
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Pwning the Pixel remotely using the Mobile Pwn2Own 2016 bugs @ keen_lab https://youtu.be/ip7FsZpuHT4 (maybe first in the world?)
"Pwning Nougat 7.1 on Pixel,来自腾讯科恩实验室(video): https://t.co/fH73UiQaRj"
-
[ Attack ] .#BlackNurse Low-Volume DoS Attack Targets Firewalls https://threatpost.com/blacknurse-low-volume-dos-attack-targets-firewalls/121916/
"针对防火墙的拒绝服务攻击(基于ICMP): https://t.co/YCTO6idpat"
-
[ Browser ] #DeepSec MitM 'Captive portals', HSTS & cookies by @ atrox_at https://www.dropbox.com/s/zktz1gurst6zlxr/deepsec2016.pdf [cache side channel leak brows… https://t.co/Yj6kgNx9UM
"HSTS and Cookies: Side-channels to Steal Browsing History(PDF),来自 Deepsec 2016: https://t.co/2BTTS6nxpt "
-
[ Exploit ] Heap Exploitation - Modern Binary Exploitation : http://security.cs.rpi.edu/courses/binexp-spring2015/lectures/17/10_lecture.pdf (Slides)
"来自美国伦斯勒理工大学的课程PPT -- 堆利用技术︰ https://t.co/H9ZuciFSCz "
-
[ iOS ] needle - The iOS Security Testing Framework http://www.kitploit.com/2016/11/needle-ios-security-testing-framework.html
"needle -- 一个 iOS 安全测试框架: https://t.co/S4hAmmT677"
-
[ IoTDevice ] IoT worm can hack Philips Hue lightbulbs, spread across cities http://www.theregister.co.uk/2016/11/10/iot_worm_can_hack_philips_hue_lightbulbs_spread_across_cities/
"物联网蠕虫利用智能 Philips Hue lightbulb 来进行传播: https://t.co/wDllb63V5I"
-
[ MachineLearning ] Introduction to Machine Learning for Developers : http://blog.algorithmia.com/introduction-machine-learning-developers/
"机器学习介绍︰ https://t.co/WcA7a23xK9"
-
[ Malware ] Telecrypt ransomware abuses Telegram Messenger’s communication protocol http://securityaffairs.co/wordpress/53295/malware/telecrypt-ransomware.html
"新的勒索软件 Telecrypt 使用即时通信软件 Telegram 来作为 C&C 服务器: https://t.co/ellVGx0luf"
-
[ MalwareAnalysis ] Floki Bot and the stealthy dropper https://blog.malwarebytes.com/threat-analysis/2016/11/floki-bot-and-the-stealthy-dropper/
"Floki Bot 分析: https://t.co/9q3hahRLnQ"
-
[ Others ] PowerShell Empire module for logging USB keystrokes via ETW : https://github.com/CyberPoint/ETWKeyLogger_PSE , KeyloggerPOC : https://github.com/CyberPoint/Ruxcon2016ETW/tree/master/KeyloggerPOC
"PowerShell Empire 模块可通过 ETW 记录 USB 击键︰ https://t.co/FZtU8oli2d,KeyloggerPOC: https://t.co/dSD7WeZtQs"
-
[ Others ] Over 96 million unique malware variants detected in October. Find out more in our Latest Intelligence:… https://t.co/ylFLYEbocX
"10 月安全情报,来自 Symantec: https://t.co/ylFLYEbocX"
-
[ Others ] Create arch independent malicious documents and templates and bypass security software with wePWNise https://labs.mwrinfosecurity.com/tools/wepwnise/
"wePWNise -- 可生成平台独立的恶意文件及样本的工具: https://t.co/tNftcOjJzQ"
-
[ Pentest ] Metasploit - Low Level View : https://www.exploit-db.com/docs/18532.pdf (pdf) cc @ Sa3dtalaat
"Metasploit-Low Level View ,code injector and payload encoder(PDF)︰ https://t.co/g2OgzXNP9U "
-
[ Protocol ] How we ditched HTTP and transitioned to MQTT : https://blog.hypertrack.io/2016/11/10/how-we-ditched-http-and-transitioned-to-mqtt/ ; MQTT Essentials : http://www.hivemq.com/mqtt-essentials/ https://t.co/nff1dkmL5n
"我们是如何抛弃了 HTTP 并切换到 MQTT 的: https://blog.hypertrack.io/2016/11/10/how-we-ditched-http-and-transitioned-to-mqtt/ MQTT 要点︰ https://t.co/SutgP0OIbn MQTT(中文版): https://github.com/mcxiaoke/mqtt"
-
[ Sandbox ] Infect to Protect: sandboxing executables using elementary virus-writing techniques https://tia.mat.br/posts/2016/11/08/infect_to_protect.html
"Infect to Protect: sandboxing executables using elementary virus-writing techniques: https://t.co/v0mvak67Vb "
-
[ Tools ] MSBuildShell, a Powershell Host running within MSBuild.exe. Bypass App Whitelisting using MSBuild.exe -> By @subTee… https://t.co/xgh96el2b7
"MSBuildShell -- 一个包含在 MSBuild.exe 中的 powershell 模块。利用 MSBuild.exe 可用来绕过对 powershell 白名单的检测: https://github.com/Cn33liz/MSBuildShell"
-
[ WirelessSecurity ] infernal twin Automated Evil Twin Attack http://www.kalitut.com/2016/01/infernal-twin-automated-evil-twin-attack.html #EvilTwin #WiFiSecurity #wifi #kalilinux https://t.co/eIpkbWa92y
" infernal-twin -- 一个自动化的 wifi hacking 工具,文章对此工具进行了介绍,同时提出了防御方法: https://t.co/UnDsRFYKqY "