¶¥¼â´ó¿§ÔƼ¯±±¾© £¬µÚÆ߽춶ȦΪ¶Ä¶øÉúADLab³¤ÀÏ»áÀֳɾٰì

Ðû²¼Ê±¼ä 2020-11-02

11ÔµĵÚÒ»Ìì £¬ÎÒÃÇϲӭµÚÆ߽춶ȦΪ¶Ä¶øÉúADLabÄþ¾²É³Áú £¬¼¸Ê®Î»ADLab³¤ÀÏÃÇ´Ó¸÷µØ¸ÏÀ´ £¬¹²¾ÛÒ»Ìà £¬ÅäºÏ̽ÌÖÇ°Ñؼ¼ÊõÇ÷ÊÆÓëÐÐÒµ¶¯Ì¬ £¬·ÖÏí×îм¼ÊõÑо¿½á¹ûÓë˼·¡£ÔÚÀÏÓÑÖØ·êºÍ21ÖÜÄê¼ÍÄîµÄϲÔÃÆø·ÕÏ £¬ÁÐ볤ÀÏÃÇ»ý¼«·¢ÑÔ £¬ÈÈÁÒµÄÌÖÂÛÓë½»Á÷ £¬²»Í£µØÅöײ³öеÄÖǻۻ𻨡£


1.jpg


ADLabµÄ½á¹ûÀë²»¿ªÃ¿Ò»Î»¡°³¤ÀÏ¡±µÄÖ§¸¶£¡


2.png


¶¶È¦Îª¶Ä¶øÉúÖúÀí×ܲá¢ADLab¼¼ÊõÂôÁ¦ÈËÖìÇ®º¼¿ªÄ»Ö´ǣº¡°½ñÄêÊǵÚÆß½ìADLab³¤ÀÏ»á £¬ÕâЩÄêÀ´ADLabÒ»Ö±ÖÂÁ¦ÓÚ´Ù½øѧÊõ½»Á÷¡¢ÅàÑøÍøÂçÄþ¾²¼¼ÊõÈ˲Š£¬ÏÖÔÚ¹æÄ£Ò²ÈÕÒæ׳´ó £¬ËùÓÐÈ¡µÃµÄÕâЩ½á¹ûÒ²Àë²»¿ªADLabÔø¾­ÓëÏÖÔÚµÄÐֵܽãÃÃÃÇÿһ·ÝÐÁÇÚµÄÖ§¸¶ £¬ÔÚÕâÀïлл¸÷ÈË£¡¡±


ÕâЩ¡°´ó¿§¡±×ö¼¼Êõ·ÖÏí


3.jpg


À´×ÔADLabµÄ¼¼Êõר¼ÒdwfaultΧÈÆ¡¶JavaScriptÒýÇ橶´ÍÚ¾òÖ®Âá·½øÐзÖÏí £¬Ïêϸ½éÉÜÁËÁ½ÖÖ¾ßÓдú±íÐÔµÄÈô¸ÉÔ­´´Â©¶´£º


1¡¢CVE-2020-0768 IE/Edge ChakraCoreÒýÇæJIT©¶´


2¡¢CVE-2019-0607/6201/8583 WebKit/Safari JavaScriptCoreÒýÇæ  WebAssembly ÀàÐÍ»ìÏý©¶´¡¢Edge ChakraCoreÒýÇæWebAssembly ÀàÐÍ»ìÏý©¶´


Õë¶ÔChakraCoreÒýÇæµÄJIT©¶´ £¬dwfault½éÉÜÁË´ÓÄ£ºý²âÊÔµ½Íß½âµ÷ÊÔµ½·ÖÎö³ö»ù´¡Ô­ÒòµÄÍêÕû¹ý³Ì £¬ÆäÖÐ×ÅÖØÌåÏÖ©¶´µ÷ÊÔÖеĸú×ٺͻØËݵÄÅÓ´óÐÔ¡£WebAssembly©¶´Öк¬ÓÐÒ»¸öSafari/Edgeä¯ÀÀÆ÷µÄ¡°Ë«É±¡± £¬Õë¶ÔÕâЩ©¶´Ôò¼òÃ÷ËùÔÚ³ö±¾ÖʳÉÒòºÍÀûÓÃÒªÁì £¬Ò²½éÉÜÁËͨ¹ýÀ©Õ¹Â©¶´Ä£Ê½ÍÚ¾òÏàËÆ©¶´µÄ˼·¡£


