本帖最后由 Prnceton 于 2013-12-23 13:32 编辑
“iOS 7 越狱来了!咦?里面怎么还有一个太极助手?” 昨晚到今天,“太极”成为了国外越狱社区,以及国内社交网络上的热门话题。evasi0n 还特意针对这一情况发布了声明。正如王崇旭所说,“这一天,对以‘追求自由’‘打破桎梏’为核心价值观的越狱黑客们来说,注定是不光彩的。” 本文一步一步还原“太极”背后的支持者。由于是在 Linux 环境下用终端命令查询,因此如果打算亲自尝试,请先检查一下自己的操作系统是否 Linux。 第一步,用 Whois 命令查询域名信息。 - $ whois taig.com
- Domain Name: TAIG.COM
- Registry Domain ID: 5070333_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: [url=http://www.godaddy.com]http://www.godaddy.com[/url]
- Update Date: 2013-11-05 18:27:16
- Creation Date: 1999-04-06 23:00:00
- Registrar Registration Expiration Date: 2015-04-06 23:00:00
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [url=mailto:abuse@godaddy.com]abuse@godaddy.com[/url]
- Registrar Abuse Contact Phone: +1.480-624-2505
- Domain Status: clientTransferProhibited
- Domain Status: clientUpdateProhibited
- Domain Status: clientRenewProhibited
- Domain Status: clientDeleteProhibited
- Registry Registrant ID:
- Registrant Name: zhou shengjin
- Registrant Organization:
- Registrant Street: Beijing changping district changping road
- Registrant City: Beijing
- Registrant State/Province: beijing
- Registrant Postal Code: 100096
- Registrant Country: China
- Registrant Phone: +1.8811225068
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: [url=mailto:nomas.chow@gmail.com]nomas.chow@gmail.com[/url]
- Registry Admin ID:
- Admin Name: zhou shengjin
- Admin Organization:
- Admin Street: Beijing changping district changping road
- Admin City: Beijing
- Admin State/Province: beijing
- Admin Postal Code: 100096
- Admin Country: China
- Admin Phone: +1.8811225068
- Admin Phone Ext:
- Admin Fax:
- Admin Fax Ext:
- Admin Email: [url=mailto:nomas.chow@gmail.com]nomas.chow@gmail.com[/url]
- Registry Tech ID:
- Tech Name: zhou shengjin
- Tech Organization:
- Tech Street: Beijing changping district changping road
- Tech City: Beijing
- Tech State/Province: beijing
- Tech Postal Code: 100096
- Tech Country: China
- Tech Phone: +1.8811225068
- Tech Phone Ext:
- Tech Fax:
- Tech Fax Ext:
- Tech Email: [url=mailto:nomas.chow@gmail.com]nomas.chow@gmail.com[/url]
- Name Server: NS3.DNSV4.COM
- Name Server: NS4.DNSV4.COM
复制代码从以上信息可看出, taig.com 是一个 1999 年就注册的域名。这个域名里的联系电话, +1.8811225068 应为 +86-18811225068。这是我们的线索之一。地址“北京市昌平区昌平路”与手机号码归属地北京相匹配。 Email 地址则是另一个有效的线索。 第二步,用 host 命令解析 www.taig.com,得到与该命令相关联的 IP 地址和 DNS 地址。- $ host [url=http://www.taig.com]www.taig.com[/url]
- [url=http://www.taig.com]www.taig.com[/url] has address 211.155.82.248
- [url=http://www.taig.com]www.taig.com[/url] has address 203.191.148.133
- [url=http://www.taig.com]www.taig.com[/url] has address 42.62.21.140
- [url=http://www.taig.com]www.taig.com[/url] has address 42.62.21.141
- [url=http://www.taig.com]www.taig.com[/url] has address 42.62.21.142
- [url=http://www.taig.com]www.taig.com[/url] has address 42.62.21.143
- [url=http://www.taig.com]www.taig.com[/url] has address 42.62.21.144
- [url=http://www.taig.com]www.taig.com[/url] has address 211.155.82.233
复制代码 这些 IP 地址告诉我们什么呢?www.taig.com 这家网站拥有好几个机房,启用了 CDN 加速,不像是小公司的基础设施。通过 whois 命令查询这些 IP 地址,得到的结果令人失望,因为结果均指向各个数据中心。然后再用查询 IP 以及域名信息的工具 bgp.he.net 查询,也同样没有给出更多的信息。 不过,也不必气馁,以上所找到的信息已经布满疑点。