2020考研双语阅读:iOS系统的漏洞
2019.09.23 11:25

  坚持英语阅读是考研英语拿高分必须要做的一件事情。新东方在线考研网整理了一些与考研英语阅读同源文章,供同学们阅读,希望对大家有所帮助。

  加入新东方外语考试交流群,获取更多考研英语资料。新东方外语考试交流群

  考研英语双语阅读:iOS系统的漏洞

  Google's Threat Analysis Group (TAG) has published a blog post detailing a number of exploitsin iOS that allowed hacked websites to hack into an iPhone simply if the iPhone visited the site.

  谷歌威胁分析小组(TAG)在博客上详细介绍了一些iOS上的漏洞,iPhone只要访问被黑客入侵的网站,这些网站就能轻易黑进iPhone。

  Once an iPhone did that, malware was installed on the device that allowed the hackers tomonitor the iPhone's live location every 60 seconds as well as upload virtually any files from theiPhone—including iMessage and WhatsApp messages.

  iPhone一旦访问这些网站,就会被安装恶意软件,黑客每隔60秒就能监控iPhone的实时位置,还可以从iPhone上上传任何文件,包括iMessage和WhatsApp的信息。

  TAG says the exploit "may be one of the largest attacks against iPhone users ever." Itreportedly affected iPhones running iOS 10 to iOS 12:

  威胁分析小组称这个漏洞“可能是目前针对iPhone用户最大的一个威胁”,据称它会影响iPhone iOS 10到iOS12的每个版本。

  Working with TAG, we discovered exploits for a total of fourteen vulnerabilities across the fiveexploit chains: seven for the iPhone's web browser, five for the kernel and two separatesandbox escapes. Initial analysis indicated that at least one of the privilege escalationchains was still 0-day and unpatched at the time of discovery.

  我们和威胁分析小组合作发现五个攻击链中共有14个漏洞:其中7个针对iPhone的网络浏览器、5个针对内核,还有2个独立的沙箱逃逸。初步分析表明特权升级链中至少有一个仍然是零日漏洞(指被发现后立即被恶意利用的安全漏洞),而且发现以后没有进行修复。

  There is some good news, however. First, an iPhone user had to visit one of the hackedwebsites in order for their iPhone to be infected. TAG did not specify which websites werehacked, but their report says the sites received "thousands of visitors per week," suggesting thesites received relatively minor traffic relative to the number of iPhones in the wild.

  但也有好消息。首先iPhone用户需要访问一个被黑的网站才会被攻击,威胁分析小组并未具体说明哪些网站被黑了,但报告中称这些网站“每周有数千访问者”,相比iPhone的使用量来说这些网站的访问量只是很小一部分。

  Further, even if the malware made it onto an iPhone, when a user restarted their iPhone, themalware would be wiped clean in most instances. Of course, news of any exploits in iOS isn'tgood—no matter how few users were impacted.

  而且即使iPhone被安装了恶意软件,在大多数情况下用户重启手机后恶意软件都会被清理干净。当然任何关于iOS漏洞的消息都不是好消息,即使受影响人数很少。

  The good news is that Apple acted quickly once TAG alerted them to the exploits. TAG says itcontacted Apple about the exploits on February 1, 2019, and Apple fixed all of the exploits justsix days later with the release of iOS 12.1.4 on February 7, 2019.

  好消息是威胁分析小组一提醒苹果公司漏洞的问题,他们就立刻采取了行动,威胁分析小组称在2019年2月1日就漏洞问题联系了苹果公司,该公司仅用6天就修复了所有漏洞,在2019年2月7日发布了iOS 12.1.4。

MORE+

    相关阅读 MORE+

    版权及免责声明
    1.凡本网注明"稿件来源:新东方在线"的所有文字、图片和音视频稿件,版权均属北京新东方迅程网络科技有限公司所有,任何媒体、网站或个人未经本网协议授权不得转载、链接、转贴或以其他方式复制发表。已经本网协议授权的媒体、网站,在下载使用时必须注明"稿件来源:新东方在线",违者本网将依法追究责任。
    2.本网末注明"稿件来源:新东方在线"的文/图等稿件均为转载稿,本网转载出于传递更多信息之目的,并不意味着赞同其观点或证实其内容的真实性。如其他媒体、网站或个人从本网下载使用,必须保留本网注明的"稿件来源",并自负版权等法律责任。如擅自篡改为"稿件来源:新东方在线”,本网将依法追究责任。
    3.如本网转载稿涉及版权等问题,请作者致信weisen@xdfzx.com,我们将及时外理

    Copyright © 2011-202

    All Rights Reserved