作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2013, Vol. 39 ›› Issue (1): 313-317. doi: 10.3969/j.issn.1000-3428.2013.01.069

• 开发研究与设计技术 • 上一篇    下一篇

IE8.0登录信息保护机制的缺陷分析与利用

张 航,吴 灏,许 蓉   

  1. (国家数字交换系统工程技术研究中心,郑州 450002)
  • 收稿日期:2011-10-18 修回日期:2011-12-01 出版日期:2013-01-15 发布日期:2013-01-13
  • 作者简介:张 航(1986-),女,硕士,主研方向:网络安全;吴 灏,教授;许 蓉,硕士

Analysis and Utilization of Flaw for IE8.0 Login Information Protection Mechanism

ZHANG Hang, WU Hao, XU Rong   

  1. (National Digital Swich System Engineering & Technological R&D Center, Zhengzhou 450002, China)
  • Received:2011-10-18 Revised:2011-12-01 Online:2013-01-15 Published:2013-01-13

摘要: 为有效获取Windows 7操作系统自带IE 8.0浏览器的登录信息,从存储策略和加密机制2个方面,对IE登录信息的保护机制进行分析,研究保护机制的不足,根据用户对IE的安全设置,提出拦截历史记录的还原方法。在拦截用户访问网站地址的基础上,筛选出登录信息对应的网站地址,获取解密密钥,得到用户自动保存的登录信息。实验结果表明,该方法能够在用户进行安全设置后,有效获取用户自动保存的登录信息。

关键词: Windows 7操作系统, 浏览器, 登录信息, 保护机制, 存储策略

Abstract: In order to get the browser IE8.0 login information of Windows 7 operating system, by analyzing two aspects of the login information storage policy and encryption mechanism, in the study of the shortcomings of the protective mechanism. For user’s security settings for IE, this paper proposes a reduction method to intercept the historical records. On the basis of the interception user access the Web site address, it filters out the Web site address to obtain the decryption key, and gets the login information which is automatically saved by users. Experimental results show that this method can effectively obtain the user’s login information which is established by user’s security settings

Key words: Windows 7 operating system, browser, login information, protection mechanism, storage strategy

中图分类号: