
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Decrypting Google Chrome Safe Storage Passwords on OS X http://bufferovernoah.com/2016/10/17/chrome/
"在 OS X 系统,解密 Chrome 存储的用户密码: https://t.co/6OR4qkFE5V "
-
[ Conference ] the speakers' list for SyScan360 in Shanghai is out. go check out https://www.syscan360.org/en/speakers/ http://fb.me/7QGGFHoQv
"SyScan360 2016 上海会议的演讲者及议题名单,会议将于 11 月 24-25 日举办: https://t.co/KIwdK6ddUE https://t.co/0fiu5tZOq4"
-
[ Crypto ] #AppSecUSA2016 HTTP & TLS in 2016 by @ kennwhite https://speakerdeck.com/kwhite/https-and-tls-in-2016-security-practices-from-the-front-lines [v hard https://twitter.com/daniel_bilar/statuses/573434668655091713?tw_i=573434668655091713&tw_e=permalink&tw_p=archive see also… https://t.co/vb7rsz5puM
" AppSecUSA2016 大会上关于 HTTP&TLS 的议题:Security practices from the front line : https://speakerdeck.com/kwhite/https-and-tls-in-2016-security-practices-from-the-front-lines "
-
[ Forensics ] Writeup on extracting LastPass Site Credentials and LastPassPrivateKey from Memory with… https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory/ https://t.co/qej0KfO0DT
"从内存中获取密码管理软件 LastPass 的凭据及其私钥的方法: https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory "
-
[ IoTDevice ] Setting up a Research Environment for IP Cameras https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/
"对于嵌入式设备 EDIMAX IP camera 的分析: https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras"
-
[ Language ] The slides for my high performance #golang workshop are online, http://talks.godoc.org/github.com/davecheney/high-performance-go-workshop/high-performance-go-workshop.slide#1 Enjoy!
"High Performance Go【PPT】: http://talks.godoc.org/github.com/davecheney/high-performance-go-workshop/high-performance-go-workshop.slide#6"
-
[ Linux ] Exploiting #Linux kernel heap using a real #UAF method against CVE-2016-6187 vulnerability. cc: @binitamshah… https://t.co/to3ApobQvF
" CVE-2016-6187: Exploiting Linux kernel heap off-by-one: https://cyseclabs.com/blog/cve-2016-6187-heap-off-by-one-exploit "
-
[ Malware ] #PrincessLocker increases ransom to 3 bitcoins when victim fails to pay within 7 days. Other detections: http://bit.ly/2do2W7p #ransomware
"Trend Micro 对上一周恶意软件情况的总结分析: http://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/ransomware-recap-oct-7-2016 "
-
[ Others ] Insecure Defaults - Exploiting LOAD DATA LOCAL INFILE https://blog.tarq.io/insecure-defaults-exploiting-load-data-local-infile/
"不安全的默认配置 - Exploiting LOAD DATA LOCAL INFILE: https://t.co/i3jvwskunx"
-
[ Others ] This is a great blog post about applied CFI on OSX/Linux. Let’s talk about CFI: clang edition | Trail of Bits Blog https://t.co/E1x1NJfjXM
" OS X/Linux CFI(Control Flow Integrity)是如何实现的,又将如何使用,这篇 Blog 是基于 Clang 来介绍的: https://t.co/E1x1NJfjXM"
-
[ Others ] New on the MicrosoftEdge GitHub: We've open-sourced the scripts we use to generate our free testing VMs https://t.co/H2Y50iqjwA
" 微软 Edge GitHub 项目的一个子项目,用于生成免费虚拟机的自动化脚本: https://t.co/H2Y50iqjwA"
-
[ Others ] New blog post: Linq Injection – From Attacking Filters to Code Execution https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/
" Linq(语言集成查询)注入 - 从攻击过滤器到代码执行: https://t.co/ggnBnN3NIb"
-
[ Popular Software ] [remote] - Ruby on Rails - Dynamic Render File Upload Remote Code Execution https://www.exploit-db.com/exploits/40561/
" Ruby on Rails 动态渲染文件上传远程代码执行漏洞(CVE-2016-0752): https://t.co/KUDImryNwP"
-
[ Popular Software ] Security assessement of VeraCrypt 1.18. http://blog.quarkslab.com/security-assessment-of-veracrypt-fixes-and-evolutions-from-truecrypt.html
" VeraCrypt 1.18 安全评估: https://t.co/x897W61oui"
-
[ Programming ] Exploring ARM inline assembly in @ rustlang http://embed.rs/articles/2016/arm-inline-assembly-rust/ < awesome!
"ARM 内联汇编(inline assembly)探索: http://embed.rs/articles/2016/arm-inline-assembly-rust "
-
[ Tools ] Hypercalls fuzzing is now supported from within Linux VMs as well: https://github.com/chipsec/chipsec/pull/103
"Hypercall IOCTL for Linux driver: https://github.com/chipsec/chipsec/pull/103"
-
[ Web Security ] Published the Net Cease tool to help admins to harden their environments against malicious net sessions scans… https://t.co/fineC6RNfw
"Net Cease -- 一个用于防止恶意网络会话扫描的工具: https://gallery.technet.microsoft.com/Net-Cease-Blocking-Net-1e8dcb5b "
-
[ Windows ] Use the new Nano Server Image Builder to create a custom Nano image: https://blogs.technet.microsoft.com/nanoserver/2016/10/15/introducing-the-nano-server-image-builder/
" 用 Nano Server Image Builder(镜像制作工具)创建自己定制版的 Nano 镜像︰ https://t.co/fsOmPVfVam"
-
[ Windows ] Windows: DFS Client Driver Arbitrary Drive Mapping EoP https://bugs.chromium.org/p/project-zero/issues/detail?id=885
" Windows: DFS Client Driver Arbitrary Drive Mapping EoP: https://t.co/SJt3fxjuqW"
-
[ WirelessSecurity ] Code is up! Transmit your own HD Radio signal with a HackRF or USRP. https://github.com/argilo/nrsc-5 #GnuRadio #SDR https://t.co/m3TgRwYJ6q
" HD Radio (NRSC-5-C) 的软件实现版本: https://t.co/RiwLfOeV6S "
-
[ Windows ] 巧用COM接口IARPUninstallStringLauncher绕过UAC: http://www.freebuf.com/articles/system/116611.html
-
[ Linux ] An LKM rootkit targeting Linux 2.6/3.x on x86(_64), and ARM: https://github.com/citypw/suterusu