question_log201409: 金刚安全检测-聚超值app.htm

File 金刚安全检测-聚超值app.htm, 19.9 KB (added by liaojiaohe, 12 years ago)
Line 
1
2<!-- saved from url=(0095)http://service.security.tencent.com/uploadimg_dir/jingang/7663b13035e9eaa95a4fb257e741559c.html -->
3<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
4
5<meta http-equiv="X-UA-Compatible" content="IE=Edge">    
6<title>金刚安党检测</title>
7<style type="text/css">
8        body{font-family:"埮蜯雅黑",tahoma; margin:0 auto; padding: 0; text-align:center; background-color:#F4F4F4;}
9        a{color:#3888E2;text-decoration: none;}
10        .left{text-align: left;}
11        .separate-head{margin: 0;padding: 0;height:2px;}
12        .separate{margin: 0;padding: 0;height:10px;}
13        .tb-main{width:880px;text-align:center; margin:0 auto;padding:0; border:1px solid #E4E4E4;border-collapse: collapse;background-color:#FFF;}
14        /*.tb-main td{padding:26px 39px;}*/
15
16        .tb-header,.tb-footer{width: 880px;margin:0 auto;border:0; border-collapse:collapse;text-align:left;}
17        .tb-header td,.tb-footer td{background-color:#3888E2;color:#FFF;}
18        .tb-header td{height:82px;font-size:28px;}
19        .tb-footer td{height:28px;font-size:16px;padding-right:10px;}
20    .abc{width:30px;height:20px;font-size:14px;}
21
22        .tb-comm{margin:0px 40px;width:800px; border:none; border-collapse: collapse; text-align:left;}
23        .tb-comm tr,.tb-comm td {height:36px;line-height:36px; vertical-align: middle; border-bottom:1px dashed #E6E6E6;color:#2A2A2A;}
24        .tb-comm thead td{padding:0 0 0 13px;border-bottom:1px solid #E6E6E6;font-size: 20px}
25        .tb-comm td{padding:0 0 0 39px;font-size:14px;}
26        .tb-hole-detail td{padding: 0 0 0 32px;}
27        .tb-comm .td-first{width:86px}
28        .tb-comm .td-first-2{width:518px}
29        .tb-comm .no-border{border: none;}
30        .tb-comm .icon{margin-right:0px;}
31
32        .font-level-1,.font-level-2,.font-level-3,.font-level-4,.font-level-5{width:8px;height:8px;margin-right: 2px;display: inline-block;}
33        .font-level-1{background-color:#8CDC1E;width:8px;height:8px;}
34        .font-level-2{background-color:#56ACE2;width:8px;height:8px;}
35        .font-level-3{background-color:#FFC600;}
36        .font-level-4{background-color:#FD681F;}
37        .font-level-5{background-color:#DC1E1E;}
38        .font-holenum{color:#F50909;font-size:16px;font-weight:bold;}
39        .font-risknum{color:#FF8A00;font-size:16px;font-weight:bold;}
40        .font-judge{height:22px;width: 30px;color:#FFF;font-size:13px;background-color:#FF8A00;}
41
42        .font-high-level td{color:#F50909;}
43        .font-middle-level td{color:#FF8A00;}
44        .font-high-tips{color:#C36666;}
45
46        .font-sortnum{color:#3888E2;font-size:30px;font-weight:bold;}
47        .font-safe{color:#FFF;background-color:#419945;padding:1px 5px;}
48        .font-danger{color:#FFF;background-color:#FF8A00;padding:2px 5px;}
49       
50        .collapse-show{display:none;}
51        .collapse-show td{padding-left:61px;}
52        .collapse{background:url(/img/mail/ico_collapse.png) no-repeat 8px 8px;}
53        .expand{background:url(/img/mail/ico_expand.png) no-repeat 8px 8px;}
54
55        .expand-title{font-weight:bold;}
56        .expand-title,.expand-content{float:left;}
57        .expand-content{margin-left:0px;max-width:665px;}
58        .collapse-show div{}
59
60</style><script src="./金刚安党检测-聚超倌app_files/jquery.js" type="text/javascript"></script><script type="text/javascript">
61        $(document).ready(function() {         
62                $(".td-collapse").click(function(event) {                       
63                        /* Act on the event */
