
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] #Unit42 finds #KRBanker targeting South Korea through adware and exploit kits http://bit.ly/1T1kscO
" KRBanker 利用恶意广告和 Exploit Kit 攻击韩国: https://t.co/jaMXjffCqC "
-
[ Browser ] My selection of new Chromium and Firefox intents: https://github.com/simevidas/browser-intents/blob/master/README.md https://t.co/pdP9wBHOPD
"Chromium 和 Firefox 浏览器项目上的一些特性以及开发者的意图 ︰ https://t.co/NpzKE6mdXA https://t.co/pdP9wBHOPD"
-
[ Browser ] Too lazy to use ROP in your Chrome IPC memory corruption sandbox escape? This is what you _could_ have used :-) https://bugs.chromium.org/p/chromium/issues/detail?id=564238
" Chrome IPC 内存破坏沙箱逃逸时不想用 ROP? 那可以用这个: https://t.co/YIzNTKyu6c Windows Image Sections 允许映射任意可执行内存到高权限进程"
-
[ Conference ] #HITB2016AMS Conference Agenda (PDF) - http://conference.hitb.org/hitbsecconf2016ams/wp-content/uploads/2014/06/HITB2016AMS-Conference-Agenda.pdf
"5 月底的 HITB 2016(阿姆斯特丹) 会议的日程: https://t.co/xAqLvEOK6s"
-
[ Exploit ] Modern Objective-C Exploitation Techniques : http://phrack.org/issues/69/9.html#article #Phrack
"现代 Objective-C 漏洞利用技术, 来自 Phrack 第 69 期︰ https://t.co/EbFwerMJuB "
-
[ Forensics ] Memory Forensics http://resources.infosecinstitute.com/memory-forensics/
"内存取证技术综述, 来自 InfoSec Blog: https://t.co/DHmz7xqMh1"
-
[ iOS ] One of the jailbreak tests can detect from within the sandbox via timing attack if someone patched kernel to allow task_for_pid0 in iOS 8
"在 iOS 8 系统,如果被 Patch 后的内核支持 task_for_pid0, 那可以通过 Timing Attack 在沙箱内实现越狱检测。 Stefan Esser 写了一个检测工具: https://itunes.apple.com/de/app/system-and-security-info/id1080681261?l=en&;mt=8 关于这个工具的介绍: https://www.sektioneins.de/en/blog/16-05-09-system-and-security-info.html "
-
[ Mac OS X ] Revisiting Mac OS X Kernel Rootkits : http://phrack.org/issues/69/7.html#article cc: @ osxreverser #Phrack
"重访 Mac OS X 内核 Rootkits, 来自 Phrack 第 69 期: https://t.co/Csc67Ex8kY "
-
[ Malware ] Android Banker Trojan preys on credit card information https://blog.avast.com/android-banker-trojan-preys-on-credit-card-information
"Android 银行木马利用社工技巧盗取用户信用卡信息, 来自 Avast Blog: https://t.co/5vypsZOhcQ"
-
[ Malware ] An Introduction to AlphaLocker https://blog.cylance.com/an-introduction-to-alphalocker
"AlphaLocker 勒索软件家族介绍, 来自 Cylance Blog: https://t.co/HDIJJoPywa"
-
[ Malware ] Antihooking techniques used by Andromeda aim to defeat Cuckoo-like Sandboxes.Find out more! http://bit.ly/AntihookingTech https://t.co/jazpoRekfC
"Andromeda 用于对抗 Cuckoo 类沙箱的 Antihooking 技术: https://t.co/bRZJKaLvqo https://t.co/jazpoRekfC"
-
[ Malware ] Gamarue, Nemucod, and JavaScript https://blogs.technet.microsoft.com/mmpc/2016/05/09/gamarue-nemucod-and-javascript/
" 由于 JavaScript 体积小、易混淆, 恶意软件喜欢用它作为下载器, 来自微软的 Blog:《Gamarue、 Nemucod 和 JavaScript》: https://t.co/2zqZ2LfI1P"
-
[ Others ] Twitter Turns Off Fire Hose For Intelligence Community https://threatpost.com/twitter-turns-off-fire-hose-for-intelligence-community/117935/
"Twitter 禁止情报部门使用消息分析服务: https://t.co/TBjj21yUsv cnbeta 的报道: http://www.cnbeta.com/articles/499511.htm "
-
