腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Android 9.0 与 APK 安全研究(slides): https://connortumbleson.com/slides/2019-01-19-SecurityAndPieDevFest.pdf
-
[ Exploit ] 通过三个字节覆盖对 vulnserver.exe TRUN 命令漏洞进行利用: https://www.doyler.net/security-not-included/three-byte-overwrite-vulnserver-trun
-
[ Others ] 使用 C-Reduce 寻找编译器中的错误: https://nickdesaulniers.github.io/blog/2019/01/18/finding-compiler-bugs-with-c-reduce/
-
[ ReverseEngineering ] 通过 NTDLL IAT Hook 来绕过 EDR 的内存保护抓取内存凭证: https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6
-
[ Vulnerability ] Cisco ISE 无需身份验证的 XSS 漏洞到高权限远程代码执行详情披露: https://ssd-disclosure.com/index.php/archives/3778
-
[ Vulnerability ] 如何破解 iPhone 基带的详细介绍: https://github.com/userlandkernel/baseband-research?files=1
-
[ Browser ] 深入了解浏览器中的 WebAssembly : https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/understanding-web-assembly.pdf
-
[ Mitigation ] 安全保护机制是如何在 ELF 文件中实现的: http://bitlackeys.org/papers/secure_code_partitioning_2018.txt
-
[ Tools ] 探讨后渗透测试工具 SILENTTRINITY 的工作原理与检测技巧: https://countercept.com/blog/hunting-for-silenttrinity/