这种security model根本没什么太大意义,code, kernel里面有bug,很容易就让人绕 过sandbox然后compromise了。 刚结束的pwn2own结果: Vupen Security, the French security and hacking company, cracked IE 10. Vupen reported, via Twitter, that they "pwned MS Surface Pro with two IE10 zero-days to achieve a full Windows 8 compromise with sandbox bypass." 不知道是win8不够secure还是IE10不够secure,反正是如果真的想hack,什么security 都是小儿科
【在 c*c 的大作中提到】 : 这种security model根本没什么太大意义,code, kernel里面有bug,很容易就让人绕 : 过sandbox然后compromise了。 : 刚结束的pwn2own结果: : Vupen Security, the French security and hacking company, cracked IE 10. : Vupen reported, via : Twitter, that they "pwned MS Surface Pro with two IE10 zero-days to achieve : a full Windows 8 compromise with sandbox bypass." : 不知道是win8不够secure还是IE10不够secure,反正是如果真的想hack,什么security : 都是小儿科