
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Disclosure of [CVE-2016-2468], OOB write in Qualcomm MSM GPU driver http://retme.net/index.php/2016/06/12/CVE-2016-2468.html
" 高通 MSM GPU 驱动越界写漏洞(CVE-2016-2468),来自 Retme 的 Blog: https://t.co/tsErCP79N3"
-
[ Conference ] Slides from my NDC Oslo talk "Coding to fight online abuse" are now at https://www.slideshare.net/secret/jWlrJQ7UbipRjy #ndcoslo
" NDC Oslo 会议的一篇演讲《Coding to fight online abuse》: https://t.co/LKiFPIMlil "
-
[ Crypto ] OpenSSL DSA key recovery attack : http://eprint.iacr.org/2016/594.pdf (pdf)
"OpenSSL DSA 密钥恢复攻击, Paper︰ https://t.co/aGVDoGCrnu "
-
[ Firmware ] ASUS UEFI Update Driver Physical Memory Read/Write https://codeinsecurity.wordpress.com/2016/06/12/asus-uefi-update-driver-physical-memory-readwrite/
"华硕 UEFI 更新驱动(AsUpIO.sys)物理内存读写漏洞: https://t.co/JWRaDctbdF"
-
[ Hardware ] Cold Boot Attacks on Encryption Keys : http://citpsite.s3-website-us-east-1.amazonaws.com/oldsite-htdocs/pub/coldboot.pdf (pdf)
"针对加密密钥的冷启动(Cold Boot)攻击, Paper︰ https://t.co/r1Tq5zfbCa "
-
[ iOS ] inpuTbag - A 15-year-old Kernel HeapOverFlow Vulnerability has just been fixed by Apple in iOS 9.3.2 @ SparkZheng http://translate.wooyun.io/2016/06/12/54.html
"inpuTbag 漏洞 - iOS 冰与火之歌 – UAF and Kernel Pwn, 作者 '蒸米' 利用该漏洞实现了 iOS 9.3.2 版本的越狱,来自乌云 Drops: https://t.co/0Rj75HygIo"
-
[ IoTDevice ] Startup @ XipiterSec Sniffs Out Stealth #IoT Devices on your Network https://securityledger.com/2016/06/startup-senrio-sniffs-out-stealth-iot-devices-on-your-network/ via @ securityledger https://t.co/06jIeiDg1F
" Senrio - 网络中的 IoT 设备发现工具: https://t.co/5PaSGHGJFi "
-
[ Malware ] Lurk Banker Trojan: Exclusively for Russia https://securelist.com/blog/research/75040/lurk-banker-trojan-exclusively-for-russia/
" 专为俄罗斯定制的银行木马 - Lurk,来自 Kaspersky Blog: https://t.co/SaBXYmMnNY"
-
[ MalwareAnalysis ] Anti-Disassembly Techniques Used by Malware (a primer) by @ 0xrnair http://malwinator.com/anti-disassembly-used-in-malware-a-primer/ https://t.co/w8USAgmxr0
" 恶意软件使用的反汇编分析对抗技术: https://t.co/pJyliz7M1f "
-
[ Others ] Regarding to recent Intel CFI buzz, "Data-Oriented Programming" https://www.comp.nus.edu.sg/~shweta24/publications/dop_oakland16.pdf
" Data-Oriented Programming - 非控制流劫持攻击,Paper: https://t.co/CXZyyMxNNP"
-
[ Tools ] Turn your handwriting into a font : http://www.myscriptfont.com/
" 将手写体笔迹转成字体的工具 ︰ https://t.co/nzrPWWsmrO"
-
[ Web Security ] My Google XSS ;) http://arsiadi.net/2016/06/11/stories-of-xss-in-google-april-may-2016/ #Google #XSS #BugBounty
" 我在 Google BugBounty 计划中发现的几个 XSS 漏洞: https://t.co/nvrqxFaDYm "
-
[ Windows ] Here are the slides of my talk on Windows Privilege Escalation Techniques: https://null.co.in/event_sessions/831-windows-privilege-escalation-techniques #pentest #nullblr cc @ Nullblr
" 渗透测试中常用的 Windows 提权技术 ︰ https://t.co/KRnJeaGlJG "