¶¥¼â´ó¿§ÔƼ¯±±¾©£¬µÚÆß½ì×ðÁú¿­Ê±ADLab³¤ÀÏ»áÀֳɾÙÐÐ

Ðû²¼Ê±¼ä 2020-11-02

11ÔµĵÚÒ»Ì죬ÎÒÃÇϲӭµÚÆß½ì×ðÁú¿­Ê±ADLabÇ徲ɳÁú£¬¼¸Ê®Î»ADLab³¤ÀÏÃÇ´Ó¸÷µØ¸ÏÀ´£¬¹²¾ÛÒ»Ìã¬ÅäºÏ̽ÌÖÇ°ÑØÊÖÒÕÇ÷ÊÆÓëÐÐÒµ¶¯Ì¬£¬·ÖÏí×îÐÂÊÖÒÕÑо¿Ð§¹ûÓë˼Ð÷¡£ÔÚÀÏÓÑÖØ·êºÍ21ÖÜÄêËêÄîµÄϲÔÃÆø·ÕÏ£¬ÁÐ볤ÀÏÃÇÆð¾¢½²»°£¬ÈÈÁÒµÄÌÖÂÛÓë½»Á÷£¬Ò»Ö±µØÅöײ³öеÄÖǻۻ𻨡£


1.jpg


ADLabµÄЧ¹ûÀë²»¿ªÃ¿Ò»Î»¡°³¤ÀÏ¡±µÄÖ§¸¶£¡


2.png


×ðÁú¿­Ê±ÖúÀí×ܲá¢ADLabÊÖÒÕÈÏÕæÈËÖìÇ®º¼¿ªÄ»Ö´ǣº¡°½ñÄêÊÇµÚÆß½ìADLab³¤ÀϻᣬÕâЩÄêÀ´ADLabÒ»Ö±ÖÂÁ¦ÓÚÔö½øÑ§Êõ½»Á÷¡¢×÷ÓýÍøÂçÇå¾²ÊÖÒÕÈ˲Å£¬ÏÖÔÚ¹æÄ£Ò²ÈÕÒæ×³´ó£¬ËùÓÐÈ¡µÃµÄÕâЩЧ¹ûÒ²Àë²»¿ªADLabÒ»¾­ÓëÏÖÔÚµÄÐֵܽãÃÃÃÇÿһ·ÝÐÁÇÚµÄÖ§¸¶£¬ÔÚÕâÀïлл¸÷ÈË£¡¡±


ÕâЩ¡°´ó¿§¡±×öÊÖÒÕ·ÖÏí


3.jpg


À´×ÔADLabµÄÊÖÒÕר¼ÒdwfaultÎ§ÈÆ¡¶JavaScriptÒýÇæÎó²îÍÚ¾òÖ®Âá·¾ÙÐзÖÏí£¬ÏêϸÏÈÈÝÁËÁ½ÖÖ¾ßÓдú±íÐÔµÄÈô¸ÉÔ­´´Îó²î£º


1¡¢CVE-2020-0768 IE/Edge ChakraCoreÒýÇæJITÎó²î


2¡¢CVE-2019-0607/6201/8583 WebKit/Safari JavaScriptCoreÒýÇæ  WebAssembly ÀàÐÍ»ìÏýÎó²î¡¢Edge ChakraCoreÒýÇæWebAssembly ÀàÐÍ»ìÏýÎó²î


Õë¶ÔChakraCoreÒýÇæµÄJITÎó²î£¬dwfaultÏÈÈÝÁË´ÓÄ£ºý²âÊÔµ½Íß½âµ÷ÊÔµ½ÆÊÎö³ö»ù´¡Ôµ¹ÊÔ­ÓɵÄÍêÕûÀú³Ì£¬ÆäÖÐ×ÅÖØÌåÏÖÎó²îµ÷ÊÔÖеĸú×ٺͻØËݵÄÖØ´óÐÔ¡£WebAssemblyÎó²îÖк¬ÓÐÒ»¸öSafari/Edgeä¯ÀÀÆ÷µÄ¡°Ë«É±¡±£¬Õë¶ÔÕâЩÎó²îÔò¼òÃ÷ËùÔÚ³öʵÖʳÉÒòºÍʹÓÃÒªÁ죬ҲÏÈÈÝÁËͨ¹ýÀ©Õ¹Îó²îģʽÍÚ¾òÏàËÆÎó²îµÄ˼Ð÷¡£


