
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] APT Campaign against Ukranian Separatists http://www.welivesecurity.com/wp-content/uploads/2016/05/Operation-Groundbait.pdf
" Groundbait - 针对乌克兰分裂分子的 APT 行动,来自 WeLiveSecurity 的分析报告: https://t.co/MInMiJ3r33 "
-
[ Attack ] Indian organizations targeted in Suckfly attacks http://www.symantec.com/connect/ko/blogs/indian-organizations-targeted-suckfly-attacks
"印度多个组织受到 Suckfly 的定向攻击,来自 Symantec Blog: https://t.co/ehtHNi0hhw"
-
[ Attack ] Bank Hack – How to steal $25 Billion with a few lines of code http://securityaffairs.co/wordpress/47420/security/25-billion-bank-hack.html
" 安全专家发现了一个漏洞,利用这个漏洞,任何人都可以从印度最大的一家银行盗走 250 亿美元,来自 SecurityAffairs 的报道: https://t.co/r73Tw6i6jB "
-
[ Attack ] A cybercriminal puts the email addresses and passwords of 117M LinkedIn users up for sale http://bit.ly/1YCvWHx
" 1.17 亿的 LinkedIn 用户邮箱和密码正在被黑客售卖: https://t.co/9PQs6Xok9c"
-
[ Cloud ] We share how different application settings within #Azure can be used to increase security of the web app: http://intel.ly/1Tfn5NC
" Azure App 服务 Web App 开发最佳安全实践, Part 3︰ https://t.co/8KoK7zkElJ Part 2: https://blogs.mcafee.com/mcafee-labs/azure-app-service-web-apps-security-best-practices-part-2/ Part 1: https://blogs.mcafee.com/mcafee-labs/security-best-practices-azure-app-service-web-apps-part-1/ "
-
[ Detect ] Introducing Falco: open source, behavioral security from Sysdig http://www.sysdig.org/falco/
" Sysdig Falco - 一个开源的基于行为的检测工具,可以检测容器、主机、网络的异常活动: https://t.co/ZoHexmIwMJ"
-
[ Forensics ] All your BLOBs are belong to us. http://goo.gl/x02NnF interests forensics source in the OSX QuickLook DB
" OS X 系统取证,All your BLOBs are belong to us: https://t.co/Rsx3vmhYg1 "
-
[ Fuzzing ] ProtoFuzz is a generic fuzzer for Google’s Protobuf, now available on Github http://blog.trailofbits.com/2016/05/18/protofuzz-a-protobuf-fuzzer
"ProtoFuzz - 为 Google ProtoBuf 写的一个通用 Fuzzer: https://t.co/WmCAMJ5FQF GitHub Repo: https://github.com/trailofbits/protofuzz "
-
[ Linux ] Analysis of CVE-2016-1887, sendmsg FreeBSD kernel heap overflow : http://cturt.github.io/sendmsg.html
" FreeBSD sendmsg 内核堆溢出漏洞及利用(CVE-2016-1887)︰ https://t.co/gnk1kLqSwx"
-
[ Linux ] Analysis of CVE-2016-1886, SETFKEY FreeBSD kernel vulnerability: http://cturt.github.io/SETFKEY.html
" FreeBSD SETFKEY 内核堆溢出漏洞分析及利用(CVE-2016-1886)︰ https://t.co/iErUvJq5ik"
-
[ Malware ] #Ransomware spikes in March, steadily increasing in 2016 http://bddy.me/27zD3q9 #cyber https://t.co/PI5DgR2lOO
" 3 月份勒索软件活动出现峰值,总体来说,一直在稳步提升,来自 FireEye Blog: https://t.co/xF6oDdqZPd https://t.co/PI5DgR2lOO "
-
[ Malware ] ATM infector https://securelist.com/blog/research/74772/atm-infector/
" Skimer - 七年前就被用于感染 ATM 的恶意软件,来自 Kaspersky Blog: https://t.co/mFenZUK4cd"
-
[ Malware ] Malicious macro using a sneaky new trick https://blogs.technet.microsoft.com/mmpc/2016/05/17/malicious-macro-using-a-sneaky-new-trick/
"恶意宏代码使用的新隐藏技巧,来自微软 MMPC Blog: https://t.co/Lm9FoZI2Xn"
-
[ Malware ] Research team uncovered malware operation the world’s largest attack infrastructures. malware-as-a-service (MaaS) http://www.infosecurity-magazine.com/news/enormous-malware-as-a-service
