¶¥¼â´ó¿§ÔƼ¯±±¾©£¬µÚÆß½ì¶«É­Æ½Ì¨ADLab³¤ÀÏ»áÀֳɾٰì

Ðû²¼Ê±¼ä 2020-11-02

11ÔµĵÚÒ»Ì죬ÎÒÃÇϲӭµÚÆß½ì¶«É­Æ½Ì¨ADLabÄþ¾²É³Áú£¬¼¸Ê®Î»ADLab³¤ÀÏÃÇ´Ó¸÷µØ¸ÏÀ´£¬¹²¾ÛÒ»Ìã¬ÅäºÏ̽ÌÖÇ°ÑØ¼¼ÊõÇ÷ÊÆÓëÐÐÒµ¶¯Ì¬£¬·ÖÏí×îм¼ÊõÑо¿½á¹ûÓë˼·¡£ÔÚÀÏÓÑÖØ·êºÍ21ÖÜÄê¼ÍÄîµÄϲÔÃÆø·ÕÏ£¬ÁÐ볤ÀÏÃÇ»ý¼«·¢ÑÔ£¬ÈÈÁÒµÄÌÖÂÛÓë½»Á÷£¬²»Í£µØÅöײ³öеÄÖǻۻ𻨡£


1.jpg


ADLabµÄ½á¹ûÀë²»¿ªÃ¿Ò»Î»¡°³¤ÀÏ¡±µÄÖ§¸¶£¡


2.png


¶«É­Æ½Ì¨ÖúÀí×ܲá¢ADLab¼¼ÊõÂôÁ¦ÈËÖìÇ®º¼¿ªÄ»Ö´ǣº¡°½ñÄêÊÇµÚÆß½ìADLab³¤ÀϻᣬÕâЩÄêÀ´ADLabÒ»Ö±ÖÂÁ¦ÓÚ´Ù½øÑ§Êõ½»Á÷¡¢ÅàÑøÍøÂçÄþ¾²¼¼ÊõÈ˲Å£¬ÏÖÔÚ¹æÄ£Ò²ÈÕÒæ×³´ó£¬ËùÓÐÈ¡µÃµÄÕâЩ½á¹ûÒ²Àë²»¿ªADLabÔø¾­ÓëÏÖÔÚµÄÐֵܽãÃÃÃÇÿһ·ÝÐÁÇÚµÄÖ§¸¶£¬ÔÚÕâÀïлл¸÷ÈË£¡¡±


ÕâЩ¡°´ó¿§¡±×ö¼¼Êõ·ÖÏí


3.jpg


À´×ÔADLabµÄ¼¼Êõר¼ÒdwfaultÎ§ÈÆ¡¶JavaScriptÒýÇæÂ©¶´ÍÚ¾òÖ®Âá·½øÐзÖÏí£¬Ïêϸ½éÉÜÁËÁ½ÖÖ¾ßÓдú±íÐÔµÄÈô¸ÉÔ­´´Â©¶´£º


1¡¢CVE-2020-0768 IE/Edge ChakraCoreÒýÇæJIT©¶´


2¡¢CVE-2019-0607/6201/8583 WebKit/Safari JavaScriptCoreÒýÇæ  WebAssembly ÀàÐÍ»ìÏý©¶´¡¢Edge ChakraCoreÒýÇæWebAssembly ÀàÐÍ»ìÏý©¶´


Õë¶ÔChakraCoreÒýÇæµÄJIT©¶´£¬dwfault½éÉÜÁË´ÓÄ£ºý²âÊÔµ½Íß½âµ÷ÊÔµ½·ÖÎö³ö»ù´¡Ô­ÒòµÄÍêÕû¹ý³Ì£¬ÆäÖÐ×ÅÖØÌåÏÖ©¶´µ÷ÊÔÖеĸú×ٺͻØËݵÄÅÓ´óÐÔ¡£WebAssembly©¶´Öк¬ÓÐÒ»¸öSafari/Edgeä¯ÀÀÆ÷µÄ¡°Ë«É±¡±£¬Õë¶ÔÕâЩ©¶´Ôò¼òÃ÷ËùÔÚ³ö±¾ÖʳÉÒòºÍÀûÓÃÒªÁ죬Ҳ½éÉÜÁËͨ¹ýÀ©Õ¹Â©¶´Ä£Ê½ÍÚ¾òÏàËÆÂ©¶´µÄ˼·¡£


