中國利用iphone 漏洞監控維吾爾族 - 手機討論

By Hedy
at 2019-09-02T03:16
at 2019-09-02T03:16
Table of Contents
※ [本文轉錄自 iOS 看板 #1TR1Z1Fv ]
作者: kyle5241 (Kyle Korver) 看板: iOS
標題: [情報]中國利用iphone 漏洞監控維吾爾族
時間: Mon Sep 2 03:15:10 2019
情報來源:
https://www.inside.com.tw/article/17391-google-iphone-secretly-hacked
iPhone 最安全?Google:iPhone 早已被惡意網站入侵多年
以為拿 iPhone 就不用擔心資安嗎?Google 資安研究員發現,有不少惡意網站透過尚未
公開的軟體漏洞悄悄入侵 iPhone,目前已有不知情受害者造訪這些惡意網站數千次,時
間至少長達兩年。
根據 TechCrunch 報導,Google 資安團隊 Project Zero 日前發佈一篇文章,指出駭客
先入侵這些網站,之後當 iPhone 使用者造訪這些網站時,就會發送惡意軟體,甚至在手
機裡植入監控程式。
研究人員發現 5 個不同的漏洞利用鏈(exploit chain),從 iOS 10 到 iOS 12 版本都
有,這些利用鏈涉及了 12 種不同的安全漏洞。其中,有 7 個安全漏洞與 iPhone 內建
的網頁瀏覽器 Safari 有關。
這 5 個攻擊鏈讓駭客擁有 iPhone 設備最高等級的「Root」權限,代表駭客可以在使用
者不知情、甚至不同意的情況下,悄悄在手機裡安裝惡意程式,並監視使用者的手機行為
。
他們可以做什麼事呢?駭客可以竊取使用者手機裡的照片和訊息、跟蹤手機目前的即時定
位資訊,甚至還能獲取使用者在手機上儲存的各個密碼。
https://9to5mac.com/2019/09/01/china-iphone-attack-uyghur-muslims/
這些漏洞的可能使用者:
Report: China used iPhone website exploit attacks to target Uyghur Muslims
中國利用iphone的網路漏洞攻擊維吾爾族
A few days ago, Google Project Zero security researchers detailed a chain of
malicious website exploits targeting iPhone users. Now, TechCrunch reports
that the Chinese government used these attacks to target Uyghur Muslims.
之前google 發現了iphone史上最大的漏洞,現在發生這是被中國用來鎖定維吾爾族
Citing sources familiar with the matter, TechCrunch says that the malicious
websites used to hack into iPhones, first detailed by Google, were part of a
“state-backed attack,” likely from China, designed to “target the Uyghur
community in the country’s Xinjiang state.”
The report goes on to detail that according to United Nations data, Beijing
has detained “more than 1 million Uyghurs in internment camps” over the
last year.
Google researchers first explained that the victims were tricked into opening
a link which would direct them to an infected webpage. On that webpage, the
malware was deployed. The implant “primarily focused on stealing files and
uploading live location data,” as often as every 60 seconds. Because the end
device itself had been compromised, services like iMessage were also
affected, researchers said.
受害者只要按下連結就會跳到被感染的網頁,那個網頁會植入不良程式。接下來
這個程式每60秒就會傳送你的位置和你的檔案
When Google security researchers first detailed this attack, it was unclear
who it was specifically targeting. TechCrunch’s report now provides more
detail on that.
The websites were part of a campaign to target the religious group by
infecting an iPhone with malicious code simply by visiting a booby-trapped
web page. In gaining unfettered access to the iPhone’s software, an attacker
could read a victim’s messages, passwords, and track their location in
near-real time.
當iphone被感染了,它們就可以擁有你軟體的權限,讀你的訊息、密碼和位置
The report adds that the websites in question would also infect non-Uyghurs
who happened to visit the infected website. The domains were indexed in
Google search results, which made it relatively easy for anyone to stumble
upon them.
當然這個網站是可以被google到的,所以這是個無差別攻擊,所有人都會被監控
心得:
