
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Android: RKP EL1 Code Loading Bypass https://bugs.chromium.org/p/project-zero/issues/detail?id=981
-
[ Browser ] Apple WebKit: Type confusion in RenderBox with accessibility enabled https://bugs.chromium.org/p/project-zero/issues/detail?id=1038
" WebCore::AXObjectCache::gAccessibilityEnabed 启用时,WebKit RenderBox 存在一个类型混淆漏洞(CVE-2017-2373): https://t.co/R3J3jFvXd1"
-
[ Browser ] Apple WebKit: Type confusion in HTMLKeygenElement https://bugs.chromium.org/p/project-zero/issues/detail?id=999
" Apple WebKit: Type confusion in HTMLKeygenElement(CVE-2017-2369): https://t.co/KwI7aCz5Da "
-
[ Browser ] Also derestricted some other bugs: https://bugs.chromium.org/p/project-zero/issues/detail?id=994, 999 (userAgentShadowRoot fun, affecting both Blink and WebKit) and 1038.
" Google Chrome: Type confusion in HTMLKeygenElement::shadowSelect(),Chrome 55 版本已经修复该漏洞︰ https://t.co/ERxPwwO29I "
-
[ Browser ] Open-sourcing Chrome on iOS! https://blog.chromium.org/2017/01/open-sourcing-chrome-on-ios.html
"iOS 版本的 Chrome 开源了: https://t.co/FM6jnquzlJ"
-
[ Linux ] local privilege escalation in #illumos via permissions not being enforced in /proc http://benmmurphy.github.io/blog/2017/01/31/local-privilege-escalation-in-illumos-via-slash-proc/ https://t.co/EqXucUWB1o
" Illumos 基于 /proc 实现的本地提权(Illumos 是 OpenSolaris 的衍生版本): https://t.co/mWFXdUexXn https://t.co/EqXucUWB1o "
-
[ Malware ] EyePyramid: An Archaeological Journey http://blog.talosintel.com/2017/01/Eye-Pyramid.html
" 恶意软件 EyePyramid 的考古之旅: https://t.co/XHPtquntTh"
-
[ NetworkDevice ] Bypassing Authentication on NETGEAR Routers : https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2017-5521--Bypassing-Authentication-on-NETGEAR-Routers/ cc @ Simon_Kenin //CVE-2017-5521
"绕过 Netgear 路由器上的身份验证(CVE-2017-5521)︰ https://t.co/bnJQKapTYX "
-
[ Others ] 41 vulnerabilities in #tcpdump, most of which are remotely exploitable! Upgrade to tcpdump 4.9.0.1 ASAP!… https://t.co/l30ezSMYeo
"tcpdump 发布安全公告,修复了 41 个漏洞,其中有部分可以远程利用: https://t.co/l30ezSMYeo"
-
[ Others ] From Mimikatz to Kekeo, Passing by New Microsoft Security Technologies https://onedrive.live.com/view.aspx?resid=A352EBC5934F0254!3316&ithint=file%2cpptx&app=PowerPoint
"从 Mimikatz 到 Kekeo,以及微软新引入的安全技术: https://t.co/CU71LolLZQ"
-
[ Popular Software ] PHP Crashers https://github.com/hannob/php-crashers scripts that cause segfaults in PHP
"能够使 PHP 解释器发生段错误崩溃的几个脚本: https://t.co/ZF4PBbP5HT "
-
[ Virtualization ] VirtualBox Privilege Escalation https://packetstormsecurity.com/files/140791/virtualbox-escalate.txt
" VirtualBox 5.1.14 提权漏洞(CVE-2017-3316),附 PoC: https://t.co/9GV2fzJgAi"
-
[ Web Security ] 5 ways to File upload vulnerability Exploitation http://www.hackingarticles.in/5-ways-file-upload-vulnerability-exploitation/
"文件上传漏洞的 5 种利用方法: https://t.co/Sh9YefxaVO"