High Sierra 安全隐患: 应用程序可以访问钥匙串并收集密码 - V2EX
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
Chingim
V2EX    Apple

High Sierra 安全隐患: 应用程序可以访问钥匙串并收集密码

  •  
  •   Chingim Sep 26, 2017 4464 views
    This topic created in 3136 days ago, the information mentioned may be changed or developed.

    Patrick Wardle, Synack ’ s head of research, posted a video on Monday that shows how code he wrote can be used to get passwords from macOS ’ s Keychain. Keychain is the password manger built into macOS, and it usually requires a master password to access it. But Wardle ’ s code was able to access Keychain and collect passwords.

    source

    13 replies    2017-09-26 17:11:24 +08:00
    0xcb
        1
    0xcb  
       Sep 26, 2017 via Android
    之前版本都可以的啊,只要你授权管理员帐户,dump keychain 简单的很
    Chingim
       2
    Chingim  
    OP
       Sep 26, 2017
    @0xcb 不用授权
    bkmi
        3
    bkmi  
       Sep 26, 2017 via Android
    按理说这应该是个大新闻,但是竟然没人关注的,神奇神奇
    Chingim
        4
    Chingim  
    OP
       Sep 26, 2017
    @bkmi macOS 的关注度是没有 iOS 的高, 大家普遍更加关注升 iOS 11 卡不卡, 耗电有没有增加.
    bkmi
        5
    bkmi  
       Sep 26, 2017 via Android
    @Chingim 首页还一堆讨论升级的呢
    tairan2006
        6
    tairan2006  
       Sep 26, 2017
    …这个很严重啊,还升什么级。。
    usedname
        7
    usedname  
       Sep 26, 2017
    这个 bug 没人关注?
    BearD01001
        8
    BearD01001  
       Sep 26, 2017
    持续关注...
    NVDA
        9
    NVDA  
       Sep 26, 2017
    看到了,原作者说给 Apple 发邮件了但是没有回应,我也好奇这明明就是个大新闻为什么没人发...
    wuhao930301
        10
    wuhao930301  
       Sep 26, 2017
    手动关注。为什么 Beta 版的时候没曝出来,是正式版才有的 bug 么
    Chingim
        11
    Chingim  
    OP
       Sep 26, 2017
    @wuhao930301 小人之心地不负责任地推断, 这漏洞估计早就发现了, 就等苹果发布正式版吧
    onevcat
        12
    onevcat  
       Sep 26, 2017
    https://twitter.com/patrickwardle/status/912254053849079808

    这个吧?看起来是一直就有的吧,作者也说“ other versions of macOS are vulnerable too ”

    只有 unsign app 能干这事儿,没签名或者签名不对的 app 别用就是了..
    warking
        13
    warking  
       Sep 26, 2017
    Correction: The exploit affects other macOS versions too, including the latest High Sierra, but is not specific to the latter only. Apple has actually fixed a number of critical security flaws with macOS 10.13 making it an important update.

    http://wccftech.com/macos-high-sierra-hackers-steal-passwords/
    About     Help     Advertise     Blog     API     FAQ     Solana     6043 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 156ms UTC 02:04 PVG 10:04 LAX 19:04 JFK 22:04
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86