
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ iOS ] (PDF Slides) Analysis of iOS 9.3.3 Jailbreak & Security Enhancements of iOS 10 -- https://lnkd.in/g6eU5ed #iOS #Security
"Analysis of iOS 9.3.3 Jailbreak & Security Enhancements of iOS 10(PDF),来自 POC 2016 Pangu Team: https://t.co/X4aq1kO1I2"
-
[ Linux ] Cryptosetup LUKS Volume compromised - CVE 2016-4484 http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html #infosec #vulnerability #linux
"Linux 中 Cryptosetup 存在漏洞(CVE-2016-4484),可获取一个 root initramfs shell,本文对此漏洞进行了分析: http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html#exploit "
-
[ Linux ] Nginx (Debian-based distros) - Root Privilege Escalation - http://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html
"基于 Debian 发行版的 Nginx 存在提权漏洞(CVE-2016-1247),含 POC: https://t.co/xObQ5ChI3Y"
-
[ MalwareAnalysis ] Fake fax ushers in revival of a ransomware family https://blogs.technet.microsoft.com/mmpc/2016/11/15/fake-fax-ushers-in-revival-of-a-ransomware-family/
"假传真引领勒索软件家族的复兴: https://t.co/60d7IfP654"
-
[ Mobile ] I released a new blog post called, JTAGing Mobile Phones - https://sysforensics.org/2016/08/jtaging-mobile-phones/ #DFIR #JTAG #infosec
"JTAGing Mobile Phones: https://t.co/qDxcZjtuSA "
-
[ Others ] LogViewer v0.0.8 released. Added file lock checks, improved loading and also view line window. https://github.com/woanware/LogViewer/releases/tag/v0.0.8
"LogViewer v0.0.8 发布,新加了文件锁定检查等新功能: https://t.co/iNDGysh9mL"
-
[ Others ] Trace-Execution.ps1 -> uses @ capstone_engine to statically trace execution flow of PE's - https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Trace-Execution.ps1 https://t.co/W4d4flVMRN
"PowerShell-Suite 渗透框架中的一个 trace PE 的模块: https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Trace-Execution.ps1"
-
[ Others ] Metasploitable3 : An Intentionally Vulnerable Machine for Exploit Testing : https://community.rapid7.com/community/metasploit/blog/2016/11/15/test-your-might-with-the-shiny-new-metasploitable3 , Github : https://github.com/rapid7/metasploitable3
"Metasploitable3 虚拟机介绍︰ https://t.co/IeOkv85a5u Github: https://t.co/S1k8V8ucKh"
-
[ Others ] The number of samples in the McAfee Labs malware “zoo” now totals over 600 million. See what we found:… https://twitter.com/i/web/status/798758777503633408
"来自 McAfee Labs 的威胁报告(9月): https://t.co/jK7wcSFXOj"
-
[ Popular Software ] Cross-Site Scripting in All In One WP Security & Firewall WordPress Plugin https://goo.gl/fb/LdtKMC #FullDisclosure
" WordPress All In One WP Security & Firewall 插件存在 xss 漏洞: https://t.co/sAwDkIpbD4 "
-
[ Programming ] x86-64 Assembly Language Programming with Ubuntu : http://www.egr.unlv.edu/~ed/assembly64.pdf (pdf)
" Ubuntu x86-64 汇编语言编程 : https://t.co/IPH4CtqHQU "
-
[ Tools ] Download Visual Studio 2017 RC today. As usual, the C++ compiler has a few worthy improvements. https://www.visualstudio.com/downloads/
"Microsoft 发布 Visual Studio 2017 RC: https://t.co/xoz50BH6BK"
-
[ Tools ] Genuinely interesting approach to VBA and Malicious Office analysis https://twitter.com/jedisct1/status/798934873293484032
"vba-dynamic-hook -- 一个利用 hooking 技术动态分析 VBA 的工具: https://t.co/ivEX2e96zK"
-
[ Tools ] I've released PoisonTap; attacks *locked* machines, siphons cookies, exposes router & backdoors browser w/RasPi&Node https://t.co/mbTAti33wy
" PoisonTap -- 一个只需 5 美元的设备能在一分钟内黑掉你的电脑 ,video: https://t.co/mbTAti33wy Source code: https://samy.pl/poisontap/"
-
[ Tools ] A new application uses Capstone disassembler inside: W-SWFIT is a Software Fault Injection Tool for Windows 64bit. https://t.co/4HEGuuySe3
"W-SWFIT -- 一个 Windows X64 软件故障注入工具: https://t.co/4HEGuuySe3"
-
[ Tools ] B00m XEN Support for memory dumping & soon to add memory integrity checking :) https://github.com/ShaneK2/inVtero.net/commit/4ced28d1bdba7d067bee08be3726ac2cf63d2c30
"inVtero.net 工具现已支持 XEN(inVtero.net 是一个使用微架构的虚拟机自省技术,可用来 DUMP 内存): https://t.co/8SmY4G6FAh"
-
[ Vulnerability ] Java deserialization endpoint found by Jacob Baines in VMwaew vRealize Operations http://www.vmware.com/security/advisories/VMSA-2016-0020.html #javadeser
"vRealize Operations 更新处理了 REST API 反序列化漏洞: https://t.co/AWEouStZ4z "
-
[ WirelessSecurity ] .@ IBM opens attack simulation test center - https://threatpost.com/ibm-opens-attack-simulation-test-center/122004/
"IBM 开设了攻击模拟测试中心: https://t.co/VCWisBHzkk"
-
[ WirelessSecurity ] Researcher hacks city's WiFi service using buffer-overflow exploit https://www.scmagazine.com/researcher-hacks-citys-wifi-service-using-buffer-overflow-exploit/article/573203/
"安全人员利用负载均衡器中的缓冲区溢出漏洞黑掉了其城市的 wifi 服务: https://t.co/hnZzDQkgtp "
-
[ WirelessSecurity ] New Comparison Videos from Leif SM5BSZ: Airspy vs SDRplay vs Several Other SDRs http://www.rtl-sdr.com/new-comparison-videos-from-leif-sm5bsz-airspy-vs-sdrplay/
"Airspy 、SDRplay 及其它几个 SDR 的对比视频: https://t.co/rvMIPu5UuT"
-
[ Others ] CVE-2016-5007:Spring Security / MVC Path Matching Inconsistency: http://bobao.360.cn/learning/detail/3199.html
-
[ WirelessSecurity ] 使用USRP探索无线世界 Part 1:USRP从入门到追踪飞机飞行轨迹: http://www.freebuf.com/articles/wireless/119950.html