腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] [PDF] We did the first and crazy-large-scale study on how Android apps use native code. Our NDSS'16 paper is online! http://cs.ucsb.edu/~yanick/publications/2016_ndss_native.pdf
"通过大规模分析 Android 应用,创建一个实用的 Native-Code 沙盒策略,来自 NDSS(网络与分布式系统安全) 2016 会议 Paper: https://t.co/KxHONrZ3OQ"
-
[ Android ] Keyboard or Keylogger?: a security analysis of third-party keyboards on #Android http://seclab.skku.edu/wp-content/uploads/2015/07/mka.pdf [PDF] https://t.co/ZVgPeDakUI
"Keyboard or Keylogger? Android 第三方键盘输入法应用的安全性分析, 来自韩国成均馆大学的 Paper: https://t.co/ZVgPeDakUI https://t.co/wXTiUswkQG "
-
[ Android ] Life after App Uninstallation: Are the Data Still Alive? Data Residue Attacks on #Android http://www.cis.syr.edu/~wedu/Research/paper/data_residue_ndss2016.pdf https://t.co/CsONww3KE5
"应用程序卸载后的日子 - 数据还在吗? Android 系统的数据残留攻击,来自 NDSS 2016 会议 Paper: https://t.co/B6IytIQrKk https://t.co/CsONww3KE5"
-
[ Android ] SlemBunk Part II: Prolonged Attack Chain and Better-Organized Campaign http://www.fireeye.com/blog/threat-research/2016/01/slembunk-part-two.html
"Android 银行恶意软件 SlemBunk Part 2 - 延长的攻击链与有组织的攻击活动。之前 Part 1 中介绍过 SlemBunk 伪造银行界面,截获银行账户信息的技术细节。 Part 2 从攻击链的角度继续分析: https://t.co/hnvFkRySip"
-
[ Attack ] Endpoint Exploitation Trends 2015 http://blogs.bromium.com/2016/01/14/endpoint-exploitation-trends-2015 https://t.co/gkLJAMO08k
"2015 年软件漏洞利用攻击趋势报告, 来自 Bromium Labs: https://t.co/gkLJAMO08k https://t.co/VFSRYk1OzH "
-
[ Defend ] What are the challenges and solutions of protecting sensitive #data? Find out: http://symc.ly/1UN0Zhr https://t.co/LybpDNUadX
"保护敏感数据的挑战和解决方案: https://t.co/LybpDNUadX https://t.co/viDEKLupkM"
-
[ Detect ] A simple example of creating an event log entry upon detecting WMI lateral movement. https://gist.github.com/mattifestation/aff0cb8bf66c7f6ef44a This could be easily extended.
"一旦检测到攻击者横向渗透行为,创建告警日志, 代码 Demo: https://t.co/FdnJYzL2BJ "
-
[ Detect ] Automatically Evading Classifiers. A Case Study on PDF Malware Classifiers http://www.cs.virginia.edu/~evans/pubs/ndss2016/evademl.pdf [PDF] https://t.co/47klU9yxMT
"自动化地逃逸分类器 - PDF 恶意样本分类器案例研究,来自美国弗吉尼亚大学的 Paper: https://t.co/47klU9yxMT https://t.co/5U5aVFoot6 "
-
[ Device ] Ingenious ideas (II): Devil in a Box. Installing Backdoors in Electronic Door Locks http://seclab.skku.edu/wp-content/uploads/2015/07/Devil_PST2015_IEEE_express.pdf [PDF] https://t.co/XElbeq2ggo
"在电子门锁中装后门,来自韩国成均馆大学的 Paper: https://t.co/9GrzMOos7n "
-
[ Device ] Cisco Patches Hardcoded Password, DoS Vulnerabilities in Software, Devices: https://threatpost.com/cisco-patches-hardcoded-password-dos-vulnerabilities-in-software-devices/115881/ via @ threatpost
"Cisco 修复了软件、设备中的硬编码密码问题和拒绝服务漏洞,来自 ThreatPost: https://t.co/evZ0kenytL"
-
