腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Detect ] win_susp_powershell_enc_cmd - 检测 Powershell 以 Base64 编码命令启动的 Sigma 规则: https://github.com/Neo23x0/sigma/blob/master/rules/windows/builtin/win_susp_powershell_enc_cmd.yml
-
[ Forensics ] 通过网络取证对恶意软件进行动态行为分析: https://freddiebarrsmith.com/mastersthesis.pdf
-
[ Language ] nodebestpractices - Node.JS 最佳实践列表: https://github.com/i0natan/nodebestpractices
-
[ Others ] BADFET - 使用二阶脉冲电磁故障注入击败现代安全启动: https://www.usenix.org/system/files/conference/woot17/woot17-paper-cui.pdf
-
[ Pentest ] Red Teaming Microsoft Part1 - 通过普通用户访问 Azure AD 管理门户泄露活动目录信息: https://www.blackhillsinfosec.com/red-teaming-microsoft-part-1-active-directory-leaks-via-azure/
-
[ ReverseEngineering ] reverse-engineering-tutorials- 基于 OllyDbg 的逆向工程基础教程: https://github.com/maestron/reverse-engineering-tutorials
-
-
-
-
[ Industry News ] SonarSnoop 技术将智能手机转变为迷你声纳系统跟踪用户手指对屏幕的操作以窃取手机解锁图案: https://www.zdnet.com/article/sonarsnoop-attack-can-steal-smartphone-unlock-patterns/
-
[ Industry News ] 某BTC所有者在 10 天内向 Bitfinex 和Binance 转移约1亿美元的 BTC: https://www.reddit.com/r/Bitcoin/comments/9ceb5v/1b_bitcoins_on_the_move_owner_transfers_100m_to/?st=jllzvphy&sh=c516ae2f
-
-
-
[ Popular Software ] Oracle PeopleSoft 8.54, 8.55, 8.56 Java 反序列化漏洞利用: https://github.com/blazeinfosec/CVE-2017-10366_peoplesoft/blob/master/CVE-2017-10366_peoplesoft.py
-
[ Tools ] 在 Windows 上使用 Yubikey 进行 GPG 和 SSH 的方法介绍: https://suchsecurity.com/gpg-and-ssh-with-yubikey-on-windows.html
-
-
-
-
[ Vulnerability ] ImageMagick 7.0.8-11 Q16 中,从ParseImageResourceBlocks函数调用PushShortPixel函数时有一个缓冲区溢出 : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16413 https://github.com/ImageMagick/ImageMagick/issues/1249 https://github.com/ImageMagick/ImageMagick/issues/1251
-