腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] PowerSpy: Location Tracking using Mobile Device Power Analysis https://crypto.stanford.edu/powerspy/
"PowerSpy - 通过分析手机的电量消耗跟踪手机的位置,来自斯坦福大学: https://t.co/ZnTlt21mxf "
-
[ Android ] This week's #MobSec5: @ cdump's #FFmpeg bug, @ CopperheadSec finds Android UAF errors & more http://ow.ly/X3Sjz https://t.co/pZq0S2OQlJ
"来自 NowSecure 的上周手机安全动态摘要: https://t.co/npnAekBj5R https://t.co/pZq0S2OQlJ 更多"
-
[ Android ] diva-Android : (Intentionally) Damn Insecure and vulnerable App for Android : https://github.com/payatu/diva-android/ cc: @ aseemjakhar
"diva-Android - 浑身漏洞的 Android 应用,专为研究、学习 Android 应用漏洞准备: https://t.co/gP8SR15qGM "
-
[ Attack ] #Hyatt discovers POS #malware at 250 hotels http://www.scmagazine.com/hyatt-discovers-malware-at-250-hotels/article/465560/ via @ TeriRnNY
"凯悦旗下 250 家酒店被发现 POS 恶意软件,可能泄露客户的支付卡信息: https://t.co/I1hOKBBEv5 "
-
[ Defend ] New blog post: Using Intel SGX to harden password hashing https://jbp.io/2016/01/17/using-sgx-to-hash-passwords/
"通过 Intel SGX 加固密码 Hash,Hash 运算时引入硬件相关策略,使离线攻击变的不可能: https://t.co/RkQRrHfpK7"
-
[ Exploit ] Added "Intro to Windows kernel exploitation part 2" to @ WhitehattersA feat the @ HackSysTeam extremely vuln driver :D https://www.whitehatters.academy/intro-to-windows-kernel-exploitation-2-windows-drivers/
"Windows 内核漏洞利用介绍 Part 2,这篇 Blog 是基于 HackSys 的 'Extreme Vulnerable Windows Driver', 'Extreme Vulnerable Windows Driver' 是专为学习内核漏洞及利用构建的一个驱动: https://t.co/VfTBx0tDhM"
-
[ IoTDevice ] Damn vulnerable router firmware : http://b1ack0wl.com/projects/2015/12/25/Damn-Vulnerable-Router-Firmware/
"浑身漏洞的路由器固件 - 路由器固件漏洞练习靶场: https://t.co/5b977FnpLD"
-
[ IoTDevice ] UPC Ubee EVW3226 Fail : https://firefart.at/post/upc_ubee_fail/ cc: @ _FireFart_
"UPC Ubee EVW3226 路由器固件逆向: https://t.co/2ce7umTmcx "
-
[ Linux ] All about Linux signals : http://www.linuxprogrammingblog.com/all-about-linux-signals?page=show
"Linux signals: https://t.co/ucO5s8tszO"
-
[ Mac OS X ] Understanding OS X and iOS Code Signing to Hide Data : https://github.com/secretsquirrel/Shmoocon2016/blob/master/preso_shmoocon_2016.pdf (pdf)
"了解 OS X 和 iOS 代码签名,实现数据隐藏: (PDF) https://t.co/JMqDWv6dBa"
-
[ Mac OS X ] Source code release for my @ shmoocon talk with @ drraid , OSX VR and Why We wrote Our own Debugger. Check it out: https://github.com/blankwall/MacDBG
"MacDBG - OS X 调试器框架,底层由 C 语言编写,上层为 Python 接口,: https://t.co/huj5YPQPkq"
-
[ Malware ] Dealing With Script Kiddies – Cryptear.B Incident : http://www.utkusen.com/blog/dealing-with-script-kiddies-cryptear-b-incident.html
"对抗脚本小子 - 上周 TrendMicro 发 Blog 称 Cryptear.B 勒索软件在加密时将解密的 Key 也同时加密了,所以这些被加密的文件不可能再被还原了。然而本篇 Blog 的作者认为他可以: https://t.co/oixV6eWrHm"
-
