腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Build an Android Penetration Testing lab http://www.hackingarticles.in/build-android-penetration-testing-lab/
" Android 渗透测试实验环境搭建: https://t.co/RPX9voDL1g"
-
[ Attack ] Hong Kong Government Hacked by APT3 Group before elections http://securityaffairs.co/wordpress/50918/cyber-crime/apt3.html
"香港政府在 9 月 4 日的选举之前被 APT3 组织攻击: https://t.co/VqtdA5XCaR "
-
[ Crypto ] My #appseceu slides: Practical Attacks on Real World Crypto Implementations http://2016.appsec.eu/wp-content/uploads/2016/09/2016-06-OWASP-Crypto-Attacks.pdf
" 真实环境加密实现的攻击实战: https://t.co/VKecBm3sqV "
-
[ Fuzzing ] #QtCon #FSFEsummit talk on American Fuzzy Lop and Address Sanitizer slides https://www.int21.de/slides/qtcon-fuzzing/ (almost same as @ BornHax talk)
"QtCon 会议关于 AFL 和 Address Sanitizer 的演讲: https://t.co/39mBfdwPj9 "
-
[ iOS ] How Apple fixed OSUnserialzeBinary() in response to PEGASUS http://pastebin.com/raw/JSej0pUi
" Apple 是如何修复 iOS PEGASUS OSUnserializeBinary() 漏洞的: https://t.co/iQsRJqRmwQ "
-
[ Malware ] Guest blog: Nemucod ransomware analysis https://www.virusbulletin.com/blog/2016/september/guest-blog-nemucod-ransomware-analysis/
" Nemucod 勒索软件分析: https://t.co/K5uQAnZ26n"
-
[ Others ] Slides from my talk at #softwarecircus on Thinking Evil Thoughts, all about threat modeling https://speakerdeck.com/garethr/thinking-evil-thoughts
" 关于威胁建模的一些邪恶想法: https://t.co/dceJTewcSQ "
-
[ Others ] New blog post outlining the implementation of Seccomp and Seccomp-BPF https://illogicalexpressions.com/linux/2016/08/31/seccomp-and-seccomp-bpf.html
" Seccomp 和 Seccomp BPF 实现上的比较: https://t.co/VSrVdc8r3T"
-
[ Others ] Interesting analysis by @ ThreatConnect on state election hack links to some other campaigns https://threatconnect.com/blog/state-board-election-rabbit-hole/ https://t.co/WVvS78JNJO
" 兔子窝装得下一只熊吗? 针对土耳其和乌克兰政府的定向攻击行动: https://t.co/QhF9hCd0Rz https://t.co/WVvS78JNJO "
-
[ Others ] How to Read and Write Other Process Memory - http://nullprogram.com/blog/2016/09/03/
"如何读写其他进程的内存: https://t.co/rlU9baID2a"
-
[ Others ] Hacking Air-Gapped Networks http://resources.infosecinstitute.com/hacking-air-gapped-networks/
" Hacking 物理隔离网络的方法总结,来自 InfoSec Blog: https://t.co/mWxr1rMPIB"
-
[ Web Security ] Introducing ‘XSS Payloads’ repository: Cross Site Scripting doesn’t have to be boring - https://labs.nettitude.com/blog/cross-site-scripting-doesnt-have-to-be-boring/
" Nettitude 团队分享了一些 XSS Payloads: https://t.co/5NYw66M0pK https://github.com/nettitude/xss_payloads "