现在,再尝试用 curl -s 将 www.taig.com 的页面源代码下载到本地,然后通过 grep -Eo “http://[^\"']+” 从源代码里找到特定的网址,结果很有意思:- $ curl -s [url=http://www.taig.com]www.taig.com[/url]|grep -Eo "http://[^"']+"[/size][/font][/color][/align][align=left]http://bbdown.iphonespirit.com/site/image/logo.ico[/align][align=left]http://js.pingguoyingyong.com/taiji-home/css/style.css[/align][align=left]http://bbs.taig.com[/align][align=left]http://www.taig.com/archives/category/news[/align][align=left]http://static.youku.com/v1.0.0334/v/swf/player_yk.swf[/align][align=left]http://static.youku.com/v1.0.0334/v/swf/player_yk.swf[/align][align=left]http://www.adobe.com/go/getflash[/align][align=left]http://bbdown.iphonespirit.com/ios/7/TaiG_JailBreak_iOS7_ForWin_v1.0.zip[/align][align=left]http://bbdown.iphonespirit.com/ios/7/TaiG_JailBreak_iOS7_ForMac_v1.0.dmg[/align][align=left]http://www.taig.com/archives/category/news[/align][align=left]http://www.taig.com/archives/548[/align][align=left]http://bbdown.iphonespirit.com/site/docpic/2348.jpg[/align][align=left]http://www.taig.com/archives/548[/align][align=left]http://www.taig.com/archives/548[/align][align=left]http://www.taig.com/archives/253[/align][align=left]http://www.taig.com/archives/251[/align][align=left]http://www.taig.com/archives/249[/align][align=left]http://www.taig.com/archives/247[/align][align=left]http://www.taig.com/archives/241[/align][align=left]http://www.taig.com/archives/239[/align][align=left]http://www.taig.com/archives/237[/align][align=left]http://www.taig.com/archives/233[/align][align=left][color=rgb(51, 51, 51)][font=Arial, Helvetica, sans-serif][size=14px]http://js.pingguoyingyong.com/taiji-home/js/build.js
复制代码 以上结果说明,我们在 www.taig.com 的网页上,还找到了其它网站的域名。这些网站的域名必定不是无缘无故出现在这里的。我们再次使用 whois 命令,查询这些看上去可疑的域名,首先是 pingguoyingyong.com 这个域名:- $ whois pingguoyingyong.com
- Domain Name: PINGGUOYINGYONG.COM
- Registry Domain ID: 1701302087_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: [url=http://www.godaddy.com]http://www.godaddy.com[/url]
- Update Date: 2013-02-04 05:56:33
- Creation Date: 2012-02-09 09:52:46
- Registrar Registration Expiration Date: 2015-02-09 09:52:46
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [url=mailto:abuse@godaddy.com]abuse@godaddy.com[/url]
- Registrar Abuse Contact Phone: +1.480-624-2505
- Domain Status: clientTransferProhibited
- Domain Status: clientUpdateProhibited
- Domain Status: clientRenewProhibited
- Domain Status: clientDeleteProhibited
- Registry Registrant ID:
- Registrant Name: John Lennon
- Registrant Organization: Apple Application INC.
- Registrant Street: China
- Registrant City: guangdong
- Registrant State/Province: baiyun
- Registrant Postal Code: 000000
- Registrant Country: China
- Registrant Phone: +86.138000138000
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: [url=mailto:fidate@gmail.com]fidate@gmail.com[/url]
- Registry Admin ID:
- Admin Name: John Lennon
- Admin Organization: Apple Application INC.
- Admin Street: China
- Admin City: guangdong
- Admin State/Province: baiyun
- Admin Postal Code: 000000
- Admin Country: China
- Admin Phone: +86.138000138000
- Admin Phone Ext:
- Admin Fax:
- Admin Fax Ext:
- Admin Email: [url=mailto:fidate@gmail.com]fidate@gmail.com[/url]
- Registry Tech ID:
- Tech Name: John Lennon
- Tech Organization: Apple Application INC.
- Tech Street: China
- Tech City: guangdong
- Tech State/Province: baiyun
- Tech Postal Code: 000000
- Tech Country: China
- Tech Phone: +86.138000138000
- Tech Phone Ext:
- Tech Fax:
- Tech Fax Ext:
- Tech Email: [url=mailto:fidate@gmail.com]fidate@gmail.com[/url]
- Name Server: F1G1NS1.DNSPOD.NET
- Name Server: F1G1NS2.DNSPOD.NET
复制代码 如果想知道一个域名的持有者,还持有什么其它的域名,那么持有此域名的邮箱是首要的调查对象。经过查询,此域名的邮箱 fidate@gmail.com 还拥有另一个域名,idestop.com。 再用 whois 命令查询 iphonespirit.com 这个域名,发现它采用了保护手段,防止别人查询 whois 域名信息。- $ whois iphonespirit.com
- Domain Name ..................... iphonespirit.com
- Sponsoring Registrar ............ HICHINA ZHICHENG TECHNOLOGY LTD.