[ Network ] HTTP Evasions Explained 10 - Lazy Browsers http://noxxi.de/research/http-evader-explained-10-lazy-browsers.html
"HTTP 逃逸系列 10 - Lazy Browsers: https://t.co/BIR4KaIbB9"
-
[ Network ] Building a UDP Scanner : http://bt3gl.github.io/black-hat-python-building-a-udp-scanner.html
"用 Python 写一个 UDP 扫描器: https://t.co/Mrvst5w0Nj"
-
[ Operating System ] VxWorks Fuzzing 之道:VxWorks工控实时操作系统漏洞挖掘调试与利用揭秘 - http://blog.knownsec.com/2016/01/vxworks-real-time-operation-system-fuzzing/
"VxWorks Fuzzing 之道:VxWorks工控实时操作系统漏洞挖掘调试与利用揭秘,来自知道创宇 Blog - https://t.co/5z4jIsrxLp"
-
[ Others ] An introduction to Machine Learning : https://docs.google.com/presentation/d/1O6ozzZHHxGzU-McpvEG09hl7K6oQDd2Taw0FOlnxJc8/preview?slide=id.p
"机器学习导论,来自 Underflow404, Google Docs: https://t.co/zYJdRqKVy9"
-
[ Others ] WARP-CTC artificial intelligence • Baidu releases open source AI code https://thestack.com/world/2016/01/15/baidu-releases-open-source-ai-code/
"百度开源了自己的人工智能项目代码 - WARP-CTC: https://t.co/cfeXkSobP2"
-
[ Others ] PoC || GTFO Issue 10 : http://n0k.r4n0k.com/pocorgtfo/pocorgtfo10.pdf (pdf - 58.4 Mb)
"PoC|GTFO 杂志第 10 期, PDF: https://t.co/DdsUAEp1bB"
-
[ Others ] Microsoft starts pushing Windows 10 to domain-joined PCs http://bit.ly/1ZmbGsM https://t.co/g0xKxwIEkV
"微软开始向入域的 PC 推送 Windows 10: https://t.co/0hHkKLj4O7 https://t.co/g0xKxwIEkV Pc"
-
[ Others ] Genode - An in-depth look into the ARM virtualization extensions http://genode.org/documentation/articles/arm_virtualization
"Genode - 深入了解 ARM 的虚拟化扩展: https://t.co/OsFXtE56MQ"
-
[ Pentest ] Secret Pentesting Techniques Shhh... : http://www.trustedsec.com/files/BSIDESLV_Secret_Pentesting_Techniques.pdf (Slides)
"作者分享渗透测试中自己常用的一些私密的渗透技术方法: 来自 BSIDES 会议,Slides: https://t.co/PUyVIHtO48"
-
[ Pentest ] foolav : Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host : https://github.com/hvqzao/foolav
"foolav - 渗透工具,逃逸杀软检测,在目标 Windows 系统中运行任意 Payload: https://t.co/pebWWLH9dj"
-
[ Programming ] Free Programming Books : https://github.com/vhf/free-programming-books/blob/master/free-programming-books.md
"各种编程语言的电子书下载: https://t.co/NRrfhhoP4t"
-
[ Tools ] inih : Simple .INI file parser in C, good for embedded systems : https://github.com/benhoyt/inih
"inih: C 语言写的 .INI 文件解析库: https://t.co/p9yoCAcl4v"
-
[ Tools ] Privilege Escalation on Windows 7,8,10, Server 2008, Server 2012 … and a new network attack http://foxglovesecurity.com/2016/01/16/hot-potato/
"Potato - 通过 Windows 的已知问题(如 NTLM 重放、NBNS 欺骗)实现本地提权: https://t.co/4jbzVb5Pv7 Github 源码: https://github.com/foxglovesec/Potato/ "
-
[ Web Security ] My Hash Is My Passport : Understanding Web and Mobile Authentication : http://www.darthnull.org/media/presentations/HashPassport-AuthMethods_ShmooCon_2016.pdf (Slides)
"我的 Hash 就是我的护照 - 了解 Web 和手机的身份验证技术,来自 ShmooCon 2016 会议, PDF: https://t.co/Ov0aGlbNBd"