找回密碼
 註冊
查看: 2168|回覆: 17

[OS X軟件] iOS用Wifi者, 必需立即取 安全更新- 严重程度 9.8/10 [轉...

    [複製鏈接]
簽到
2910
發表於 2017-7-24 04:43:35 | 顯示全部樓層 |閱讀模式

登入後,內容更豐富

您需要 登錄 才可以下載或查看,沒有賬號?註冊

×
本帖最後由 jgyjgw 於 2017-7-24 04:47 編輯 1 F+ O) A. ^3 Z& ^2 o8 M, g, e
& P1 F  @7 [6 C- I3 p$ @
如你 iOS 用 Wifi, 必需立即取security update安全更新 10.3.3 -- Broadpwn 严重程度 9.8/10,  [轉載,英文] -  待板主大佬翻译吧? 6 N3 M0 M6 l: n5 v

  p  J9 D# P- e4 G. TIf you use Wi-Fi on your iOS device, get this security update -- Apple released the update on Wednesday to stop an exploit that targeted open Wi-Fi signals- S0 L* z3 ]$ l1 r* x
8 Z/ }+ x; F8 a* P7 m
BY ALFRED NG  JULY 19, 2017 1:06 PM PDT
+ b; f/ w# k3 n+ X1 a+ M+ r/ Y! Bhttps://www.cnet.com/news/apple- ... -ios-hack-broadpwn/8 w6 k+ V5 W2 Y; W3 S& M5 L- \- ?
5 X4 F/ _4 ^1 |  ]( k6 f# f
Apple released a security patch on Wednesday that you should really consider updating to if you enjoy using Wi-Fi on your iOS devices.
& Z- p" c9 D0 k& U# q% R/ q' d
So, you know, just about everybody should update.% R6 L) w- O/ r4 ^- {/ O. Q

. }) S. j4 i2 eThe iOS 10.3.3 update addresses vulnerabilities with your Contacts, Messages, Notifications, Safari and other issues. One of the more potentially damaging exploits was hidden in the iPhone's Wi-Fi chipset, where an attacker could take over a device remotely if it was searching for a signal.
% C3 Y3 z  `8 t% n+ _
: v" N* t/ z/ i, ~& T# xHackers are constantly looking for vulnerabilities in systems, and outdated devices make for an easy target. Just look at how many old computers the WannaCry ransomware attack was able to take advantage of. Companies like Microsoft, Google and Apple can release updates to fix their flaws, but it doesn't matter if people aren't downloading them.2 h8 r/ P+ ]( E8 W. ~8 N" s
: e4 g; l7 w! {& [% h
For this Wi-Fi-based attack, you'll want to upgrade. If your iOS device has its Wi-Fi turned on, attackers in range could find your device, remotely take over its Wi-Fi chip and crash your phone.
9 b* q$ M7 }. [2 h4 g6 Y, O  N' ?. b0 Y8 q$ f! [, _1 p1 }! L2 ^
This is the Broadpwn exploit, which Google patched for Android devices on July 5, listing it as a critical security flaw. It affected a broad range of devices from companies like HTC, LG and Samsung. The attack doesn't need your device's PIN or password to exploit the weakness.4 ]5 |6 s. S# i3 s& s& \

3 [& y$ K1 l. G5 f, e4 @9 N" bOn the US's National Institute of Standards and Technology severity scale, Broadpwn scored a 9.8 out of 10.. {- Y* H2 q0 C- T) H( P
3 E. ^( S- @! l/ g5 U" d  }2 q
Apple said the vulnerability it patched affected the iPhone 5 to iPhone 7, the fourth-generation iPad and later versions, and the iPod Touch 6th generation.& x3 Q( _5 t- h" r3 m
, S6 H& X# l% ^# W2 D
Nitay Artenstein, a security researcher at Exodus Intelligence, discovered the exploit and will be providing more details about his findings at a Black Hat presentation in Las Vegas on July 27.
 樓主| 發表於 2017-7-24 04:49:58 | 顯示全部樓層
iPhone, iPad owners: Update now to block 'Broadpwn' Wi-Fi hack4 ?/ o7 _5 b, b  g  B
http://www.zdnet.com/article/iph ... roadpwn-wi-fi-hack/9 K/ @$ c/ F; a
Apple has used an update to iOS 10 to fix a potentially dangerous Wi-Fi bug affecting most of its hardware.2 U7 c( k+ P' q
By Liam Tung | July 20, 2017 -- 09:38 GMT (02:38 PDT) | Topic: Security! K4 h3 V  Y9 _* n6 A+ r
4 N3 [  I* N* L  u* J! b: W' G
Apple has updated iOS 10 to fix 47 security flaws, including one that can be used to hack iPhones and iPads within Wi-Fi range.. X; c- \& T& t% G
It's hard to hack iOS without relying on user interaction, but it can still be done by attacking a softer target: the Wi-Fi chip in most iOS devices, as well as Android mobiles.
7 Z& @2 ?  {" b! O
: s: B5 A4 \# J+ L. y5 UApple's latest iOS update, version 10.3.3, addresses yet another critical bug in the Broadcom43xx Wi-Fi chipset on the iPhone.
2 P; K0 T, ~3 [2 T, t# o; E- i: t# d5 F* ^( B- i
The vulnerability, known as 'Broadpwn' (CVE-2017-9417), was discovered by researcher Nitay Artenstein of Exodus Intelligence. He'll detail his hack at the Black Hat conference in August and explain how to move from controlling the chip to hacking the main OS.# _0 L9 M, E& s' o

