
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Conference ] CanSecWest 2017 speakers list revealed http://bit.ly/2lmgwtO
"CanSecWest 2017 入选议题公布: https://t.co/uSHMgqvYyP"
-
[ Crypto ] Using Ordered Markov Chains and User Information to speed up Password Cracking http://fsecurify.com/using-ordered-markov-chains-and-user-information-to-speed-up-password-cracking/
"使用有序的 Markov 链和用户信息提升密码破解速度: https://t.co/ej1s96Rz5x"
-
[ Linux ] Analyzing a .NET Core Core Dump on Linux http://blogs.microsoft.co.il/sasha/2017/02/26/analyzing-a-net-core-core-dump-on-linux/
"Analyzing a .NET Core Core Dump on Linux: http://blogs.microsoft.co.il/sasha/2017/02/26/analyzing-a-net-core-core-dump-on-linux/ "
-
[ Linux ] Proof-of-Concept local root exploit for the double-free in Linux kernel DCCP implementation (CVE-2017-6074): https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-6074
" Linux 内核 DCCP Double Free 代码执行漏洞(CVE-2017-6074) poc: https://t.co/WbEHTqK3b0"
-
[ Others ] Introduction to Return Oriented Programming (ROP) https://ketansingh.net/Introduction-to-Return-Oriented-Programming-ROP/
"ROP 入门介绍: https://t.co/zkWRUnWCre "
-
[ SecurityProduct ] Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution https://cxsecurity.com/issue/WLB-2017020253
"趋势科技 InterScan Messaging Security 远程代码执行漏洞: https://t.co/TdrbKYqcIc"
-
[ Tools ] DNSDelivery : Provides delivery + in memory execution of shellcode /.Net assembly using DNS req. delivery channel : https://github.com/Arno0x/DNSDelivery
"DNSDelivery -- 利用 DNS 请求传输 shellcode 或 .NET 程序并进行内存执行︰ https://t.co/3iH1iRFuI4"
-
[ Tools ] Open Source Fuzzers list (and other fuzzing tools) : https://www.peerlyst.com/posts/resource-open-source-fuzzers-list cc @ ClausHoumann
"开源 Fuzz 工具列表︰ https://t.co/t3XXcjGKi0 "
-
[ Tools ] Git-dit : A distributed issue tracker for git : https://github.com/neithernut/git-dit
"Git-dit -- git 问题跟踪器︰ https://t.co/21KoqeqLrT"
-
[ Web Security ] Mastering HTTP Caching - from request to response and everything : https://blog.fortrabbit.com/mastering-http-caching
"掌握 HTTP 缓存技术-从请求到响应 ︰ https://t.co/YnO6Di4ofW"
-
[ Windows ] A primer on "Windows active directory recon and Authenticated remote code execution techniques". Technical Read! https://t.co/LeioQdKZDx
"域渗透之信息收集与横向移动: https://t.co/LeioQdKZDx"
-
[ Web Security ] Web客户端追踪(上)—Cookie追踪: http://paper.seebug.org/227/ Web客户端追踪(下)—浏览器指纹追踪: http://paper.seebug.org/229/
-
[ Browser ] Chrome 和 Edge 浏览器在内存安全防护上的比较,背后是隔离机制与缓解措施的比较: https://medium.com/@justin.schuh/securing-browsers-through-isolation-versus-mitigation-15f0baced2c2#.d43zzgbsr