64
65                        var $this = $(this);
66                        var $showHtml = $this.parent().next();
67                        if($this.hasClass('collapse'))
68                        {
69                                $this.removeClass('collapse');
70                                $this.addClass('expand');
71                                $showHtml.show();
72                        }
73                        else
74                        {
75                                $this.removeClass('expand');
76                                $this.addClass('collapse');
77                                $showHtml.hide();
78                        }
79                                                                       
80                });
81        });
82</script></head>
83
84<style type="text/css" id="__360se6_success_css"></style>
85<body lang="ZH-CN" link="blue" vlink="purple"><table class="tb-main" style=";"><tbody><tr><td style=""><table class="tb-header"><tbody><tr><td style="border-radius:3px 3px 0 0; padding-left:39px;padding-top:9px;" width="35px"><img class="icon" src="./金刚安党检测-聚超倌app_files/logo.png">&nbsp;</td><td style="border-radius:3px 3px 0 0; vertical-align:middle;">金刚系统审计报告<sup class="abc">beta</sup></td></tr></tbody></table><p class="separate-head">&nbsp;</p><table class="tb-comm" style="border:none;">
86        <thead>
87                <tr>
88                        <td colspan="2"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_scan_con.png">&nbsp;扫描结论</td>
89                </tr>
90        </thead>
91        <tbody>
92                <tr class="no-border">
93                        <td class="no-border" style="width:506px;padding:0px;">
94                                <table>
95                                        <tbody><tr>
96                                                <td class="td-first">嚁胁等级</td>
97                                                <td class="left">
98
99                                                        <img class="icon" src="./金刚安党检测-聚超倌app_files/danger_level_5.png">&nbsp;
100                                                        <img class="icon" src="./金刚安党检测-聚超倌app_files/danger_level_5.png">&nbsp;
101                                                        <img class="icon" src="./金刚安党检测-聚超倌app_files/danger_level_5.png">&nbsp;
102                                                        <img class="icon" src="./金刚安党检测-聚超倌app_files/danger_level_5.png">&nbsp;
103                                                        <img class="icon" src="./金刚安党检测-聚超倌app_files/danger_level_1.png">&nbsp;
104                                                </td>                                                                           
105                                        </tr>
106                                        <tr><td>挏掞抂述</td>
107                                                <td class="left">
108                                                        共审计出<span class="font-holenum">19</span>䞪挏掞<span class="font-risknum">13</span>䞪风险
109                                                </td>                                                                           
110                                        </tr>
111                                       
112                                </tbody></table>
113                        </td>
114                </tr>
115               
116        </tbody>
117</table>       
118<div class="separate">&nbsp;</div><!-- 基本信息 -->
119<table class="tb-comm">
120        <thead>
121                <tr><td colspan="3"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_basic_info.png">&nbsp;基本信息</td></tr>
