腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
- 
[ Android ] CVE-2016-6526 Possible Privilege Escalation in telecom of Samsung Mobile… http://goo.gl/fb/If2rAr #FullDisclosure
"三星手机通讯 APP 可能存在的两个提取漏洞,来自 FullDisclosure 的公告,CVE-2016-6526: http://seclists.org/fulldisclosure/2016/Aug/33 CVE-2016-6527: http://seclists.org/fulldisclosure/2016/Aug/34 "
 - 
[ Browser ] MP3/HTML polygot PoC for Firefox: http://pastebin.com/raw/x2bTAv4q
"Firefox MP3/HTML polygot PoC︰ https://t.co/p7XsnUvVVE"
 - 
[ Cloud ] Google Compute Engine disk encryption with customer-managed (off-cloud) keys released to production https://cloud.google.com/security/encryption-at-rest/resources/encryption-whitepaper.pdf via @ jmckenty
" Google 云计算环境加密存储实现白皮书: https://t.co/NaHDU8IBTB "
 - 
[ Fuzzing ] Guided in-process fuzzing of Chrome components http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/40jBXgzhCfQ/guided-in-process-fuzzing-of-chrome.html
" 基于 libFuzzer 的 Chrome 组件 Fuzz 方法,来自 Google 官方 Blog,这里提到了一种称为 in-process 的 Fuzz 方式,这种 Fuzz 不用每次都重启目标进程,而是在内存中直接变异 Fuzz: https://security.googleblog.com/2016/08/guided-in-process-fuzzing-of-chrome.html "
 - 
[ macOS ] Slides for our talk on sandboxes at #defcon24 https://goo.gl/eM4oSC @ marcograss https://t.co/v4aeBN0hqi
" 科恩实验室 Flanker 在 DefCon24 会议的演讲《Escaping The Sandbox By Not Breaking It》,关于 OS X 系统 Safari 和 Chrome 的沙箱逃逸: https://speakerdeck.com/flankerhqd/escaping-the-sandbox-by-not-breaking-it "
 - 
[ Mitigation ] Microsoft EMET 5.51 is out https://www.microsoft.com/en-us/download/details.aspx?id=53354 https://t.co/AZB5IY2leO
"微软漏洞利用缓解工具 EMET 5.51 版本下载: https://t.co/q8omg5AE1T "
 - 
[ Others ] Very nice work by @ Fire30_! Thanks for sharing: https://github.com/Fire30/PS4-3.55-Code-Execution-PoC
" PS4 3.55 代码执行 PoC︰ https://t.co/8EeMwfgCE8 利用的是一个 WebKit 漏洞"
 - 
[ Pentest ] slides for @ 424f424f's, @ Killswitch_GUI's, and my "Building an EmPyre with Python" @ BSidesLV presentation are up at http://www.slideshare.net/harmj0y/building-an-empyre-with-python
" Building an EmPyre with Python,EmPyre 是一个渗透测试工具: https://t.co/3sv2hOKRaL"
 - 
[ SecurityProduct ] Kaspersky Safe Browser iOS Application - MITM SSL Certificate Vulnerability… http://goo.gl/fb/DEuDXu #FullDisclosure
"卡巴斯基安全浏览器 iOS APP 存在 SSL 证书中间人劫持漏洞,来自 FullDisclosure 公告: https://t.co/ykGoiZSgdr "
 - 
[ Tools ] The evolution of 3D visuals at Shodan: ICS Radar: https://ics-radar.shodan.io/ Shodan 3D: https://3d.shodan.io/ and now https://simple.shodan.io/
" Shodan 支持 3D 可视化展示了,酷炫。ICS 雷达︰ https://t.co/iyEgmxCnWO Shodan 3D API 以及相关的介绍: https://t.co/Lh5TsnrWNP 搜索结果 3D 展示: https://t.co/gwLnLHdyKr "
 - 
[ Tools ] #BloodHound Domain Admin mapping tool released at #defcon2016 by @ _wald0 @ CptJesus @ harmj0y http://bit.ly/GetBloodHound https://t.co/jfGaiaUbd6
" BloodHound - AD 域管理员的六度空间探测工具,通过图的形式帮助管理员发现 AD 域内节点间的关系: https://t.co/EnwZ3g0ZHB "
 - 
[ Tools ] NCC Group Tool: BinProxy - a proxy for arbitrary TCP connections - https://github.com/nccgroup/BinProxy by Ryan #BlackHat2016
" BinProxy - NCC Group 开源的一个 TCP 连接代理工具: https://t.co/Q8VLA3To3U "
 - 
[ WirelessSecurity ] Slides of my talk @ defcon about Bluetooth Smart Man in the Middle is now online https://speakerdeck.com/virtualabs/btlejuice-the-bluetooth-smart-mitm-framework#
" 智能蓝牙中间人攻击框架,来自 DefCon 会议的演讲: https://t.co/BBN2E8wJbx"