查看: 3363|回复: 4
收起左侧

[转帖] FREAK: All Windows versions are affected too

[复制链接]
诸葛亮
发表于 2015-3-7 11:00:13 | 显示全部楼层 |阅读模式
本帖最后由 诸葛亮 于 2015-3-7 11:01 编辑

                           FREAK: All Windows versions are affected too
UPDATE on the FREAK OpenSSL vulnerability: it affects not only Android and iOS but all Windows versions too.

We about the new SSL vulnerability called FREAK – Factoring RSA Export Keys – affects around 36% of all sites trusted by browsers and around 10% of the Alexa top one million domains, according to computer scientists at the University of Michigan.

Android, iOS and a lot of embedded devices that make use of the affected SSL clients (including Open) are in danger of having their connections to vulnerable websites intercepted.

The two most used operating systems for smartphones, tablets, laptops and embedded devices are in good company. Yesterday, Microsoft made known that all its supported Windows versions are also affected due to the presence of the vulnerability in the Windows Secure Channel (SChannel) – the Microsoft own implementation of SSL/TLS:

Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 8 and 8.1
Windows Server 2012
Windows RT
where the problem is analyzed and solutions are offered. Also a patch is promised to fix all supported operating systems.

What does it mean for the user?

FREAK vulnerability
[/url]
What should the users do?


转自[url]http://blog.avira.com/freak-windows/







我测试了一下我的谷歌浏览器是safe,IE11是vulnerable
IE11(可能是我没有升级IE)


谷歌浏览器

测试地址https://freakattack.com/

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
__情义丶飞雪
发表于 2015-3-7 11:12:04 | 显示全部楼层
什么鬼...
诸葛亮
 楼主| 发表于 2015-3-7 11:18:24 | 显示全部楼层
g550
发表于 2015-3-9 21:21:52 | 显示全部楼层
Good News! Your browser appears to be safe from the FREAK attack.

tete009 firefox 24.8.1
aaa839
发表于 2015-3-10 18:48:35 | 显示全部楼层
本帖最后由 aaa839 于 2015-3-10 22:12 编辑


隨了IE外,所有新版本的瀏覽器應該已經修復此問題
Avira已提及了此問題
其他Windows 用戶,包括XP/Server 2003至8.1用戶請留意
Microsoft Security Advisory 3046015
IE雖然可以使用微軟Security Advisor
但留意,Security Advisor內的臨時方法是禁用左部份TLS,
但會令部份加密網頁無法載入

https://technet.microsoft.com/en ... PPError=-2147217396
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 09:13 , Processed in 0.129536 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表