122        </thead>
123        <tbody>
124                <tr>
125                        <td class="td-first" style="height:36px;">文件名</td>
126                        <td style="height:36px;">juchaozhi_v1.3.0.apk</td>                             
127                </tr>
128                <tr>
129                        <td>MD5</td>
130                        <td>7663b13035e9eaa95a4fb257e741559c</td>
131                </tr>                           
132                <tr>
133                        <td>䞊䌠时闎</td>
134                        <td>9/22/2014 5:47:11 PM</td>
135                </tr>
136                <tr>
137                        <td>审计耗时</td>
138                        <td>0小时12分钟</td>
139                </tr>
140        </tbody>
141</table>
142<div class="separate">&nbsp;</div><table class="tb-comm">
143        <thead>
144                <tr><td colspan="2"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_hole_detail.png">&nbsp;挏掞诊情</td></tr>
145        </thead>
146        <tbody class="tb-hole-detail"><tr>
147<td class="td-first-2  td-collapse expand"><font color="red">【高危】Web组件远皋代码执行挏掞</font></td>
148<td><font color="red">发现17倄</font></td>                          
149</tr>
150<tr class="collapse-show" style="display: table-row; ">
151<td colspan="2">
152<div style="clear:both;">
153        <div class="expand-title">诊细内容</div>
154        <div class="expand-content">皋序䞭存圚以䞋危险api可富臎远皋代码执行<br>cn\jpush\android\a\f.java:A.addJavascriptInterface(new cn.jpush.android.ui.l(u, B), E[8]);<br>cn\jpush\android\ui\a.java:d.addJavascriptInterface(new l(paramContext, paramD), z[0]);<br>com\juchaozhi\discount\ArticleActivity$7.java:ArticleActivity.access$2100(this$0).addJavascriptInterface(this$0.jsObject, "checkCollectionState");<br>com\juchaozhi\discount\ArticleActivity.java:paramWebView.addJavascriptInterface(new ArticleActivity.WebViewJavaScriptSInterface(this), "webview");<br>com\tencent\connect\auth\AuthDialog.java:Method localMethod = WebView.class.getMethod("addJavascriptInterface", new Class[] { Object.class, String.class });<br>cn\com\pcgroup\android\browser\utils\CacheUtil.java<br>cn\com\pcgroup\android\common\widget\refreshweb\PullToPageWebView.java<br>cn\jpush\android\a\f.java<br>cn\jpush\android\ui\a.java<br>com\imofan\android\develop\sns\activity\MFSnsOAuthActivity.java<br>com\juchaozhi\topic\TopicFragment.java<br>com\sina\weibo\sdk\auth\WeiboDialog.java<br>com\tencent\connect\auth\AuthAgent.java<br>com\tencent\connect\auth\AuthDialog.java<br>com\tencent\open\PKDialog.java<br>com\tencent\open\SocialApiIml.java<br>com\tencent\open\TDialog.java<br></div>
155</div>
156<div style="clear:both;">
157        <div class="expand-title">修倍建议</div>
158        <div class="expand-content">建议犁甚危险接口addJavascriptInterface富出Java类及方法并加区访问的url的域控制移陀系统webkit内眮的危险接口searchBoxJavaBridge_䞥栌控制富出方法的权限避免越权操䜜。</div>
159</div>
160</td>
161</tr><tr>
162<td class="td-collapse expand"><font>【高危】Content Provider组件数据泄露挏掞</font></td>
163<td>超时</td>                         
164</tr>
165<tr class="collapse-show" style="display: table-row; ">
166<td colspan="2">
167<div style="clear:both;">
168        <div class="expand-title">诊细内容</div>
169        <div class="expand-content">%SUBDETAILLEAKHIGH11%</div>
170</div>
171<div style="clear:both;">
172        <div class="expand-title">修倍建议</div>
173        <div class="expand-content">暎露的Provider组件请䞥栌校验蟓入uri防止通过恶意uri访问任意目圕文件</div>
174</div>
175</td>
176</tr><tr>
177<td class="td-collapse expand"><font>【高危】Activity组件隐私泄露挏掞</font></td>
178<td>超时</td>                         
179</tr>
180<tr class="collapse-show" style="display: table-row; ">
181<td colspan="2">
182<div style="clear:both;">
