腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
- 
[ Conference ] 乌云2016年白帽子大会 - https://drive.google.com/folderview?id=0B_thUFNIy8TdWVA4c0tEdl8zQTg&usp=sharing
"乌云 2016 白帽大会的 PPT 下载: https://t.co/9Bfp6vulez"
 - 
[ Debug ] This is also a cool windbg extension. https://netext.codeplex.com/
" WinDbg 的 netext 扩展,可以通过类 select 的查询命令查询 .NET 对象: https://t.co/0ILLnZDS0c"
 - 
[ Defend ] YARRA,- Modular Protections against Non-control Data Attacks - https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/paper-60.pdf #dataisolation
" YARRA - 为 C 语言提供非控制流型的数据攻击保护,来自微软的 Paper: https://t.co/6IrPdPA49R "
 - 
[ Defend ] Intel CPU security features https://github.com/huku-/research/wiki/Intel-CPU-security-features
" Intel CPU 的安全特性总结: https://t.co/HY5gSEmpmf"
 - 
[ Fuzzing ] 非主流Fuzzing-模糊测试在⾮内存型漏洞挖掘中的应⽤ - http://blog.knownsec.com/2016/07/some-unique-fuzzing/
"非主流 Fuzzing - 模糊测试在⾮内存型漏洞挖掘中的应⽤,来自知道创宇 Blog,作者为黑哥: https://t.co/QQ8FRX8xrG"
 - 
[ iOS ] Aloha! Slides of my talk "Fruit vs Zombies: Defeat Non-jailbroken iOS Malware" at @ shakacon is available here: https://github.com/secmobi/slides/blob/master/2016.NonjailbrokeniOSMalware_Shakacon.pdf
" 水果大战僵尸 - 攻击非越狱 iOS 的恶意软件,来自 Claud Xiao 在 ShakaCon 会议的演讲︰ https://t.co/usKOOzA7ov"
 - 
[ macOS ] Mac malware OSX.Keydnap steals keychain https://blog.malwarebytes.com/cybercrime/2016/07/mac-malware-osx-keydnap-steals-keychain/
" Keydnap - 专门偷 OS X Keychain 信息的恶意软件,来自 MalwareBytes Blog: https://t.co/JKcfFZvmPc"
 - 
[ Malware ] Untangling Kovter’s Persistence Methods (Uses regsrv32.exe and more) cc @ subTee http://buff.ly/29zWRko #malware https://t.co/nHGFsOGqJ4
"点击欺诈恶意软件 Kovter 的持久性控制方法分析: https://t.co/4TZhabZehw "
 - 
[ Malware ] A New Neutrino Exploit Kit in the china ... && locky http://bobao.360.cn/news/detail/3302.html
" Neutrino EK 来袭,爱拍网遭敲诈者病毒挂马,来自 360 安全播报: https://t.co/WFPNCvxSFi"
 - 
[ Malware ] A look at the 'offline mode' of the Locky ransomware https://blog.avira.com/locky-goes-offline/ https://t.co/tUbzeXXxhE
" Locky 勒索软件的'离线模式'分析: https://t.co/nNdvj9r8BM https://t.co/tUbzeXXxhE"
 - 
[ Malware ] Ransomware Recap: New Families and Updated Variants in June: http://bit.ly/29D7vsj
"勒索软件 6 月份的发展情况:新家族和新变种,来自 TrendMicro Blog︰ https://t.co/hes3JB45CW"
 - 
[ Mitigation ] ROP is Dying and Your Exploit Mitigations are on Life Support https://www.endgame.com/blog/rop-dying-and-your-exploit-mitigations-are-life-support
" ROP 快死了,而且 ROP 漏洞利用缓解并不是那么有效。防御目标是落后于攻击技术的: https://t.co/bcW8a0OOzA"
 - 
[ Network ] .@ Cisco Patches #DoS Flaw in NCS 6000 Routers: https://threatpost.com/cisco-patches-dos-flaw-in-ncs-6000-routers/119296/ via @ threatpost
" Cisco 补掉了 NCS 6000 系列路由器的拒绝服务漏洞,来自 ThreatPost 的报道: https://t.co/ZVxV5TXfJe"
 - 
