ÎÒÃÇÖØÊÓ×ÊѶ°²È«£¬²¢ÖÂÁ¦ÓÚ³ÖÐøÇ¿»¯ÎÒÃǵÄÍøÕ¾·À»¤ÄÜÁ¦¡£Èç¹ûÄúÊÇ×ʰ²Ñо¿ÈËÔ±£¬²¢ÔÚÎÒÃǵÄÍøÕ¾Öз¢ÏÖDZÔÚ©¶´£¬ÎÒÃdzÏÖ¿ÑûÇëÄúÐÖú»Ø±¨£¬ÎÒÃǽ«¶Ô·ûºÏ×ʸñµÄ»Ø±¨Ìṩ½±Àø¡£
¼Æ»·¶Î§ |
±¾Â©¶´»Ø±¨¼Æ»½öÊÊÓÃÓÚÏÂÁÐÍøÓò£º
»Ø±¨ÄÚÈݽöÏÞÓÚÒÔÉÏÍøÕ¾ÖÐËùÊôµÄ¹«¿ªÒ³ÃæÓ빦ÄÜ¡£ÇëÎð¶Ô¹«Ë¾ÄÚ²¿ÏµÍ³¡¢µÚÈý·½·þÎñ»ò·Ç¹«¿ª¶Ëµã½øÐвâÊÔ£¬AUO ÓÐÈ¨ËæÊ±¸ü¸ÄÕâ·ÝÇåµ¥£¬Ë¡²»ÁíÐÐ֪ͨ¡£
×ʸñÌõ¼þ |
Ϊȷ±£ºÏ·¨ÐÔÓëÉó²é±ãÀû£¬±¾¼Æ»½ö½ÓÊܾßÖлªÃñ¹ú¹ú¼®ÇÒÄêÂú 18 ËêÖ®²ÎÓëÕß¡£²ÎÓëÕßÐèÓڻر¨Ê±ÌṩÓÐЧÉí·ÝÖ¤Ã÷Îļþ£¬ÒÔ¹©×ʸñºËʵ¼°ºóÐø½±Àø·¢·Å¡£
¿É½ÓÊÜ֮©¶´ÀàÐÍ (°üº¬µ«²»ÏÞÓÚ)£º
- ¿çÕ¾½Å±¾¹¥»÷ (XSS)
- ¿çÕ¾ÇëÇóαÔì (CSRF)
- Éí·ÝÑéÖ¤ÈÆ¹ý
- ȨÏÞÌáÉý
- ËÅ·þÆ÷¶Ë³Ìʽ´íÎó (ÈçÔ¶¶Ë³ÌʽÂëÖ´ÐС¢SQL Injection)
- Ãô¸Ð×ÊѶй© (ÈçδÊÚȨ´æÈ¡µÄ¸ö×Ê¡¢É趨µµ)
²»ÔÚ½±Àø·¶Î§Ö®ÏîÄ¿ |
Ϊ¾Û½¹ÓÚÍøÕ¾°²È«±¾Éí£¬ÒÔÏÂÏîÄ¿½«²»ÁÐÈë½±Àø·¶Î§£º
- ×Ô¶¯»¯¹¤¾ßɨÃè³öµÄµÍ·çÏÕ×ÊѶ
- Clickjacking
- HTTP headers ȱʧ (Èç CSP, HSTS µÈ)
- ¹«¿ª×ÊѶÈç whois ×ÊÁÏ»ò metadata
- ·þÎñÖжϲâÊÔ (Èç DoS ¹¥»÷)
- Éç½»¹¤³Ì»òÍøÂ·µöÓã
- 90ÌìÄÚ¹«¿ªµÄÁãʱ²î©¶´»ò¹¥»÷
- δÏêÊö°²È«ÎÊÌâÓ°ÏìµÄ°²È«ÈõµãɨÃ豨¸æ
- ȱ·¦¾ßÌå¸ÅÄîÖ¤Ã÷ (PoC) µÄÀíÂÛÐÔ·çÏÕ
»Ø±¨Ë³Î»ÔÔò |
ÈôÓÐÁ½Î»»òÒÔÉϲÎÓëÕßͬʱ·¢ÏÖ²¢»Ø±¨Ïàͬ©¶´£¬ÎÒÃǽ«ÒÔ×îÏÈÍêÕûÌá½»»Ø±¨Õß×÷ΪÓÐЧ»Ø±¨È˲¢Ìṩ½±Àø¡£ºóÐø»Ø±¨ÕßËä¸Ðл²ÎÓ룬µ«²»ÔÙÁíÐÐÌṩ½±Àø¡£
ÔðÈνÒ¶Õþ²ß |
ÎÒÃǹÄÀø¸ºÔðÈεÄ©¶´½Ò¶ÐÐΪ£¬²ÎÓëÕßÐë×ñÊØÒÔÏÂÔÔò£º
- ²»µÃÀûÓûò¹«¿ªÂ©¶´×ÊѶ¡£
- ²»µÃ¶Ô·þÎñÔì³ÉÖжϻòÓ°ÏìÆäËûʹÓÃÕß¡£
- ½öÏÞ½øÐзÇÇÖÈëÐԵIJâÊÔ¡£
- Ò»¾·¢ÏÖ©¶´£¬Ó¦Á¢¼´Í£Ö¹²âÊÔ²¢Ìá³ö»Ø±¨¡£
- ËùÓÐͨ±¨µÄ©¶´×ÊѶÔÚδ¾ÎÒÃÇÃ÷È·ÊéÃæÐí¿Éǰ£¬²»µÃÒÔÈκÎÐÎʽ¹«¿ª½Ò¶£¬°üÀ¨µ«²»ÏÞÓÚÉ罻ýÌå¡¢ÂÛ̳»òÆäËû¹«¿ªÆ½Ì¨¡£
»Ø±¨Á÷³Ì |
Ç뽫ÄúµÄ·¢ÏÖ͸¹ýÒÔÏ·½Ê½»Ø±¨ÎÒÃÇ£º
- µç×ÓÓʼþÐÅÏ䣺bugbounty@auo.com
- »Ø±¨ÄÚÈÝÐë°üº¬£º
- ·¢ÏÖÈÕÆÚÓëʱ¼ä
- ÊÜÓ°ÏìÒ³Ãæ URL
- ©¶´Ïêϸ˵Ã÷ÓëÖØÏÖ²½Öè
- ²âÊÔʱËùʹÓõŤ¾ßÓë·¶Àý×ÊÁÏ (ÈôÓÐ)
¾ÄÚ²¿Éó²éÈ·ÈÏΪÓÐЧ©¶´ºó£¬ÎÒÃǽ«ÒÀ·çÏյȼ¶Ìṩ½±Àø£¬²¢ÁªÏµÄú½øÐÐÉí·ÖÈ·ÈÏÓë½±Àø·¢·Å³ÌÐò¡£
½±Àø»úÖÆ |
½±Àø½ð¶î½«ÊÓ©¶´µÄÑÏÖØÐÔÓëÓ°Ïì³Ì¶ÈÆÀ¹À£¬·¶Î§ÈçÏ£º
|
ÎÒÃDZ£Áô½±Àø½ð¶î×îÖÕ½âÊÍÓëºË·¢È¨Àû¡£