V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
est

今天闹得沸沸扬扬的 XCodeGhost,微信 6.2.5 也中招了!还有就是 盗走 22 万 icloud 信息的红包插件也中了这次的 init.icloud-analysis.com

  •  1
     
  •   est · Sep 18, 2015 · 4900 views
    This topic created in 3877 days ago, the information mentioned may be changed or developed.
    http://www.freebuf.com/articles/terminal/78808.html

    好消息是目前微信版本是6.2.6了。。。我好奇鹅厂是怎么发现并修正这个问题的?换XCode?不太可能吧。。。。
    7 replies    2015-09-19 18:32:37 +08:00
    hoogle
        1
    hoogle  
       Sep 19, 2015
    可能最新一个包用 Xcode 7 提的吧。。 发布会上苹果演示有微信,也可能提前开发适配 iOS 9 的。。
    bitinn
        2
    bitinn  
       Sep 19, 2015
    The important question to ask is: how is it possible to have only a certain version affected by this trojan? Is there a sudden urge to get a copy of Xcode during that period? How long has this bug been around?
    est
        3
    est  
    OP
       Sep 19, 2015
    @bitinn That's exactly what I thought. What triggered the sudden change of XCode for this version 6.2.6 inside Tencent?

    Also CNCERT knows this issue way earlier than everyone else http://www.cert.org.cn/publish/main/12/2015/20150914152821158428128/20150914152821158428128_.html
    wanliang1221
        5
    wanliang1221  
       Sep 19, 2015
    作为开发者,要下个 Android SDK 你告诉我不百度不迅雷如何下?
    lawder
        6
    lawder  
       Sep 19, 2015
    @hoogle 看这里应该是鹅厂自己无意中发现的 http://security.tencent.com/index.php/blog/msg/96
    est
        7
    est  
    OP
       Sep 19, 2015
    @lawder 对。今天发现了。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   941 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 39ms · UTC 19:00 · PVG 03:00 · LAX 12:00 · JFK 15:00
    ♥ Do have faith in what you're doing.