The Qihoo 360 backdoor Midao surfaced


Chinese-style Apples


The independent investigators deliberately installed in a virtual machine for testing full Qihoo 360 products, and thus found 360 products, many do not behave behavior ", he readily publish these findings microblogging immediately drew a lot of attentionbut has also been some attacks."Some people obviously is of Qihoo 360 people in provocative, it angered me, I do not like to pay lip service, software professionals, I talk about the evidence," independent investigators so said.

Independent investigators found a very abnormal situation, Qihoo 360 browser network communication, "the most just found its Time cyclical: every five minutes, the browser will initiate the communication process between the time with the server, although it does not knowdoing, but its short the cyclical very suspicious. "

Why not open any page and does not move the keyboard and mouse, Qihoo 360 browser still too busy to do? "All domestic and foreign well-known browser does not exist such a pattern of behavior can be sure, there is a world there must be something wrong".

Thus, on October 29 last year through the microblogging announced the the Qihoo 360 browser backdoor fact.

The independent investigators Direct scolded: "The company's '360 Qihoo 360 security browser 'hidden' back door ', is a serious potential threat to the user system security and information security.

"By process of elimination, the final confirmation is the extended component SmartWiz in dirty tricks. Delete it, the browser on the quiet that one five minutes Upload assigned activities disappear."

However, it is not over yet.To further check minch Tiger 360 backdoor truth, independent investigators need to reverse compile assembly code and tracking test.

Independent investigator to master the 360 browser in SmartWiz entire assembly to establish communication between Qihoo 360 server, download, temporary storage, perform load, and delete (destruction of evidence) of the process through a series of technical processes, but also know its clock control scheduling mechanism (5-minute interval timer).

  • Qihoo 360: Internet "goldenrod"
  • The Qihoo 360 backdoor: kidnapping user remote control
  • Qihoo 360 backdoor Shame of security

No comments:

Post a Comment