: K: K; E9 L$ I+ d# `Google patched the same issue in its July Android update, which according to Artenstein also affects devices from LG, Google's Nexus phones, and nearly all Samsung flagships.5 l4 C( T9 j6 c6 B9 t- D
2 o" H8 _6 I7 b; Q2 h* _' H
Google's Project Zero researchers, who have also investigated the chipset, believe hackers are likely to target it as an easier entry point than flaws in the better defended OS or apps.( s; s- M& s- }9 z9 ~

" L; r( [  ?6 fApple patched a similar Broadcom Wi-Fi bug found by Project Zero in iOS 10.3.1 this April.- H; k6 ~0 m8 E; X
+ l9 }7 E4 \. Z
Apple says the latest memory corruption exploit allows an attacker within Wi-Fi range to execute attack code on the Wi-Fi chip.
7 q2 ?* G! p2 G; ?
9 a% Y$ U5 q8 E" W; J6 D  ~3 TThe iPhone maker fixed 46 other flaws in its latest update, including a handful of bugs in the iOS kernel, Safari, and its WebKit browser engine.- z- b+ y! J* t! a6 O) }1 R
  ?) M8 y# J' H1 _! M( e
The Broadpwn bug also affects Mac hardware, Apple TV, and Apple Watch. Apple fixed the issue for Macs in the macOS Sierra 10.12.6 update, and updates for TVos, and watchOS.& C7 R$ O3 ?; U; p+ m: k* m! X( O7 Q

9 D% ]8 B8 r3 `8 }6 q$ g1 rApple's macOS update fixes 37 bugs and 25 bugs in Safari for macOS.
  Z2 `6 g& C; A5 [: X
+ `$ q2 `2 ]' a) gFeature-wise, iOS 10.3.3 offers little, and it may be one of the final updates before iOS 11's arrival in fall.
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 04:59:48 | 顯示全部樓層
Thank you for sharing, I am not an apple fans.
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 06:32:54 | 顯示全部樓層
Shutdown wifi connection when you don't need to use it.
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 07:45:01 | 顯示全部樓層
An important update indeed for Apple users
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 07:47:35 | 顯示全部樓層
Apple fans be careful
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 09:18:12 | 顯示全部樓層
提示: 作者被禁止或刪除 內容自動屏蔽
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-24 21:56:56 | 顯示全部樓層
又是駭客攻擊事件
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-25 16:13:27 | 顯示全部樓層
回復 jgyjgw #1 的帖子
6 W% C, w  k2 L3 E
+ y% L8 f2 R: d, p  r/ x4 PAdnroid未有fix喎?
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-25 22:36:21 | 顯示全部樓層
& M2 d$ R; O; T6 k
Apple fans be careful
回覆 讚好 不讚 使用道具

舉報

 樓主| 發表於 2017-7-26 00:22:36 | 顯示全部樓層
5 z( Q! [2 J1 E/ V6 L5 X, `% q
https://source.android.com/security/bulletin/2017-07-01
) p  V5 \8 u  u$ @) F1 ?8 ^$ [' ~. r" E
Android Security Bulletin—July 2017
' s0 d6 O, O( L6 p9 J( j; a' s+ }& V9 a" z' o" z% c# j# t
Published July 5, 2017 | Updated July 6, 2017# G# ]8 \- }5 h% k/ z9 Q
5 _. u% E# L- K; E1 {
The Android Security Bulletin contains details of security vulnerabilities affecting Android devices. Security patch levels of July 05, 2017 or later address all of these issues. Refer to the Pixel and Nexus update schedule to learn how to check a device's security patch level.
* Y% a+ F  y# l+ `! r" m) }$ s' y) S, C" i
Partners were notified of the issues described in the bulletin at least a month ago. Source code patches for these issues have been released to the Android Open Source Project (AOSP) repository and linked from this bulletin. This bulletin also includes links to patches outside of AOSP.6 g# I9 b% h9 k) X+ l' s/ x: z
0 y5 G( V* U+ {" @+ L4 F2 X; v
The most severe of these issues is a critical security vulnerability in media framework that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process. The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed., H: o" I2 s% l) }$ @" s+ a: ]
4 ~( b( i; A5 ?- C
We have had no reports of active customer exploitation or abuse of these newly reported issues. Refer to the Android and Google Play Protect mitigations section for details on the Android security platform protections and Google Play Protect, which improve the security of the Android platform.
, ?; p2 m4 H4 i4 }
; Y" h- Q; _4 m1 N4 _We encourage all customers to accept these updates to their devices.
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-26 10:54:35 | 顯示全部樓層
nice info !!!!
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-26 11:38:48 | 顯示全部樓層
多謝資訊
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-27 00:58:55 | 顯示全部樓層
實用資訉
回覆 讚好 不讚 使用道具

舉報

發表於 2017-7-29 10:36:50 | 顯示全部樓層
beckham3 發表於 2017-7-25 16:13 & t! Q8 e  m$ J. w9 S
回復 jgyjgw #1 的帖子% p2 `% v$ i) Q- z
  _& I/ K  L3 b
Adnroid未有fix喎?

2 \  W  {! x6 J4 m( _  R* o! V4 K小米出左, 昨日有更新
回覆 讚好 不讚 使用道具

舉報

發表於 2017-8-1 10:10:20 | 顯示全部樓層
咁大錯誤架,快D減價啦。
回覆 讚好 不讚 使用道具

舉報

發表於 2017-8-7 14:11:03 | 顯示全部樓層
一直在最新版本便安全
回覆 讚好 不讚 使用道具

舉報

發表於 2017-8-9 01:52:22 | 顯示全部樓層
真是要小心啊
回覆 讚好 不讚 使用道具

舉報

您需要登錄後才可以回帖 登錄 | 註冊

本版積分規則

Archiver|聯絡我們|141華人社區

GMT+8, 2024-4-25 02:12

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

快速回覆 返回頂部 返回列表