腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Blockchain ] 区块链剖析:分析以太坊智能合约之死,来自 Blackhat USA 2018: https://i.blackhat.com/us-18/Wed-August-8/us-18-Little-Blockchain-Autopsies-Analyzing-Ethereum-Smart-Contract-Deaths.pdf
-
[ Browser ] 将 PWAs 做为 Chrome 扩展程序发布: https://dev.to/samthor/shipping-pwas-as-chrome-extensions-3l5c
-
[ Browser ] Edge InlineArrayPush OpCode 远程代码执行 : https://blogs.projectmoon.pw/2018/08/17/Edge-InlineArrayPush-Remote-Code-Execution/
-
[ Detect ] Sigma 规则指南:将 Sigma 集成到 ArcSight ESM、Command Center 和 Logger 中进行威胁狩猎: https://community.softwaregrp.com/t5/ArcSight-User-Discussions/Sigma-rules-guide-threat-hunting-for-ESM-ArcSight-Command-Center/td-p/1662079
-
[ Firmware ] 使用电压的 glitch 攻击,提取汽车 ECU 的固件,来自 Blackhat USA 2018: https://i.blackhat.com/us-18/Wed-August-8/us-18-Milburn-There-Will-Be-Glitches-Extracting-And-Analyzing-Automotive-Firmware-Efficiently.pdf
-
[ Linux ] Linux 缓冲区溢出 x86 Part 2 - 覆盖和操作返回地址: https://scriptdotsh.com/index.php/2018/08/18/linux-buffer-overflows-x86-part-2-overwriting-and-manipulating-the-return-address/
-
[ Pentest ] 使用 WSHController / WSHRemote 对象进行横向渗透: http://www.hexacorn.com/blog/2018/08/18/lateral-movement-using-wshcontroller-wshremote-objects-iwshcontroller-and-iwshremote-interfaces/
-
[ Popular Software ] XIGNCODE3 的 xhunter1.sys 驱动缺陷, 从泄漏内核模式进程句柄到提权: https://x86.re/blog/xigncode3-xhunter1.sys-lpe/
-
-
[ Tools ] massh-enum - OpenSSH 2.3-7.4 版本用户名枚举工具: https://github.com/trimstray/massh-enum
-
[ Tools ] DbgShell - Windows 调试引擎的 PowerShell 前端: https://github.com/Microsoft/DbgShell
-
[ Tools ] Binary Ninja 开始支持 python : https://insinuator.net/2018/08/ipython-support-for-binary-ninja/
-
[ Tools ] DetoursNT - 使 Microsoft Detours 只依赖没有任何修改的 NTDLL.DLL 原始代码: https://github.com/wbenny/DetoursNT
-
[ APT ] 利用CVE-2018-8373 0day漏洞的攻击与Darkhotel团伙相关的分析: https://ti.360.net/blog/articles/analyzing-attack-of-cve-2018-8373-and-darkhotel/
-
-
-