Ô´´·Òë°æÈ¨ËùÓУ¬ÈçÓû×ªÔØ£¬Çë±êÃ÷Ô´´·Òë×÷ÕßÓë±¾ÎÄÖÐÎijö´¦£ºÈüµÏÍø¡£Î¥Õߣ¬½«×·¾¿ÆäÏàÓ¦·¨ÂÉÔðÈΣ¡
¡°ÌìÄÄ£¬ÎÒÔÙÒ²²»ÉÏÍøÁË£¡¡±ÕâÊÇÎÒÉÏÍø±»ºÚÁ˺óµÄµäÐÍ·´Ó¦¡£×î½üÎÒÓÃ×Ô¼ºµÄ¾ÀúÑéÖ¤ÁËÆÕÍ¨ÍøÕ¾»òÕßÓû§ÊǶàôÈÝÒ×±»ºÚ¡£ºÁÎÞÒÉÎÊ£¬ÈËÃÇÌýÁËÌ«¶à¹ØÓÚÕâ·½ÃæµÄËÊÈËÌýÎŵı¨µÀ£¬²¢ÇÒÒâʶµ½Ç¡µ±µÄ°²È«´ëÊ©µÄ±ØÒªÐÔ¡£ÈËÃǾ³£ÎÊÎÒÊÇ·ñ»¹ÓÃÍøÉÏÒøÐлòÕßÍøÉϹºÎ﹦ÄÜ£¬»òÕßÎÊÔÚʹÓÃÕâЩ¹¦ÄܵÄʱºò£¬ÔõÑù±£»¤×Ô¼ºµÄÐÅÏ¢¡£ÕâÀïÓÐ5¸öÇÏÃÅ£¬¶ÔÓÚÄÇЩ²»ÊǵçÄÔ°²È«×¨¼ÒµÄÈËÃÇÀ´Ëµ£¬ËüÃÇÄÜÈÃÄã¸ü°²È«µÄÔÚÍøÉϳåÀË£¨°üÀ¨·À»ðǽ£¬·À¶¾Èí¼þÒÔ¼°¾³£´ò²¹¶¡£©¡£
1£©Ê¹ÓÃFirefox, Mozilla, Safari»òÕßÈκÎIEÖ®ÍâµÄä¯ÀÀÆ÷
Õâ¿ÉÄÜÊÇÄ㰲ȫÉÏÍøµÄΨһ×îÖØÒªµÄÒ»¼þÊÂÁË¡£ÎÒÒÔǰ˵¹ý£¬ÎÒ±£Ö¤×Ô¼º°²È«µÄ°ì·¨¾ÍÊÇÔ¶Àë²»°²È«µÄÊÂÎï¡£IEÒÔÒ×Êܲ¡¶¾£¬¼äµýÈí¼þÒÔ¼°¹ã¸æÈí¼þ¹¥»÷¶øÖø³Æ¡£¾¡¹Ü£¬ÎÒÖªµÀ΢Èí¼´½«·¢²¼±¸ÊÜÆÚÍûµÄIE7.0£¬¾Ý˵½«ÊÇ×ȫµÄä¯ÀÀÆ÷¡£Ëü¸üÐÂÈç´Ë¿ìµÄÔÒòÊÇËü×ÜÊÇÔâµ½¹¥»÷¶ø²»µÃ²»Éý¼¶£¡ÕâÊÇÒ»¸ö¶ñÒâ¹¥»÷ÕߺÜϲ»¶µÄÒ»¸ö¹¥»÷Ä¿±ê¡£ÔÚÎÒ¿´À´£¬×îºÃÓÃÆäËûµÄ²úÆ·£¬Ô¶ÀëÂé·³¡£Èç¹ûÉÏÄ³Ð©ÍøÕ¾È·ÊµÐèҪʹÓÃIE¶øÄãȷʵÐèÒª·ÃÎÊËü£¬ÄÇÄã¾ÍµÃÈ·±£Õâ¸öÕ¾µãÊǺϷ¨µÄ£¬È·±£Ëü¶ÔIEÊǰ²È«µÄ¡£
2)Ìá¸ßÍøÂçä¯ÀÀÆ÷µÄ°²È«ÐÔ
