
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] Operations of a Brazilian Payment Card Fraud Group http://www.fireeye.com/blog/threat-research/2016/10/operations_of_a_braz1.html
" 巴西支付卡欺诈组织的一系列攻击行动: https://t.co/dVQnP5zfYj"
-
[ Browser ] MS Edge: open default txt/css apps without user interaction. PoC: http://www.cracking.com.ar/demos/edgedefaultapp/ Notepad and Visual Studio are opened in my case.
"MS Edge 浏览器在没有用户交互的情况下会以默认应用打开 txt/css,PoC︰ : https://t.co/04V7TxLr1y "
-
[ Challenges ] Pwning My Life: HITCON CTF Qual 2016 - House of Orange Write up http://4ngelboy.blogspot.com/2016/10/hitcon-ctf-qual-2016-house-of-orange.html?spref=tw
" Orange 为 HITCON CTF Qual 2016 写的一篇 Writeup: https://t.co/rMZTJFu5lA"
-
[ IoTDevice ] Old SSH Vulnerability at Center of Credential-Stuffing Attacks: https://threatpost.com/old-ssh-vulnerability-at-center-of-credential-stuffing-attacks/121266/ via @ threatpost
" 12 年前的一个 SSH 老漏洞正在被黑客用于攻击大量 IoT 设备: https://t.co/pwXLHEcyJW"
-
[ MachineLearning ] Five myths about machine learning in cybersecurity: https://securelist.com/blog/opinions/76351/five-myths-about-machine-learning-in-cybersecurity/ via @ Securelist
-
[ Malware ] Surge of email attacks using malicious WSF attachments https://www.symantec.com/connect/ko/blogs/surge-email-attacks-using-malicious-wsf-attachments
"一波携带恶意WSF 附件的邮件攻击来袭: https://www.symantec.com/connect/ko/blogs/surge-email-attacks-using-malicious-wsf-attachments"
-
[ Malware ] 黑产上演《三体》剧情:蠕虫病毒入侵手机群发“钓鱼”短信 - http://blog.avlsec.com/2016/10/3849/worm/
"黑产上演《三体》剧情:蠕虫病毒入侵手机群发“钓鱼”短信 - https://t.co/pT2mWSluF0"
-
[ Malware ] Our #VB2016 ppt for topic One-Click Fileless Infection is publicly available https://www.virusbulletin.com/uploads/pdf/conference_slides/2016/Anand_Menrige-vb-2016-One-Click-Fileless.pdf
" One Click 实现无文件型感染,来自 VB2016 会议: https://t.co/hSPjzO97LE"
-
[ Malware ] Talos Blog: LockyDump - All Your Configs Are Belong To Us http://bit.ly/2eaFsAu
" LockyDump - All Your Configs Are Belong To Us: https://t.co/JYG9r1B4Y0"
-
[ Network ] Google Creates New Algorithm for Handling TCP Traffic Congestion Control http://news.softpedia.com/news/google-creates-new-algorithm-for-handling-tcp-traffic-congestion-control-508398.shtml
-
[ NetworkDevice ] Cisco Patches Critical Bug In Video Conferencing Server Hardware: https://threatpost.com/cisco-patches-critical-bug-in-video-conferencing-server-hardware/121268/ via @ threatpost
"思科修复了视频会议服务器硬件设备的一个严重漏洞,来自 ThreatPost 的报道: https://t.co/bwiIxZSeow "
-
[ OpenSourceProject ] Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309) http://blog.fortinet.com/2016/10/12/analysis-of-openssl-large-message-size-handling-use-after-free-cve-2016-6309
"针对 OpenSSL 因发布补丁而引入的 UAF 漏洞分析(CVE-2016-6309): https://blog.fortinet.com/2016/10/12/analysis-of-openssl-large-message-size-handling-use-after-free-cve-2016-6309"
-
[ Others ] Direct Memory Attack the Kernel : https://github.com/ufrisk/presentations/blob/master/DEFCON-24-Ulf-Frisk-Direct-Memory-Attack-the-Kernel-Final.pdf (pdf)
" Direct Memory Attack the Kernel,来自 Defcon 24 会议的演讲︰ https://t.co/3joaTRRy8f "
-
[ Tools ] malusb : HID spoofing multi-OS payload for Teensy (Win* & Mac OSX) : https://github.com/LightWind/malusb ,Slides : http://www.slideshare.net/elie-bursztein/does-dropping-usb-drives-really-work-blackhat-usa-2016
"malusb: 实现 HID 欺骗的 Teensy Payload,包含多个系统的 Payload: https://t.co/vljm9vEl3l PPT︰ https://t.co/XQWMXx2JqX"
-
[ Vulnerability ] New post: A Look at the BIND Vulnerability: CVE-2016-2776 http://bit.ly/2ddIgvM @ TrendMicro
"开源域名解析软件 BIND 漏洞(CVE-2016-2776)分析: http://blog.trendmicro.com/trendlabs-security-intelligence/look-bind-vulnerability-cve-2016-2776/ "
-
[ Windows ] Analysing the NULL SecurityDescriptor kernel exploitation mitigation in the latest Windows 10 v1607 Build 14393 http://nzzl.us/nNJ2n0H
" 分析最新版本 Windows 10 v1607 Build 14393 中新添加的空安全描述符内核利用缓解特性: https://t.co/OATUAXcRY1 "
-
[ Windows ] Windows Server 2016 GA'd today (and of course you can now create 2016 GA VMs in Azure)! https://techcrunch.com/2016/10/12/microsofts-windows-server-2016-is-now-generally-available/
" Windows Server 2016 可以用了,当然在 Azure 云环境中也可以直接创建了: https://t.co/q0jeJSyV3K"
-
[ Windows ] [Blog Post] Using Application Compatibility Shims http://subt0x10.blogspot.com/2016/10/using-application-compatibility-shims.html So much fun to be had with these. :-)
" Application Compatibility Shims 可以被用于绕过应用白名单的限制: https://t.co/LqdORIdodw "
-
[ Windows ] Use ARP UninstallString Launcher to bypass uac: https://github.com/ExpLife/ARPUninstallStringLauncherBypassUac