[ Network ] Github Engineering: SYN Flood Mitigation with synsanity http://githubengineering.com/syn-flood-mitigation-with-synsanity/
" 利用 Linux 3.x 内核的 Synsanity 模块缓解 SYN Flood 攻击: https://t.co/8kEWYpc8yJ"
 - 
[ OpenSourceProject ] Dropbox releases Lepton - A new streaming image compression format, under the Apache license https://github.com/dropbox/lepton https://blogs.dropbox.com/tech/2016/07/lepton-image-compression-saving-22-losslessly-from-images-at-15mbs/
"Dropbox 开源了 Lepton - 一个流式图片压缩格式,GitHub Repo: https://t.co/zoZZYHO0d5 Blog: https://t.co/78M3q0aM3a"
 - 
[ Others ] Part two of • The Mechanics of Bug Injection with LAVA ~ http://moyix.blogspot.in/2016/07/the-mechanics-of-bug-injection-with-lava.html?m=1
" LAVA(Bug 植入系统)的原理介绍: https://t.co/RiibaAewhF"
 - 
[ Popular Software ] Snapchat disclosed a bug submitted by notnaffy: https://hackerone.com/reports/128114 - Bounty: $1,000 #hackerone #bugbounty https://t.co/fc8RLKpInC
"Snapchat 在 Hackerone 上被披露的一个漏洞:以管理员身份访问 Django 管理员界面: https://hackerone.com/reports/128114 "
 - 
[ Popular Software ] Adobe Flash Player fpb.tmp Privilege Escalation https://cxsecurity.com/issue/WLB-2016070113
"Adobe Flash Player fpb.tmp 提权漏洞(CVE-2016-4247): https://t.co/uiKqTgckdL"
 - 
[ Popular Software ] Recieved 3 CVE numbers for vulnerabilities in ws-xmlrpc library from Apache Security Team https://0ang3el.blogspot.ru/2016/07/beware-of-ws-xmlrpc-library-in-your.html
"小心你 Java APP ws-xmlrpc 库中的漏洞: https://t.co/5SokOQjcoW "
 - 
[ Tools ] New tool release! icmptunnel, a tool for Pivoting with Ping :D writeup: https://labs.mwrinfosecurity.com/tools/pivot-with-ping/ & code: https://github.com/jamesbarlow/icmptunnel
" icmptunnel - 以 ICMP(ping)请求响应数据包作为隧道传输数据的工具︰ https://t.co/UgzAClsIDe GitHub Repo︰ https://t.co/1rRQBW1Wjt"
 - 
[ Tools ] BadCode, a way to verify code safety with regex and detect them in opensource projects : https://github.com/pwnsdx/BadCode https://t.co/UhPhIOmLKH
" BadCode - 通过正则在开源项目中找漏洞的工具︰ https://t.co/Xi6SldkQgj https://t.co/UhPhIOmLKH"
 - 
[ Tools ] LogViewer v0.0.2: drag and drop file loading, copy line contents to clipboard status bar info, operation timing: https://github.com/woanware/LogViewer
" LogViewer 日志查看器︰ https://t.co/RQmd4nVxeN"
 - 
[ Windows ] New blog post "Practice ntds.dit File Part 3: Password Cracking With hashcat – Wordlist" https://blog.didierstevens.com/2016/07/14/practice-ntds-dit-file-part-3-password-cracking-with-hashcat-wordlist/
" Windows ntds.dit 文件密码破解练习, Part 1: https://blog.didierstevens.com/2016/07/12/practice-ntds-dit-file-part-1/ Part 2: https://blog.didierstevens.com/2016/07/13/practice-ntds-dit-file-part-2-extracting-hashes/ Part 3: https://blog.didierstevens.com/2016/07/14/practice-ntds-dit-file-part-3-password-cracking-with-hashcat-wordlist/ "