腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Debug ] JavaScript AntiDebugging Tricks: https://x-c3ll.github.io/posts/javascript-antidebugging/
-
[ Forensics ] Docker 环境中的事件分析与取证: https://static.ernw.de/whitepaper/ERNW_Whitepaper64_IncidentForensicDocker_signed.pdf
-
[ Industry News ] Github 宣布移除匿名用户创建 gist 的功能: https://github.com/blog/2503-deprecation-notice-removing-anonymous-gist-creation
-
[ iOS ] 苹果发布 iOS 11.2.6/macOS High Sierra 10.13.3,解决坏字符导致崩溃的问题: https://support.apple.com/en-us/HT208535https://support.apple.com/en-us/HT208534
-
-
[ MalwareAnalysis ] 对 jRAT/Adwind 恶意变种的技术分析: https://blog.fortinet.com/2018/02/16/new-jrat-adwind-variant-being-spread-by-ups-scam5a861017942e7
-
[ Others ] 我是如何在 bug bounty 项目中绕过双因素认证的: http://c0d3g33k.blogspot.it/2018/02/how-i-bypassed-2-factor-authentication.html
-
[ Others ] Bypasss User-Mode Hooks: https://secrary.com/Random/BypassUserHooks/
-
[ Popular Software ] 对 7-Zip 中两个有趣的微补丁的分析 (CVE-2017-17969 、CVE-2018-5996): https://0patch.blogspot.com/2018/02/two-interesting-micropatches-for-7-zip.html
-
-
[ Tools ] elf-parser - 轻量级 ELF 二进制头解析工具: https://github.com/finixbit/elf-parser
-
[ Tools ] 基于 S2E 符号执行分析平台自动化地发现漏洞、生成 PoC: https://github.com/S2E/docs/blob/master/src/Tutorials/pov.rst