4.jpg


ÊÖÒÕ´ó¿§crowlÎ§ÈÆ¡¶½©Ê¬ÃÛÍø¡ª¡ªÐÂÐÍÎïÁªÍø½©Ê¬ÍøÂçÄ£×ӵķ¢Ã÷Óë̽ÌÖ¡·×öÑݽ²·ÖÏí£¬Ëû´Ó»ØÊ×½©Ê¬ÍøÂçÉú̬µÄÑݱäÓëÉú³¤£¬µ½ÔõÑù·¢Ã÷½©Ê¬ÃÛÍø£¬ÏêϸÐðÊöÁËÕâÖÖÄ£×ÓµÄÌØµãºÍÍþв£¬²¢ÍŽὩʬÃÛÍøµÄ°¸Àý¾ÙÐÐÁËÏêϸÆÊÎö¡£


ËûÌåÏÖ£¬Ëæ×Ž©Ê¬ÍøÂç¹¥·À¶Ô¿¹µÄÒ»Ö±Éý¼¶£¬ÎÒÃÇÍŶӷ¢Ã÷ÁËÒ»ÖÖÄܹ»²¶»ñÆäËü²»·¨·Ö×Ó¹¥»÷×ÊÔ´¡¢¾ß±¸ÓÕ²¶ºÍÓÕÆ­ÌØÕ÷µÄÐÂÐͽ©Ê¬ÍøÂ磬ÓÉÓÚÕâÖÖÌØÕ÷ºÍÃÛ¹ÞÊ®·ÖÏàËÆ£¬Òò´ËÎÒÃǽ«ÆäÃüÃûΪ¡°½©Ê¬ÃÛÍø¡±¡£Ëü¿ÉÒÔÔÚÔ­Óв»·¨·Ö×Ó×ÊÔ´µÄ»ù´¡ÉÏÌṩ¸ü¿ìµÄÇ鱨·´Ó¦ÄÜÁ¦£¬ÊµÏÖÈëÇÖ×ÊÔ´µÄ¿ìËÙ¼¯ÖкÍÎäÆ÷»¯£¬crowlÒÔΪ½©Ê¬ÃÛÍøÎ´À´ÓпÉÄÜ»á³ÉΪ½©Ê¬ÍøÂçÈëÇÖµÄÐÂÇ÷ÊÆ¡£


5.jpg


ÊÖÒÕÑо¿×¨¼ÒÁº±ò½ÌÊÚÒÔ¡¶µçÈÝÆÁÊÖ»úÓÎÏ·ÊÖ±úµÄ¼ì²â¡·ÎªÖ÷Ìâ¸ø¸÷ÈË´øÀ´ÁËÒ»³¡¾«²Ê·×³ÊµÄÑݽ²£¬Áº½ÌÊÚ¼°ÆäÏàÖúÕßͨ¹ý¶ÔµçÈÝÊÖ±úÊÂÇéÔ­Àí¾ÙÐÐÆÊÎö£¬Ìá³öÁËÒ»ÖÖ»ùÓÚìØÖµÆÊÎöºÍ͹½çÏßʶ±ðµÄµçÈÝÊÖ±ú¼ì²âÒªÁ졣ͨ¹ýÕæÊµÓÎÏ·ÖеÄʵÑ飬֤ʵÎú¸ÃÒªÁì¿ÉÒÔÓÐÓõؼì²â³öÎÞÇý¶¯¡¢ÎÞÁ´½Ó¡¢¼´²å¼´ÓõĵçÈÝÊÖ±ú£¬Äܹ»µÖ´ïά»¤ÊÖ»úÓÎÏ·µÄ¹«ÕýÐÔµÄÄ¿µÄ¡£