4.jpg


¼¼Êõ´ó¿§crowlΧÈÆ¡¶½©Ê¬ÃÛÍø¡ª¡ªÐÂÐÍÎïÁªÍø½©Ê¬ÍøÂçÄ£Ð͵ķ¢ÏÖÓë̽ÌÖ¡·×öÑݽ²·ÖÏí £¬Ëû´Ó»Ø¹Ë½©Ê¬ÍøÂçÉú̬µÄÑݱäÓëÉú³¤ £¬µ½ÈçºÎ·¢ÏÖ½©Ê¬ÃÛÍø £¬ÏêϸÂÛÊöÁËÕâÖÖÄ£Ð͵ÄÌصãºÍÍþв £¬²¢½áºÏ½©Ê¬ÃÛÍøµÄ°¸Àý½øÐÐÁ˾ßÌå·ÖÎö¡£


ËûÌåÏÖ £¬Ëæ׎©Ê¬ÍøÂç¹¥·À·´¿¹µÄ²»Í£Éý¼¶ £¬ÎÒÃÇÍŶӷ¢ÏÖÁËÒ»ÖÖÄܹ»²¶×½ÆäËü·Ç·¨·Ö×Ó¹¥»÷×ÊÔ´¡¢¾ß±¸ÓÕ²¶ºÍÆÛÆ­ÌØÐÔµÄÐÂÐͽ©Ê¬ÍøÂç £¬ÒòΪÕâÖÖÌØÐÔºÍÃÛ¹ÞÊ®·ÖÏàËÆ £¬Òò´ËÎÒÃǽ«ÆäÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£Ëü¿ÉÒÔÔÚÔ­ÓзǷ¨·Ö×Ó×ÊÔ´µÄ»ù´¡ÉÏÌṩ¸ü¿ìµÄÇ鱨·´Ó³ÄÜÁ¦ £¬ÊµÏÖÈëÇÖ×ÊÔ´µÄ¿ìËÙ¼¯ÖкÍÎäÆ÷»¯ £¬crowlÈÏΪ½©Ê¬ÃÛÍøδÀ´ÓпÉÄÜ»á³ÉΪ½©Ê¬ÍøÂçÈëÇÖµÄÐÂÇ÷ÊÆ¡£


5.jpg


¼¼ÊõÑо¿×¨¼ÒÁº±ò½ÌÊÚÒÔ¡¶µçÈÝÆÁÊÖ»úÓÎÏ·ÊÖ±úµÄ¼ì²â¡·ÎªÖ÷Ìâ¸ø¸÷ÈË´øÀ´ÁËÒ»³¡¾«²Ê·×³ÊµÄÑݽ² £¬Áº½ÌÊÚ¼°ÆäºÏ×÷Õßͨ¹ý¶ÔµçÈÝÊÖ±úÊÂÇéÔ­Àí½øÐзÖÎö £¬Ìá³öÁËÒ»ÖÖ»ùÓÚìØÖµ·ÖÎöºÍ͹½çÏÞʶ´ËÍâµçÈÝÊÖ±ú¼ì²âÒªÁ졣ͨ¹ýÕæʵÓÎÏ·ÖеÄʵÑé £¬Ö¤Ã÷Á˸ÃÒªÁì¿ÉÒÔÓÐЧµØ¼ì²â³öÎÞÇý¶¯¡¢ÎÞÁ´½Ó¡¢¼´²å¼´ÓõĵçÈÝÊÖ±ú £¬Äܹ»µ½´ïά»¤ÊÖ»úÓÎÏ·µÄ¹«ÕýÐÔµÄÄ¿µÄ¡£


