Hongbo's profile真实的ertPhotosBlogListsMore ![]() | Help |
|
June 12 对绿坝的安全漏洞分析 by UMich看到一个对国产软件绿坝的安全漏洞分析。我没有时间翻译这篇分析文章,不过可以看出来的总结就是 We examined the Green Dam software and found that it contains serious security vulnerabilities due to programming errors. Once Green Dam is installed, any web site the user visits can exploit these problems to take control of the computer. This could allow malicious sites to steal private data, send spam, or enlist the computer in a botnet. In addition, we found vulnerabilities in the way Green Dam processes blacklist updates that could allow the software makers or others to install malicious code during the update process. We found these problems with less than 12 hours of testing, and we believe they may be only the tip of the iceberg. Green Dam makes frequent use of unsafe and outdated programming practices that likely introduce numerous other vulnerabilities. Correcting these problems will require extensive changes to the software and careful retesting. In the meantime, we recommend that users protect themselves by uninstalling Green Dam immediately. 这是一个有着严重安全漏洞的软件。如果被强制安装在每一台家用电脑上,那么后果将是所有的安装该软件的电脑都会成为高潜质的被控制僵尸电脑。病毒网站可以利用这些漏洞而控制主机,窃取数据。另外升级过程将会给人提供插入恶意代码的机会。并且这个检查只是在12个小时内测试的结果,可以相信如果经过更多时间的分析,更多的问题将会被发现。这款软件需要更长时间的测试和修正才能被使用。所有的用户应该立即卸载该软件。 |
|
|