
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Execute millions of SQL statements in milliseconds in the browser with WebAssembly and Web Workers : https://medium.com/@ mikeptweet/execute-millions-of-sql-statements-in-milliseconds-in-the-browser-with-webassembly-and-web-workers-3e0b25c3f1a6#.3i59zl6xr
"通过 WebAssembly 和 Web Workers 可在浏览器中以毫秒级执行上百万条 SQL 语句︰ https://t.co/6lFSvpT0v5"
-
[ Browser ] Mozilla Firefox < 50.1.0 - Use After Free https://cxsecurity.com/issue/WLB-2017010092
"Mozilla Firefox < 50.1.0 UAF 漏洞(CVE-2016-9899)PoC: https://t.co/c6W3aJUfGn"
-
[ Linux ] How SELinux helps blocking a 0day Docker vulnerability (CVE-2016-9962) : http://rhelblog.redhat.com/2017/01/13/docker-0-day-stopped-cold-by-selinux/
"使用 SELinux 防御 Docker 0 day 攻击(CVE-2016-9962): https://t.co/RxgEttffmp"
-
[ Mobile ] DIY smartphone based on Raspberry Pi Zero : https://hackaday.io/project/19035-zerophone-a-raspberry-pi-smartphone/log/51839-project-description-and-frequently-asked-questions https://t.co/YtOQPnhIzp
"50 美元,打造一个你自己的智能手机︰ https://t.co/K7gvdSIUgj https://t.co/YtOQPnhIzp"
-
[ Others ] Hide your ELKs, hide your Kibanas! Linux server ransomware has also begun hitting exposed Elasticsearch instances: http://www.zdnet.com/article/first-came-mass-mongodb-ransacking-now-copycat-ransoms-hit-elasticsearch/
"继 MongoDB 勒索事件后,Elasticsearch 或将成为第二个'受害者'︰ https://t.co/wvMZve9wH4"
-
[ Others ] The bug is finally fixed: How to inject JS in a static PDF to steal it without user interaction http://insert-script.blogspot.co.at/2016/10/pdf-how-to-steal-pdfs-by-injecting.html
"在 PDF 中注入 JS 代码来窃取用户数据: https://t.co/vNHKouTU5A"
-
[ Rootkit ] Finfisher mssounddx.sys rootkit analysis. http://goo.gl/2KUuzI
"Finfisher rootkit 分析: https://t.co/snunoqSz2v"
-
[ Tools ] Exploiting Misconfigured Apache server-status Instances with server-status_PWN : http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
"Apache server-status 利用工具: https://github.com/mazen160/server-status_PWN"
-
[ Tools ] metasploit unicorn powershell downgrade attack via "corrupt" word/excel doc http://goo.gl/qFi5eO
"Unicorn -- Powershell 降级攻击工具: https://t.co/8QA6dPeXJe"
-
[ Windows ] New Bluetooth features in Windows 10 Creators Update (a.k.a. GATT Server and friends) http://dlvr.it/N64ssg https://t.co/eZc408fNcv
"Windows 10 Creators Update 蓝牙三大新特性介绍: https://t.co/HNUyXEpmrf "