Free talk»·½ÚÓë»á³¤ÀÏÃÇÆð¾¢ÌÖÂÛ


6.jpg


ADLab³¤ÀÏ»á³ÉÔ±´óÅË̸µ½£º¡°Î´À´Á½ÈýÄêÊǹ¤Òµ´ó±ä¾ÖµÄ½Úµã£¬ADLabÔÚ×ðÁú¿­Ê±¾ßÓоÙ×ãÇáÖØ¡¢¾öÒéÐÔµÄְλ£¬Ï£ÍûADLabδÀ´»áÇý¶¯×ðÁú¿­Ê±×ߵĸüºÃ¡¢¸üÔ¶¡£¡±


7.png


нú³¤ÀÏËïÞ±ÌåÏÖ£º¡°ºÜÐÒÔ˽ñÄêÈÙÉýΪ³¤ÀÏ»áµÄÒ»Ô±£¬ÎÒÃÇËù´ÓʵÄÍøÂçÇå¾²Ñо¿£¬ÊµÖÊÉÏÒ²ÊÇÈËÓëÈË¡¢ÊÖÒÕÓëÊÖÒÕ¡¢Í·ÄÔÓëÍ·ÄԵĶԿ¹£¬ÓÐÈ˵ĵط½¾Í»áÓйÊÊ£¬ÓÈÆäÊÇÔÚÎÒÃÇÍøÂçÇå¾²ÁìÓò£¬ÓÀÔ¶»áÓÐеĹÊÊÂÉÏÑÝ£¬¸÷È˶¼ÊÇÕâ¸öÎę̀ÉϵÄÖ÷½Ç£¬ºÜÊÇÆÚ´ýδÀ´¸÷È˶ÔÕⳡ¹ÊʵÄÑÝÒï¡£¡±


´Ó1999Ä꽨ÉèÖÁ½ñ£¬21ÄêµÄËêÔÂÖУ¬ADLabÒ²ÂúÔØÉùÓþ£¬Ë¶¹ûÀÛÀÛ£¬×÷ΪÖйú×îÔçµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒ¡¢Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±¡¢¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕߣ¬×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î900Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼£¬Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£


21ÄêµÄÁ÷½ðËêÔ£¬ADLabµÄ³ÉÔ±ÃÇÒ²ÓÃËûÃǵÄÇà´ºÆ×дADLabµÄ»ªÃÀƪÕ¡£Ëæ×ÅÍøÂçÇå¾²ÐÐÒµµÄÉú³¤£¬´Ó×ðÁú¿­Ê±ADLab×ß³öÁËÒ»ÖÚ´ó¿§£¬ÎÞÂÛÊÇ×ÔÖ÷ÃÅ»§ÕÕ¾ÉÒµÄÚ×ÊÉîר¼Ò£¬Ã¿Ò»ÄêÁÐ볤ÀÏÃǶ¼»á¿çÔ½¾àÀ룬Ïà¾ÛÒ»Æð¸ÐÊÜÀÏÓÑÖØ·êµÄϲÔÃÓëÓÅÃÀ£¬Ò»Æð·ÖÏíǰհµÄÊÖÒÕÑо¿ÓëÍ»ÆÆ£¬³ä·Ö¸ÐÊÜÊÖÒÕµÄ÷ÈÁ¦£¬ÐÅÍÐ×ðÁú¿­Ê±ADLab³¤ÀÏ»áµÄ¸÷ÈËÍ¥»áÒ»Ö±¸øÍøÂçÇå¾²ÐÐÒµ×¢ÈëÐÂÏʵÄѪҺ£¬Ïòµ¼ÍøÂçÇå¾²ÐÐÒµ×ßÏò¸ü¸ßÔ¶µÄδÀ´£¡