腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Chrome 中 sw::Surface::Buffer::read 的栈缓冲区溢出漏洞(CVE-2018-16082): https://bugs.chromium.org/p/chromium/issues/detail?id=851398
-
[ Fuzzing ] 介绍如何进行基于语法的网络协议 Fuzzing: https://arxiv.org/pdf/1810.04755.pdf
-
[ MalwareAnalysis ] 虚假的 Flash 更新工具用于传播挖矿木马: https://researchcenter.paloaltonetworks.com/2018/10/unit42-fake-flash-updaters-push-cryptocurrency-miners/
-
[ Mitigation ] 针对 Detrahere 恶意软件使用新的rookit技术介绍,BlueHat 演讲议题: https://www.slideshare.net/MSbluehat/bhv18-return-of-the-kernel-rootkit-malware-on-windows-10
-
[ Others ] 使用 Powershell 查看无线网络配置的密码: https://blogs.technet.microsoft.com/heyscriptingguy/2017/01/13/view-passwords-of-wireless-profiles-without-using-netsh-exe/
-
[ Others ] None
-
[ Tools ] 一种针对二进制文件与源代码进行比较的工具: https://docs.google.com/presentation/d/1ifvugStGL7Qc8xSFeYXp2MGQ6jQGOOMSolBrJy8kCMY/edit#slide=id.p
-
[ Vulnerability ] Microsoft 重新发布修复 Jet 数据库引擎 RCE 漏洞(CVE-2018-8423) 的补丁始末: https://blog.0patch.com/2018/10/patching-re-patching-and-meta-patching.html