腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Forensics ] PowerShell 攻击调查技术分享: http://files.brucon.org/2018/03-Matt-Ryan-ReInvestigating-Powershell-Attacks.pdf
-
[ Malware ] Golem - 隐藏在 Windows 字体文件夹中的恶意软件: http://sysadminconcombre.blogspot.com/2018/11/golem-malware-malware-hiding-in-your.html
-
-
[ Tools ] 恶意文档执行命令提取工具 - CMD Watcher: http://www.kahusecurity.com/posts/cmd_watcher_and_maldocs.html
-
[ Tools ] awesome-burp-extensions - 优秀 Burp 扩展收集: https://github.com/snoopysecurity/awesome-burp-extensions
-
[ Vulnerability ] 多个 Apple 产品的安全漏洞分析(CVE-2017-13890、CVE-2018-4176、CVE-2018-4175、): https://blogs.dropbox.com/tech/2018/11/offensive-testing-to-make-dropbox-and-the-world-a-safer-place/
-
[ Windows ] Windows 环境中的提权漏洞挖掘: https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
-
[ Crypto ] 在 Android Java 中使用 AES 进行对称加密的介绍 : https://proandroiddev.com/security-best-practices-symmetric-encryption-with-aes-in-java-7616beaaade9
-
-
-
[ MalwareAnalysis ] KoiMiner挖矿木马变种入侵 超5000台SQL Server服务器被控制: https://s.tencent.com/research/report/567.html
-
-
[ Programming ] 如何在浏览器中运行.NET标准代码?可以使用Mono和Blazor先将C#编译为 WASM,然后使用 Chrome DevTools 中的远程调试功能来调试.NET源代码 : https://www.hanselman.com/blog/CompilingCToWASMWithMonoAndBlazorThenDebuggingNETSourceWithRemoteDebuggingInChromeDevTools.aspx
-
[ SecurityProduct ] Microsoft 发布对于 Windows Defender ATP 新功能的介绍 : https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/
-
[ Vulnerability ] SUSE Linux Enterprise Server 的 RegistrationSharing 模块中的多个漏洞介绍(CVE-2018-12470、CVE-2018-12471、CVE-2018-12472) : https://netsequitur.com/research/reports/suse_smt_multiple_vulnerabilities