腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Just released dex-oracle, an Android deobfuscation tool: https://github.com/CalebFenton/dex-oracle
"dex-oracle - Android 反混淆工具: https://t.co/Ej1lPWEcmH 另外 TetCon 2016 会议上有一个相关的演讲 http://www.slideshare.net/tekproxy/tetcon-2016 "
-
[ Android ] Dex Education: Practicing Safe Dex http://www.strazzere.com/papers/DexEducation-PracticingSafeDex.pdf by @ timstrazz
"Android Dex 及其在反调试和反虚拟机方面的方法: https://t.co/9KPvNVfndo "
-
[ Android ] Today's #Android Nexus Security Bulletin patches a critical vulnerability in #Mediaserver - http://ow.ly/WC8nB
"Android 本月的补丁中修复了一个 Mediaserver 严重漏洞, ThreatPost 的报道: https://t.co/fqoQyyj4un Android 官方补丁公告: https://source.android.com/security/bulletin/2016-01-01.html "
-
[ Browser ] Firefox's blacklist of GPU drivers and related bugs, useful if you're fuzzing/researching WebGL: https://hg.mozilla.org/mozilla-central/file/tip/widget/windows/GfxInfo.cpp#l817
"Firefox GPU 驱动程序黑名单和相关的 Bug 列表,这些信息对 Fuzz WebGL 或许有用: https://t.co/FVFXBp0hMT"
-
[ Debug ] Debugging Early Boot Stages of Windows http://standa-note.blogspot.com.es/2014/11/debugging-early-boot-stages-of-windows.html
"如何在 Windows 引导的早期阶段 Attach 上调试器,方便调试 Bootkit https://t.co/YqXlLCS2St"
-
[ Defend ] NCC Group Blog: Phishing Mitigations: Configuring Microsoft Exchange to Clearly Identify External Emails - https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/january/phishing-mitigations-configuring-microsoft-exchange-to-clearly-identify-external-emails/
"NCC Group Blog: 网络钓鱼缓解方法: 如何配置 Microsoft Exchange,清晰地识别外部邮件 https://t.co/x2bCqmul5W"
-
[ Malware ] Radamant Ransomware distributed via Rig EK http://www.cyphort.com/radamant-ransomware-distributed-via-rig-ek/
"Radamant 勒索软件通过 Rig Exploit Kit 实现分发: https://t.co/XnX6HeVFZS "
-
[ Mitigation ] My analysis of the lib injection mitigation of #Edge: http://www.sekoia.fr/blog/microsoft-edge-binary-injection-mitigation-overview/ & source code of the tools mentioned: https://github.com/SekoiaLab/BinaryInjectionMitigation
"Windows 10 TH2 (Build 10156)更新中,微软增加了一个新的缓解措施,用于限制向敏感进程注入二进制。这篇 Blog 介绍 Edge 如何应用这项缓解措施避免加载未授权的 DLL 到当前进程: https://t.co/pl7Ggs7KdD 提到的工具源码: https://t.co/sbKMvSSDDt"
-
[ Network ] HTTPS Bicycle Attack https://guidovranken.wordpress.com/2015/12/30/https-bicycle-attack/
"HTTPS Bicycle Attack,每个请求中都存在的明文 HTTP 头部信息可以被用于泄露特定部分(如密码)的长度: https://t.co/zmcwUSrPye"
-
[ Network ] Linode data centers targeted with #DDoS attacks http://www.scmagazine.com/cloud-hosting-company-linode-sees-service-interruptions-for-ddos-attacks/article/462535/ (@ TeriRnNY)
"Linode 数据中心遭到针对性的 DDoS 攻击 https://t.co/W6WdLV9vbW "
-
[ Network ] Testing for DNS recursion and avoiding being part of DNS amplification attacks, (Mon, Jan 4th) https://isc.sans.edu/diary.html?storyid=20567&rss
"测试 DNS 递归解析,避免成为 DNS 放大攻击的一部分: https://t.co/sC6rLtHt0d"
-
[ Others ] Timing side-channel in ECDSA signature verification http://www.openwall.com/lists/oss-security/2016/01/03/3
"PHP JWT 库 phpecc 的 ECDSA 签名验证过程存在时间边信道攻击的问题 https://t.co/XXt0CE7MQ7 "
-
[ Others ] US-Cert Bulletin (SB16-004) Vulnerability Summary for the Week https://www.us-cert.gov/ncas/bulletins/SB16-004
"US-Cert 的漏洞公告(SB16-004) https://t.co/1BuKSglM5y "
-
[ Others ] New blog post: #threatintel technology and tradecraft in 2015 >>> http://www.cyintanalysis.com/intelligence-technology-and-tradecraft-in-2015/. Enjoy!
