腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Bug Bounty ] [PayPal Bug Bounty] Node.js code injection vulnerability http://artsploit.blogspot.com/2016/08/pprce2.html #bugbounty #nodejs #rce https://t.co/TDaWRxnkju
" demo.paypal.com Node.js 代码注入漏洞: https://t.co/3dV5i5r88O "
-
[ Challenges ] #LabyREnth Docs track solution blog is up: http://researchcenter.paloaltonetworks.com/2016/08/labyrenth-capture-the-flag-ctf-document-track-solutions/
" Palo Alto 公开了 LabyREnth CTF 挑战比赛的解题方法︰ https://t.co/z4oHOymISU"
-
[ Exploit ] Exploiting WebKit on Vita 3.60 https://blog.xyz.is/2016/webkit-360.html
" Exploiting WebKit on Vita 3.60: https://t.co/jFIKyGOql4"
-
[ Malware ] Brazilian banking Trojans meet PowerShell https://securelist.com/blog/virus-watch/75831/brazilian-banking-trojans-meet-powershell/
"巴西银行木马开始将 PowerShell 作为其重要工具: https://t.co/HtykPZQFSR"
-
[ Malware ] New Mac malware OSX.FakeFileOpener discovered: https://blog.malwarebytes.com/threat-analysis/2016/08/pcvark-plays-dirty/?utm_source=twitter&utm_medium=social
" 一款新的 Mac OS X 恶意软件出现 - OSX.FakeFileOpener: https://t.co/V3pNlPQ5Aa"
-
[ Network ] Updated Whitepaper Available: AWS Best Practices for DDoS Resiliency http://blogs.aws.amazon.com/security/post/Tx6QAIBSQTJPHB/Updated-Whitepaper-Available-AWS-Best-Practices-for-DDoS-Resiliency
" AWS DDoS 防御最佳实践白皮书: https://t.co/EJt0d2KR64 "
-
[ NetworkDevice ] A Wonderful (and !Secure) Router from China http://blog.ioactive.com/2016/08/multiple-vulnerabilities-in-bhu-wifi.html
" 必虎 uRouter WiFi 路由器被曝多个漏洞,来自 IOActive: https://t.co/IHevO4itpT "
-
[ NetworkDevice ] Equation Group's BENIGNCERTAIN tool - a remote exploit to extract Cisco VPN private keys https://musalbas.com/2016/08/18/equation-group-benigncertain.html
" 方程式组织泄漏压缩包中被忽视的一个工具 - BENIGNCERTAIN,这是个思科 VPN 私钥远程提取工具,看描述有点像 HeartBleed: https://t.co/BFx1t3pFhb"
-
[ Windows ] Hyper-V bugs details released -- https://bugs.chromium.org/p/project-zero/issues/detail?id=688 https://bugs.chromium.org/p/project-zero/issues/detail?id=689 https://bugs.chromium.org/p/project-zero/issues/detail?id=690
" Project Zero 研究员发现了 Hyper-V vmswitch.sys 驱动的 3 个漏洞: https://t.co/lU4zEBJXQA https://t.co/mcgcZAUHcD https://t.co/LAeBRAhFXH"
-
[ Windows ] Root Cause Analysis of Windows Kernel UAF Vulnerability lead to CVE-2016-3310 http://blog.fortinet.com/2016/08/17/root-cause-analysis-of-windows-kernel-uaf-vulnerability-lead-to-cve-2016-3310
" Fortinet 研究员在分析 Project Zero 的 Windows 内核 UAF 漏洞(CVE-2015-6100)时,发现了另一条漏洞触发路径,而且微软的补丁并没有修复这条路径。于是就发现了 CVE-2016-3310: https://t.co/z97lelCJWW"
-
[ Windows ] Invoke-SMBShell, POC shell that uses encrypted SMB for communication - https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Invoke-SMBShell.ps1 https://t.co/tXBRLyngj6
" SMBShell - 基于命名管道创建 SMB 加密 C&C 信道: https://t.co/ps9MUBDTGv "