1
gtar 2014-11-10 01:50:46 +08:00
我最近电脑也是百度先到7do什么的,会不会跟7do.net也有点关系?
|
3
so898 2014-11-10 02:01:07 +08:00 1
连上xcode检查iPhone上安装的证书方可查看是否感染
不过现在苹果已经在根服务器上把WireLurker的相关证书都给deactive了,所以不会存在什么问题了 越狱的话需要检查是否存在sfbase.dylib文件 |
4
Claud 2014-11-10 03:06:34 +08:00 4
@konakona 你好,我是PANW的Claud Xiao。关于这个变种和iPhone的问题,能否直接和我联系?我们一起看看是怎么回事。
我的邮箱是 [email protected] (可以在Github或者LinkedIn看到这个地址)。 谢谢啦! |
6
ReSur 2014-11-10 07:48:29 +08:00 via Android
比较在意那个官网下载的MAMP是怎么回事
|
7
66beta 2014-11-10 09:35:43 +08:00
MAMP官网都带?
还好我用的XAMPP,楼主快来XAMPP的怀抱吧 |
9
typcn 2014-11-10 09:38:01 +08:00 via iPhone
还好我是自己配的环境
|
10
duoglas 2014-11-10 10:10:55 +08:00
|
11
hitsmaxft 2014-11-10 10:13:18 +08:00
补一句吧, 让别人越狱, 还是商家, 这也太不小心了.
|
12
revival83 2014-11-10 10:24:48 +08:00
不越狱也会中招吗
|
13
c0878 2014-11-10 10:35:20 +08:00
手机还原掉自己越狱吧
|
14
tedd 2014-11-10 10:43:44 +08:00 via iPhone
怎么检测mac有中呢?
|
15
braineo 2014-11-10 10:55:39 +08:00
|
17
yanke 2014-11-10 11:53:47 +08:00
一段时间之前,某天手机突然多了一个企业分发的游戏。当时觉得不对劲。
后来装10.10抹盘了,再也木有查出来过了。 |
18
Showfom 2014-11-10 11:57:48 +08:00
我也中招 nnd
|
19
DXpro 2014-11-10 12:17:32 +08:00
Your OS X system isn't infected by the WireLurker. Thank you!
|
20
jiongjionger 2014-11-10 13:12:15 +08:00
怎么检测是否中招?我也是用的MAMP = =
|
21
bullettrain1433 2014-11-10 15:01:40 +08:00
@DXpro 请问用的什么检测
|
22
musicx 2014-11-10 15:12:54 +08:00
|
23
jiongjionger 2014-11-10 15:45:45 +08:00
= =我也中招
|
24
bullettrain1433 2014-11-10 16:51:22 +08:00
@musicx Your OS X system isn't infected by the WireLurker. Thank you! 谢谢
|
26
braineo 2014-11-10 17:21:12 +08:00 1
@duoglas 有说啊,认真看看。越狱后的就把一个sfbase的文件删掉,未越狱的就去把不知名的profile删掉。越狱后的iOS因为可以会在app里植入木马,看看发行商对不对得上。未越狱的把企业部署的奇怪的APP删了就好了
|
27
duoglas 2014-11-10 17:30:00 +08:00
@braineo 果然 刚才没看仔细 , 谢谢~!
Remediation If WireLurker is found on any OS X computer, we recommend the deletion of respective files and removal of applications reported by the script. As of the publication date of this report, the iOS component of WireLurker is only spread through an infected Mac computer; accordingly, if WireLurker is found on a Mac, we recommend inspection of all iOS devices that have connected with that computer. A quick check for iOS devices includes determining whether any unauthorized enterprise provisioning profiles were created by navigating to “Settings -> General -> Profile”. If an anomalous profile is found, it should be removed and a subsequent check of all applications should be performed. Delete any strange applications found on the device. For jailbroken devices, we recommend that you check whether the file “/Library/MobileSubstrate/DynamicLibraries/sfbase.dylib” exists. If so, you should delete it through a terminal connection, via an application like MobileTerminal or Secure Shell (SSH). |
28
gtar 2014-11-10 20:21:46 +08:00
[+] Your OS X system isn't infected by the WireLurker. Thank you!
https://github.com/PaloAltoNetworks-BD/WireLurkerDetector |
29
aaron2go 2014-11-10 21:10:08 +08:00
以前我还专门去找这个麦客孤独的D版软件。。。。现在我基本全换成正版了。。太恐怖了
|
32
xieguobihaha 2014-11-11 19:23:07 +08:00 via iPhone
中招已修复;-)
|
34
dotpig 2014-11-15 13:30:49 +08:00
@zeroday 用 xcode 查看删除(或者 iPhone Configuration Utility 也可以)。如果没有越狱的话,删不删那个证书无所谓,因为已经被苹果屏蔽了。
|
35
zeroday 2014-11-15 23:14:37 +08:00
|