"2015 年网络空间中威胁情报技术和间谍情报的一些变化 https://t.co/HXjlyIdkK5 "
-
[ Others ] New blog post "XOR Known-Plaintext Attack" http://blog.didierstevens.com/2016/01/01/xor-known-plaintext-attack/
"XOR 已知明文攻击,来自 Didier Stevens Blog https://t.co/085ovL6Ngz"
-
[ Others ] Large Scale Authorship Attribution from Executable Binaries of Compiled Code ~ by: Aylin Caliskan-Islam @ 32nd CCC http://m.theregister.co.uk/2015/12/31/automated_stylometry_can_deanonymise_programmers_binaries/
"在机器学习的帮助下,编程风格特征可以被抽象识别出来,而且这种特征在被编译后的二进制程序中仍然存在。研究者开始尝试利用这项技术识别恶意软件作者 https://t.co/IznCchhsfs"
-
[ Pentest ] Phpsploit - Stealth Post-Exploitation Framework http://fuhs.eu/s74
"Phpsploit - 隐蔽的 Post-Exploitation 框架 https://t.co/WPctt3rK35"
-
[ Popular Software ] Ganeti vulnerabilities allowing to take over VMs remotely https://pierrekim.github.io/blog/2016-01-05-Ganeti-Info-Leak-DoS.html CVE-2015-7944 CVE-2015-7945 #DoS #infoleak #DRBD
"虚拟机集群管理工具 Ganeti 存在漏洞,可以实现远程控制虚拟机,获取敏感信息。 CVE-2015-7944 CVE-2015-7945 https://t.co/ArZfi2GbnH"
-
[ Tools ] Part 3 of #Unit42 series on how to use IDAPython to make your life easier. http://bit.ly/1PG84z9 @ jgrunzweig @ Unit42_Intel
"IDAPython 使你的生活更轻松 Part 3: https://t.co/gF0Pps16bC"
-
[ Tools ] Wrote a DXE driver for taking screenshots from UEFI apps (aimed for non-ugly Setup shots) and a blog post about it. https://github.com/NikolajSchlej/CrScreenshotDxe
"用于从 GOP 兼容的图形 Console 中实现截屏的 UEFI DXE 驱动 https://t.co/BfXiQBd6mP"
-
[ Web Security ] Exploiting Server Side Request Forgery on a Node/Express Application (hosted on Amazon EC2) http://sethsec.blogspot.com/2015/12/exploiting-server-side-request-forgery.html
"Amazon EC2 Node/Express 应用服务端请求伪造漏洞利用 https://t.co/WMBp2aH24F"
-
[ Web Security ] On The Design and Implementation of a Stealth Backdoor for Web Applications https://paragonie.com/blog/2016/01/on-design-and-implementation-stealth-backdoor-for-web-applications
"Web 应用程序隐形后门的设计与实现, Blog: https://t.co/jC52EfH1qR "
-
[ Windows ] Cracking Kerberos Tickets (Kerberoast) – Exploiting Kerberos to Compromise #ActiveDirectory: https://adsecurity.org/?p=2293 https://t.co/2MjOb5DCSE
"通过攻击 Kerberos 搞定 Active Directory 域: https://t.co/2MjOb5DCSE https://t.co/lXFWQtunMT"
-
[ Windows ] Attack Methods for Gaining Domain Admin Rights in Active Directory https://adsecurity.org/?p=2362
"获取 Active Directory 域管理员权限的攻击方法 https://t.co/PgA3nDeSgA "