腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Covert Communication in Mobile Applications [pdf] http://j.mp/1SkwkXQ
"移动应用程序中的隐蔽通信,来自麻省理工学院的 Paper: https://t.co/HqHyptVLx2 "
-
[ Android ] Vulnerability in #Android mediaserver could allow remote attacks. #MobileMonday http://symc.ly/1Ouu0de https://t.co/uwpb18s9pZ
"Android mediaserver 漏洞(CVE-2015-8507)可以允许远程任意代码执行,来自 NVD 的漏洞描述: https://t.co/5EbP6euHBh https://t.co/uwpb18s9pZ"
-
[ Android ] It's that time of the month again... Security fixes for Android https://source.android.com/security/bulletin/2016-01-01.html with some details here http://changes.droidsec.org/2016/01/04/android-5.1.1_r33.html
"Android 1 月份的漏洞公告: https://t.co/FPnHRSZAZd 代码变动的细节: https://t.co/ynpcnI2x19"
-
[ Android ] “百脑虫”手机病毒分析报告 - http://blogs.360.cn/360mobile/2016/01/06/analysis_of_bainaochong/
"“百脑虫”手机病毒分析报告 - https://t.co/Mw4c9vfguK"
-
[ Android ] Get the resources for #Secure #coding for #Android #app. #Blrdroid #mobsec #Androidsecurity http://buff.ly/1SIkiKr https://t.co/aQCZNFTQBL
"面向开发者的 Android 安全指南: https://t.co/RDLxckOmdl https://t.co/aQCZNFTQBL "
-
[ Attrack ] Angler Exploit Kit continues to evade detection, #Unit42 finds over 90,000 websites compromised http://bit.ly/1JFOMKV
"Angler Exploit Kit 不断地躲避检测, Palo Alto Unit42 发现,超过 9 万个网站已经被攻击: https://t.co/NkUAuSmcm8"
-
[ Attrack ] NCC Group Blog: Cyber Security For The Financial Sector - https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2016/january/cyber-security-for-the-financial-sector/
"NCC Blog 谈金融部门的网络安全 https://t.co/vuCim2wDok"
-
[ Attrack ] Analysis confirms coordinated hack attack caused Ukrainian power outage http://arstechnica.com/security/2016/01/analysis-confirms-coordinated-hack-attack-caused-ukrainian-power-outage/
"分析证实乌克兰电力中断事件是一次黑客分工协作攻击的结果: https://t.co/WWYJXaNdb3"
-
[ Browser ] Google Chrome - Javascript Execution Via Default Search Engines http://goo.gl/fb/7Z6Z9e #FullDisclosure
"Google Chrome 通过默认搜索引擎触发 Javascript 执行: https://t.co/ICPloMb51u"
-
[ Conference ] YouTube videos of security conferences in 2015: https://www.tunnelsup.com/online-security-conferences/
"2015 年多个安全会议的 YouTube 视频: https://t.co/9sOG2RsG6V"
-
[ Crypto ] My favourite #realworldcrypto talk is online. K. Bhargavan: No more downgrades. Protecting TLS from legacy crypto. https://drive.google.com/file/d/0By2exizVD04fRW1kTnpPY1RTc1lOMnA4bXZYa1dQU0ROMG9N
"保护 TLS,免遭降级攻击: https://t.co/i7YadjR23n"
-
[ Detect ] A Hybrid Real-time Zero-day Attack Detection and Analysis System http://www.mecs-press.org/ijcnis/ijcnis-v7-n9/IJCNIS-V7-N9-3.pdf
"混合实时 0Day 攻击检测和分析系统,来自印度 Thapar Patiala 大学, Paper: https://t.co/8RO6gwCIeH"
-
[ Exploit ] AuthentiShellcode Pops Calc From Authenticode block Signature Checks Out vie Sigcheck.exe https://gist.github.com/subTee/a48d38ceba8e1e9d75ed :) https://t.co/EZhxF0jsAp
"AuthentiShellcode - 将 Shellcode 注入到 InstallUtil.exe https://t.co/rcXEGln0v9 https://t.co/EZhxF0jsAp"
-
[ Hardware ] NCC Group Research Insights Vol 8 - Hardware Design: FPGA Security Risks - https://www.nccgroup.trust/uk/our-research/research-insights-vol-8-hardware-design-fpga-security-risks/?research=Whitepapers
"硬件设计之 FPGA 的安全风险,来自 NCC Group 的 Paper: https://t.co/rVCNhklbbu"
-
[ iOS ] iOS 8.1.2 越狱过程详解及相关漏洞分析 - http://nirvan.360.cn/blog/?p=887 by Proteas of Qihoo 360 Nirvan Team
"iOS 8.1.2 越狱过程详解及相关漏洞分析,来自 360 Nirvan Blog,作者为 Proteas: https://t.co/CQQC3dk8Hl "
-
[ Linux ] Amanda 3.3.1 local root exploit (0day) https://github.com/HackerFantastic/Public/blob/master/exploits/amanda-backup.txt - fun for all the family on Monday.