4.jpg


¼¼Êõ´ó¿§crowlÎ§ÈÆ¡¶½©Ê¬ÃÛÍø¡ª¡ªÐÂÐÍÎïÁªÍø½©Ê¬ÍøÂçÄ£Ð͵ķ¢ÏÖÓë̽ÌÖ¡·×öÑݽ²·ÖÏí£¬Ëû´Ó»Ø¹Ë½©Ê¬ÍøÂçÉú̬µÄÑݱäÓëÉú³¤£¬µ½ÈçºÎ·¢ÏÖ½©Ê¬ÃÛÍø£¬ÏêϸÂÛÊöÁËÕâÖÖÄ£Ð͵ÄÌØµãºÍÍþв£¬²¢½áºÏ½©Ê¬ÃÛÍøµÄ°¸Àý½øÐÐÁ˾ßÌå·ÖÎö¡£


ËûÌåÏÖ£¬Ëæ×Ž©Ê¬ÍøÂç¹¥·À·´¿¹µÄ²»Í£Éý¼¶£¬ÎÒÃÇÍŶӷ¢ÏÖÁËÒ»ÖÖÄܹ»²¶×½ÆäËü·Ç·¨·Ö×Ó¹¥»÷×ÊÔ´¡¢¾ß±¸ÓÕ²¶ºÍÆÛÆ­ÌØÐÔµÄÐÂÐͽ©Ê¬ÍøÂ磬ÒòΪÕâÖÖÌØÐÔºÍÃÛ¹ÞÊ®·ÖÏàËÆ£¬Òò´ËÎÒÃǽ«ÆäÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£Ëü¿ÉÒÔÔÚÔ­ÓзǷ¨·Ö×Ó×ÊÔ´µÄ»ù´¡ÉÏÌṩ¸ü¿ìµÄÇ鱨·´Ó³ÄÜÁ¦£¬ÊµÏÖÈëÇÖ×ÊÔ´µÄ¿ìËÙ¼¯ÖкÍÎäÆ÷»¯£¬crowlÈÏΪ½©Ê¬ÃÛÍøÎ´À´ÓпÉÄÜ»á³ÉΪ½©Ê¬ÍøÂçÈëÇÖµÄÐÂÇ÷ÊÆ¡£


5.jpg


¼¼ÊõÑо¿×¨¼ÒÁº±ò½ÌÊÚÒÔ¡¶µçÈÝÆÁÊÖ»úÓÎÏ·ÊÖ±úµÄ¼ì²â¡·ÎªÖ÷Ìâ¸ø¸÷ÈË´øÀ´ÁËÒ»³¡¾«²Ê·×³ÊµÄÑݽ²£¬Áº½ÌÊÚ¼°ÆäºÏ×÷Õßͨ¹ý¶ÔµçÈÝÊÖ±úÊÂÇéÔ­Àí½øÐзÖÎö£¬Ìá³öÁËÒ»ÖÖ»ùÓÚìØÖµ·ÖÎöºÍ͹½çÏÞʶ´ËÍâµçÈÝÊÖ±ú¼ì²âÒªÁ졣ͨ¹ýÕæÊµÓÎÏ·ÖеÄʵÑ飬֤Ã÷Á˸ÃÒªÁì¿ÉÒÔÓÐЧµØ¼ì²â³öÎÞÇý¶¯¡¢ÎÞÁ´½Ó¡¢¼´²å¼´ÓõĵçÈÝÊÖ±ú£¬Äܹ»µ½´ïά»¤ÊÖ»úÓÎÏ·µÄ¹«ÕýÐÔµÄÄ¿µÄ¡£