ÎÞÂÛÄãÑ¡ÔñÄÄ¿îä¯ÀÀÆ÷£¬ÍøÂçʼÖÕÊǸö³äÂúΣÏյĵط½¡£Äã¶¼ÐèÒª²ÉȡЩ´ëÊ©À´±£»¤ÄãµÄä¯ÀÀÆ÷¡£NoScript (Firefox À©Õ¹°æ), Netcraft ·´µöÓ㹤¾ßÌõ, E-Bay¹¤¾ßÌõ, ÒÔ¼°Google¹¤¾ßÌõ¶¼ÊDz»´íµÄ¹¤¾ß¡£ÕâЩ²å¼þ°ïÖúÄãʶ±ðµöÓãÍøÕ¾£¬±£»¤Äã²»±»ºÚ¿ÍÏ®»÷ÒÔ¼°²»ÈÃÄãµÄÃÜÂ뱻й©¸ø±ðÈË¡£´ó²¿·ÖÈËÖ»ÐèҪǰÁ½¸ö²å¼þ¾Í¿ÉÒÔÁË£¬µ«Èç¹ûÄãÔÚE-BayÉÏÂò¶«Î÷£¬µ±È»»¹ÊÇʹÓÃËûÃǵŤ¾ßÌõ±È½ÏºÃ¡£
3£©±ðµã»÷ÓʼþÖеÄÁ´½Ó
¾¡¿ÉÄܲ»µã»÷ÓʼþÖеÄÈκÎÁ´½Ó£¬ÕâЩÁ´½Ó±¾Éí¾Í·Ç³£Î£ÏÕ£¬¸ü²»ÓÃ˵ÄãÓÖºÜÄÑʶ±ðµöÓãÓʼþÁË¡£Èç¹ûÎÒ²»È·¶¨ÓʼþÊÇ·ñ°²È«£¬ÎҾͻá°ÑÓʼþµÄÓòÃûÊäÈëµ½ÍøÂçä¯ÀÀÆ÷µÄµØÖ·À¸ÖС£ÕâÑù£¬ÎÒ¿ÉÒÔÖªµÀÕâ¸öµØÖ·ÊDz»ÊÇÕæµÄ¡£Èç¹ûWells FargoÐèÒªÑéÖ¤ÎÒµÄÕÊ»§ÐÅÏ¢£¬ÈÃÎÒ¡°µã»÷ÕâÀ£¬ÎÒ¾ÍÔÚµØÖ·À¸ÊäÈëwellsfargo.comÈ»ºóµÇÈë¡£Èç¹ûWells Fargo(»òÕß²»¹ÜÄã´ò½»µÀ)£¬ËüȷʵÐèÒªÑéÖ¤ÄãµÄÕÊ»§ÐÅÏ¢µÄ»°£¬ËûÃÇ»áÔÚÍøÕ¾ÉÏÒ²ÕâôҪÇóµÄ¡£ÓÐЩÓʼþÖеÄÁ´½ÓÏà¶Ô±ÈÁíһЩ°²È«¡£±ÈÈçÄÇЩÊǶÔÄãµÄһЩÐж¯µÄ·´À¡µÄÓʼþ£¨ÕʺÅ×¢²á£¬¸ü¸ÄÃÜÂ룬ҪÇóÈ·Èϵȵȣ©£¬ÕâЩ¶¯×÷¿ÉÄÜÊÇÄ㼸·ÖÖÓǰÔÚÍøÉϲÙ×÷¹ý£¬ËùÒÔϵͳ×Ô¶¯·¢¹ýÀ´·´À¡Óʼþ¡£
4£©±£»¤ÍøÂçÓʼþ
