
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Blockchain ] 详细介绍区块链相关的安全问题: https://aumasson.jp/data/talks/balccon18.pdf
-
[ Browser ] iOS Chrome 的 uXSS 漏洞(CVE-2018-6128)细节: https://bugs.chromium.org/p/chromium/issues/detail?id=841105
-
[ Crypto ] 对开源加密与闭源加密哪个更安全的探讨: https://research.kudelskisecurity.com/2018/10/02/open-source-crypto-is-no-better-than-closed-source-crypto/
-
[ iOS ] iOS-v11.4.1 unstripped ios kernels: https://twitter.com/mobilesecurity_/status/1049021921122242561
-
[ MalwareAnalysis ] 介绍如何逆向 Android 中用于对抗分析的本地库: https://github.com/maddiestone/ConPresentations/blob/master/VB2018.UnpackingThePackedUnpacker.Slides.pdf
-
[ Obfuscation ] 二进制反混淆的艺术: https://speakerdeck.com/ntddk/the-art-of-de-obfuscation
-
[ Pentest ] 介绍如何在注册表中隐藏数据: https://dfir.ru/2018/10/07/hiding-data-in-the-registry/
-
[ Pentest ] 活动目录中的欺骗技术: https://www.slideshare.net/nikhil_mittal/forging-trusts-for-deception-in-active-directory
-
[ Programming ] 使用汇编编写可引导的操作系统 Part 6 编写一个小游戏(1/2): https://0x00sec.org/t/realmode-assembly-writing-bootable-stuff-part-6/4915(2/2): https://0x00sec.org/t/realmode-assembly-writing-bootable-stuff-part-7/8798
-
[ Virtualization ] 介绍虚拟化是如何工作,Part 2: https://0x00sec.org/t/a-lot-about-paging-a-little-about-virtualization-part-2/8868
-
[ Virtualization ] hypervisor 入门教程 Part 4 - 使用扩展页表(EPT)进行地址转换: https://rayanfam.com/topics/hypervisor-from-scratch-part-4/
-
[ Vulnerability ] RouterOS 漏洞挖掘 : https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf
-
[ Windows ] Windows RID 劫持攻击介绍 : https://github.com/r4wd3r/RID-Hijacking/blob/master/slides/derbycon-8.0/RID_HIJACKING_DERBYCON_2018.pdf
-
-
[ Attack ] 使用 RWEvrything 驱动(http://rweverything.com )攻击UEFI 攻击的 POC 程序: https://twitter.com/matrosov/status/1045922881677352961
-
[ Mitigation ] Microsoft 发布 Mitigation Bypass 和 Bounty 条目: https://www.microsoft.com/en-us/msrc/bounty-mitigation-bypass
-
[ Popular Software ] 关于 Cisco Prime Infrastructure (CPI) 中存在的文件包含和远程代码执行并可以提权到 root 的漏洞详细介绍(CVE-2018-15379): https://blogs.securiteam.com/index.php/archives/3723
-
[ Tools ] WinIPT - 一款针对 Windows 操作系统的 Intel Process Trace (IPT) 库和命令行工具集合,目前更新支持 Windows v1809 版本 : https://github.com/ionescu007/winipt
-
[ Vulnerability ] Android 8.1 默认打印服务的中间人攻击漏洞披露: https://blogs.securiteam.com/index.php/archives/3751
-
[ Windows ] 介绍如何在 Windows 10 上快速部署 Enforced Windows Defender Application Control(WDAC) 策略并进行测试: https://github.com/bohops/Notes/blob/master/Windows/WDAC-DeviceGuard/Win10_WDAC_DeviceGuard_Testing_Policy_Quick_Deploy.txt