腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Backdoor ] Felixroot 后门技术分析报告: https://medium.com/@Sebdraven/when-a-malware-is-more-complex-than-the-paper-5822fc7ff257
-
[ Browser ] Safari 技术预览版 64 发布: https://webkit.org/blog/8406/release-notes-for-safari-technology-preview-64/
-
[ Compiler ] Quickpost:在 Windows 上使用 MinGW 编译 DLL: https://blog.didierstevens.com/2018/08/28/quickpost-compiling-dlls-with-mingw-on-windows/
-
[ MalwareAnalysis ] 安卓银行木马 Asacub 分析: https://securelist.com/the-rise-of-mobile-banker-asacub/87591/
-
[ MalwareAnalysis ] 窃取密码的恶意软件 AcridRain 分析: https://thisissecurity.stormshield.com/2018/08/28/acridrain-stealer/
-
[ Pentest ] 红队技术从零到一 ,Part 2: https://payatu.com/redteaming-zero-one-part-2/ Part 1: https://payatu.com/redteaming-from-zero-to-one-part-1/
-
[ Programming ] 使用 gsl::span 替换原始指针直接访问数组的方法,其提供了一种简单的方法来防止越界读/写类的安全问题: https://twitter.com/i/web/status/1034858682125758464
-
[ SecurityReport ] TrendMicro 发布 2018 年中安全威胁概览: https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/unseen-threats-imminent-losses
-
[ Tools ] Invoke-TheHash - PowerShell 实现的哈希传递攻击套件: https://github.com/Kevin-Robertson/Invoke-TheHash
-
[ Virtualization ] Hypervisor 入门 - Part 1:基本概念和配置测试环境: https://rayanfam.com/topics/hypervisor-from-scratch-part-1/
-
[ Virtualization ] VirtualBox 的多个漏洞(CVE-2018-2830、CVE-2018-2835、CVE-2018-2686、CVE-2018-2687): https://www.zerodayinitiative.com/blog/2018/8/28/virtualbox-3d-acceleration-an-accelerated-attack-surface
-
[ WirelessSecurity ] 研究和逆向和433MHz的无线插座的通讯协议,并使用发射器+路由的方式实现了远程开关这个无线插座的功能: http://blog.rona.fr/post/2016/10/22/Home-automation-with-cheap-433MHz-plugs-a-1%24-433MHz-transmitter-and-a-TP-Link-TL-WR703N-router
-
[ Challenges ] Rode0day - 每个月发布一个存在漏洞的二进制文件,供大家对其查找BUG的比赛: https://www.usenix.org/sites/default/files/conference/protected-files/woot18_slides_fasano.pdf https://rode0day.mit.edu/
-
[ Compiler ] Oops, I Wrote a C++ Compiler,作者写了一个app,可以进行电路的仿真设计和模拟,这次的更新他增加了对Arduino的支持。因为arduino开发使用的是C语言开发的,所以作者写了一个编译器,将 C 语言的代码编译成了他的 app 能够解析的字节码: https://praeclarum.org/2018/08/27/oops-i-wrote-a-c-compiler.html
-
[ Forensics ] Windows 手写识别功能记录文件 WaitList.dat 取证分析: https://b2dfir.blogspot.com/2016/10/touch-screen-lexicon-forensics.html
-
-
-
[ MalwareAnalysis ] CVE-2018-8414:SettingContent-ms文件任意代码执行漏洞及在野攻击分析: http://www.freebuf.com/vuls/182005.html
-
[ Pentest ] 权限提升与后渗透测试文档: https://rmusser.net/docs/Privilege%20Escalation%20&%20Post-Exploitation.html
-
[ ThreatIntelligence ] Ducky-Exploit - Arduino 橡皮鸭利用框架: https://github.com/itsmehacker/Ducky-Exploit