆäËûÓ×ÎÒÊý¾Ý¡£´Ë±í£¬Ä¾ÂíÄ£¿é½«¿ÉÄܽӼûÊܱ£»¤µÄä¯ÀÀÆ÷Îļþ²¢ÇÔÈ¡´æ´¢ÔÚ·¨Ê½Ä¿Â¼ÖеÄÃÜÂë¡£


¼øÓÚUCä¯ÀÀÆ÷ÔÚÈ«ÇòÁìÓòÄÚµÄ×°»úÁ¿£¬¸Ã·ì϶Ëù´øÀ´µÄÍþв²»ÈÝÓ×êï¡£³ýÁËUCä¯ÀÀÆ÷Ö®±í£¬Google Play»¹ÉϼÜÁËÒ»¿î¡°UC ä¯ÀÀÆ÷ Mini°æ¡±£¬ÏÔʾװÖôÎÊýÒѾ­³¬¹ý1ÒÚ¡£ÔÚUC ä¯ÀÀÆ÷ Mini°æ±¾ÖУ¬Í¬Ñù´æÔÚÈÆ¹ýGoogle PlayÏÂÔØÎ´¾­²âÊÔ²å¼þµÄÐÐΪ£¬ÕâÅúעͬÑù´æÔÚÖÐÑëÈ˹¥»÷µÄ·çÏÕ¡£²»Í⣬ÏÂÊö·ì϶ÀûÓÃËùչʾµÄÖÐÑëÈ˹¥»÷·½Ê½²¢²»ºÏÓÃÓÚMini°æ±¾µÄUCä¯ÀÀÆ÷¡£
 
 GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÀûÓÃ


ÏÂÃæÎªÑéÖ¤°¸Àý¡£ÏÔʾÁËͨ¹ýUCä¯ÀÀÆ÷ÏÂÔØPDFÎĵµ²¢³¢ÊԲ鿴µÄDZÔÚÊܺ¦Õß¡£

Òª´ò¿ªÎļþ£¬ä¯ÀÀÆ÷»á³¢ÊÔ´ÓºÅÁîºÍ½ÚÔì·þÎñÆ÷ÏÂÔØÏàÓ¦µÄ²å¼þ¡£µ«ÊÇ£¬ÓÉÓÚMITM´úÌæ£¬ä¯ÀÀÆ÷»áÏÂÔØ²¢Æô¶¯·ÖÆçµÄ¿â¡£¶øºó£¬¸Ã¿â»á´´½¨Ò»ÌõÎı¾ÐÂÎÅ£¬ÉÏÃæÐ´×Å¡°PWNED£¡¡±¡£


ÏÂÔØPDFÎĵµ¡£
  

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ò¿ªPDF¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀûÓÃÖÐÑëÈ˹¥»÷´úÌæÏÂÔØµÄÏàÓ¦µÄ²å¼þ£¬¸ÄΪ»á´´½¨Ò»¸öд×ÅpwnedÎĵµµÄÎı¾ÐÂÎŵIJå¼þ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


½ØÖ¹±¾Îİ䲼ǰ£¬UCä¯ÀÀÆ÷¹Ù·½»¹Î´½¨¸´´ËÎÊÌ⣬½¨ÒéÓû§ÁÙʱ¾¡Á¿Ô¤·ÀʹÓÃUCä¯ÀÀÆ÷£¬²¢ÔÚ¹Ù·½°ä²¼¸üк󣬾¡¿ìÉý¼¶½øÐн¨¸´¡£


²Î¿¼Á´½Ó


https://news.drweb.com/show/?lng=en&i=13176
https://thehackernews.com/2019/03/uc-browser-android-hacking.html