腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] 大量安卓设备开启 ADB 调试并可通过 5555 端口连接: https://doublepulsar.com/root-bridge-how-thousands-of-internet-connected-android-devices-now-have-no-security-and-are-b46a68cb0f20
-
[ Industry News ] 思科删除了 WAAS 软件中的硬编码凭证: https://securityaffairs.co/wordpress/73353/hacking/hardcoded-credentials-cisco.html
-
[ iOS ] iOS 11.0 - 11.3.1 越狱代码发布: https://twitter.com/i/web/status/1005266518492438528
-
[ iOS ] Jonathan Levin 的 iOS 12 和 MacOS 14 预览版 changelog : http://newosxbook.com/articles/12-10.14.html
-
[ Language ] 如何使用 Java 本地接口(JNI)直接与汇编器工作: https://dzone.com/articles/pushing-the-jni-boundaries-java-meets-assembly
-
[ MalwareAnalysis ] 对正在开发中的 Karius 银行木马的分析: https://0ffset.wordpress.com/2018/06/09/post-0x09-a-wip-banking-trojan/
-
[ Pentest ] RDPCLIP - 通过 RDP 会话获取剪贴板内容: https://rastamouse.me/2018/06/rdpclip/
-
[ Pentest ] Mimikatz DCsync 使用介绍: https://www.c0d3xpl0it.com/2018/06/active-directory-attack-dcsync.html
-
[ Programming ] 通过 C 语言来实现虚拟机: https://felixangell.com/blog/virtual-machine-in-c
-
[ Programming ] 如何用 C 语言实现哈希表: https://github.com/jamesroutley/write-a-hash-table
-
[ Tools ] archaeologit - 扫描指定 GitHub 仓库历史记录寻找敏感信息泄露的工具: https://github.com/peterjaric/archaeologit
-
[ Virtualization ] 500 行代码实现 Linux containers: https://blog.lizzie.io/linux-containers-in-500-loc.html
-
[ Windows ] Windows 内核漏洞利用系列: https://rootkits.xyz/blog/tag/exploitation/
-
-
[ MalwareAnalysis ] 另辟蹊径:Kuzzle木马伪装万能驱动钓鱼:https://mp.weixin.qq.com/s/XoCvTlaxsZx6f2eC11UsZw
-
[ Programming ] Python 语言一些匪夷所思的一些小特性(Features)代码片段收集,譬如 is not xxx 并不等于 is (not xxx): https://github.com/satwikkansal/wtfpython
-