苹果iCloud在中国遭中间人攻击
中国当局对苹果的云服务iCloud发起中间人攻击(MITM)。此前,有调查显示,中国对Github、谷歌、雅虎和微软都发动了中间人攻击。此次对iCloud的中间人攻击,与此前对谷歌、Github和雅虎的攻击不同。此次对苹果的攻击,是为了盗取用户的登录名和密码,以及储存在iCloud上的所有数据,包括iMessage、照片、联络人等。
此次对苹果的攻击是全国性的,且发生在iPhone 6在中国开售首日(10月18日)。中国防火墙GFW正在通过一张假的安全证书,对苹果的iCloud发起中间人攻击。当局仅攻击了IP地址 23.59.94.46. 。并非中国大陆的所有用户都受到影响,因为iCloud的DNS服务器返回的IP地址可能不同。
此前对谷歌和雅虎的中间人攻击,中国当局从中获取了中国网民这两个平台上所获得的信息。此次对苹果的攻击中,如果用户忽视安全警告,直接点进苹果网站并输入用户名和密码,他们的登入信息将被当局获取。许多苹果用户使用iCloud来存储个人信息,包括iMessages,照片和联络人等。Greatfire推测,此次苹果受攻击,可能与香港占中的图像信息被分享到大陆有关。
iCloud #截图存档 伪造证书下载: http://t.co/iqGasmynMx pic.twitter.com/FHFAA1AKR2
— 陈少举 (@chenshaoju) October 19, 2014
用户要如何对抗此次攻击?
中国网民首先要在电脑和移动设备上使用可靠的浏览器:Firefox和Chrome在某网站遭中间人攻击时,都会阻止用户通向该网站。而奇虎360浏览器则没有安全防范,会直接打开受中间人攻击的网页。
如果用户忽略了安全提示,就应该使用不受干扰的方式来连接iCloud。用户可以通过VPN、或者不同的网络连接点,因为中国防火墙的中间人攻击并不稳定。用户还应该启用iCloud账户的两步认证法。这样,即使密码被盗取,iCloud账户也将受到保护。
Iphone加密系统升级惹恼中国?
最新的中间人攻击也可能与iPhone 6的安全措施升级有关。当新的苹果手机细节被公布之后,中国当局似乎不愿意新的iPhone在中国大陆发售。苹果为了防止NSA的窃听,升级了手机的加密功能。但这迫使中国当局无法窥视苹果用户的资料。iPhone 6可以正式在中国发售,不知苹果是否在中国改制了该手机的安全设置。但此次对iCloud的中间人攻击,似乎说明,中国当局与苹果在新手机的某些功能上有分歧。
苹果公司曾与中国当局有过一点暧昧的浪漫史,当中国当局要求苹果在其中国网店删除某些app时,苹果就范。因此,难以想象苹果高层对此次苹果受中国攻击有何感想。
此次攻击也给与积极配合中国审查要求的外国公司发出一个清晰的信号:协助当局审查网络并不能保证这些公司在中国财路通畅。相反,协助当局审查将被视为外国公司最糟糕的决定。不仅当局会反咬你一口,而且还将失去全球其他地方的客户。我们已要求苹果公司对此次攻击作出评论。
Technical evidence of attacks against iCloud.com (Apple) and login.live.com (Microsoft)
iCloud
The GFW (Great Firewall of China) is now wiretapping Apple’s iCloud. GFW implemented a MITM attack on iCloud using a self-signed certificate.
The authorities only attacked IP 23.59.94.46. Not all users in China are affected because the iCloud DNS might return different IP addresses.
Wirecapture with MITM: https://www.cloudshark.org/captures/03a6b0593436
Self-signed certificate used in the attack: http://www.mediafire.com/download/ampbnqncc277krv/fakeicloudcert.zip
Connection log: http://pastebin.com/tN7kbDV3
Traceroute: http://pastebin.com/8Y6ZwfzG
Hotmail MITM
Wirecap: https://www.cloudshark.org/captures/6011389a8ea3
TCP Traceroute: https://twitter.com/siyanmao/status/518963824481681408
评论
uk.yahoo.com is also giving untrusted certificate warnings at this present time.
I'm surprised they've used self-signed. Surely they could have issued certs through cnnic (www.cnnic.cn). Most browsers trust their CA. You can test your browser by going to Https://Evdemo.cnnic.cn
@Anonymous: Because if they did that, cnnic would definitely not be trusted anymore...
Pretty creepy, they don't mind being as obvious as this...and this 360 browser accepts self-signed certificates by default? Wow.