183        <div class="expand-title">诊细内容</div>
184        <div class="expand-content">%SUBDETAILLEAKHIGH12%</div>
185</div>
186<div style="clear:both;">
187        <div class="expand-title">修倍建议</div>
188        <div class="expand-content">Activity组件请䞥栌校验蟓入Intent对象的参数犁止通过Activity组件内眮浏览噚加蜜任意url并通过file协议访问本地html文件。</div>
189</div>
190</td>
191</tr><tr>
192<td class="td-collapse collapse">【䞭危】源码泄挏挏掞</td>
193<td>安党</td>                         
194</tr>
195<tr class="collapse-show" style="display: none; ">
196<td colspan="2">
197<div style="clear:both;">
198        <div class="expand-title">诊细内容</div>
199        <div class="expand-content">圓前应甚皋序代码混淆率䞺: 85.52%,源码文件数: 2085, 未混淆文件数: 302</div>
200</div>
201<div style="clear:both;">
202        <div class="expand-title">修倍建议</div>
203        <div class="expand-content">无</div>
204</div>
205</td>
206</tr><tr>
207<td class="td-collapse collapse">【䞭危】随机数加密砎解挏掞</td>
208<td>安党</td>                         
209</tr>
210<tr class="collapse-show" style="display: none; ">
211<td colspan="2">
212<div style="clear:both;">
213        <div class="expand-title">诊细内容</div>
214        <div class="expand-content">SecureRandom密码挏掞检测通过<br></div>
215</div>
216<div style="clear:both;">
217        <div class="expand-title">修倍建议</div>
218        <div class="expand-content">无</div>
219</div>
220</td>
221</tr><tr>
222<td class="td-collapse expand"><font color="orange">【䞭危】https敏感数据劫持挏掞</font></td>
223<td><font color="orange">发现2倄</font></td>                        
224</tr>
225<tr class="collapse-show" style="display: table-row; ">
226<td colspan="2">
227<div style="clear:both;">
228        <div class="expand-title">诊细内容</div>
229        <div class="expand-content">皋序䞭存圚以䞋api可胜富臎https加密䌠蟓劫持挏掞<br>com\imofan\android\develop\sns\MFSnsSSLSocketFactoryEx$1.java(new X509TrustManager):L19: public void checkServerTrusted(X509Certificate[] paramArrayOfX509Certificate, String paramString)<br>com\imofan\android\develop\sns\MFSnsHttpUtil.java:L77: localMFSnsSSLSocketFactoryEx.setHostnameVerifier(SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER);<br></div>
230</div>
231<div style="clear:both;">
232        <div class="expand-title">修倍建议</div>
233        <div class="expand-content">建议对自定义的X509TrustManager实现对证乊的䞥栌校验setHostnameVerifier接口请讟眮安党选项级别劂STRICT_HOSTNAME_VERIFIER</div>
234</div>
235</td>
236</tr><tr>
237<td class="td-collapse expand"><font>【䞭危】系统组件本地拒绝服务挏掞检测</font></td>
238<td>超时</td>                         
239</tr>
240<tr class="collapse-show" style="display: table-row; ">
241<td colspan="2">
242<div style="clear:both;">
243        <div class="expand-title">诊细内容</div>
244        <div class="expand-content">%SUBDETAILLEAKMIDDLE10%</div>
245</div>
246<div style="clear:both;">
247        <div class="expand-title">修倍建议</div>
248        <div class="expand-content">泚册的组件请䞥栌校验蟓入参数泚意空倌刀定和类型蜬换刀断防止由于匂垞蟓入富臎的应甚厩溃</div>
249</div>
250</td>
251</tr></tbody>
252</table>
253<div class="separate">&nbsp;</div><table class="tb-comm">
254        <thead>
255                <tr><td colspan="2"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_danger_detail.png">&nbsp;风险诊情</td></tr>
256        </thead>
257        <tbody class=""><tr>
258<td class="td-first-2  td-collapse expand">Activity组件暎露风险</td>
259<td><span class="font-danger">有风险</span></td>                            
260</tr>
261<tr class="collapse-show" style="display: table-row; ">
262<td colspan="2">
263<div style="clear:both;">
264        <div class="expand-title">诊细内容</div>
265        <div class="expand-content">以䞋Activity接口可被其它应甚调甚甚于执行特定的敏感操䜜或钓鱌欺骗建议添加 android:exported="false"<br>若需芁倖郚调甚需自定义signature或者signatureOrSystem级别的权限<br>cn.com.pcgroup.android.common.cropphoto.CropActivity<br>com.tencent.tauth.AuthActivity<br>cn.jpush.android.ui.PushActivity<br></div>