認為iphone很安全不會中毒而隨便亂按網站的,還是不要亂按了~
之前以色列也這樣監控別人的iphone
--
作者: kyle5241 (Kyle Korver) 看板: iOS
標題: [情報]中國利用iphone 漏洞監控維吾爾族
時間: Mon Sep 2 03:15:10 2019
情報來源:
https://www.inside.com.tw/article/17391-google-iphone-secretly-hacked
iPhone 最安全?Google:iPhone 早已被惡意網站入侵多年
以為拿 iPhone 就不用擔心資安嗎?Google 資安研究員發現,有不少惡意網站透過尚未
公開的軟體漏洞悄悄入侵 iPhone,目前已有不知情受害者造訪這些惡意網站數千次,時
間至少長達兩年。
根據 TechCrunch 報導,Google 資安團隊 Project Zero 日前發佈一篇文章,指出駭客
先入侵這些網站,之後當 iPhone 使用者造訪這些網站時,就會發送惡意軟體,甚至在手
機裡植入監控程式。
研究人員發現 5 個不同的漏洞利用鏈(exploit chain),從 iOS 10 到 iOS 12 版本都
有,這些利用鏈涉及了 12 種不同的安全漏洞。其中,有 7 個安全漏洞與 iPhone 內建
的網頁瀏覽器 Safari 有關。
這 5 個攻擊鏈讓駭客擁有 iPhone 設備最高等級的「Root」權限,代表駭客可以在使用
者不知情、甚至不同意的情況下,悄悄在手機裡安裝惡意程式,並監視使用者的手機行為
。
他們可以做什麼事呢?駭客可以竊取使用者手機裡的照片和訊息、跟蹤手機目前的即時定
位資訊,甚至還能獲取使用者在手機上儲存的各個密碼。
https://9to5mac.com/2019/09/01/china-iphone-attack-uyghur-muslims/
這些漏洞的可能使用者:
Report: China used iPhone website exploit attacks to target Uyghur Muslims
中國利用iphone的網路漏洞攻擊維吾爾族
A few days ago, Google Project Zero security researchers detailed a chain of
malicious website exploits targeting iPhone users. Now, TechCrunch reports
that the Chinese government used these attacks to target Uyghur Muslims.
之前google 發現了iphone史上最大的漏洞,現在發生這是被中國用來鎖定維吾爾族
Citing sources familiar with the matter, TechCrunch says that the malicious
websites used to hack into iPhones, first detailed by Google, were part of a
“state-backed attack,” likely from China, designed to “target the Uyghur
community in the country’s Xinjiang state.”
The report goes on to detail that according to United Nations data, Beijing
has detained “more than 1 million Uyghurs in internment camps” over the
last year.
Google researchers first explained that the victims were tricked into opening
a link which would direct them to an infected webpage. On that webpage, the
malware was deployed. The implant “primarily focused on stealing files and
uploading live location data,” as often as every 60 seconds. Because the end
device itself had been compromised, services like iMessage were also
affected, researchers said.
受害者只要按下連結就會跳到被感染的網頁,那個網頁會植入不良程式。接下來
這個程式每60秒就會傳送你的位置和你的檔案
When Google security researchers first detailed this attack, it was unclear
who it was specifically targeting. TechCrunch’s report now provides more
detail on that.
The websites were part of a campaign to target the religious group by
infecting an iPhone with malicious code simply by visiting a booby-trapped
web page. In gaining unfettered access to the iPhone’s software, an attacker
could read a victim’s messages, passwords, and track their location in
near-real time.
當iphone被感染了,它們就可以擁有你軟體的權限,讀你的訊息、密碼和位置
The report adds that the websites in question would also infect non-Uyghurs
who happened to visit the infected website. The domains were indexed in
Google search results, which made it relatively easy for anyone to stumble
upon them.
當然這個網站是可以被google到的,所以這是個無差別攻擊,所有人都會被監控
心得:
認為iphone很安全不會中毒而隨便亂按網站的,還是不要亂按了~
之前以色列也這樣監控別人的iphone
--
Tags:
手機
All Comments