[ Others ] excellent new research paper from ARM: End-to-End Verification of ARM Processors with ISA-Formal https://69cb7e9e-a-62cb3a1a-s-sites.googlegroups.com/site/alastairdreid/publications/cav2016_isa_formal.pdf?attachauth=ANoY7crDM18kSkqmprgGg0S-uKGMXJy9-p5Pjitf_LRGm7E755AuOF2dvuKm1pdr83a2dqxbHNL-wRIAOM-zfiiNRYC3CMZVjQ4Ebu5Mwq90DhqbY6QFQ7PoMqlNvjZdtI6EnBdCXFve7eXtiYUPpKrupnNuc3h0fSbtGFBF1S4JYvku5qJkO5dLWlkNKwB3avUBWJPdNwEwkEn5KTUjCizeB58r8Ela_mvP6qimwdFXx-hkSpCIGBPkxIVMQ-Q2pv8eugA_XY7w&attredirects=0
"端到端的 ARM 处理器验证技术: https://t.co/Xk2rOgSxpF"
-
[ Others ] Step by step guide for #VirtualBox Hardened (4.3.14+) VM detection mitigation configuring: http://www.kernelmode.info/forum/viewtopic.php?f=11&t=3478 by @ hFireF0X
" 一步一步配置 VirtualBox,缓解自身被探测,来自 KernelMode 论坛: https://t.co/9BqkGtJvYq"
-
[ Others ] The hidden information behind 12,000 PoC Exploits shared online http://securityaffairs.co/wordpress/47150/hacking/poc-exploits-study.html
"12000 个线上共享的 PoC 背后隐藏的信息: https://t.co/6sCDDVKjTE 社交媒体是 PoC 主要的传播渠道"
-
[ Pentest ] @ bartblaze @ hasherezade nice! I found this to be a useful repo too: https://github.com/tennc/webshell
"Tennc 收集整理的 Webshell 列表 ︰ https://t.co/AtXibkRHbk"
-
[ Popular Software ] ASUS driver uses copypasta'd code from 1993 sample, enables RW access to physical memory. PoC available http://rol.im/asux/
" 华硕内存映射驱动物理内存读写 PoC: https://t.co/gjiF2qvRsK"
-
[ Popular Software ] [remote] - Ruby on Rails Development Web Console (v2) Code Execution https://www.exploit-db.com/exploits/39792/
"Ruby on Rails Web 控制台远程代码执行漏洞: https://t.co/aGQVVyecTC"
-
[ ReverseEngineering ] Panopticon - A libre, cross platform disassembler for reverse engineering https://panopticon.re/
"Panopticon - 一个开源的跨平台反汇编工具,可以展示控制流图(CFG): https://t.co/m3AFhCKVa9"
-
[ Rootkit ] How to hide a hook - A hypervisor for rootkits : http://phrack.org/issues/69/15.html#article #Phrack
"如何隐藏 Hook - 基于 Hypervisor 的 Rootkit, 来自 Phrack 第 69 期: https://t.co/Gt7F740ZCO "
-
[ SecurityProduct ] Know the Truth: Signatures and Multi-AV Scanners https://blog.cylance.com/know-the-truth-signatures-and-multi-av-scanners
"故事的真相 - 病毒签名与多引擎反病毒扫描器: https://t.co/LoTqjY1zQ3"
-
[ Tools ] SPF (SpeedPhish Framework) – E-mail Phishing Toolkit http://www.darknet.org.uk/2016/05/spf-speedphish-framework-e-mail-phishing-toolkit/
"SPF (SpeedPhish Framework) — 邮件钓鱼工具: https://t.co/PvWn8oOqbl"
-
[ Tools ] optimizevm - Make Windows VMs Faster http://bit.ly/273qW4o — Shell OSS (oss_sh) May 5, 2016
"Windows 虚拟机性能优化脚本,禁用掉一些用处不大又频繁访问磁盘的功能: https://t.co/YhyInsVb9n"
-
[ Tools ] List of IDA plugins: https://github.com/onethawt/idaplugins-list
"IDA 热门插件列表︰ https://t.co/xzYvLb9BWA"
-
[ Tools ] Introduction to Fridump: Dumping memory from iOS, Android and other applications using Frida @ fridadotre http://pentestcorner.com/introduction-to-fridump/
"Fridump - 用于转储内存的工具,支持多种设备和操作系统,如 iOS、Android,该工具基于 Frida 框架实现: https://t.co/kpNrG6jxUz"
-
[ Web Security ] GoDaddy Addresses Blind XSS Vulnerability Affecting Online Support: https://threatpost.com/godaddy-addresses-blind-xss-vulnerability-affecting-online-support/117950/ via @ threatpost
" 域名注册商 GoDaddy 修复了一个 XSS 漏洞,成功利用该漏洞可以登录、篡改、删除用户 ︰ https://t.co/k4FwWVDBdO"