腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Challenges ] PwnAdventure3 - 一款易受攻击的 MMORPG 游戏,目的在于提升游戏开发人员的安全编码能力: https://github.com/LiveOverflow/PwnAdventure3/
-
[ iOS ] iOS Instruments Server 通信协议分析: https://github.com/troybowman/dtxmsg/blob/master/slides.pdf
-
[ Others ] 基于可执行文件格式的静态检测,来自 Recon 18 大会 Romain Thomas : http://romainthomas.fr/slides/18-06-Recon18-Formats-Instrumentation.pdf
-
[ Tools ] 用于协助探索 .NET 内部原理的工具整理: http://mattwarren.org/2018/06/15/Tools-for-Exploring-.NET-Internals/
-
[ Tools ] exploit_playground - 针对几个 iOS 及 Android 漏洞的分析: https://github.com/externalist/exploit_playground
-
[ Vulnerability ] EternalRomance 客户端(FuzzBunch)中的 BUG 分析: https://zerosum0x0.blogspot.com/2018/06/dissecting-bug-in-eternalromance-client.html
-
[ Web Security ] 高级 CORS 利用技术介绍: https://www.sxcurity.pro/advanced-cors-techniques/
-
[ Windows ] FortiGuard Labs 团队发现 Windows 远程内核崩溃漏洞(CVE-2018-1040),并做出分析: https://www.fortinet.com/blog/threat-research/microsoft-windows-remote-kernel-crash-vulnerability.html
-
[ Windows ] Windows 系统恶意软件隐藏方式介绍:1) https://blog.varonis.com/living-off-the-land-lol-with-microsoft-part-ii-mshta-hta-and-ransomware/ 2) https://blog.varonis.com/living-of-the-land-lol-with-microsoft-tools-part-i-intro-to-regsvr/ 3) https://blog.varonis.com/the-malware-hiding-in-your-windows-system32-folder-part-iii-certutil-and-alternate-data-streams/