https://sparkle-project.org/documentation/security/
http://www.macrumors.com/2016/02/09/sparkle-hijacking-vulnerability/
https://www.evilsocket.net/2016/01/30/osx-mass-pwning-using-bettercap-and-the-sparkle-updater-vulnerability/
一些采用该框架的软件列表
https://github.com/sparkle-project/Sparkle/issues/717
比如 http://www.xquartz.org/releases/index.html 用的是 HTTP Feed
defaults write org.macosforge.xquartz.X11 SUFeedURL http://www.xquartz.org/releases/sparkle/beta.xml
1
rushcheyo 2016-02-11 10:13:05 +08:00
咦?不早就修复了吗? MacDown 的 release notes 里还写了。
|