中國利用iphone 漏洞監控維吾爾族 - iOS
By Delia
at 2019-09-02T03:15
at 2019-09-02T03:15
Table of Contents
iPhone 最安全?Google:iPhone 早已被惡意網站入侵多年
以為拿 iPhone 就不用擔心資安嗎?Google 資安研究員發現,有不少惡意網站透過尚未
公開的軟體漏洞悄悄入侵 iPhone,目前已有不知情受害者造訪這些惡意網站數千次,時
根據 TechCrunch 報導,Google 資安團隊 Project Zero 日前發佈一篇文章,指出駭客
先入侵這些網站,之後當 iPhone 使用者造訪這些網站時,就會發送惡意軟體,甚至在手
研究人員發現 5 個不同的漏洞利用鏈(exploit chain),從 iOS 10 到 iOS 12 版本都
有,這些利用鏈涉及了 12 種不同的安全漏洞。其中,有 7 個安全漏洞與 iPhone 內建
的網頁瀏覽器 Safari 有關。
這 5 個攻擊鏈讓駭客擁有 iPhone 設備最高等級的「Root」權限,代表駭客可以在使用
Report: China used iPhone website exploit attacks to target Uyghur Muslims
A few days ago, Google Project Zero security researchers detailed a chain of
malicious website exploits targeting iPhone users. Now, TechCrunch reports
that the Chinese government used these attacks to target Uyghur Muslims.
之前google 發現了iphone史上最大的漏洞,現在發生這是被中國用來鎖定維吾爾族
Citing sources familiar with the matter, TechCrunch says that the malicious
websites used to hack into iPhones, first detailed by Google, were part of a
“state-backed attack,” likely from China, designed to “target the Uyghur
community in the country’s Xinjiang state.”
The report goes on to detail that according to United Nations data, Beijing
has detained “more than 1 million Uyghurs in internment camps” over the
last year.
Google researchers first explained that the victims were tricked into opening
a link which would direct them to an infected webpage. On that webpage, the
malware was deployed. The implant “primarily focused on stealing files and
uploading live location data,” as often as every 60 seconds. Because the end
device itself had been compromised, services like iMessage were also
affected, researchers said.
When Google security researchers first detailed this attack, it was unclear
who it was specifically targeting. TechCrunch’s report now provides more
detail on that.
The websites were part of a campaign to target the religious group by
infecting an iPhone with malicious code simply by visiting a booby-trapped
web page. In gaining unfettered access to the iPhone’s software, an attacker
could read a victim’s messages, passwords, and track their location in
near-real time.
The report adds that the websites in question would also infect non-Uyghurs
who happened to visit the infected website. The domains were indexed in
Google search results, which made it relatively easy for anyone to stumble
upon them.
All Comments
By Mia
at 2019-09-05T16:36
at 2019-09-05T16:36
By Blanche
at 2019-09-06T20:14
at 2019-09-06T20:14
By Christine
at 2019-09-06T21:21
at 2019-09-06T21:21
By Kristin
at 2019-09-09T23:32
at 2019-09-09T23:32
By Ivy
at 2019-09-13T21:15
at 2019-09-13T21:15
By Kristin
at 2019-09-15T14:30
at 2019-09-15T14:30
By Joe
at 2019-09-17T07:30
at 2019-09-17T07:30
By Faithe
at 2019-09-20T08:41
at 2019-09-20T08:41
By Mary
at 2019-09-24T01:48
at 2019-09-24T01:48
By Emily
at 2019-09-26T10:31
at 2019-09-26T10:31
By James
at 2019-09-30T19:43
at 2019-09-30T19:43
By Harry
at 2019-10-04T15:25
at 2019-10-04T15:25
By Jacky
at 2019-10-08T15:22
at 2019-10-08T15:22
By Aaliyah
at 2019-10-13T04:58
at 2019-10-13T04:58
By Kyle
at 2019-10-18T00:09
at 2019-10-18T00:09
By Dorothy
at 2019-10-18T07:21
at 2019-10-18T07:21
By Sarah
at 2019-10-20T02:14
at 2019-10-20T02:14
By Hamiltion
at 2019-10-21T04:53
at 2019-10-21T04:53
By Irma
at 2019-10-25T19:43
at 2019-10-25T19:43
By Ethan
at 2019-10-27T03:21
at 2019-10-27T03:21
By Irma
at 2019-10-27T23:12
at 2019-10-27T23:12
Related Posts
粉絲製 By invitation only 桌布
By Ingrid
at 2019-09-02T00:00
at 2019-09-02T00:00
剪片需求應該買哪個 iPad 規格?
By Jack
at 2019-09-01T22:43
at 2019-09-01T22:43
By Valerie
at 2019-09-01T22:21
at 2019-09-01T22:21
京站往台鐵樓梯撿到AirPods 左耳
By Victoria
at 2019-09-01T20:28
at 2019-09-01T20:28
Apple Watch 4 卡在管理介面
By David
at 2019-09-01T19:51
at 2019-09-01T19:51