
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Solving an #Android #Crackme with a Little Symbolic Execution http://www.vantagepoint.sg/blog/81-solving-an-android-crackme-with-a-little-symbolic-execution
"利用符号执行解决 Android Crackme: https://t.co/l5RmlSW13m "
-
[ Conference ] Drone Hijacking and other IoT hacking with GNU Radio and SDR by ARTHUR GARIPOV, http://bit.ly/2izXfDM https://t.co/vRvlMLfrKQ
"nullcon 2017 大会议题放出: http://nullcon.net/website/goa-2017/about-speakers.php"
-
[ Conference ] Slides of some RWC talks are already online: https://www.realworldcrypto.com/rwc2017/program. Here are my slides on FourQ: https://t.co/p9ZUQRdsOA #realworldcrypto
"Real World Cryptography 2017 大会一些议题 PPT 已公布︰ https://t.co/HLjh7Bw77s"
-
[ Fuzzing ] Finding Bugs in TensorFlow with LibFuzzer https://da-data.blogspot.com.es/2017/01/finding-bugs-in-tensorflow-with.html
"利用 LibFuzzer 挖掘 TensorFlow 中的 bug: https://t.co/IxlH1kvmd0"
-
[ Hardware ] The Common Methods of Hardware Hacking https://www.sparkfun.com/news/1314 https://t.co/PdyQYSJB9d
"Hardware Hacking 的常用方法: https://t.co/GO7wf8lQ7R https://t.co/PdyQYSJB9d"
-
[ IoTDevice ] Huawei Flybox B660 - (POST Reboot) CSRF Vulnerability https://goo.gl/fb/DiiTXh #FullDisclosure
"华为 Flybox B660 路由器 CSRF 漏洞: https://t.co/3KWET8NJ0f "
-
[ Linux ] Attacking UEFI Runtime Services and Linux : http://blog.frizk.net/2017/01/attacking-uefi-and-linux.html , Demo : https://www.youtube.com/watch?v=PiUVRHYTDUg ,… https://twitter.com/i/web/status/819185214618566660
"通过修改计算机固件攻击 UEFI 运行服务可进一步控制 Linux 系统︰ https://t.co/fntFEX3JS6 ; Demo︰ https://t.co/LLdLKDe4On"
-
[ Malware ] Shamoon Can Now Destroy Virtual Desktops, Too http://arstechnica.com/security/2017/01/shamoon-disk-wiping-malware-can-now-destroy-virtual-desktops-too/
"Shamoon 恶意软件现在能够破坏虚拟桌面: https://t.co/UUbF38o7oc"
-
[ MalwareAnalysis ] Find out which #ransomware infected a smart TV and used a ransom note mimicking the FBI. Report:… https://twitter.com/i/web/status/819182083427958785
"Trendmicro 对恶意软件的回顾(2016 年 12 月 19-31日 ): https://t.co/Nm0hxoQE2j"
-
[ Mobile ] OnePlus 3/3T Vulnerability Allows Changing of SELinux to Permissive Mode in Fastboot: https://www.xda-developers.com/oneplus-33t-bootloader-vulnerability-allows-changing-of-selinux-to-permissive-mode-in-fastboot/
"一加手机 3/3T Bootloader 存在漏洞,允许在 Fastboot 中将SELinux 更改为 Permissive 模式︰ https://t.co/l14j8BMnVI"
-
[ Others ] New from @ acar_can: whitepaper detailing pointer authentication on ARMv8.3 https://www.qualcomm.com/news/onq/2017/01/10/qualcomm-releases-whitepaper-detailing-pointer-authentication-armv83
"Pointer Authentication on ARMv8.3 白皮书: https://www.qualcomm.com/media/documents/files/whitepaper-pointer-authentication-on-armv8-3.pdf "
-
[ Others ] Disabling Intel-ME https://goo.gl/ajBKaS
"如何禁用 Intel ME: https://t.co/XA2qjo8LH2"
-
[ Popular Software ] Adobe Acrobat Pro DC ImageConversion TIFF Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-17-030/
"Adobe Acrobat Pro DC ImageConversion TIFF 解析存在堆溢出漏洞可导致远程代码执行(CVE-2017-2966): https://t.co/vzogSUvkl8"
-
[ SecurityProduct ] Bit Defender #39 - Auth Token Bypass Vulnerability https://goo.gl/fb/R774pk #FullDisclosure
"杀软 Bit Defender Auth Token 绕过漏洞: https://t.co/jXQeMcZX66 "
-
[ SecurityProduct ] Art of Anti Detection – Intro to AV & Detection : https://pentest.blog/art-of-anti-detection-1-introduction-to-av-detection-techniques/ , Part 2 – PE Backdoor Manufacturing :… https://twitter.com/i/web/status/819183101108776960
"反检测的艺术介绍︰ https://t.co/6XeeyiVC2K 反检测的艺术之 PE 后门制作: https://t.co/zC2onjCP6w"
-
[ Tools ] Nice and useful site from Microsoft: http://rise4fun.com/, pretty cool stuff there to explore!
"Microsoft 公开的多个领域的工具列表︰ https://t.co/JIJvkwvmeM"
-
[ Windows ] Windows DLL Injection Basics : http://blog.opensecurityresearch.com/2013/01/windows-dll-injection-basics.html
"Windows DLL 注入基础︰ https://t.co/S83ggJ8IL1"
-
[ Windows ] The Unpatched LSASS Remote Denial of Service (MS16-137) https://www.coresecurity.com/blog/unpatched-lsass-remote-denial-service-ms16-137
"未修复的 LSASS 远程拒绝服务(MS16-137): https://t.co/YnslRcCBr7"
-
[ WirelessSecurity ] OpenAirinterface - Towards Truly Open-Source Solutions for 5G #IoT #SDR [PDF]http://www.openairinterface.org/docs/workshop/1_OAI_Workshop_20160122/OAI-obj2016.pdf https://t.co/IVUOJQY0mM
"OpenAirinterface - 5G开源实现方案: https://t.co/FdrMyN075H https://t.co/IVUOJQY0mM"