
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] We're excited to announce that we've open-sourced part of our WebGL renderer: https://github.com/MicrosoftEdge/WebGL More coming soon on the Edge Dev Blog!
" 微软开源了 Edge 浏览器的 WebGL 渲染器, GitHub Repo︰ https://t.co/DHhkeBPUVE "
-
[ Defend ] IARPA exploring deceptive cyber defenses http://bit.ly/1U7lkPJ RFI PDF: http://1.usa.gov/1U7mbzS
"IARPA 提出的《欺骗性网络防御解决方案》: https://t.co/qglNIdQkL1 PDF: https://t.co/nSfSJPnlKC"
-
[ Hardware ] Hijacking almost any toy drone or quadcopter with a $5 NRF24L01+ module : https://dronegarageblog.wordpress.com/2016/06/07/deviationtx-with-nrf24l01-module-the-universal-drone-remote/ https://t.co/AfoQXjfuMc
" 利用 5 美元的 NRF24L01+ 模块劫持任意玩具无人机: https://t.co/SxdWsVUZcI https://t.co/AfoQXjfuMc"
-
[ IoTDevice ] Unpatched D-Link Wi-Fi Camera Flaw Remotely Exploitable: https://threatpost.com/unpatched-d-link-wi-fi-camera-flaw-remotely-exploitable/118549/ via @ threatpost
" D-link Wi-Fi 摄像头存在一个可远程攻击的漏洞(未修复),来自 ThreatPost 的报道: https://t.co/VWGet4fYjr"
-
[ Mac OS X ] Finally had a real use for my iPad Pro in explaining JTGPFFAP with a race condition https://www.evernote.com/shard/s229/sh/df845562-76c0-46d2-ab31-e3e33939e1e4/1a31c26bc09cd3a36cc61e4183a2a3c5 https://www.exploit-db.com/docs/17784.pdf
" Jumping the Guard Page for Fun and Profit,手绘草稿: https://t.co/gYJ379EDx6 文档: https://t.co/pDBCmWJvql "
-
[ Malware ] Malicious Documents leveraging new Anti-VM & Anti-Sandbox techniques : https://www.zscaler.com/blogs/research/malicious-documents-leveraging-new-anti-vm-anti-sandbox-techniques https://t.co/xfl6qg4XtC
" Zscaler 在最近发现的恶意文档类样本中发现了新的虚拟机、沙箱逃逸技术︰ https://t.co/VcHrn2WYaN https://t.co/xfl6qg4XtC"
-
[ MalwareAnalysis ] My #BSidesLDN2016 Slides and Speaker notes are up! Offensive Anti-Analysis https://www.gracefulsecurity.com/bsides-talk-offensive-anti-analysis/ #InfoSec #Malware
" 进攻型分析对抗技术,对抗基于行为的分析引擎: https://t.co/8iIag3MkVs "
-
[ Others ] Ruby on Rails 脆弱性解説 - CVE-2016-2098 - http://io.cyberdefense.jp/entry/2016/06/09/Ruby_on_Rails_%E8%84%86%E5%BC%B1%E6%80%A7%E8%A7%A3%E8%AA%AC_-_CVE-2016-2098
"Ruby on Rails CVE-2016-2098 漏洞分析(日文): https://t.co/eQFK8NSKlb"
-
[ Others ] Using LLVM on GPUs to Drive Multi-Billion Row Database Queries : http://www.mapd.com/blog/2016/04/27/massive-throughput-database-queries-with-llvm-on-gpus/
" 用运行在 GPU 上的 LLVM 驱动数十亿条数据的数据库查询: https://t.co/TmMgsfYMTw"
-
[ Popular Software ] Vulnerability Spotlight: ESnet iPerf3 JSON parse_string UTF Code Execution Vulnerability http://feedproxy.google.com/~r/Vrt/~3/sKM6kisIaQE/esnet-vulnerability.html
" 网络性能测试工具 iPerf3 在解析 JSON UTF 字符串时存在代码执行漏洞(CVE-2016-4303),来自 Talos Blog: https://t.co/7TAFNyuQnf"
-
[ Tools ] Open Sourcing Commit Watcher: https://blog.srcclr.com/announcing-commit-watcher/ Find hazardous commits in git projects like leaked keys & undisclosed vulnerabilities.
" Commit Watcher - 该工具可以在每次 Git 提交时检查是否会泄漏敏感信息 ︰ https://t.co/AEi7dQ9IOj "
-
[ Web Security ] PHDays VI: WAF Bypass Contest http://blog.ptsecurity.com/2016/06/phdays-vi-waf-bypass-contest.html
" PHDays 会议 WAF Bypass 比赛的结果: https://t.co/eAYHhMIS1K"
-
[ Windows ] Windows network services internals - http://www.hsc.fr/ressources/articles/win_net_srv/
"Windows 网络服务内幕: https://t.co/f9CJYU88qa"
-
[ Windows ] Win/Mac #MSFT Word #0day POC having 3 different forced triggers. Happy exploitation! https://www.dropbox.com/s/h19x0ywmyhzvsk1/poc_003.docx?dl=0
"Windows/Mac Word 0Day PoC 下载: https://t.co/ClCjEVf8mV"
-
[ Windows ] How the Windows Subsystem for Linux Redirects Syscalls : https://blogs.msdn.microsoft.com/wsl/2016/06/08/wsl-system-calls/
" Windows 操作系统 Linux 子系统是如何重定向 Syscall 的,来自微软 Blog︰ https://t.co/wKtntpwlCo"
-
[ Windows ] Breaking BitLocker Encryption : Brute Forcing the Backdoor (Part I) : http://blog.elcomsoft.com/2016/06/breaking-bitlocker-encryption-brute-forcing-the-backdoor-part-i/
" 攻击 BitLocker 加密︰ 暴力破解后门(Part 1)︰ https://t.co/CHDO7lh0ez"
-
[ Windows ] Reviewing Microsoft's Automatic Insertion of Telemetry into C++ Binaries https://www.infoq.com/news/2016/06/visual-cpp-telemetry
" VS 编译器会在 C++ 代码中自动插入遥测功能,来自 InfoQ 的报道: https://t.co/Q0pDKrsKnZ 截图: http://imgur.com/TiVrXyf "