On the other hand, can we rule out that it was an attack not connected to the Chinese government? Were all DNS servers in China affected? Why would they stop the attack this quick (icloud goes to the right IP for me now and I use my provider's DNS servers)? Not that I would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...). Hmm when thinking about it, this poisoning must have been done through the GFW...any more detailed technical analysis available? Any official comments from CNNIC?
看我口型。操~~~他~~~妈~~~
Is the information obtained limited to iCloud users' data?
Is the information obtained limited to iCloud users' data?
inspired a lot from this post am following this blog regularly and found very good for bookmarking thanks admin
new year sms in hindi 2015
happy new year sms 2015
happy new year 2015 wallpapers
happy new year 2015 quotes
happy new year 2015
happy new year wishes 2015
This is really bad.Hope that steps will be taken in Year 2015 for better security.
Vry..Vry..Vry..Needful 4 my computer PPT....Thankxxx sooo much
Thanks a really nice post thanks for sharing.
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Republic Day 2015
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Republic Day 2015
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Happy Republic Day 2015 SMS
happy rose day sms
happy Chocolate day sms
Happy Valentines Day status
happy kiss day sms
McCoy does not shy from prevents and by most reports they
was a team participant with all the Eagles. and it has a huge amount of
has under his belt|it has a huge amount of carries under his belt and is 27 Your examination of the business and We agree generally, but the material about McCoyis
mindset and designed -the- problems is baloney.
Check out my web site: gift.ii-houyou.com (Jacob)
this post is awesome, great msg for us, plz update ur blog for daily basis, i am regular visitor of this site, so keep posting for us,
click the below links to create backlink
best free backlink website click here for msg movie
Paragraph writing is also a fun, if you know
then you can write otherwise it is complicated to write.
My website How To Seo Html (Http://Support.Semanticmastery.Com/)
thanks for this post, keep it up for updating us, i am waiting for ur new article.
IPL8 live stream 2015
thanks again
IPL Live Stream
IPL Live Score 2015
Mind Blowing.. post great work
PC Games
Thanks Great Share.
Technology
LinkedIn decided to create a China-hosted version ?
Tech Blog
this is great information. article is ol;d but information is great
http://www.surveyremoveronline.com/
this is great information. article is ol;d but information is great
http://www.surveyremoveronline.com/
its time to grow up now for the best world and info you'll got.
Facebook Hacker
Exclusive release first on Internet Fifa 16 Crack arrived. Try the latest version of our fifa crack today and impress all of your friends with amazing highscores rankings - free of charge.
We have spent months developing this crack so that you can generate an unlimited amount of free Points, Coins.
http://fifacrack.com/
Republic Day 2016 Images
http://festivalsbag.com/
Republic Day 2016 Images
http://festivalsbag.com/
Republic Day 2016 Images
http://festivalsbag.com/
On the other hand, can we rule out that it was an attack not connected to the Chinese government? Were all DNS servers in China affected? Why would they stop the attack this quick (icloud goes to the right IP for me now and I use my provider's DNS servers)? Not that
would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...). Hmm when thinking about it, this poisoning must have been done through the GFW...any more detailed technical analysis available? Any official comments from CNNIC http://www.sbnation.com/users/obatperangsang
is also giving untrusted certificate warnings at this present time. http://obatfrigid.com/obat-perangsang-pria.html
is also giving untrusted certificate warnings at this present time
http://toko-qta.com/
would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...
http://tokovital.com/obat-perangsang-wanita.html
would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly
https://www.sbnation.com/users/perangsangwanita
Berita Terkini ElangNews.com http://www.elangnews.com/
Nonton bola online streaming http://nobartv.com
Komunitas fans bola indonesia http://soccerio.net
thank you very much for the article, hopefully by reading this article can add to my knowledge and experience and all friends who have read the content in this article http://www.obatpengikatwanita.com/
Tanks Info
http://www.alatbantuseksualitas.org/
the application permits you making this examination on any kind of network, androdumpperr as well as run the installer data to comply with the setup directions.
Progression as it speeds with the DHL network. You'll Tracking to awaiting distributions that do not turn up as intended.
is also giving untrusted certificate warnings at this present time
http://www.tokomurah.id/
Progression as it speeds with the DHL network. You'll Tracking (http://www.tokomurah.id/obat-pelangsing-badan/) to awaiting distributions that do not turn up as intended.
Indeks berita bola terbaru hari ini pada NobarTV http://nobartv.com/index-berita/2018
Indeks jadwal streaming bola online hari ini di NobarTV http://nobartv.com/index-pertandingan/2018
Thank you for sharing the post. I didn't know that the Chinese authorities are now staging a man-in-the-middle (MITM) attack on Apple’s iCloud, Yooying where will they want to reach now, there were too many website and apps are blocked in China already.
Thanksa: https://www.behance.net/kaffahmedia
添加新评论