腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] 日志注入以及不安全的 tail -f: https://disconnect3d.pl/2018/02/24/log-injection-aka-tailing-logs-is-unsafe/
-
[ Others ] Hack 游戏模拟器,单人游戏变双人游戏: https://mcclure.github.io/emu-coop/https://mcclure.github.io/emu-coop/MODDING.html
-
[ Programming ] 用 IDAPython 写一个简单的 x86 模拟器: http://0xeb.net/2018/02/writing-a-simple-x86-emulator-with-idapython/
-
[ ReverseEngineering ] 使用 Frida 逆向分析 Android 应用与 BLE 设备的通信: https://www.pentestpartners.com/security-blog/reverse-engineering-ble-from-android-apps-with-frida/
-
[ Web Security ] 挖掘 help.twitter.com 上持久化 DOM XSS 漏洞的详情: https://hackerone.com/reports/297968
-
[ Windows ] .Net over .net – Breaking the Boundaries of the .Net Framework : https://jimshaver.net/2018/02/22/net-over-net-breaking-the-boundaries-of-the-net-framework/
-
[ Windows ] SMBv3 空指针反引用漏洞分析,包含PoC(CVE-2018-0833): https://krbtgt.pw/smbv3-null-pointer-dereference-vulnerability/