腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Attack on Zygote: a new twist in the evolution of mobile threats https://goo.gl/SjQ1mk
"对 Zygote 的攻击 - 手机上的威胁一直在进化发展, 攻击者开始用 ROOT 工具传播复杂的手机木马. 来自 Kaspersky Blog: https://t.co/BkSqUl3IJ5 "
-
[ Browser ] @ MarkYason on WinRT PDF: https://securityintelligence.com/winrt-pdf-a-potential-route-for-attacking-edge/
"WinRT PDF 是 Edge 浏览器的一个新的攻击界面, WinRT PDF 是 Edge 浏览器用于处理 PDF 文件的类库,最早出现在 Windows 8: https://t.co/GNUuNSQNS5 这篇 Blog 的作者 Mark Yason 在这几天的 RSA 2016 会议上也有一个相关的演讲< EdgeHTML 引擎的攻击界面和漏洞利用缓解技术>: http://www.rsaconference.com/writable/presentations/file_upload/hta-w04-understanding-the-attack-surface-and-attack-resilience-of-edgehtml.pdf Edge "
-
[ Defend ] Slides from my @ RSAConference session, "Machine Learning and the Cloud: Disrupting Threat Detection and Prevention" https://onedrive.live.com/redir?resid=D026B4699190F1E6!2574&authkey=!AP2orZJTO6RhYiM&ithint=file%2cpptx
"基于机器学习和云的威胁检测、防护技术, 来自微软在 RSA 2016 会议的演讲(Slides): https://t.co/BntSOeTP7z "
-
[ Defend ] Sucker-punching Malware: A Case Study in Using Bad Malware Design Against Attackers Bambenek, Modi for @ bsidessf http://ig2.me/bm
" 利用恶意软件设计上的错误反击攻击者, 来自 Bsides 会议(视频): https://t.co/AHxBl6EXq7 "
-
[ Detect ] Slides from my @ RSAConference session "Tracking Hackers on Your Network with Sysinternals Sysmon" https://onedrive.live.com/redir?resid=D026B4699190F1E6!2575&authkey=!AGFBok7JLkOZSgE&ithint=file%2cpptx
"利用 Sysinternals Sysmon 工具追踪内网中的黑客,黑客是怎么攻击进来的?横向渗透了吗? 来自 RSA 2016 会议(Slides): https://t.co/vDxc5Dp0uO "
-
[ Detect ] Advanced techniques for real-time detection of polymorphic malware Ajit Thyagarajan fpr @ bsidessf http://ig2.me/bv
"多态恶意软件的实时检测技术, 来自 Ajit Thyagarajan 在 BsidesSF 2016 会议的演讲(视频): https://t.co/y6ZY0Rp3K0"
-
[ Detect ] The Ransomware Threat: Tracking the Digital Footprints Kevin Bottomley for @ bsidessf http://ig2.me/bq
"跟踪勒索软件的数字指纹信息, 来自 Bsides 2016 会议(视频): https://t.co/Rr80KeNene "
-
[ Fuzzing ] Coverage-guided kernel fuzzing with syzkaller https://lwn.net/SubscriberLink/677764/02236e45d8b181f0/
"基于 syzkaller、 覆盖率为制导的 Linux 内核 Fuzz, 来自 LWN 网站: https://t.co/lygxfssJcs"
-
[ Hardware ] I am giving a short talk tonight in Singapore (on lessons I learnt from Rowhammer). My slides are here: https://docs.google.com/presentation/d/1x7syhRv8Kxi78fpbcp4vSsslriGOj5cuHUgCUuZcZ3U/edit?usp=sharing
"Rowhammer 教会我的三件事儿(PDF): https://t.co/Wn3S1vlefg"
-
[ IoTDevice ] Rediscovering NetUSB vulnerability http://blog.newskysecurity.com/2016/02/rediscovery-of-netusb-vulnerability-in-broadband-routers/
"Netgear R6050 路由器 NetUSB 缓冲区溢出漏洞的再次发现(之前被 SEC Consult 发现并报告过, CVE-2015-3036): https://t.co/XxQby2MmxL"
-
[ Malware ] TDSS botnet: full disclosure : http://www.nobunkum.ru/analytics/en-tdss-botnet
"TDSS 僵尸网络全面披露, Blog: https://t.co/Cp5hoBgouC"
-
[ Malware ] First step in cross-platform Trojan bankers from Brazil done | Securelist https://securelist.com/blog/research/74051/first-step-in-cross-platform-trojan-bankers-from-brazil-done/ (by @ dimitribest) https://t.co/QjakXsRHEn
"kaspersky 对来自巴西的跨平台木马的初始组件 'Banloader' 的分析: https://t.co/qhePzZpfay https://t.co/QjakXsRHEn 这款木马可以运行在 Linux, OS X, Windows. Blog 中提到, 巴西的攻击者们一直在和俄罗斯 '同事们' 比赛 "
-
[ Malware ] PHP ransomware attacks blogs, websites, content managers and more… – Naked Security http://ow.ly/Z0vlj
