
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] PoC for Microsoft Internet Explorer ‘DrawMultiple’ Memory Corruption Vulnerability (MS16-144) (CVE-2016-7283): https://t.co/Hscco5p7Fj
"Microsoft IE 'DrawMultiple' 内存破坏漏洞 (CVE-2016-7283) PoC: https://t.co/Hscco5p7Fj"
-
[ Crypto ] How to create a x86 polymorphic encryption engine in C++ https://www.pelock.com/articles/polymorphic-encryption-algorithms
"如何用 C++ 创建一个 x86 下的多态加密引擎: https://t.co/4Rd62naVrf"
-
[ MachineLearning ] A Visual and Interactive Guide to the Basics of Neural Networks - https://jalammar.github.io/visual-interactive-guide-basics-neural-networks/
"一个基础的神经网络可视化交互指南: https://t.co/5RVJaADVta"
-
[ MalwareAnalysis ] Abusing File Processing in Malware Detectors for Fun and Profit : https://www.cs.cornell.edu/~shmat/shmat_oak12av.pdf (pdf)
"在恶意软件检测中欺骗文件操作(PDF)︰ https://t.co/6H6xtFIiXs "
-
[ MalwareAnalysis ] Malicious Macro Bypasses UAC to Elevate Privilege for Fareit Malware http://blog.fortinet.com/2016/12/16/malicious-macro-bypasses-uac-to-elevate-privilege-for-fareit-malware
"对能绕过 UAC 并执行 Fareit 恶意软件的恶意宏分析: https://t.co/y8tNRcRz5H"
-
[ MalwareAnalysis ] GNISREVER - A Polymorphic File-Infecting Ransomware : https://def.camp/wp-content/uploads/dc2016/Day%201/RaulAlvarez_DefCamp7.pdf (Slides) https://t.co/F8QrDkQXZG
"文件感染型勒索软件 Virlock 的分析(Slides): https://t.co/F8QrDkQXZG"
-
[ Others ] NAB Sent Details Of 60,000 Customers To Wrong Email Address http://www.zdnet.com/article/nab-sent-details-of-60000-customers-to-wrong-email-address/
"澳洲国民银行将 6 万用户数据发错 Email 地址: https://t.co/UVpSztCC1l"
-
[ Others ] As of today, we've published 672 advisories this year. That's a record for us, & 2017 looks even busier. http://bit.ly/2cLxnau #StayTuned
"ZDI 在 2016 年披露的所有漏洞的列表: https://t.co/B0OsaZXE0y "
-
[ Popular Software ] CSRF/stored XSS in Quiz And Survey Master (Formerly Quiz Master Next… https://goo.gl/fb/yC2gUi #FullDisclosure
"WordPress 插件 Quiz And Survey Master 存在 CSRF/存储型 XSS 漏洞: https://t.co/OsGKqfq1YH"
-
[ Tools ] Published another IDA plugin — https://github.com/ax330d/ida_pdb_loader. Sometimes IDA crashes for me when loading PDB, so I came up with this simple plugin.
"IDA PDB Loader: https://t.co/VfrnOiOITM"
-
[ Tools ] An Open Source Tool for Visually Analyzing and Diffing SELinux/SE for Android Security Policies https://www.invincealabs.com/blog/2016/12/v3spa-announcement/
"V3spa -- Android SELinux /SE 安全策略的分析与 dif 工具: https://t.co/CETGuucMAP"
-
[ Tools ] Burp Suite Professional 1.7.14 - The Leading Toolkit for Web Application Security Testing http://bit.ly/2hFnAQu… https://t.co/1J6SUC1eAM
"Burp Suite Professional 1.7.14 新版本的介绍与下载: https://t.co/rcwGPTLJjx"