TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How a Web Link Can Take Control of Your Phone

29 点作者 mdariani超过 13 年前

4 条评论

ge0rg超过 13 年前
TL;DR: some guys bought a bunch of WebKit zero-days, gained root on an Android 2.x device, installed a surveillance app and demoed it at RSA conf.<p>It would be nice to get hold of some more of the technical details involved.
评论 #3660768 未加载
ajray超过 13 年前
Maybe I'm not sure about how tech-savvy most people are, but when I get a text message from an unknown number claiming to be my provider asking me to click a web link to update my phone, I know something's up.
评论 #3662466 未加载
emmelaich超过 13 年前
It's not that clear, but apparently this requires the pre-installation of a malicious app.<p>Quote: "The CrowdStrike team reverse engineered a Remote Access Tool (RAT) called Nickispy (a RAT from China that successfully disguised itself as a Google+ app)."<p>from <a href="http://blogs.computerworld.com/19803/mobile_rat_attack_makes_android_the_ultimate_spy_tool" rel="nofollow">http://blogs.computerworld.com/19803/mobile_rat_attack_makes...</a>
Cieplak超过 13 年前
I'm curious if they used any Flash exploits in addition to the webkit vulnerabilities.