腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ iOS ] 我是如何在 iOS 上发现 Instagram 即将推出的视频通话功能的: https://medium.com/@guilhermerambo/how-i-discovered-instagrams-upcoming-video-calling-feature-on-ios-934d7085da57
-
[ Mitigation ] 挖掘隐藏在堆栈中的宝藏—通过栈数据修改绕过控制流保护(CFG),作者为 SUN BING: https://sites.google.com/site/bingsunsec/stackdatacorruption
-
[ Popular Software ] SAMSUNG Display Solutions 应用的内容注入漏洞披露(CVE-2018-6019): http://seclists.org/fulldisclosure/2018/Mar/4?utm_source=feedburner&;utm_medium=twitter&utm_campaign=Feed%3A+seclists%2FFullDisclosure+%28Full+Disclosure%29
-
[ Programming ] 使用 Go 语言编写反向代理钓鱼工具: https://medium.com/@cooperthecoder/phishing-with-a-reverse-proxy-23dd99557b5b
-
[ Programming ] 编写 Bash 自动补全脚本: https://iridakos.com/tutorials/2018/03/01/bash-programmable-completion-tutorial.html
-
[ Programming ] 使用汇编编写 X86 "Hello World" bootloader: http://50linesofco.de/post/2018-02-28-writing-an-x86-hello-world-bootloader-with-assembly
-
[ Tools ] Invoke-CradleCrafter - PowerShell 远程 Download Cradle 生成器和混淆器: https://github.com/danielbohannon/Invoke-CradleCrafter
-
[ Tools ] MADLIRA - 使用机器学习和信息检索进行 Android 恶意软件检测的工具: https://github.com/dkhuuthe/MADLIRA
-
[ Tools ] Exchange-AD-Privesc - 利用 Microsoft Exchange 的 DACL 问题提升域内权限: https://github.com/gdedrouas/Exchange-AD-Privesc
-
[ Tools ] sarlacc - 用于收集恶意垃圾邮件的 SMTP 服务器: https://github.com/scrapbird/sarlacc
-
[ Tools ] Passhunt - 用于搜索网络设备,Web 应用程序等的默认凭证的工具: https://github.com/Viralmaniar/Passhunt
-
[ Tools ] iOS OTA 更新补丁文件名/文件内容的简单 Diff 工具,用于快速了解补丁的变动部分: http://newosxbook.com/articles/OTA6.html