[ iOS ] #iOSREssence I've open sourced SMSNinja on GitHub https://github.com/iosre/SMSNinja, hoping someone can pick it up and bring it back
"SMSNinja - 一个轻量级的 iOS 短信、彩信、iMessage、电话等防火墙应用, Github Repo: https://t.co/Lsgg6lgSnR "
-
[ Linux ] Here's an implementation of a SMM rootkit based on an idea by @ coreykal @ xenokovah et al.: http://bit.ly/1RNPBCK https://t.co/Yp0WOCkgwE
"SMM Rookit 的实现(Linux),作者看到今年 BlackHat USA 《Extreme Privilege Escalation on Windows 8/UEFI Systems》 的演讲后,自己在 Linux 实现了一个 SMM Rootkit: https://t.co/Yp0WOCkgwE https://t.co/ARluAzDaho"
-
[ Malware ] Flawed RANSOM_CRYPTEAR ransomware makes impossible the file recovery http://securityaffairs.co/wordpress/43585/cyber-crime/flawed-ransom_cryptear-ransomware.html
"有 Bug 的加密勒索软件使得被加密的文件无法再恢复: https://t.co/mYttWaO2cS"
-
[ Malware ] A Case of Too Much Information: Ransomware Code Shared Publicly for “Educational Purposes”, Used Maliciously Anyway http://blog.trendmicro.com/trendlabs-security-intelligence/a-case-of-too-much-information-ransomware-code-shared-publicly-for-educational-purposes-used-maliciously-anyway/
"以 '教学目的' 放在 Github 上的恶意代码被攻击者用在实际的勒索软件中: https://t.co/NPA7egebPl"
-
[ Malware ] When URL Shorteners and Ransomware Collide http://blog.malwarebytes.org/security-threat/2016/01/when-url-shorteners-and-ransomware-collide/
"当短网址服务和勒索软件碰到一起的时候: https://t.co/cHw97mMhok"
-
[ Malware ] Dridex Down Under: Raytheon | Websense® Security Labs™ has been tracking malicious email campaigns associated with… http://wb-sn.com/1Q0uETp
"Dridex 银行木马的攻击目标切换为澳大利亚,来自 ForcePoint 11 月份的一篇 Blog: https://t.co/wWvswhrD1y"
-
[ Malware ] Newest Flash Player Exploit & Double Nuclear Exploit Kit Payload: Yesterday, we blogged about a malvertising… http://wb-sn.com/1Q0uH1o
"Flash Exploit 与 Nuclear Exploit Kit,来自 ForcePoint 11 月份的一篇 Blog: https://t.co/jbWy1O4kch"
-
[ Malware ] Updated BlackEnergy Trojan Grows More Powerful https://blogs.mcafee.com/mcafee-labs/updated-blackenergy-trojan-grows-more-powerful/
"更新后的 BlackEnergy 木马变地更强大了: https://t.co/pgs08dkYTC"
-
[ Network ] How email in transit can be intercepted using DNS hijacking - http://bit.ly/1W9uA68 #gmail #security #privacy #SSL
"邮件在传输过程中是如何通过 DNS 劫持被截获的: https://t.co/luQkPZh3nf"
-
[ Others ] For our Korean friends: Enumeration attacks on finding friends w/ phone numbrs. A case study http://seclab.skku.edu/wp-content/uploads/2013/05/Kakao_COSE_15.pdf https://t.co/SlFcc4Kj9W
"通过电话号码枚举所有的朋友列表,针对韩国朋友,一篇 2013 年的 Paper: https://t.co/J1yKNyPB6F https://t.co/SlFcc4Kj9W"
-
[ Others ] OpenSGX + TOR = https://github.com/sslab-gatech/opensgx/tree/master/Tor paper http://ina.kaist.ac.kr/~dongsuh/paper/kim-hotnets2015.pdf
"Intel OpenSGX + TOR, 网络应用可信执行环境的第一步, Paper: https://t.co/TWvVRYsCjp Github: https://t.co/PzLF3aNi1a "
-
