腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] OWAS Hacking Playground - Android application with common vulnerabilities - https://github.com/OWASP/OMTG-Hacking-Playground
" OWAS Hacking Playground - Android 漏洞学习、练习工具: https://t.co/5icZQhtZze"
-
[ Attack ] The RC6 implementation from Shadowbrokers leak is the trademark of the Equation group. Our analysis: https://securelist.com/blog/research/75812/the-equation-giveaway/
" Shadowbrokers 泄漏工具中的 RC6 算法实现可以说是方程式组织的商标,RC5/RC6 这两种算法的实现比较罕见︰ https://t.co/dS23aKQ14x"
-
[ Attack ] The Equation Group Cisco ASA exploit works, turns off password requirement for SSH: https://xorcatt.wordpress.com/2016/08/16/equationgroup-tool-leak-extrabacon-demo/
"方程式组织泄漏工具中的一个关于 Cisco PIX/ASA 的 Exploit︰ https://t.co/UJX3pfMrtn"
-
[ Browser ] A new blog post on Google Chrome, Firefox Address Bar Spoofing Vulnerability (CVE-2016-5267): http://www.rafayhackingarticles.net/2016/08/google-chrome-firefox-address-bar.html #infosec #security
" Chrome、Firefox 浏览器地址栏欺骗漏洞分析(CVE-2016-5267): https://t.co/Be3BriW1oi "
-
[ iOS ] POC for Secure Enclave based crypto on iOS9 https://github.com/crazyquark/KeySafe
" iOS 9+ 系统使用 KeySecGeneratePair() 加密 API 的示例代码: https://t.co/D5IrOsAa5N "
-
[ Malware ] $2.5 Million-a-Year Ransomware-as-a-Service Ring Uncovered: https://threatpost.com/2-5-million-a-year-ransomware-as-a-service-ring-uncovered/119902/ via @ threatpost
" Ransomware-as-a-Service(勒索软件即服务)一年能产生约 250 万美元: https://t.co/lB3uQOzsnT"
-
[ Malware ] Great find by our @ McAfee_Labs team: utilities repackaged to include browser hijacking malware. Details here: http://intel.ly/2biMbLY
" 利用正常的 APP 劫持浏览器的恶意软件 - Bing.vc,来自 McAfee Blog︰ https://t.co/GbO9v7fDsV"
-
[ Others ] VxWorks Packet Execution (!) http://goo.gl/AMmrxD
" VxWorks Packet Execution,Exodus 年初时候发现了 VxWorks 的 3 个漏洞: https://t.co/cW2waQubvz"
-
[ Others ] [webapps] - GitLab - "impersonate" Feature Privilege Escalation: GitLab - "impersonate" Feature Privilege Escalation http://bit.ly/2btHkVE
" GitLab '身份模拟' 功能提权漏洞: https://t.co/rAqB65RCs6"
-
[ Tools ] Hackable HTTP proxy: Toxy https://n0where.net/hackable-http-proxy-toxy/ #InfoSec #CyberSecurity
" Toxy - 可编程配置的 HTTP 代理工具,可以模拟各种网络环境及错误现象,常用于 Fuzz 测试: https://t.co/jdK2LTNrjZ "
-
[ Windows ] Quick blogspot on #fuzzing #ioctls with #angr, following my talk at the #LSEWeek '16! http://thunderco.re/project/security/2016/07/18/fuzzing-ioctls/
" 用 angr 框架 Fuzz ioctls: https://t.co/6FTDws3B55"
-
[ Windows ] Project Zero blog: A Shadow of our Former Self by @ tiraniddo - https://goo.gl/nygHKZ
" James Forshaw 的一篇新 Blog《A Shadow of our Former Self》,介绍的是沙箱内对 CVE-2016-3219 漏洞的利用: https://t.co/toG0FwAncf"