理想天空
理想天空
  • 发布:2023-04-15 15:25
  • 更新:2023-04-15 22:05
  • 阅读:448

安全漏洞问题

分类:uni-app

我们的app被国家计算机网络应急技术处理协调中心扫描发现以下漏洞,一看应该不是我们代码的,请uniapp官方看看是否是你们这边的代码?

漏洞类型:本地数据存储安全

检测项:动态调试攻击风险

危害:
如果App存在C层代码动态调试的风险,攻击者可以利用GDB、IDA、Ptrace等调试器跟踪运行的目标程序,查看、修改内存中的代码和数据,甚至分析篡改程序的业务逻辑,对客户关键数据或者服务器进行恶意攻击,例如修改客户端业务操作的数据,比如转账账号、金额等,导致用户的损失。

日志Error while mapping shared library sections:Could not open `target:/system/app/webview/webview.apk!/lib/x86_64/libwebviewchromium.so' as an executable file: No such file or directorywarning: section .dynsym not found in target:/system/framework/x86_64/boot.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot.oatwarning: section .hash not found in target:/system/framework/x86_64/boot.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-core-libart.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-core-libart.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-core-libart.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-core-libart.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-conscrypt.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-conscrypt.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-conscrypt.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-conscrypt.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-okhttp.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-okhttp.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-okhttp.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-okhttp.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-core-junit.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-core-junit.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-core-junit.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-core-junit.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-bouncycastle.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-bouncycastle.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-bouncycastle.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-bouncycastle.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-ext.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-ext.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-ext.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-ext.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-framework.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-framework.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-framework.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-framework.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-telephony-common.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-telephony-common.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-telephony-common.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-telephony-common.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-voip-common.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-voip-common.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-voip-common.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-voip-common.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-ims-common.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-ims-common.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-ims-common.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-ims-common.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-apache-xml.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-apache-xml.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-apache-xml.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-apache-xml.oatwarning: section .dynsym not found in target:/system/framework/x86_64/boot-org.apache.http.legacy.boot.oatwarning: section .dynstr not found in target:/system/framework/x86_64/boot-org.apache.http.legacy.boot.oatwarning: section .hash not found in target:/system/framework/x86_64/boot-org.apache.http.legacy.boot.oatwarning: section .dynamic not found in target:/system/framework/x86_64/boot-org.apache.http.legacy.boot.oat0x00007f0facdc444a in __epoll_pwait () from target:/system/lib64/libc.so

2023-04-15 15:25 负责人:无 分享
已邀请:
FullStack

FullStack - 【插件开发】【专治疑难杂症】【ios上架、马甲包、白包、过审、已成功上架过几百个】【多款插件已上架:https://ext.dcloud.net.cn/publisher?id=22130】【非诚勿扰】QQ:543610866

可以对app进行加固

该问题目前已经被锁定, 无法添加新回复