266</div>
267<div style="clear:both;">
268        <div class="expand-title">修倍建议</div>
269        <div class="expand-content">无需暎露的组件请讟眮exported=”false”若需芁倖郚调甚建议添加自定义signature或signatureOrSystem级别的私有权限保技需芁暎露的组件请䞥栌检查蟓入参数避免应甚出现拒绝服务。</div>
270</div>
271</td>
272</tr><tr>
273<td class="td-collapse collapse">Service组件暎露风险</td>
274<td><span class="font-safe">安党</span></td>                         
275</tr>
276<tr class="collapse-show" style="display: none; ">
277<td colspan="2">
278<div style="clear:both;">
279        <div class="expand-title">诊细内容</div>
280        <div class="expand-content">service权限检测通过<br></div>
281</div>
282<div style="clear:both;">
283        <div class="expand-title">修倍建议</div>
284        <div class="expand-content">无</div>
285</div>
286</td>
287</tr><tr>
288<td class="td-collapse expand">BroadcastReceiver组件暎露风险</td>
289<td><span class="font-danger">有风险</span></td>                            
290</tr>
291<tr class="collapse-show" style="display: table-row; ">
292<td colspan="2">
293<div style="clear:both;">
294        <div class="expand-title">诊细内容</div>
295        <div class="expand-content">以䞋广播可被倖郚调甚富臎敏感信息泄露,建议讟眮android:exported="false"<br>若需芁倖郚调甚需定义signature或者signatureOrSystem级别的权限<br>com.imofan.android.basic.notification.MFAlarmReceiver<br>com.imofan.android.basic.MofangReceiver<br>cn.com.pcgroup.android.common.jpush.JPushReceiver<br>cn.jpush.android.service.PushReceiver<br>com\tencent\a\b\f.java:L381: b.registerReceiver(P, new IntentFilter("android.net.conn.CONNECTIVITY_CHANGE"));<br>com\tencent\a\b\g.java:L87: a.registerReceiver(c, localIntentFilter);<br>com\tencent\mm\sdk\platformtools\LBSManager.java:L236: R.registerReceiver(this, localIntentFilter);<br>com\tencent\mm\sdk\plugin\MMPluginAPIImpl.java:L153: R.registerReceiver(bz, new IntentFilter("com.tencent.mm.sdk.plugin.Intent.ACTION_QRCODE_SCANNED"));<br></div>
296</div>
297<div style="clear:both;">
298        <div class="expand-title">修倍建议</div>
299        <div class="expand-content">无需暎露的组件请讟眮exported="false"若需芁倖郚调甚建议添加自定义signature或signatureOrSystem级别的私有权限保技需芁暎露的组件请䞥栌检查蟓入参数避免应甚出现拒绝服务。<br>进皋内劚态广播泚册建议䜿甚LocalBroadcastManager或者䜿甚registerReceiver(BroadcastReceiver, IntentFilter, broadcastPermission, Handler)替代registerReceiver(BroadcastReceiver, IntentFilter)</div>
300</div>
301</td>
302</tr><tr>
303<td class="collapse td-collapse">ContentProvider组件暎露风险</td>
304<td><span class="font-safe">安党</span></td>                         
305</tr>
306<tr class="collapse-show">
307<td colspan="2">
308<div style="clear:both;">
309        <div class="expand-title">诊细内容</div>
310        <div class="expand-content">provider权限检测通过<br></div>
311</div>
312<div style="clear:both;">
313        <div class="expand-title">修倍建议</div>
314        <div class="expand-content">无</div>
315</div>
316</td>
317</tr><tr>
318<td class="td-collapse expand">自定义权限滥甚风险</td>
319<td><span class="font-danger">有风险</span></td>                            
320</tr>
321<tr class="collapse-show" style="display: table-row; ">
322<td colspan="2">
323<div style="clear:both;">
324        <div class="expand-title">诊细内容</div>
325        <div class="expand-content">以䞋权限䞺"normal"权限,可胜富臎敏感信息泄露,建议修改䞺"signature"或者"signatureOrSystem"<br>com.juchaozhi.permission.JPUSH_MESSAGE<br></div>
326</div>
327<div style="clear:both;">
328        <div class="expand-title">修倍建议</div>
329        <div class="expand-content">私有权限建议讟眮signature或者signatureOrSystem的保技级别</div>
330</div>
331</td>
332</tr><tr>
333<td class="td-collapse expand">Intent组件数据组件泄露风险</td>
334<td><span class="font-danger">有风险</span></td>                            
335</tr>
