
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] [Blog] Remote Code Execution in the Baidu Browser for Android http://bit.ly/1oP2KRS #android #mobile #security
"百度 Android 浏览器 RCE, 来自 Lifeform-Labs Blog: https://t.co/yLU5UjBrqD "
-
[ Fuzzing ] [ReverseEngineering]Quick introduction into SAT/SMT solvers and symbolic execution http://yurichev.com/tmp/SAT_SMT_DRAFT.pdf
"SAT/SMT 求解器和符号执行介绍: https://t.co/qzyEb91Vev"
-
[ Fuzzing ] Little HTML event attributes fuzzer - http://pastebin.com/AayLzNyB - #chrome and #firefox only
"HTML 事件属性 fuzzer, 只支持 Chrome 和 Firefox, 来自 Pastebin: https://t.co/y2p6q6n3JC "
-
[ Mac OS X ] Apple blacklisted their own enet driver in a silent security update, SIP prevents fixing: http://forums.macrumors.com/threads/software-update-031-51913-will-break-your-ethernet-driver.1958521/ https://t.co/i8YIfs6jhf
"Apple 在一次静默安全更新中拉黑了以太网网卡驱动: https://t.co/PJQ0q5WEK4 https://t.co/i8YIfs6jhf"
-
[ Malware ] Coding python malware http://www.primalsecurity.net/0xc-python-tutorial-python-malware/
"如何用 Python 和 PyInstaller 编写 Windows 恶意代码, Blog: https://t.co/Fi0e0vXQYG"
-
[ Network ] Google Project Shield DoS Mitigation Service Is Free to News Sites http://mobile.eweek.com/security/google-project-shield-dos-mitigation-service-is-free-to-news-sites.html
"Google Shield(盾牌)项目免费为新闻网站提供 DoS 攻击缓解服务: https://t.co/Sr9oJKpVPZ"
-
[ Others ] ASM.JS code Using Rust and Emscripten http://ashleysommer.com.au/how-to/articles/asm-js-code-using-rust-and-emscripten
"通过 Rust 语言和 Emscripten 编译器生成 Asm.js 代码, Blog: https://t.co/P6hOe6Z6JU"
-
[ Pentest ] Getting Domain Admin with Kerberos Unconstrained Delegation http://www.labofapenetrationtester.com/2016/02/getting-domain-admin-with-kerberos-unconstrained-delegation.html
"通过 Kerberos Unconstrained Delegation 获取域管理权限: https://t.co/WxxrtdoOEI 关于 Kerberos Unconstrained Delegation, 参考微软的文档: https://technet.microsoft.com/en-us/library/cc995228.aspx "
-
[ Popular Software ] A Quite Rare MSSQL Injection http://c0rni3sm.blogspot.com/2016/02/a-quite-rare-mssql-injection.html #bugbounty
"一个非常罕见的 MSSQL 注入漏洞案例, Blog: https://t.co/bMex3axfwV "
-
[ ThirdParty ] OpenSSL CVE-2016-0799: heap corruption via BIO_printf https://guidovranken.wordpress.com/2016/02/27/openssl-cve-2016-0799-heap-corruption-via-bio_printf/ #exploitdev #hacking #infosec https://t.co/Qk1RDUnJaP
"OpenSSL BIO_printf 堆破坏漏洞(CVE-2016-0799): https://t.co/2FhLdGR7Kb 修复后的版本还没有发布, Github 上的代码 Patch: https://github.com/openssl/openssl/commit/9cb177301fdab492e4cfef376b28339afe3ef663 https://t.co/Qk1RDUnJaP"
-
[ Virtualization ] Xen XSA 155: Double fetches in paravirtualized devices https://www.insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/ < @ _fel1x to provide demo & PoC at @ SyScan & @ InfiltrateCon
"Xen XSA 155 - XEN 半虚拟化设备 Double Fetch 漏洞: https://t.co/Ne9KquDSYt "
-
[ Web Security ] 21 0day XSS on yahoo - https://blog.sergeybelove.ru/2016/02/21-0day-xss-on-yahoo-after-1-year/ (just want to write someting to my blog again, lol)
"Yahoo XSS 0Day, 影响 21 个域名, 都两年了还没有修复: https://t.co/GEc2AuvURq "