
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Tool to reverse engineer your app online to get API tokens and Secrets https://android.fallible.co/
"一个在线检测 Android app 密钥的工具: https://t.co/61tO5qX6LG"
-
[ Attack ] Abusing npm libraries for data exfiltration https://blog.sourceclear.com/all-your-secrets-belong-to-us/
"利用 npm 进行数据渗漏(data exfiltration )攻击: https://t.co/I8aRALevoh "
-
[ Crypto ] Slides for @ deepsec talk about Post Quantum Cryptography https://www.int21.de/slides/deepsec-postquantum/
"Post Quantum Cryptography,来自 deepsec 2016 (slides): https://t.co/TKYLZwkoYk"
-
[ iOS ] Blink Shell for iOS : an Open-Sourcea full-fledged terminal emulator / SSH client for iOS (support for Mosh) : http://www.blink.sh/
"Blink Shell -- 一个 iOS 下的开源终端仿真器 / SSH 客户端: https://t.co/j0Ee6XCvex"
-
[ macOS ] CIS Apple OSX 10.12 Benchmark https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.12_Benchmark_v1.0.0.pdf
"CIS Apple OSX 10.12 Benchmark: https://t.co/iIAWthtll8"
-
[ MalwareAnalysis ] Angry Duck, FakeLock, and new variants of Locky are some the #ransomware we spotted recently. Report: http://bit.ly/2fBWXLO
"Trend Micro 对 10 月 24 - 11 月 4 日期间勒索软件的回顾: https://t.co/unXedwtg2C"
-
[ MalwareAnalysis ] CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox http://www.kitploit.com/2016/11/cuckoodroid-automated-android-malware.html
"CuckooDroid -- 基于Cuckoo Sandbox 的自动化 Android 恶意软件分析工具: https://t.co/iY6Xdj36mY"
-
[ Others ] #oredev CLRMD talk materials -- Slides: https://s.sashag.net/oredev1 Demo: https://www.dropbox.com/s/6pvrh5ljq25uhm3/oredev-clrmd-demo.zip?dl=0 msos (better demo): https://t.co/IVvFOdSxyT
"Automating Problem Analysis and Triage(Slides): https://s.sashag.net/oredev1 Demo: https://t.co/ihqYeY7bCY (msos)︰ https://t.co/IVvFOdSxyT"
-
[ Others ] bWAPP Command Injection Exploitation using Commix (Bypass All Security) http://www.hackingarticles.in/bwapp-command-injection-exploitation-using-commix-bypass-security/
"bWAPP Command Injection Exploitation using Commix (Bypass All Security): https://t.co/PCxrOVFn3s"
-
[ Popular Software ] .NET platform in the Burp Infiltrator tool. http://releases.portswigger.net/2016/11/1711.html
"Burp Suite 1.7.11 发布,同时宣布支持 .NET 平台: https://t.co/9lUusRKmm7"
-
[ Popular Software ] vBulletin 4.2.3 SQL Injection https://packetstormsecurity.com/files/139688/vbulletin423-sql.txt
"vBulletin 4.2.3 存在 SQL 注入漏洞: https://t.co/laMst88k7r"
-
[ Tools ] CHIPSEC v1.2.5 published! Major package setup/install improvements https://github.com/chipsec/chipsec/releases/tag/v1.2.5
"PC 平台安全评估框架 CHIPSEC v1.2.5 发布: https://t.co/ze07rFJnW1"
-
[ Tools ] Codehash.db : A public database of software and firmware hashes : https://github.com/rootkovska/codehash.db
"Codehash.db -- 软件及固件的哈希值公共数据库︰ https://t.co/Um2eaqfivl"
-
[ Tools ] Slides from my Linux Plumbers talks on kernel sanitizers and syzkaller (syscall fuzzer): https://goo.gl/G6P0dX https://t.co/OLsh50BkI8
"Sanitizers -- 新一代的 bug 发现工具,来自 Linux Plumbers 2016 大会(PDF): http://www.linuxplumbersconf.org/2016/ocw//system/presentations/3471/original/Sanitizers.pdf"
-
[ Tools ] VolatilityBot – An automated memory analyzer for malware samples and memory dumps by @ MartinKorman https://github.com/mkorman90/VolatilityBot
"VolatilityBot —— 对恶意软件样本及内存 dump 的自动分析器: https://t.co/jgM6og6dTA "
-
[ Vulnerability ] Observium Remote Command Execution https://cxsecurity.com/issue/WLB-2016110101
"Observium 存在远程命令执行漏洞: https://t.co/oyFaU0AsuF"
-
[ WirelessSecurity ] Inferring your mobile phone password via wifi signals https://blog.acolyer.org/2016/11/10/when-csi-meets-public-wifi-inferring-your-mobile-phone-password-via-wifi-signals/
"通过 wifi 信号推断你的手机密码: https://t.co/tslEehn6WB"
-
[ WirelessSecurity ] SDRuno Updated to V1.1: Now supports up to 2.4 MSPS for the RTL-SDR http://www.rtl-sdr.com/sdruno-updated-to-v1-1-now-supports-up-to-2-4-msps-for-the-rtl-sdr/
"SDRuno V1.1 发布,同时增加了新特性: https://t.co/xvR37Tja3T"
-
[ WirelessSecurity ] A new GNU Radio OOT module. https://github.com/drmpeg/gr-ule Allows DVB-T2 or DVB-S2 links to be used for IP network interlinks. #gnuradio #dvbt2
"一个新的 GNU Radio OOT 模块: https://t.co/6GgSJTnWB8 "