腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Android++ (native development and debugging for Visual Studio) is now open-source https://github.com/webbju/android-plus-plus
"Android++ - 用于实现 Visual Studio 开发和调试 Android Native 应用的工具 https://t.co/VMs2b8LF05"
-
[ Attrack ] First known hacker-caused power outage signals troubling escalation http://ow.ly/39IsX9
"上周乌克兰数十万家庭断电,这是第一个已知的由黑客造成的断电事故 https://t.co/y2bhla05Sw"
-
[ Detect ] Applying machine learning to malware analysis slowly being demystified, see clustering 101: http://blog.deepviz.com/2016/01/04/the-basics-of-clustering-behind-deepviz-part-2/ http://blog.deepviz.com/2015/12/23/the-basics-of-clustering-behind-deepviz-part-1/
"机器学习在恶意软件分析中的应用, Part 2 聚类算法: https://t.co/DMyMRhinTI Part 1: https://t.co/FoeBXtf0bn "
-
[ Fuzzing ] FuzTip: Always enable Special Pool when fuzzing Windows Fonts/Kernel: "verifier.exe /flags 0x1 /driver Win32k.sys" (& atmfd.dll). Saves time
"Fuzz 小建议: 在 Fuzz Windows 字体和内核时启用 Special Pool, 可以节省时间,启用方法: 'verifier.exe /flags 0x1 /driver Win32k.sys'(& atmfd.dll)"
-
[ Malware ] DLL loading technique in #ZeroAccess and #Sirefef : http://goo.gl/lTrXc4 cc: @ hFireF0X @ TheEnergyStory
"木马样本 ZeroAccess/Sirefef 所用的 DLL 加载技术: https://t.co/Nr1WjtlARx "
-
[ Network ] Debugging With Wireshark: TLS http://lukasa.co.uk/2016/01/Debugging_With_Wireshark_TLS/ via @ lukasaoz
"用 Wireshark 排查 TLS 出错的情况 https://t.co/gBP8DMI83b"
-
[ Others ] @MalwareMustDie More on PHP/MySQL web shell injection: Malicious DLL Dropper & Binary Injection Shell by PRC crooks https://t.co/TRHT3oRlhP
"MalwareMustDie 又捕获了一些新样本,除了 DDoS 服务外,样本中还发现了一些 WebShell, WebShell 中内嵌了用于攻击 ElasticSearch 和 WMI 的工具 https://t.co/TRHT3oRlhP Blog: http://blog.malwaremustdie.org/2016/01/mmd-0048-2016-ddostf-new-elf-windows.html "
-
[ Others ] Adobe added isolated heap to Flash. This month we pay $100K (with sandbox) and $65K (without sandbox) per #exploit bypassing this mitigation
"Adobe 为 Flash 加入了 Isolated Heap。这个月我们将会花 10 万(包括沙箱)/6.5 万(不包括沙箱)美元的奖金奖励绕过这项缓解措施的 Exploit "
-
[ Others ] 10 Cloud Security Predictions for 2016 http://buff.ly/1OKs7PT
"SecurityPlanet 对 2016 年云安全发展趋势预测的 10 个观点 https://t.co/hufYHtocrt "
-
[ Others ] PoC code published for Cisco Jabber client STARTTLS downgrade attack: https://threatpost.com/cisco-jabber-client-vulnerable-to-man-in-the-middle-attack/115769/ via @ threatpost
"Cisco Jabber 客户端 STARTTLS 降级攻击 PoC,来自 ThreatPost Blog: https://t.co/tLdoDzRIpZ"
-
[ Others ] My presentation about '(Un)Trusted Execution Environments' @ noconname 2015: [PDF] https://docs.google.com/uc?id=0B1vYN8cImxr9d180UkEySDFLcDg&export=download video: https://vimeo.com/150787883
"非可信执行环境,主要是关于 Android 系统 https://t.co/vFATxEa7sy: https://t.co/P9igiTuiVe"
-
[ Pentest ] (Cobalt Strike's) Interoperability with the Metasploit Framework http://blog.cobaltstrike.com/2016/01/05/interoperability-with-the-metasploit-framework/
"Cobalt Strike 攻击框架和 Metasploit 框架的协同使用 https://t.co/53Xlwfynrw "
-
[ Popular Software ] Atlassian Confluence XSS / Insecure Direct Object Reference https://cxsecurity.com/issue/WLB-2016010018
"Atlassian 开发的团队协作工具 Confluence 存在 XSS 和不安全的对象引用漏洞(CVE-2015-8398/CVE-2015-8399) https://t.co/qIK9YiSrfM"
-
[ Popular Software ] Apache LDAP / Directory Studio Command Injection https://cxsecurity.com/issue/WLB-2016010020
"Apache LDAP/ Directory Studio 命令注入漏洞(CVE-2015-5349) https://t.co/QUtrMOGPTC"
-
[ Tools ] Just published a bunch of cool Sysinternals updates: Sysmon, Sigcheck, Procexp, AccessChk, Autoruns http://blogs.technet.com/b/sysinternals/archive/2016/01/05/update-sigcheck-v2-4-sysmon-v3-2-process-explorer-v16-1-autoruns-v13-51-accesschk-v6-01.aspx
"Sysinternals 工具更新,包括: Sysmon, Sigcheck, Procexp, AccessChk,Autoruns, https://t.co/vDV8BVutnV"
-
[ Tools ] MyRop - Rop tool for ARM. Based on Capstone. https://github.com/hitmoon/MyRop
"MyRop - 基于 Capstone 反汇编引擎的 ROP 工具,用于 ARM 平台 https://t.co/GstJUEMTto"
-
[ Vulnerability ] NCC Group Blog: Remote Exploitation of Microsoft Office DLL Hijacking (MS15-132) via Browsers - https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/january/remote-exploitation-of-microsoft-office-dll-hijacking-ms15-132-via-browsers/ by @ buffaloverflow
"NCC Group Blog: 通过浏览器触发 Office DLL 劫持(MS15-132) https://t.co/sGZhLudUZu"
-
[ Web Security ] HTML5 Security Cheat Sheet http://feedproxy.google.com/~r/HelpNetSecurity/~3/uFVYxF2LLRA/secworld.php
"来自 OWASP 的 HTML5 Security Cheat Sheet: https://t.co/cHMafJvBky"
-
[ Windows ] Very useful: "Windows Process Memory Usage Demystified" http://blogs.microsoft.co.il/sasha/2016/01/05/windows-process-memory-usage-demystified/ https://t.co/hSP32XRBRY
"Windows 进程内存使用情况详解 https://t.co/hSP32XRBRY https://t.co/T7svQIzeee"