336<tr class="collapse-show" style="display: table-row; ">
337<td colspan="2">
338<div style="clear:both;">
339        <div class="expand-title">诊细内容</div>
340        <div class="expand-content">以䞋intent存圚安党劫持风险, 建议采甚setClassName星匏调甚<br>cn\jpush\android\api\d.java:localIntent.setAction(z[7]);<br></div>
341</div>
342<div style="clear:both;">
343        <div class="expand-title">修倍建议</div>
344        <div class="expand-content">建议䜿甚星匏调甚方匏发送Intent进皋内发送消息建议䜿甚LocalBroadcastManager或者䜿甚sendBoardcast(Intent, receiverPermission)替代sendBoardcast(Intent)</div>
345</div>
346</td>
347</tr><tr>
348<td class="collapse td-collapse">Keystore挏掞检测</td>
349<td><span class="font-safe">安党</span></td>                         
350</tr>
351<tr class="collapse-show">
352<td colspan="2">
353<div style="clear:both;">
354        <div class="expand-title">诊细内容</div>
355        <div class="expand-content">检测通过<br></div>
356</div>
357<div style="clear:both;">
358        <div class="expand-title">修倍建议</div>
359        <div class="expand-content">无</div>
360</div>
361</td>
362</tr><tr>
363<td class="collapse td-collapse">私有文件泄挏风险</td>
364<td><span class="font-safe">安党</span></td>                         
365</tr>
366<tr class="collapse-show">
367<td colspan="2">
368<div style="clear:both;">
369        <div class="expand-title">诊细内容</div>
370        <div class="expand-content">MODE_WORLD_READABLE/MODE_WORLD_WRITEABLE挏掞检测通过<br></div>
371</div>
372<div style="clear:both;">
373        <div class="expand-title">修倍建议</div>
374        <div class="expand-content">无</div>
375</div>
376</td>
377</tr></tbody>
378</table>
379<div class="separate">&nbsp;</div><table class="tb-comm">
380        <thead>
381                <tr><td colspan="2"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_safe_tip.png">&nbsp;安党提瀺</td></tr>
382        </thead>
383        <tbody class=""><tr>
384<td class="td-first-2  collapse td-collapse">敏感权限䜿甚</td>
385<td>发现6倄</td>                            
386</tr>
387<tr class="collapse-show">
388<td colspan="2">
389<div style="clear:both;">
390        <div class="expand-content">皋序䞭存圚以䞋敏感权限<br>android.permission.READ_PHONE_STATE    允讞访问电话状态、讟倇信息<br>android.permission.GET_TASKS 允讞获取应甚列衚<br>android.permission.CAMERA   å…è®žè®¿é—®æ‘„像倎拍照<br>android.permission.RECEIVE_BOOT_COMPLETED        允讞皋序匀机自劚运行<br>android.permission.MOUNT_UNMOUNT_FILESYSTEMS  允讞挂蜜、反挂蜜倖郚文件系统<br>android.permission.READ_LOGS      允讞读取敏感日志数据<br></div>
391</div>
392</td>
393</tr><tr>
394<td class="collapse td-collapse">第䞉方库安党检测</td>
395<td>安党</td>                         
396</tr>
397<tr class="collapse-show">
398<td colspan="2">
399<div style="clear:both;">
400        <div class="expand-content">检测通过,未包含已知第䞉方库<br></div>
401</div>
402</td>
403</tr></tbody>
404</table>
405<div class="separate">&nbsp;</div><table class="tb-comm">
406        <thead>
407                <tr><td colspan="2"><img class="icon" src="./金刚安党检测-聚超倌app_files/ico_screen_shot.png">&nbsp;运行截囟</td></tr>
408        </thead>
409        <tbody class=""><tr><td>
410<img class="icon" src="./金刚安党检测-聚超倌app_files/7663b13035e9eaa95a4fb257e741559c.png" style="width:240px;height:400px;">&nbsp;
411</td></tr></tbody>
412</table>
413<div class="separate">&nbsp;</div><div class="separate">&nbsp;</div>
414                                <div class="separate">&nbsp;</div>
415                                <table class="tb-footer">
416<tbody><tr><td align="center" style="font-size:14px">  小K初来乍到还有讞倚地方需芁完善有任䜕BUG和建议请随时联系我security@tencent.com  </td></tr>
417                                        <tr><td align="center" style="">    Powered By KingKong</td></tr>
418                                </tbody></table></td></tr></tbody></table></body></html>