
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Hooking #Android System Calls for Pleasure and Benefit http://goo.gl/tTyBGN https://t.co/kOevQoVlY6
"Hooking Android 系统调用: https://t.co/mnOKSkBkwM "
-
[ Hardware ] My version of the HEVD Arbitrary Overwrite exploit in C. @ HackSysTeam https://github.com/Cn33liz/HSEVD-ArbitraryOverwrite https://t.co/kFTy9ZxnPK
"HSEVD-ArbitraryOverwrite 漏洞利用代码: https://t.co/NppWTz2Xyy "
-
[ Obfuscation ] Code Obfuscation Against Symbolic Execution Attacks : https://www.researchgate.net/profile/Sebastian_Banescu/publication/311491954_Code_obfuscation_against_symbolic_execution_attacks/links/5849b78708ae82313e7108bf.pdf?origin=publication_detail (pdf)
"利用代码混淆来对抗符号执行攻击(PDF)︰ https://t.co/0ir5vZfUY0"
-
[ Others ] Mastering Bash and Terminal : https://www.blockloop.io/mastering-bash-and-terminal
"熟练掌握 Bash 和 Terminal︰ https://t.co/gvMcnmKDZo"
-
[ Tools ] MongoDB-HoneyProxy : A honeypot proxy for mongodb. It will proxy and log all traffic to a dummy mongodb server : https://github.com/Plazmaz/MongoDB-HoneyProxy
"MongoDB-HoneyProxy -- 一个 MongoDB 网络代理工具︰ https://t.co/KiLGp7DqvD"
-
[ Tools ] QEMU Interactive Runtime Analyser https://github.com/BinaryAnalysisPlatform/qira
"QEMU 交互式运行时分析器: https://t.co/zPHhs4aWui"
-
[ Web Security ] Stealing passwords from McDonald's users through an AngularJS sandbox escape. https://finnwea.com/blog/stealing-passwords-from-mcdonalds-users https://t.co/oiNYP86A6r
"McDonald 网站 AngularJS 沙箱被绕过,导致用户数据被窃 : https://t.co/googLE2Ez5 https://t.co/oiNYP86A6r"
-
[ Web Security ] Finally, my research on "Evading All Web-Application Firewalls XSS Filters" is released. http://blog.mazinahmed.net/2015/09/evading-all-web-application-firewalls.html
"绕过所有 WAF 的 XSS 过滤器: http://t.co/fenknveq0V"
-
[ Windows ] Windows on Github https://microsoft.github.io/windows/
"Windows on Github: https://t.co/mi7p7Kdmnt"
-
[ Windows ] FuzzySec [$PSKernelPwn] -> Windows Kernel Exploitation: GDI Bitmap Abuse (Win7-10 32/64bit) -… https://twitter.com/i/web/status/820657021724856321
"Kernel Exploitation - GDI Bitmap Abuse (Win7-10 32/64bit): https://t.co/hc8D40nkhj"
-
[ Windows ] Hardening Windows 10 with 0-day exploit mitigations : https://blogs.technet.microsoft.com/mmpc/2017/01/13/hardening-windows-10-with-zero-day-exploit-mitigations/ https://t.co/5lIQfgyPZm
"Windows 内核漏洞(CVE-2016-7255、 CVE-2016-7256)分析,以及 Microsoft 针对这两个漏洞在 Windows 10 中新加的缓解措施: https://t.co/hWtQGTbizB https://t.co/5lIQfgyPZm"
-
[ Web Security ] Destoon 6.0 guestbook.php 通用SQL注入漏洞: https://www.leavesongs.com/PENETRATION/destoon-v6-0-sql-injection.html