Free talk»·½ÚÓë»á³¤ÀÏÃÇ»ý¼«ÌÖÂÛ


6.jpg


ADLab³¤ÀÏ»á³ÉÔ±´óÅË̸µ½£º¡°Î´À´Á½ÈýÄêÊǹ¤Òµ´ó±ä¾ÖµÄ½Úµã £¬ADLabÔÚ¶¶È¦Îª¶Ä¶øÉú¾ßÓоÙ×ãÇáÖØ¡¢¾ö¶¨ÐÔµÄְλ £¬Ï£ÍûADLabδÀ´»áÇý¶¯¶¶È¦Îª¶Ä¶øÉú×ߵĸüºÃ¡¢¸üÔ¶¡£¡±


7.png


нú³¤ÀÏËïÞ±ÌåÏÖ£º¡°ºÜÈÙÐÒ½ñÄêÈÙÉýΪ³¤ÀÏ»áµÄÒ»Ô± £¬ÎÒÃÇËù´ÓʵÄÍøÂçÄþ¾²Ñо¿ £¬ÊµÖÊÉÏÒ²ÊÇÈËÓëÈË¡¢¼¼ÊõÓë¼¼Êõ¡¢Ë¼Î¬Óë˼άµÄ·´¿¹ £¬ÓÐÈ˵ĵط½¾Í»áÓйÊÊ £¬ÓÈÆäÊÇÔÚÎÒÃÇÍøÂçÄþ¾²ÁìÓò £¬ÓÀÔ¶»áÓÐеĹÊÊÂÉÏÑÝ £¬¸÷È˶¼ÊÇÕâ¸öÎę̀ÉϵÄÖ÷½Ç £¬·Ç³£ÆÚ´ýδÀ´¸÷È˶ÔÕⳡ¹ÊʵÄÑÝÒï¡£¡±


´Ó1999Ä꽨Á¢ÖÁ½ñ £¬21ÄêµÄËêÔÂÖÐ £¬ADLabÒ²ÂúÔØÈÙÓþ £¬Ë¶¹ûÀÛÀÛ £¬×÷ΪÖйú×îÔçµÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒ¡¢Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±¡¢¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß £¬½ØֹĿǰ £¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö £¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´900Óà¸ö £¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼ £¬Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


21ÄêµÄÁ÷½ðËêÔ £¬ADLabµÄ³ÉÔ±ÃÇÒ²ÓÃËûÃǵÄÇà´ºÆ×дADLabµÄ»ªÀöƪÕ¡£Ëæ×ÅÍøÂçÄþ¾²ÐÐÒµµÄÉú³¤ £¬´Ó¶¶È¦Îª¶Ä¶øÉúADLab×ß³öÁËÒ»ÖÚ´ó¿§ £¬ÎÞÂÛÊÇ×ÔÁ¢ÃÅ»§»¹ÊÇÒµÄÚ×ÊÉîר¼Ò £¬Ã¿Ò»ÄêÁÐ볤ÀÏÃǶ¼ÊпçÔ½¾àÀë £¬Ïà¾ÛÒ»Æð¸ÐÊÜÀÏÓÑÖØ·êµÄϲÔÃÓëÃÀºÃ £¬Ò»Æð·ÖÏíÇ°Õ°µÄ¼¼ÊõÑо¿ÓëÍ»ÆÆ £¬³äʵ¸ÐÊܼ¼ÊõµÄ÷ÈÁ¦ £¬ÏàÐŶ¶È¦Îª¶Ä¶øÉúADLab³¤ÀÏ»áµÄ¸÷ÈËÍ¥»á²»Í£¸øÍøÂçÄþ¾²ÐÐÒµ×¢ÈëÐÂÏʵÄѪҺ £¬Áìµ¼ÍøÂçÄþ¾²ÐÐÒµ×ßÏò¸ü¸ßÔ¶µÄδÀ´£¡