Free talk»·½ÚÓë»á³¤ÀÏÃÇ»ý¼«ÌÖÂÛ


6.jpg


ADLab³¤ÀÏ»á³ÉÔ±´óÅË̸µ½£º¡°Î´À´Á½ÈýÄêÊǹ¤Òµ´ó±ä¾ÖµÄ½Úµã£¬ADLabÔÚ¶«É­Æ½Ì¨¾ßÓоÙ×ãÇáÖØ¡¢¾ö¶¨ÐÔµÄְλ£¬Ï£ÍûADLabδÀ´»áÇý¶¯¶«É­Æ½Ì¨×ߵĸüºÃ¡¢¸üÔ¶¡£¡±


7.png


нú³¤ÀÏËïÞ±ÌåÏÖ£º¡°ºÜÈÙÐÒ½ñÄêÈÙÉýΪ³¤ÀÏ»áµÄÒ»Ô±£¬ÎÒÃÇËù´ÓʵÄÍøÂçÄþ¾²Ñо¿£¬ÊµÖÊÉÏÒ²ÊÇÈËÓëÈË¡¢¼¼ÊõÓë¼¼Êõ¡¢Ë¼Î¬Óë˼άµÄ·´¿¹£¬ÓÐÈ˵ĵط½¾Í»áÓйÊÊ£¬ÓÈÆäÊÇÔÚÎÒÃÇÍøÂçÄþ¾²ÁìÓò£¬ÓÀÔ¶»áÓÐеĹÊÊÂÉÏÑÝ£¬¸÷È˶¼ÊÇÕâ¸öÎę̀ÉϵÄÖ÷½Ç£¬·Ç³£ÆÚ´ýδÀ´¸÷È˶ÔÕⳡ¹ÊʵÄÑÝÒï¡£¡±


´Ó1999Ä꽨Á¢ÖÁ½ñ£¬21ÄêµÄËêÔÂÖУ¬ADLabÒ²ÂúÔØÈÙÓþ£¬Ë¶¹ûÀÛÀÛ£¬×÷ΪÖйú×îÔçµÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒ¡¢Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±¡¢¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕߣ¬½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´900Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼£¬Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


21ÄêµÄÁ÷½ðËêÔ£¬ADLabµÄ³ÉÔ±ÃÇÒ²ÓÃËûÃǵÄÇà´ºÆ×дADLabµÄ»ªÀöƪÕ¡£Ëæ×ÅÍøÂçÄþ¾²ÐÐÒµµÄÉú³¤£¬´Ó¶«É­Æ½Ì¨ADLab×ß³öÁËÒ»ÖÚ´ó¿§£¬ÎÞÂÛÊÇ×ÔÁ¢ÃÅ»§»¹ÊÇÒµÄÚ×ÊÉîר¼Ò£¬Ã¿Ò»ÄêÁÐ볤ÀÏÃǶ¼ÊпçÔ½¾àÀ룬Ïà¾ÛÒ»Æð¸ÐÊÜÀÏÓÑÖØ·êµÄϲÔÃÓëÃÀºÃ£¬Ò»Æð·ÖÏíǰհµÄ¼¼ÊõÑо¿ÓëÍ»ÆÆ£¬³äʵ¸ÐÊܼ¼ÊõµÄ÷ÈÁ¦£¬ÏàÐŶ«É­Æ½Ì¨ADLab³¤ÀÏ»áµÄ¸÷ÈËÍ¥»á²»Í£¸øÍøÂçÄþ¾²ÐÐÒµ×¢ÈëÐÂÏʵÄѪҺ£¬Áìµ¼ÍøÂçÄþ¾²ÐÐÒµ×ßÏò¸ü¸ßÔ¶µÄδÀ´£¡