³ÉǧÉÏÍòµÄÈËÃÇʹÓÃÍøÂçÓʼþ£¬Òò´ËijÖ̶ֳÈÉÏÀ´Ëµ±£»¤µç×ÓÓʼþ±È±£»¤ÄãµÄÒøÐÐÕË»§¸üÖØÒª¡£ºÜ¶àÈ˰ÑÐ©ÖØÒªµÄÏßÉÏÕË»§¸úÍøÂçÓʼþµØÖ·°ó¶¨¡£Èç¹ûÓÐÈËÄܹ»·ÃÎÊÄãµÄÓʼþÕË»§£¬¸úÕâ¸öÕË»§°ó¶¨µÄËùÓÐÕË»§¶¼ÓпÉÄÜй©µÄ¡£Äã×îºÃʹÓÃÎÞ·¨ÆÆ½âµÄÃÜÂ룬²î²»¶àÿÁù¸öÔ¸ü»»ÃÜÂ룬²¢ÇÒ²»ÔÚ²»Í¬µÄµØ·½Ê¹ÓÃÏàͬµÄÃÜÂë¡£¼°Ê±É¾³ý´øÓÐÃô¸ÐÐÅÏ¢µÄÓʼþ½«ÈÃÄã¸ü°²È«¡£
5£©ÏßÉϹºÎïʱʹÓõ¥¶ÀµÄÒ»¸öÐÅÓÿ¨
¸ù¾Ý×î½üµÄһЩʼþËùÊö£¬ÎÒÃÇÔÚÍøÉÏʹÓÃÐÅÓÿ¨£¬¿¨µÄÃÜÂëÔÚijЩվµãÓб»Ð¹Â©µÄ¿ÉÄÜ¡£×îºÃµÄ°ì·¨¾ÍÊǾ¡¿ÉÄܵؼõСµÄËðʧ¡£ÏßÉϽ»Ò×ʱʹÓÃÒ»¸öµ¥¶ÀÐÅÓÿ¨£¬²¢ÏÞÖÆËüµÄÊÊÓ÷¶Î§£¬ÕâÑù¿ÉÒÔ·½±ãÄã¼àÊÓÄãÐÅÓÿ¨µÄÈÎºÎÆæ¹ÖµÄ½»Òס£ÁíÍ⣬¼´Ê¹Éϵ±ÊÜÆ£¬ËðʧҲ»áÖ»¾ÖÏÞÔÚÄÇÒ»ÕÅ¿¨¡£»¹ÓУ¬¾¡Á¿ÉÙʹÓýè¼Ç¿¨£¬ÒòΪÕâЩ¿¨²»Ìṩ¸úÐÅÓÿ¨Ò»ÑùµÄÏû·Ñ·¨Âɱ£»¤¡£
ͨ³£×¨¼Òµ½ÕâÀï¾Í»á¿ªÊ¼½²SSL£¬²¢ÇÒ¸æËßÄã¿ÉÒÔ¼ì²éËø·ûºÅ¡£¸ù¾ÝÎҵľÑ飬½ÓÊÜÐÅÓÿ¨µÄºÏ·¨ÍøÕ¾¶¼Ö§³ÖSSL¡£ËùÒÔÎÒ½¨ÒéÄãÈ·±£×Ô¼ºÊÇÕæµÄÔÚ·ÃÎÊÄãÒª·ÃÎʵÄÕ¾µã¡£·ñÔòSSL²¢²»»áÆðʲô×÷Óá£
=============================================
ÔÎÄÁ´½Ó£ºhttp://www.net-security.org/article.php?id=947
ÔÎÄ×÷ÕߣºJeremiah Grossman
ÎÄÕÂÕûÀí£ºÎ÷²¿ÊýÂë--רҵÌṩÓòÃû×¢²á¡¢ÐéÄâÖ÷»ú·þÎñ
http://www.west263.com
ÒÔÉÏÐÅÏ¢ÓëÎÄÕÂÕýÎÄÊDz»¿É·Ö¸îµÄÒ»²¿·Ö,Èç¹ûÄúÒª×ªÔØ±¾ÎÄÕÂ,Çë±£ÁôÒÔÉÏÐÅÏ¢£¬Ð»Ð»!