"Amanda 3.3.1 本地 Root Exploit (0Day) https://t.co/82vEeJLa1M "
-
[ Malware ] A Case Study of Information Stealers: Part II http://goo.gl/9sYYCX #Hacking #NetworkSecurity
"Pony Stealer 信息盗取工具案例研究 Part 2: https://t.co/iJXKaIJi8s"
-
[ Malware ] Web Malware Collection Github Repo #Webshells & Flooder https://github.com/nikicat/web-malware-collection https://t.co/ejVdiVCMlz
"Web 恶意样本收集,包括一些后门、Bots,恶意脚本等: https://t.co/ejVdiVCMlz https://t.co/1pvv5esPHt"
-
[ Network ] Exploring Peer to Peer Botnets - http://www.malwaretech.com/2016/01/exploring-peer-to-peer-botnets.html https://t.co/larm4yYRZ8
"探究 P2P Botnets: https://t.co/larm4yYRZ8 https://t.co/XHbPhDPqqb"
-
[ Network ] The evolution of wireless penetration testing: http://immunityservices.blogspot.com/2016/01/the-evolution-of-wireless-penetration.html
"无线渗透测试的演变: https://t.co/plDd09T8AQ"
-
[ Others ] Posted my notes on the domain generation algorithm in some DNSChanger / Alureon samples http://johannesbader.ch/2016/01/the-dga-in-alureon-dnschanger/. #dga
"DNSChanger/Alureon 恶意样本中的域名生成算法: https://t.co/viUc9ccoNL "
-
[ Others ] Two Grassroots DICOM (GDCM) advisories by CENSUS co-worker Stelios Tsampas: http://census-labs.com/news/2016/01/11/gdcm-buffer-overflow-imageregionreaderreadintobuffer/ and http://census-labs.com/news/2016/01/11/gdcm-out-bounds-read-jpeglscodec-decodeextent/
"GDCM 缓冲区溢出漏洞(CVE-2015-8396), GDCM 是一个跨平台的 DICOM 实现库: https://t.co/cWD5xVOTQI JPEGLSCodec::DecodeExtent 越界读漏洞(CVE-2015-8397) https://t.co/hJnC212ozd"
-
[ Others ] on #skylake there is a new clflushopt (optimized) instruction that allows faster #rowhammer-ing. I just added it to https://github.com/IAIK/rowhammerjs/tree/master/native
"测试 DRAM RowHammer 问题的代码,可以编译成 Sandy、Ivy、haswell、skylake 版本: https://t.co/4ezbB5djNi"
-
[ Others ] 书安第四期《JAVA反序列化》- http://down.jdsec.com/secbook-4/%E4%B9%A6%E5%AE%89-%E7%AC%AC%E5%9B%9B%E6%9C%9F.pdf
"书安 第四期《JAVA反序列化》- https://t.co/xHFrMbFe4b"
-
[ Popular Software ] TrendMicro node.js HTTP server listening on localhost can execute commands https://code.google.com/p/google-security-research/issues/detail?id=693
"趋势科技 node.js 本地 HTTP 服务器可以执行任意命令 https://t.co/FTvTKkQgVF"
-
[ Web Security ] Hijacking Verizon FiOS Accounts http://randywestergren.com/hijacking-verizon-fios-accounts/
"Verizon FiOS 帐户劫持漏洞: https://t.co/pi586p92TX"
-
[ Windows ] Virtual Bitlocker Containers, (Sat, Jan 9th) https://isc.sans.edu/diary.html?storyid=20593&rss
"虚拟 Bitlocker 容器: https://t.co/Y4czBiwmAB"
-
[ Windows ] Good Read: Caveats for Authenticode Code Signing http://blogs.msdn.com/b/ieinternals/archive/2014/09/04/personalizing-installers-using-unauthenticated-data-inside-authenticode-signed-binaries.aspx Exploring Authenticode *grin*
"代码签名验证注意事项,来自 MSDN Blog: https://t.co/wHR87CVSZ4 "