
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Androguard – Reverse Engineering & Malware Analysis For Android http://www.darknet.org.uk/2016/11/androguard-reverse-engineering-malware-analysis-for-android/
"Androguard -- 一款用于 Android 恶意软件分析及逆向的工具: https://t.co/wHm3PMIGLs"
-
[ IoTDevice ] Fitbit tracker firmware retrieval and Analysis : https://www.cs.ru.nl/bachelorscripties/2016/Maarten_Schellevis___4142616___Getting_access_to_your_own_Fitbit_data.pdf (pdf) https://t.co/AoohRmXOSF
"智能设备 Fitbit tracker 固件检索和分析(PDF)︰ https://t.co/csLWXoPm3P "
-
[ Others ] Entity provider selection confusion attack in JAX-RS apps #ZeroNights http://www.slideshare.net/0ang3el/entity-provider-selection-confusion-attacks-in-jaxrs-applications
"Entity provider selection confusion attacks in JAX-RS applications: https://t.co/OoCtLUbXN8"
-
[ Others ] Back to #Android Mode: Ported my Process Explorer to improve 'top' w/colors,sortability,filters.… https://t.co/GgWLQe5yt8
"Process Explorer -- Android 上的进程管理器 : http://newandroidbook.com/tools/procexp.html"
-
[ Popular Software ] Sending Valid Phishing E-mails From http://Microsoft.com Domain by Using Office 365 : https://www.utkusen.com/blog/sending-valid-phishing-emails-from-microsoftcom.html
"通过使用 Office 365 发送 Microsoft.com 域钓鱼邮件︰ https://t.co/1JyvoJfPsx"
-
[ Popular Software ] Just posted Sysinternals updates: Major Sysmon enhancements w/Registry and file events, Procexp, Procdump, LiveKd: https://t.co/YoZ1HmRnyQ
"Windows Sysinternals 推出更新: https://t.co/YoZ1HmRnyQ"
-
[ Popular Software ] Persistent Cross-Site Scripting in Instagram Feed plugin via CSRF https://goo.gl/fb/J3LIwz #FullDisclosure
"Instagram Feed 插件存在 XSS 漏洞: https://t.co/uRwcu6IjpD "
-
[ Tools ] ManageEngine Asset Explorer Agent - Remote Code Execution as SYSTEM https://github.com/XiphosResearch/exploits/tree/master/AssetExploder
"ManageEngine Asset Explorer Agent: https://t.co/bfnteS33yh "
-
[ Tools ] Created python scripts for removing, changing, or cracking password-protected VBA macros (Office 97-2003).… https://t.co/dtUduFIPec
"VBAMacroPWD -- 一个用于更改、破解 Office 97-2003 宏密码的 Python 工具: https://t.co/dtUduFIPec"
-
[ Vulnerability ] Cross-Site Scripting in Huge IT Portfolio Gallery WordPress Plugin https://goo.gl/fb/yB6UnR #FullDisclosure
"WordPress 插件 Huge IT Portfolio Gallery 存在 XSS 漏洞: https://t.co/ExCGSReBQj"