- Name Server ..................... ns3.dnsv4.com
- ns4.dnsv4.com
- Registrant ID ................... whois-protect
- Registrant Name ................. WHOIS AGENT
- Registrant Organization ......... DOMAIN WHOIS PROTECTION SERVICE
- Registrant Address .............. 3/F.,HiChina Mansion,No.27 Gulouwai Avenue
- Dongcheng District,Beijing 100120,China
- Registrant City ................. Beijing
- Registrant Province/State ....... Beijing
- Registrant Postal Code .......... 100120
- Registrant Country Code ......... CN
- Registrant Phone Number ......... +8610.64242266
- Registrant Fax .................. +8610.84138796
- Registrant Email ................ [url=mailto:domainadm@hichina.com]domainadm@hichina.com[/url]
- Administrative ID ............... whois-protect
- Administrative Name ............. WHOIS AGENT
- Administrative Organization ..... DOMAIN WHOIS PROTECTION SERVICE
- Administrative Address .......... 3/F.,HiChina Mansion,No.27 Gulouwai Avenue
- Dongcheng District,Beijing 100120,China
- Administrative City ............. Beijing
- Administrative Province/State ... Beijing
- Administrative Postal Code ...... 100120
- Administrative Country Code ..... CN
- Administrative Phone Number ..... +8610.64242266
- Administrative Fax .............. +8610.84138796
- Administrative Email ............ [url=mailto:domainadm@hichina.com]domainadm@hichina.com[/url]
- Billing ID ...................... whois-protect
- Billing Name .................... WHOIS AGENT
- Billing Organization ............ DOMAIN WHOIS PROTECTION SERVICE
- Billing Address ................. 3/F.,HiChina Mansion,No.27 Gulouwai Avenue
- Dongcheng District,Beijing 100120,China
- Billing City .................... Beijing
- Billing Province/State .......... Beijing
- Billing Postal Code ............. 100120
- Billing Country Code ............ CN
- Billing Phone Number ............ +8610.64242266
- Billing Fax ..................... +8610.84138796
- Billing Email ................... [url=mailto:domainadm@hichina.com]domainadm@hichina.com[/url]
- Technical ID .................... whois-protect
- Technical Name .................. WHOIS AGENT
- Technical Organization .......... DOMAIN WHOIS PROTECTION SERVICE
- Technical Address ............... 3/F.,HiChina Mansion,No.27 Gulouwai Avenue
- Dongcheng District,Beijing 100120,China
- Technical City .................. Beijing
- Technical Province/State ........ Beijing
- Technical Postal Code ........... 100120
- Technical Country Code .......... CN
- Technical Phone Number .......... +8610.64242266
- Technical Fax ................... +8610.84138796
- Technical Email ................. [url=mailto:domainadm@hichina.com]domainadm@hichina.com[/url]
- Domain Create Date .............. 2013-03-29 19:54:24
- Expiration Date ................. 2014-03-29 19:54:24
复制代码 不过,我们依然可以进一步的进行 DNS 分析。- $ host bbdown.iphonespirit.com
- bbdown.iphonespirit.com is an alias for bbdown.iphonespirit.com.51ccdn.com.
- bbdown.iphonespirit.com.51ccdn.com is an alias for c01.i08.sisyun.com.
- c01.i08.sisyun.com is an alias for c01.i08.cncsd.hadns.net.
- c01.i08.cncsd.hadns.net has address 61.156.242.76
- c01.i08.cncsd.hadns.net has address 60.210.10.77
- c01.i08.cncsd.hadns.net has address 61.156.157.183
复制代码 随手一搜索,我们可以发现“苹果核”使用的分发域名便是 iphonespirit.com。而苹果核使用了国内某公司的核心,不得不让人有某些联想。- $ host js.pingguoyingyong.com
- js.pingguoyingyong.com has address 117.121.11.32
复制代码 接下来,我们用 host 命令查询这个 IP 地址,得到了一个惊奇的发现。- $ host [url=http://www.kuaiyong.com]www.kuaiyong.com[/url]
- [url=http://www.kuaiyong.com]www.kuaiyong.com[/url] has address 117.121.11.16
复制代码 经查,海外解析地址为 .16,国内解析地址为 .32。- $ curl -s --head -H"Host: [url=http://www.kuaiyong.com]www.kuaiyong.com[/url]" 117.121.11.32
- HTTP/1.1 200 OK
- Server: nginx/1.0.15
- Date: Sun, 22 Dec 2013 22:40:11 GMT
- Content-Type: text/html
- Content-Length: 9268
- Last-Modified: Thu, 19 Dec 2013 05:47:21 GMT
- Connection: keep-alive
- Accept-Ranges: bytes
- $ curl -s -H"Host: nosuchhost.com" 117.121.11.32 | grep '<title>'
- <title>Test Page for the Nginx HTTP Server on EPEL</title>
- $ curl -s -H"Host: [url=http://www.kuaiyong.com]www.kuaiyong.com[/url]" 117.121.11.32 | grep '<title>'
- <title> 快用苹果助手 </title>
复制代码 结论由于太极的下载链接托管在了 iphonespirit.com 上,我们有理由相信太极和国内某公司或某公司投资的某些公司有某种联系。 再由于太极的 JS 资源托管到了 pingguoyingyong.com 上,我们有理由相信太极和快用助手有某种深层次的合作。还有另外一种可能太极只是快用助手的马甲。 PS: 现在打开 bbdown.iphonespirit.com,你会发现一段告示,看来已经被黑了: 致某公司
谢谢你送我们的圣诞白苹果
谢谢你送我们的捆绑太极助手
既然你们有钱和 Evad3rs 合作,再出个服务好不?白苹果了直接送台新的
这次真的很失望,因为你们已经背叛了越狱的初衷
不要继续挑战用户的底线了好吗?
|