"PHP 勒索攻击,攻击博客、网站、CMS等等, 来自 Naked Security Blog: https://t.co/JaynQ8C5Ir"
-
[ Malware ] Excellent #malware research blog by @ benkow_ about hunting for indicators on a TeslaCrypt server. http://thisissecurity.net/2016/03/02/lets-ride-with-teslacrypt/ #ransomware #yolo
" TeslaCrypt 勒索软件的攻击向量和回连服务器分析, Blog: https://t.co/kA3tmWqPQy "
-
[ Malware ] New post: Macro Malware Strides in New Direction, Uses Forms to Store its Code http://bit.ly/1Qvmlxh @ TrendMicro
"宏恶意软件的新攻击方向 - 把代码放入 UserForm(用户窗体)中, 来自 TrendMicro Blog: https://t.co/NXlrzPPEeM "
-
[ MalwareAnalysis ] Loading Cuckoo Sandbox results in IDA Pro https://github.com/arbor-jjones/idataco
"将 Cuckoo 沙盒的分析结果导入 IDA Pro,用于恶意软件分析, Github Repo: https://t.co/8NdBNGd4L1 这个分析工具、方法作者专门在 RuxCon 会议讲过一次, 这个 Repo 中有这个 Slides"
-
[ MalwareAnalysis ] Zena Forensics Blog: Analysis of a Dridex maldoc pre-Locky - The latest trends on the security threat landscape... http://ow.ly/3bWEdV
"Zena Blog 对 Dridex 样本简单分析后认为, Locky 和 Dridex 背后的攻击者是同一个: https://t.co/fGBunQN828"
-
[ NetworkDevice ] Cisco Nexus 3000 Series and 3500 Platform Switches Insecure Default Credentials Vulnerability http://ow.ly/Z0pgV
"Cisco Nexus 3000 系列和 3500 平台交换机默认静态密码漏洞, 来自 Cisco 的公告: https://t.co/G7lhO4nIwN"
-
[ Others ] Decompiler Design: http://www.backerstreet.com/decompiler/introduction.htm in case somebody feels adventurous https://t.co/hbtG5RwUBB
"反编译器设计文档: https://t.co/PraOnZ7wlR https://t.co/hbtG5RwUBB"
-
[ Sandbox ] AppLocker Execution Prevention Bypass https://packetstormsecurity.com/files/136057/applocker_bypass.rb.txt
"AppLocker 执行保护 Bypass PoC: https://t.co/vwkG0vlyJr "
-
[ ThirdParty ] OpenSSL CVE-2016-0800和CVE-2016-0703漏洞修复细节拾趣 - http://blogs.360.cn/blog/openssl-cve-2016-0800%e5%92%8ccve-2016-0703%e6%bc%8f%e6%b4%9e%e4%bf%ae%e5%a4%8d%e7%bb%86%e8%8a%82%e6%8b%be%e8%b6%a3/
"OpenSSL CVE-2016-0800 和 CVE-2016-0703 漏洞修复细节拾趣, 来自 360 Blog: https://t.co/wLnyDHVjWM"
-
[ Tools ] http://commandlinefu.com Still my fav page for command line hacks > All-time sort by votes http://www.commandlinefu.com/commands/browse/sort-by-votes https://t.co/zirFX2oJZk
" https://t.co/2Sg036AvLt 按投票排名的命令行工具: https://t.co/C5rSn2JnXa https://t.co/zirFX2oJZk"
-
[ Tools ] [/dev/random] Running #MISP in a #Docker Container https://blog.rootshell.be/?p=30204
"在 Docker 容器中运行 MISP(恶意软件共享平台): https://t.co/c0nnY3eaWs MISP 是一个用于在多个合作厂商之间交换 IOC 信息的平台, Github Repo: https://github.com/MISP/MISP "
-
[ Virtualization ] Wrote a hypervisor as a platform on Windows. Let me know if you find any issues. https://github.com/tandasat/HyperPlatform
"HyperPlatform - 为 Windows 写的一个基于 Intel VT-x 的 hypervisor, Github Repo: https://t.co/qeR1hQnXb3"
-
[ Windows ] Amazing work. Positive Research Center: Microsoft Windows 8.1 Kernel Patch Protection Analysis & Attack Vectors http://blog.ptsecurity.com/2014/09/microsoft-windows-81-kernel-patch.html
" Windows 8.1 Kernel Patch 保护技术和攻击向量分析, 来自 PtSecurity 2014 年的一篇 Blog: http://t.co/h4GsgkObsg"
-
[ Windows ] Windows 10 Device Guard and Credential Guard Demystified - http://blogs.technet.com/b/ash/archive/2016/03/02/windows-10-device-guard-and-credential-guard-demystified.aspx
"Windows 10 Device Guard 和 Credential Guard 特性探究, 来自 Ash de Zylva 的 Blog: https://t.co/ZNnBnGSZwh"