[ Others ] Not surprising that it works, but cute research: Video-Assisted Keystroke Inference from Tablet Backside Motion http://www2.hawaii.edu/~ruizhang/paper/sun-NDSS16.pdf
"视频辅助的击键记录器 - 从用户输入引起的平板电脑后向移动推理出击键序列: https://t.co/cBRQ8LiZhj "
-
[ Others ] On SMS logins: an example from Telegram in Iran. My latest blog post on why SMS logins are a bad idea: https://www.fredericjacobs.com/blog/2016/01/14/sms-login/
"Telegram 短信登陆的故事 - 为什么短信登陆不是个好主意: https://t.co/EMwIb6XWL9"
-
[ Others ] Attacking HTTP/2 Implementations https://yahoo-security.tumblr.com/post/134549767190/attacking-http2-implementations
"攻击 HTTP 2 的实现, Blog: https://t.co/cXXJOBcCKx 之前推送过相关的 PacSecjp 2015 会议的演讲: http://www.slideshare.net/JohnVillamil/attacking-http2-implementations-1 "
-
[ Others ] #JustSayNo to “Whack a Mole.” Learn effective solutions to today’s targeted intrusions http://bddy.me/232o9qi https://t.co/wAEjHp1mc7
"向 '打地鼠游戏' 说不 - 对抗定向威胁的入侵,来自 FireEye Mandiant 报告: https://t.co/wAEjHp1mc7 https://t.co/kHQMBauNyl "
-
[ Pentest ] Advanced Pentesting Techniques with Metasploit http://goo.gl/jKXAzY #Hacking #PenetrationTesting
"Metasploit 高级渗透测试技术: https://t.co/XT8QHxnbAb"
-
[ Popular Software ] uninitialized remote memory disclosure vulnerability in node. nice job, @ feross https://twitter.com/j4cob/status/687764484291600384
"Node.js 未初始化变量远程信息泄露漏洞, 来自 Github 的 issue 说明: https://github.com/nodejs/node/issues/4660 "
-
[ Popular Software ] Manage Engine Applications Manager 12 Multiple Vulnerabilities https://cxsecurity.com/issue/WLB-2016010085
"ManageEngine 应用管理器 12 版本存在多个漏洞 https://t.co/ZSdN6KD5Ez"
-
[ ReverseEngineering ] Continuing this popular series with Part 5: How to use IDAPython to make your life easier http://bit.ly/1n1R7pN @ Unit42_Intel @ jgrunzweig
"IDAPython 让你的生活更轻松 Part 5: https://t.co/RrtM2t6cne "
-
[ ReverseEngineering ] #Course materials for #Malware #Analysis by RPISEC https://github.com/RPISEC/Malware
"来自 RPISEC 的恶意软件分析系列教程: https://t.co/4GyG8ocfCS "
-
[ SecurityProduct ] .@ enirx gives step-by-step instructions for using #AutoFocus API & #Postman for automation http://bit.ly/1PuEASa
"通过 Postman 工具与 PaloAlto 下一代防火墙的 AutoFocus API 自动化地交互: https://t.co/Ap1gaIfPzd "
-
[ ThirdParty ] ffmpeg vuln: process malicious video file & exfiltrate local file contents. Affects servers & endpoints: http://permalink.gmane.org/gmane.comp.security.oss.general/18574
"ffmpeg 在处理视频文件 URL 时存在两个跨域漏洞(CVE-2016-1897/CVE-2016-1898),可以盗取本地文件: https://t.co/qqCwakj5qh"
-
[ ThirdParty ] Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778 https://www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt via @ revskills
"OpenSSH 支持一个称为 'Roaming' 的特性,该特性未文档化,该特性允许在服务端连接意外断开时客户端重建挂起的 SSH 会话,目前仅被客户端支持,并且是默认支持启用。来自 Qualys 的安全公告显示: OpenSSH 5.4 (2010 年 3 月发布)后的所有版本 Roaming 特性实现过程中存在两个漏洞: CVE-2016-0777 信息泄露漏洞,恶意的 SSH 服务端可以盗取客户端的私钥; CVE-2016-0778 缓冲区溢出漏洞: https://t.co/x4f78Rd8zi"