" Nuclear EK 的核心 - 勒索软件即服务设施,来自 InfoSecurity 杂志的报道: https://t.co/C9o9Ym7EBb 来自 CheckPoint 的分析: http://blog.checkpoint.com/2016/05/17/inside-nuclears-core-unraveling-a-ransomware-as-a-service-infrastructure/ "
-
[ Malware ] TeslaCrypt shuts down and Releases Master Decryption Key! http://www.bleepingcomputer.com/news/security/teslacrypt-shuts-down-and-releases-master-decryption-key/ #DFIR #teslacrypt #ransomeware https://t.co/VHmgSJbby3
"TeslaCrypt 开发者突然停掉了勒索软件,并且公开了主解密密钥: https://t.co/IYwvX9wnrA https://t.co/VHmgSJbby3"
-
[ MalwareAnalysis ] New blog post about what kind of semantics information Triton can provide. http://triton.quarkslab.com/blog/What-kind-of-semantics-information-Triton-can-provide/ cc @ quarkslab
" 二进制分析框架 Triton 可以提供哪种语义信息: https://t.co/SdveE9xdtq "
-
[ Others ] Intel FSP v2.0 specification published at http://www.intel.com/fsp or direct link http://www.intel.com/content/dam/www/public/us/en/documents/technical-specifications/fsp-architecture-spec-v2.pdf #IntelFSP @ vincentzimmer
" Intel FSP(固件支持包) v2.0 发布: https://t.co/ff3DJuui9z 规格说明文档: https://t.co/xQfOBRztgW "
-
[ Others ] Running python & django on NanoServer. https://blogs.technet.microsoft.com/nanoserver/2016/05/17/python-django-on-nano-server/ https://t.co/HgDorRbeZf
"在 NanoServer 上运行 Python 和 Django: https://t.co/X65w5qZbjr https://t.co/HgDorRbeZf"
-
[ Pentest ] An interesting root to domain admin- iSCSI https://www.pentestpartners.com/blog/an-interesting-route-to-domain-admin-iscsi/
" 通往域管理员的路: https://t.co/EcgteEkZAK "
-
[ Popular Software ] Unfixed XSS vuln in "Marked", an npm package with over 1.5M downloads a month https://snyk.io/blog/marked-xss-vulnerability/
" 'Marked' XSS 漏洞, 'Marked' 是用于将 Markdown 转换成 HTML 输出的一个工具: https://t.co/m9KOuJhPoI"
-
[ Programming ] Understanding the x64 code models http://eli.thegreenplace.net/2012/01/03/understanding-the-x64-code-models
" Understanding the x64 code models,来自 2012 年的一篇 Blog: https://t.co/ThSOWtYOvB"
-
[ ReverseEngineering ] Reverse Engineering a fitness tracker to control a drone on a NASA hackathon : https://medium.com/@ dimitrovskif/how-a-team-of-high-schoolers-reverse-engineered-a-fitness-trackers-to-control-a-drone-on-a-nasa-d8aad8532dde#.g2z66aykt https://t.co/qYNMrcN8Tb
" 一个高中生团队是如何通过逆向一个手环控制一部无人机的,来自 NASA 黑客马拉松活动 ︰ https://t.co/2rV9x6PLgp https://t.co/qYNMrcN8Tb"
-
[ Web Security ] AntiviruXSS : How We XSSed 8/9 Top AV Vendors : http://brutelogic.com.br/docs/antiviruxss.pdf (pdf) cc: @ brutelogic || @ strukt93
"AntiviruXSS - 我们是如何 XSS 掉 8/9 的顶级反病毒厂商的 ︰ https://t.co/whioUBej0s "
-
[ Web Security ] Blogged! / XSS Auditor bypass using Flash and base tag http://masatokinugawa.l0.cm/2016/05/xss8.html (日本語) http://mksben.l0.cm/2016/05/xssauditor-bypass-flash-basetag.html (English)
" 利用 Flash 和 base 标签 Bypass XSS Auditor: https://t.co/NfjXTTDjlR "
-
[ Windows ] Internals of Windows Memory Management (not only) for Malware Analysis : https://ub-madoc.bib.uni-mannheim.de/3148/1/InternalsOfWindowsMemoryMangement2.pdf (pdf)
" Windows 内存管理机制与恶意代码使用的内存攻击方法,来自德国曼海姆大学的一篇 Paper ︰ https://t.co/7rjZGcoTDI "
-
[ Windows ] Poor man's security analytics using Ansible, Bash, and Powershell https://morris.guru/poor-mans-windows-infrastructure-metrics-w-ansible-bash/
" 利用 Ansible、Bash 和 Powershell 批量给 Windows 安装软件: https://t.co/lr8AaBHtTC "