lack H
at Mail vºÍDefconºÚ
¿Í´ó»áµÄÎå´ó¿
´µ
ã -
51CTO.COM Temps Blackmailedslave Szh Info Aspx N 20100315091153593513 Black Mail" href="http://temps.blackmailedslave.com/feed//szh/info.aspx?n=20100315091153593513" />
lack H
at Mail vºÍDefconºÚ
¿Í´ó»áµÄÎå´ó¿
´µ
ã -
51CTO.COM Temps Blackmailedslave Szh Info Aspx N 20100315091153593513 Black Mail
lack H
at Mail vºÍDefconºÚ
¿Í´ó»áµÄÎå´ó¿
´µ
ã -
51CTO.COM Temps Blackmailedslave Szh Info Aspx N 20100315091153593513 Black Mail2¡¢DNSSECÊÇ·ñÄܱ£DNSÍòÎÞһʧ£¿
Á½Äêǰ£¬Dan Kaminsky½Ò¶ÁËÈÃÊÀÈËÕ𾪵ÄDNS©¶´£¬Kaminsky½ñÄê»á¼ÌÐø³öÏÖÔÚBlack Hat´ó»áÉÏ£¬µ«Õâ´ÎµÄÑݽ²Ö÷Ìâ±ä³ÉÁËWeb°²È«¹¤¾ß£¬ËûÒ²½«²Î¼ÓÒ»³¡¼ÇÕßÕдý»á£¬½«ºÍÀ´×ÔICANNºÍVeriSignµÄ´ú±íÌÖÂÛDNS°²È«À©Õ¹£¨DNSSEC£©¡£
´óÔ¼Á½ÖÜǰ£¬ICANN²Å½«»¥ÁªÍø12̨DNS¸ù·þÎñÆ÷Íê³ÉDNSSECµÄ²¿Êð£¬Ä¿Ç°DNSSEC»¹Ã»Óеõ½¹ã·ºÖ§³Ö£¬ICANNÏ£Íûͨ¹ý×Ô¼ºµÄʵ¼ù£¬Íƶ¯ÕâÒ»¼¼ÊõµÄÆÕ¼°¡£
Kaminsky±íʾÆÕ¼°DNSSEC½«ÓÐЧ¶ôÖÆÍøÂç¹¥»÷£¬Ëû˵£º“ÎÒÃÇÕýÔÚÑо¿ÈçºÎÈÃDNSSEC²»½ö¿ÉÒÔ½â¾öDNS©¶´£¬»¹ÒªÈÃËü½â¾öһЩºËÐÄ©¶´£¬µ±È»£¬DNSSEC²»Äܽâ¾öËùÓÐÎÊÌ⣬µ«Ëü½â¾öÁËÉí·ÝÑéÖ¤Ïà¹ØµÄÈ«²¿Â©¶´”¡£
£¨ÒëÕßÂÒÆÀ£ºDNSSECÄܶžøDNSÎÛȾÂ𣿼ÓÃÜËÑË÷ºÎʱÄܲÅÄÜÓÃÉÏ£¡£©
3¡¢Òƶ¯bug£¬ÆÕͨÈËÒ²ÄÜÍæÇÔÌý
GSM°²È«Ñо¿ÈËÔ±½ñÄ꽫³öÏÖÔÚBlack HatµÄÑݽ²Ì¨ÉÏ£¬Õâ¿ÉÄÜÊÇÃÀ¹úºÍÅ·ÖÞÒÆ¶¯ÍøÂçÔËÓªÉÌ×î²»Ïë¿´µ½µÄ£¬KrakenÊǸոշųöµÄ¿ªÔ´GSMÆÆ½âÈí¼þ£¬½áºÏ¸ß¶ÈÓÅ»¯µÄ²Êºç±í£¨rainbow table£©£¬ÈýâÃÜGSMͨ»°ºÍ¶ÌÏûÏ¢³ÉΪһ¼þÒ×Ê¡£
KrakenËù×öµÄ¾ÍÊǼàÌý¿ÕÆøÖеÄͨ»°£¬ÁíÍ⻹ÓÐÒ»¸öGSMÐá̽ÏîÄ¿ – AirProbe£¬Ê¹ÓÃÕâЩ¹¤¾ßµÄÑо¿ÈËԱ˵ËûÃÇÏÖÔÚÏ뽫ÕâЩ¼¼ÊõÕ¹ÏÖ¸øÆÕͨÈË£¬¶ø¶ÔÓÚÄÇЩ¼äµýºÍ°²È«°®ºÃÕßÔçÒѲ»ÊÇÊ²Ã´ÃØÃÜÁË£¬A5/1¼ÓÃÜËã·¨ÏÖÔÚ¿ÉÒÔÇáËÉÆÆ½â£¬¶øT-Mobile£¬AT&TµÈÔËÓªÉ̵ÄGSMÍøÂçÕýÊÇʹÓÃÁËÕâ¸ö¼ÓÃÜËã·¨¡£
