
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Exotic HTTP Headers - Exploration of HTTP security and other non-typical headers : https://peteris.rocks/blog/exotic-http-headers/
"Exotic HTTP Headers,文章详细介绍了浏览器安全相关的 HTTP Header︰ https://t.co/LBhjO5rzxf"
-
[ Firmware ] Multiple Netgear routers are vulnerable to arbitrary command injection : http://www.kb.cert.org/vuls/id/582384 , More : https://cxsecurity.com/issue/WLB-2016120049
"Netgear 路由器存在命令注入漏洞︰ https://t.co/oxvoRH1Lka"
-
[ MalwareAnalysis ] Ostap - A JScript malware used to deliver Dridex, Tinba, Ursnif, and Mr.White (leads to TinyLoader -> AbaddonPOS): https://t.co/pLD9OsNm6K
"Ostap -- 一个 JScript 后门的分析,其被用于 Dridex, Tinba, Ursnif 等恶意软件中: https://t.co/pLD9OsNm6K"
-
[ Others ] Excited about Metasploitable3? Us, too. So we're hosting an online #CTF! Check it out: http://r-7.co/2ghDgL9 https://t.co/2RfPFXuEhd
" Metasploitable3 发布: https://github.com/rapid7/metasploitable3 同时推出了 Metasploitable3 CTF︰ https://t.co/nRmPGKLjpc "
-
[ Protocol ] Reverse Engineering the HTC Vive watchman controller protocol https://www.youtube.com/watch?v=oHJkpNakswM
"逆向 HTC Vive watchman controller 协议(video): https://t.co/6N1eT3CuYw"
-
[ Tools ] New Tool: CloakifyFactory. Turn any filetype into a list of everyday strings to hide/exfiltrate/infiltrate. Enjoy!… https://t.co/LwsRHYMOvD
"CloakifyFactory -- 可将数据编码成常见字符串的工具: https://github.com/TryCatchHCF/Cloakify"
-
[ Tools ] Angular 1.6 is out https://angularjs.blogspot.se/2016/12/angular-160-released.html No more bypasses needed: {{0[a='constructor'][a]('alert(1)')()}} will do https://output.jsbin.com/hapacezilo
"Angular 1.6 发布: https://angularjs.blogspot.se/2016/12/angular-160-released.html"
-
[ Tools ] dedsploit - Framework For Attacking Network Protocols http://www.kitploit.com/2016/12/dedsploit-framework-for-attacking.html
"dedsploit -- 一个针对网络协议的攻击框架: https://t.co/o0tECps5nj"
-
[ Windows ] Windows 10: protection, detection, and response against recent Depriz malware attacks https://blogs.technet.microsoft.com/mmpc/2016/12/09/windows-10-protection-detection-and-response-against-recent-attacks/
"Windows 10︰ 对最近 Depriz 恶意软件的保护、 检测和响应: https://t.co/lN12bx6Dn8"
-
[ WirelessSecurity ] GreedyBTS – Hacking Adventures in GSM : https://repo.t0x0sh.org/Papers/Network/2014_hacking_gsm.pdf (pdf/Slides) cc @ hackerfantastic
" GSM hacking 大冒险(pdf)︰ https://t.co/6SIVWZS8ep "