By Megan
at 2019-09-02T11:39
at 2019-09-02T11:39

By Bethany
at 2019-09-02T20:03
at 2019-09-02T20:03

By Steve
at 2019-09-03T04:26
at 2019-09-03T04:26

By Quintina
at 2019-09-03T12:49
at 2019-09-03T12:49

By Steve
at 2019-09-03T21:13
at 2019-09-03T21:13

By Kumar
at 2019-09-04T05:36
at 2019-09-04T05:36

By Jacob
at 2019-09-04T13:59
at 2019-09-04T13:59

By Annie
at 2019-09-04T22:23
at 2019-09-04T22:23

By Eartha
at 2019-09-05T06:46
at 2019-09-05T06:46

By Zanna
at 2019-09-05T15:09
at 2019-09-05T15:09

By Olive
at 2019-09-05T23:33
at 2019-09-05T23:33

By Catherine
at 2019-09-06T07:56
at 2019-09-06T07:56

By Barb Cronin
at 2019-09-06T16:19
at 2019-09-06T16:19

By Anonymous
at 2019-09-07T00:43
at 2019-09-07T00:43

By Daph Bay
at 2019-09-07T09:06
at 2019-09-07T09:06

By Caitlin
at 2019-09-07T17:29
at 2019-09-07T17:29

By Regina
at 2019-09-08T01:53
at 2019-09-08T01:53

By Suhail Hany
at 2019-09-08T10:16
at 2019-09-08T10:16

By Christine
at 2019-09-08T18:39
at 2019-09-08T18:39

By Lauren
at 2019-09-09T03:03
at 2019-09-09T03:03

By Doris
at 2019-09-09T11:26
at 2019-09-09T11:26

By Elizabeth
at 2019-09-09T19:49
at 2019-09-09T19:49

By Genevieve
at 2019-09-10T04:13
at 2019-09-10T04:13

By Dorothy
at 2019-09-10T12:36
at 2019-09-10T12:36

By Andrew
at 2019-09-10T20:59
at 2019-09-10T20:59

By Hamiltion
at 2019-09-11T05:23
at 2019-09-11T05:23

By Delia
at 2019-09-11T13:46
at 2019-09-11T13:46

By Agatha
at 2019-09-11T22:09
at 2019-09-11T22:09

By Audriana
at 2019-09-12T06:33
at 2019-09-12T06:33

By Freda
at 2019-09-12T14:56
at 2019-09-12T14:56

By Skylar DavisLinda
at 2019-09-12T23:19
at 2019-09-12T23:19

By Doris
at 2019-09-13T07:43
at 2019-09-13T07:43

By Barb Cronin
at 2019-09-13T16:06
at 2019-09-13T16:06

By Harry
at 2019-09-14T00:29
at 2019-09-14T00:29

By Ethan
at 2019-09-14T08:53
at 2019-09-14T08:53

By Elizabeth
at 2019-09-14T17:16
at 2019-09-14T17:16

By Sierra Rose
at 2019-09-15T01:39
at 2019-09-15T01:39

By Mia
at 2019-09-15T10:03
at 2019-09-15T10:03

By Hazel
at 2019-09-15T18:26
at 2019-09-15T18:26

By Victoria
at 2019-09-16T02:49
at 2019-09-16T02:49

By Jack
at 2019-09-16T11:13
at 2019-09-16T11:13

By Bennie
at 2019-09-16T19:36
at 2019-09-16T19:36

By Ina
at 2019-09-17T03:59
at 2019-09-17T03:59

By Selena
at 2019-09-17T12:23
at 2019-09-17T12:23

By Kama
at 2019-09-17T20:46
at 2019-09-17T20:46

By Rebecca
at 2019-09-18T05:09
at 2019-09-18T05:09

By Aaliyah
at 2019-09-18T13:33
at 2019-09-18T13:33

By Ida
at 2019-09-18T21:56
at 2019-09-18T21:56

By Connor
at 2019-09-19T06:19
at 2019-09-19T06:19

By Oscar
at 2019-09-19T14:43
at 2019-09-19T14:43

By Dorothy
at 2019-09-19T23:06
at 2019-09-19T23:06

By Thomas
at 2019-09-20T07:29
at 2019-09-20T07:29

By Xanthe
at 2019-09-20T15:53
at 2019-09-20T15:53

By Brianna
at 2019-09-21T00:16
at 2019-09-21T00:16

By Odelette
at 2019-09-21T08:39
at 2019-09-21T08:39

By Queena
at 2019-09-21T17:03
at 2019-09-21T17:03

By Victoria
at 2019-09-22T01:26
at 2019-09-22T01:26

By William
at 2019-09-22T09:49
at 2019-09-22T09:49

By Daph Bay
at 2019-09-22T18:13
at 2019-09-22T18:13

By Blanche
at 2019-09-23T02:36
at 2019-09-23T02:36

By John
at 2019-09-23T10:59
at 2019-09-23T10:59

By Daph Bay
at 2019-09-23T19:23
at 2019-09-23T19:23

By Heather
at 2019-09-24T03:46
at 2019-09-24T03:46

By Connor
at 2019-09-24T12:09
at 2019-09-24T12:09

By Adele
at 2019-09-24T20:33
at 2019-09-24T20:33

By Rachel
at 2019-09-25T04:56
at 2019-09-25T04:56

By Kelly
at 2019-09-25T13:19
at 2019-09-25T13:19

By Barb Cronin
at 2019-09-25T21:43
at 2019-09-25T21:43

By Caroline
at 2019-09-26T06:06
at 2019-09-26T06:06

By Ophelia
at 2019-09-26T14:29
at 2019-09-26T14:29

By Mason
at 2019-09-26T22:53
at 2019-09-26T22:53

By Susan
at 2019-09-27T07:16
at 2019-09-27T07:16

By Oliver
at 2019-09-27T15:39
at 2019-09-27T15:39

By Ursula
at 2019-09-28T00:03
at 2019-09-28T00:03

By Susan
at 2019-09-28T08:26
at 2019-09-28T08:26
Related Posts
A50/Xperia 10/或其他

By Christine
at 2019-09-02T02:21
at 2019-09-02T02:21
XZ2 V40 S10e S10 Note10+

By John
at 2019-09-02T01:25
at 2019-09-02T01:25
科技美學 2016 vs 2019 新老旗艦對比

By Madame
at 2019-09-02T00:59
at 2019-09-02T00:59
我的U Ultra掛了

By Yuri
at 2019-09-02T00:51
at 2019-09-02T00:51
oppo Reno 10x怎麼那麼冷門

By Bennie
at 2019-09-02T00:12
at 2019-09-02T00:12