Chris Paget½«×öÕâ·½ÃæµÄÖ÷ÌâÑݽ²£¬Ëû½«»áÔÚ´ó»áÉÏÏÖ³¡ÑÝʾÀ¹½ØÌýÖÚµÄͨ»°£¨µ±È»µÃµ½ÑûÇëµÄÌýÖÚÊǺÜÐÒÔ˵쬵«»Ø¼Òºó¿ÉÄÜÒ²»á×½ÃþÊÇ·ñÒª½«ÊÖ»úÈÓ½øÀ¬»øÍ°£©£¬Èç¹ûºÏ·¨µÄ»°£¬Õ⽫ÊÇÒ»¸öÓÐȤµÄÑÝʾ£¬Paget»¹¿ª·¢³öÁËËû³Æ×÷“ÊÀ½ç¼Í¼”µÄRFID±êÇ©ÔĶÁÆ÷£¬¿ÉÒÔÔÚ¼¸°ÙÃ×Ô¶¶ÁÈ¡µ½RFID±êÇ©ÐÅÏ¢£¬ÔÚ±¾´ÎBlack HatÉÏËûÒ²»á¾Í´Ë×öһЩÌÖÂÛ¡£
ÁíһλÑо¿ÈËÔ±Grugq½«»áÑݽ²ÈçºÎ¹¹½¨¶ñÒâGSMÍøÂç»ùÕ¾ºÍÒÆ¶¯É豸ÉϵÄ×é¼þ£¬ËûµÄÑݽ²Ö÷ÌâÃèÊöдµÀ£º“ÏàÐÅÎÒÃÇ£¬ÔÚÑݽ²ÆÚ¼äÄã»áÓйصôÊÖ»úµÄÏë·¨”¡£
ÁíÒ»¸öÖµµÃ¹Ø×¢µÄÑݽ²ÓëÒÆ¶¯Ó¦ÓóÌÐò¹¥»÷Óйأ¬Ëæ×ÅÖÇÄÜÊÖ»úµÄÆÕ¼°£¬Òƶ¯Ó¦Óð²È«ÎÊÌâÒ²°ÚÔÚÁËÊÀÈ˵ÄÃæÇ°£¬²»Òª´æÔÚ½ÄÐÒÐÄÀí£¬ÌýÁ˸ÃÖ÷ÌâÑݽ²µÄÈËÒ»¶¨»á½÷É÷ʹÓÃÒÆ¶¯Ó¦ÓóÌÐòµÄ¡£
£¨ÒëÕßÂÒÆÀ£ºÒÔºó´òµç»°Ð¡Éùµã£¬ÊDz»ÊDZðÈ˾ÍÇÔÌý²»µ½ÁË£¿ÖØÒªÊÂÇ黹Êǵ±ÃæÌ¸±È½ÏÎÈÍ×°¡£¡£©
4¡¢³ýÁËIT¿ÉÒÔHack£¬¹¤ÒµÁìÓòÒ²¿ÉÒÔ
Î÷ÃÅ×Ó±¾ÔÂÊ״γ¢µ½ÁËSCADA£¨supervisory control and data acquisition£©±»¹¥»÷µÄ×Ì棬Æä»ùÓÚWindowsµÄ¹ÜÀíϵͳÊܵ½Á˹îÒìµÄÈ䳿¹¥»÷£¬µ«Ò²ÓÐSCADA°²È«×¨¼ÒÈÏΪÊÇÎ÷ÃÅ×ÓµÄÔËÆø²»ºÃ£¬ÒòΪÕâÖÖ¹¥»÷¿ÉÒÔÇáÒ×ÄÃÏÂÈκξºÕù¶ÔÊֵIJúÆ·£¬ÊÂʵÉÏ£¬ºÜ¶à¹¤Òµ¿ØÖÆÏµÍ³¶¼´æÔÚ´óÁ¿µÄ°²È«ÎÊÌâ¡£
ÔÚ¹ýÈ¥µÄ10ÄêÀºì»¢£¨Red Tiger£©°²È«¹«Ë¾´´Ê¼ÈËJonathan PolletÒѾÔÚ³¬¹ý120¸öSCADAϵͳÉÏÖ´ÐÐÁ˰²È«ÆÀ¹À£¬Ëû½«ÔÚÑݽ²ÖÐÖ¸³öÄÄЩµØ·½ÊÇ×îÈÝÒ׳öÏÖ°²È«Â©¶´µÄ¡£ºì»¢ÒѾÊÕ¼¯ÁË38000¸ö©¶´Êý¾Ý£¬²¢ÇÒ±àдÁËÕë¶ÔÕâЩ©¶´µÄ¹¥»÷´úÂ룬Pollet˵£º“Äã²»±ØµÈ´ýÁãÈÕ©¶´£¬ÏÖÔÚÒѾÓкܶà©¶´ÔÚÄÇÀï°Ú×Å”¡£
£¨ÒëÕßÂÒÆÀ£ºÉñ°¡£¬¸øÎÒÒ»´®´úÂë°É£¬ÎҼҵĵç±í¶ÁÊýÀÏÊǾӸ߲»ÏÂѽ£¡£©
5¡¢»òÐí»áÓÐÒâÍ⣬³äÂúѹÁ¦µÄºÚ¿Í´ó»á
ÔÚÉÏÖܺڵôÁËKevin MitnickºÍDan KaminskyµÈÆäËûºÚ¿ÍµÄZero for OwnedС×é»á»Øµ½Black HatÂð£¿AT&T»á×èÖ¹Paget¹ØÓÚGSM©¶´µÄÑݽ²Â𣿷ßŵÄATM³§ÉÌ»áÔÚ×îºóÒ»·ÖÖÓÓ÷¨ÂÉÊÖ¶Î×èÖ¹Barnaby JackµÄÑݽ²Âð£¿DefconµÄÉç»á¹¤³Ì¾ºÈü»áÈýðÈÚ·þÎñÐÐÒµµÄÈË×¥¿ñÂð£¿Ë˵µÃÇåÄØ£¬ÒòΪÀ˹ά¼Ó˹×ÜÊÇÒ»¸ö³äÂúÒâÍâµÄµØ·½¡£
£¨ÒëÕßÂÒÆÀ£º¿´À´Ã¿¸öÐÐÒµ¶¼ÓкܴóµÄѼÀæ°¡£¬Ï£ÍûÕâÒ»½ìÁ½»á²»»á·ÅÎÒÃǸë×Ó£¡£©
¡¾±à¼ÍƼö¡¿