
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Android Security Bulletin February 2017 http://source.android.com/security/bulletin/2017-02-01.html
"Android 安全公告 - 2017 年 2 月: https://t.co/DYYpvC5GgJ"
-
[ Browser ] IE11 UXSS / SOP bypass - Abusing of the ActiveXObject to access content across domains without restrictions.… https://t.co/KWjyv4XmW6
"IE11 UXSS / SOP 绕过,利用 ActiveXObject 跨域访问资源: https://t.co/KWjyv4XmW6"
-
[ Browser ] V8 5.7 news! ? ES2017 async functions now as fast as Promises ⚡️⚡️ Promises perf doubled ? 15% faster RegExp… https://t.co/LbQAIdo4tu
"V8 JavaScript Engine 5.7 版本发布: https://t.co/LbQAIdo4tu"
-
[ Industry News ] Hacker hijacks thousands of publicly exposed printers to warn owners, by @ lconstantin - http://bit.ly/2kzvblT #infosec
"数以千计的打印机被黑客劫持,受迫打印出劫持消息: https://t.co/aNr6gOoAM5 "
-
[ Linux ] Very cool. The comparison to SSP hits it home. Perf win and more with no tradeoffs vs SSP. https://twitter.com/paxteam/status/828600806500876288
"Linux Kernel 4.9 加入 RAP(Reuse Attack Protector 复用攻击保护) 机制: https://grsecurity.net/rap_announce_ret.php"
-
[ Operating System ] Remote DoS against OpenBSD http server (up to 6.0) https://goo.gl/fb/eNMIUx #FullDisclosure
" OpenBSD http server (版本 > 6.0) 存在远程拒绝服务攻击(CVE-2017-5850): https://t.co/ohWccVDxeB "
-
[ Others ] High-reputation Redirectors and Domain Fronting http://blog.cobaltstrike.com/2017/02/06/high-reputation-redirectors-and-domain-fronting https://t.co/pxmqVX4ypi
" 利用 Amazon 的 CloudFront 做高信誉的转发器及 Domain Fronting: https://t.co/CjSg1W2uMy https://t.co/pxmqVX4ypi"
-
[ Others ] [KIS-2017-01] PEAR HTML_AJAX <= 0.5.7 (PHP Serializer) PHP Object Injection… https://goo.gl/fb/xGzkHS #FullDisclosure
"PEAR HTML_AJAX 版本 <= 0.5.7 存在 PHP 对象注入漏洞(CVE-2017-5677): https://t.co/NNjOK0TKgA "
-
[ Virtualization ] Script to create templates to use with VirtualBox to make vm detection harder https://github.com/nsmfoo/antivmdetection #malware
"面向 VirtualBox 的反虚拟机检测脚本: https://t.co/7VdbLkzseb "
-
[ Windows ] Demystifying #Windows Virtualization Based #Security - Part 1: The boot process - http://blog.amossys.fr/virtualization-based-security-part1.html #VBS #DeviceGuard #CredentialGuard
"Windows 虚拟化安全 Part 1: https://t.co/HjMRdWogk8 "
-
[ Windows ] Researchers have discovered that media content protected by DRM can be used to uncloak Windows Tor Browser users. https://t.co/1U59Vm7R87
"有研究人员发现利用 Windows DRM(数字媒体版权管理)可以获取 Windows TOR 浏览器用户的真实 IP: https://t.co/1U59Vm7R87"
-
[ WirelessSecurity ] gr-keyfob. GNU Radio module to receive and reencode signals of (some) wireless car key fobs https://github.com/bastibl/gr-keyfob https://t.co/AMO2JnqnBH
" gr-keyfob -- Hella 无线车钥匙收发器的信号处理工具: https://t.co/qOyNs6cgTu https://t.co/AMO2JnqnBH"
-
[ WirelessSecurity ] Somebody's been looking for integer overflows in QCOM drivers. F.e CVE-2016-8476: EoP in Qualcomm WiFi driver https://t.co/ScGA6mCNEQ
"高通 wifi 驱动整数溢出漏洞的补丁代码: https://t.co/ScGA6mCNEQ "