腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Firefox 在隐私浏览模式下依然将数据写入 IndexedDB 导致的隐私泄漏问题( CVE-2017–7843 ): https://medium.com/@konarkmodi/breaking-bad-to-make-good-firefox-cve-2017-7843-219034357496
-
[ IoTDevice ] 智能汽车安全研究报告: https://www.computest.nl/wp-content/uploads/2018/04/connected-car-rapport.pdf
-
[ Malware ] Satan 勒索软件变种利用 EternalBlue 进行传播 : https://bartblaze.blogspot.co.uk/2018/04/satan-ransomware-adds-eternalblue.html
-
-
[ Tools ] linux-exploit-suggester - Linux 本地提权审计工具: https://github.com/mzet-/linux-exploit-suggester
-
[ Tools ] Frida-Python-Binding - 用于协助 Android 自动化逆向分析的 Frida Python 绑定脚本: https://github.com/Mind0xP/Frida-Python-Binding
-
[ Tools ] 子域名收集方法一览: http://10degres.net/subdomain-enumeration/
-
[ Tools ] arm_now - 基于 qume 环境快速搭建各种 CPU 架构虚拟机的工具: https://github.com/nongiach/arm_now
-
[ Vulnerability ] TerraMaster TOS 未授权远程命令执行漏洞披露: https://blogs.securiteam.com/index.php/archives/3602
-
[ Web Security ] Hacker101 - 用来学习 web 安全的网站 : https://www.hacker101.com/
-
[ Windows ] 使用 Windows 防火墙进行端点隔离,以阻止横向渗透: https://medium.com/@cryps1s/endpoint-isolation-with-the-windows-firewall-462a795f4cfb
-
[ Browser ] 深入剖析 JavaScriptCore: https://ming1016.github.io/2018/04/21/deeply-analyse-javascriptcore/
-
-
-
-
[ Popular Software ] Drupal 7 - CVE-2018-7600 PoC Writeup: https://ricterz.me/posts/Drupal%207%20-%20CVE-2018-7600%20PoC%20Writeup
-