
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Fake Security App for AliPay customers - Android SMS Stealer http://research.zscaler.com/2016/02/fake-security-app-for-alipay-customers.html
"伪装成支付宝安全控件的 Android 短信'小偷', 来自 Zscaler Blog: https://t.co/c2zc5GvH9t "
-
[ Android ] ARTDroid: Simple and easy to use library to intercept virtual-method calls under the Android ART runtime - https://github.com/vaioco/art-hooking-vtable
"ARTDroid: 用于在 Android ART 运行时中劫持虚函数调用的工具, Github Repo: https://t.co/mWSRsrHEXG"
-
[ Android ] git version of NoDeviceCheck Xposed module recently updated to effectively log and bypass SafetyNet checks - https://github.com/pylerSM/NoDeviceCheck
"NoDeviceCheck - 禁用 Android 设备兼容性检查的 Xposed 模块, Github Repo: https://t.co/tkWtH3ZqOS"
-
[ Browser ] Cross-Origin CSS Attacks Revisited (feat. UTF-16) http://blog.innerht.ml/cross-origin-css-attacks-revisited-feat-utf-16/
"跨域 CSS 攻击(Chrome CVE-2015-1287/CVE-2015-5826), 来自 innerht.ml Blog: https://t.co/fZ5bKUcf8Z"
-
[ Defend ] Monitoring Control Flow History To Detect Code Reuse Attacks http://www.wseas.us/e-library/conferences/2015/Seoul/ACE/ACE-14.pdf
"监控控制流历史信息,检测代码重用攻击, Paper: https://t.co/4czTroWDku"
-
[ MalwareAnalysis ] Dridex Experimenting with New Attack Vectors - A Deep Dive into 2012-0158 : http://phishme.com/dridex-experimenting-with-new-attack-vectors/
"Dridex 正在尝试新的攻击向量 - 深入分析 CVE-2012-0158, 来自 Phishme Blog: https://t.co/WjrjwVOHxm"
-
[ Others ] BDA MPEG2 Transport Information Filter DLL side loading vulnerability http://goo.gl/fb/HtyRjq #FullDisclosure
"BDA MPEG2 Transport Information Filter DLL Side Loading Vulnerability(CVE-2016-0041), 来自 FullDisclosure: https://t.co/UtuIMlqBH6 "
-
[ Popular Software ] HTTP Response Splitting in Node.js – Root Cause Analysis http://blog.safebreach.com/2016/02/09/http-response-splitting-in-node-js-root-cause-analysis/
"Node.js HTTP Response 截断漏洞(CVE-2016-2216)的根本原因分析, 来自 SafeBreach Blog: https://t.co/QNxg8X3mDH"
-
[ Popular Software ] Looking inside the (Drop) box : http://0b4af6cdc2f0c5998459-c0245c5c937c5dedcca3f1764ecc9b2f.r43.cf2.rackcdn.com/12058-woot13-kholia.pdf (pdf)
"文件存储服务 Dropbox 客户端的逆向和攻击,绕过双因素认证,劫持用户账户。 Paper: https://t.co/JiHT9O0naP "
-
[ Windows ] http://files.brucon.org/2013/advanced-excel-hacking-workshop.pdf Excellent Reference for the cmd execution in Excel.
"高级 Excel Hacking, 来自 Didier Stevens 在 BruCon 2013 会议上的演讲: https://t.co/fA2vtyfj64 "
-
[ Windows ] New post: February 2016 Patch Tuesday Includes Critical Fixes for IE Vulnerabilities; Adobe Releases http://bit.ly/20UgtnZ @ TrendMicro
"本周二,微软发了 13 个补丁,其中 6 个为严重漏洞。 另外 Adobe 也发布更新,修复若干漏洞。 来自 TrendMicro 的公告: https://t.co/S86xCsve6I "