Board logo

标题: 苹果官方回应iCloud艳照事件:是针对账号的定点攻击与云服务漏洞无关 [打印本页]

作者: yeyehas    时间: 2014-9-3 12:21     标题: 苹果官方回应iCloud艳照事件:是针对账号的定点攻击与云服务漏洞无关

引用:
Apple Media Advisory
Update to Celebrity Photo Investigation

We wanted to provide an update to our investigation into the theft of photos of certain celebrities. When we learned of the theft, we were outraged and immediately mobilized Apple’s engineers to discover the source. Our customers’ privacy and security are of utmost importance to us. After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone. We are continuing to work with law enforcement to help identify the criminals involved.

To protect against this type of attack, we advise all users to always use a strong password and enable two-step verification. Both of these are addressed on our website at http://support.apple.com/kb/ht4232.
http://www.apple.com/pr/library/ ... Media-Advisory.html
作者: 分分钟叫你做人    时间: 2014-9-3 12:34

posted by wap, platform: HTC EVO 3D
简单说就是黑客想黑某人账号?跟偷QQ号是一回事吧?
作者: ffcactus    时间: 2014-9-3 13:13

引用:
原帖由 分分钟叫你做人 于 2014-9-3 12:34 发表
posted by wap, platform: HTC EVO 3D
简单说就是黑客想黑某人账号?跟偷QQ号是一回事吧?
黑客首先是获得了对方的ID, 然后提请重置密码, 然后黑客又成功猜到或得到了对方的安全问题答案等等的必要信息,而且客户又没有开启第二道防护,所以被盗。
作者: 小文    时间: 2014-9-3 13:18

posted by wap, platform: Chrome
用户密码太简单,被黑客轻易猜出是一方面
另一方面苹果系统漏洞允许无限次试密码也是不可推卸的。
作者: emmer    时间: 2014-9-3 13:21

引用:
原帖由 小文 于 2014-9-3 13:18 发表
posted by wap, platform: Chrome
用户密码太简单,被黑客轻易猜出是一方面
另一方面苹果系统漏洞允许无限次试密码也是不可推卸的。
可以无限次试密码?how?
作者: DeepSearchz    时间: 2014-9-3 13:21

引用:
原帖由 emmer 于 2014-9-3 13:21 发表

可以无限次试密码?how?
这个漏洞已经被封锁了

方法
https://github.com/hackappcom/ibrute/blob/master/id_brute.py

[ 本帖最后由 DeepSearchz 于 2014-9-3 15:43 编辑 ]
作者: 去日留痕    时间: 2014-9-3 13:23

posted by wap, platform: Firefox
悲剧了
作者: miomibuya    时间: 2014-9-3 13:29

posted by wap, platform: VIVO
引用:
原帖由 @小文  于 2014-9-3 13:18 发表
用户密码太简单,被黑客轻易猜出是一方面
另一方面苹果系统漏洞允许无限次试密码也是不可推卸的。
这个官方说明说了和之前find my phone api漏洞无限重试密码无关了

应该强制开启两步验证 避免这个问题
作者: 丹尼K    时间: 2014-9-3 14:28

posted by wap, platform: SONY 巨猴
反正安卓不安全。




欢迎光临 TGFC Lifestyle (http://bbs.tgfcer.com/) Powered by Discuz! 6.0.0