太惨了……OSX 中了 WireLurker,现在想自检 iPhone 6!

2014-11-10 01:43:44 +08:00
 konakona
IPHONE6才买一周多,没有同步应用,也没有使用数据线链MBP。
但是在购买时,店主已用PP助手越狱,甚是担心,因为最近使用手机safari访问baidu.com竟然是先到7do..什么的,再跳转过去的!而且safari下访问网页多次出现加载失败!这问题很明显!(也有可能单纯是因为越狱,但google chrome下未出现)

好不容易刚刚在OSX下手动删除了WireLurker变种(变得还不算太离谱),搞了3个小时..

检查器不再报出我中了WireLurker了!打算买一个出口防火墙,以后支持正版!

-----------我的病毒宿主是MAMP(mamp.info这款集成开发环境的免费版,官网下载) 10月18日下载 /Users/mac/Downloads/MAMP_MAMP_PRO_3.0.7.1.pkg (要知道laracasts.com的作者也是用这个呢 )
想不到……真的想不到……

现在想知道如何能检查iphone6是否中病毒呢?跪谢...

太不安全了!
6611 次点击
所在节点    macOS
36 条回复
bullettrain1433
2014-11-10 15:01:40 +08:00
@DXpro 请问用的什么检测
musicx
2014-11-10 15:12:54 +08:00
jiongjionger
2014-11-10 15:45:45 +08:00
= =我也中招
bullettrain1433
2014-11-10 16:51:22 +08:00
@musicx Your OS X system isn't infected by the WireLurker. Thank you! 谢谢
duoglas
2014-11-10 17:03:36 +08:00
@braineo 看完了文档, 并没有说中标的ios如何处理啊
braineo
2014-11-10 17:21:12 +08:00
@duoglas 有说啊,认真看看。越狱后的就把一个sfbase的文件删掉,未越狱的就去把不知名的profile删掉。越狱后的iOS因为可以会在app里植入木马,看看发行商对不对得上。未越狱的把企业部署的奇怪的APP删了就好了
duoglas
2014-11-10 17:30:00 +08:00
@braineo 果然 刚才没看仔细 , 谢谢~!

Remediation
If WireLurker is found on any OS X computer, we recommend the deletion of
respective files and removal of applications reported by the script. As of the
publication date of this report, the iOS component of WireLurker is only spread
through an infected Mac computer; accordingly, if WireLurker is found on a Mac, we
recommend inspection of all iOS devices that have connected with that computer.
A quick check for iOS devices includes determining whether any unauthorized
enterprise provisioning profiles were created by navigating to “Settings -> General
-> Profile”. If an anomalous profile is found, it should be removed and a subsequent
check of all applications should be performed. Delete any strange applications found
on the device. For jailbroken devices, we recommend that you check whether the file
“/Library/MobileSubstrate/DynamicLibraries/sfbase.dylib” exists. If so, you should
delete it through a terminal connection, via an application like MobileTerminal or
Secure Shell (SSH).
gtar
2014-11-10 20:21:46 +08:00
[+] Your OS X system isn't infected by the WireLurker. Thank you!


https://github.com/PaloAltoNetworks-BD/WireLurkerDetector
aaron2go
2014-11-10 21:10:08 +08:00
以前我还专门去找这个麦客孤独的D版软件。。。。现在我基本全换成正版了。。太恐怖了
zeroday
2014-11-11 01:25:43 +08:00
@duoglas 8.1系统设置中的通用中没发现“Profile”
duoglas
2014-11-11 09:47:35 +08:00
@zeroday 那就说明ok了
xieguobihaha
2014-11-11 19:23:07 +08:00
中招已修复;-)
zeroday
2014-11-11 21:59:20 +08:00
@duoglas 哦,明白了,thank you.
dotpig
2014-11-15 13:30:49 +08:00
@zeroday 用 xcode 查看删除(或者 iPhone Configuration Utility 也可以)。如果没有越狱的话,删不删那个证书无所谓,因为已经被苹果屏蔽了。
zeroday
2014-11-15 23:14:37 +08:00
@dotpig 试了一下您推荐的方法,请教一个问题,iPhone Configuration Utility签发de证书怎么不被信任的呢?

dotpig
2014-11-16 10:16:50 +08:00
@zeroday 到 Keychain 里面,把 iPhone Configuration Utility 证书设为始终信任就可以了。

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/145232

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX