腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Now with working instructions for unlock/flashing. Also bootlaoder key combinations for Nexus/Pixels https://t.co/RDtI3901ky
"Android 官方给出的一些手机型号的刷机指引: https://t.co/RDtI3901ky"
-
[ Hardware ] Car Hacker's Handbook 2016 (released under cc) : http://opengarages.org/handbook/
"汽车黑客手册 2016 ︰ https://t.co/jnTqk9uDDg"
-
[ Industry News ] Docker Enterprise Edition https://blog.docker.com/2017/03/docker-enterprise-edition/
"Docker 有企业版了: https://t.co/D623Se8qQT"
-
[ Industry News ] #Dharma #ransomware decryption keys added to http://bit.ly/2aFvRkm - http://bit.ly/2mebH8V https://t.co/xdao1vgcwx
"Kaspersky Lab 发布了 Dharma 勒索软件的解密密钥: https://threatpost.com/keys-for-dharma-ransomware-released/124024/ "
-
[ Industry News ] 132 Google Play Apps Booted For Malicious IFrames: https://threatpost.com/132-google-play-apps-booted-for-malicious-iframes/124038/ via @ threatpost
"Google 应用商店移除了 132 个受恶意 IFrames 影响的应用: https://t.co/QXymi5jGcV"
-
[ Industry News ] 32 Million Yahoo Accounts Affected by Forged Cookies, Investigation Finds http://feedproxy.google.com/~r/tripwire-state-of-security/~3/zyeO_rArzWk/
"调查发现 3200 万雅虎帐户受伪造 Cookie 的影响: https://t.co/BSstH8fP4S"
-
[ IoTDevice ] Hacking Robots Before Skynet : http://www.ioactive.com/pdfs/Hacking-Robots-Before-Skynet.pdf (pdf)
"Hacking Robots Before Skynet︰ https://t.co/wnbH5XzDAl "
-
[ Linux ] Linux kernel v4.10 released last week, and I've put up some notes on security things I found interesting: https://t.co/BRVZkJkRTU
"Linux v4.10 内核安全特性上的新变化︰ https://t.co/BRVZkJkRTU"
-
[ Network ] The Story of an Expired WHOIS Server https://blog.sucuri.net/2017/03/story-expired-whois-server.html
"过期 Whois 服务器所带来的危害: https://t.co/APMaTxjInc "
-
[ Operating System ] New blog post up today. GPU Pass-through in Linux: http://www.dcellular.net/blog/?p=6
"如何搭建 Arch Linux 和 Windows 的 GPU 运行环境︰ https://t.co/SBT9Omly46"
-
[ Operating System ] Excellent article about exploiting Cypress PSoC4 (ARM) - reading system ROM, modifying low-level config, creating r… https://t.co/C4rNNZjCys
"Exploit Cypress PSoC 4,PSoC 4 是一个基于 ARM Cortex-M0/M0+ 的可编程系统: http://dmitry.gr/index.php?r=05.Projects&proj=23.%20PSoC4"
-
[ Others ] x86 Paging Tutorial : http://www.cirosantilli.com/x86-paging/ cc @ cirosantilli
"x86 Paging 教程︰ https://t.co/Rr71mNyl6r"
-
[ Others ] Covert Channels and Poor Decisions: The Tale of DNSMessenger http://blog.talosintelligence.com/2017/03/dnsmessenger.html
"Talos 团队发现了一个恶意样本,这个样本利用 DNS TXT Record 实现 C&C 隧道通信: https://t.co/EwG6oYQ6fg"
-
[ Others ] Bye Empire, Hello Nebula Exploit Kit http://malware.dontneedcoffee.com/2017/03/nebula-exploit-kit.html cc/thx @ francruar @ jspchc https://t.co/C4VvENFmvt
"Nebula Exploit Kit: https://t.co/yqYNt3djM2"
-
[ Tools ] cgPwn : A lightweight VM for hardware hacking, RE (fuzzing, symEx, exploiting etc) & wargaming tasks : https://github.com/0xM3R/cgPwn cc @ 0xM3R
"cgPwn -- 一个 Ubuntu 虚拟机,适用于硬件 hacking、逆向工程等︰ https://t.co/qXMgEBHpVX "
-
[ Tools ] AW Test Tool A single dll that allows you to test 5 AW bypass techniques. Hybrid, managed/unmanged dll ;-) https://github.com/subTee/AllTheThings
"AllTheThings -- 该工具包含了5种应用白名单绕过技术可绕过白名单防御: https://t.co/WOyA9mps01"
-
[ Tools ] ObfuscatedEmpire - Use an obfuscated, in-memory PowerShell C2 channel to evade AV signatures https://cobbr.io/ObfuscatedEmpire.html
"将 Invoke-Obfuscation 和 Empire 集成,变成一个可以逃避杀软检测的 Empire: https://t.co/V0HZPBYPTH"
-
[ Tools ] Added hints for code injection functions to #PortexAnalyzer. New version is online. https://github.com/katjahahn/PortEx/tree/master/progs https://t.co/eA9vL5MsGW
" PortEx -- 基于 Java 的恶意软件静态分析库: https://github.com/katjahahn/PortEx "
-
[ Tools ] [Release] New tool for obfuscation-resilient Android privacy leak detection! Code: https://github.com/ucsb-seclab/agrigento PDF: https://t.co/GZXq208JZ4
"Agrigento -- 通过对网络流量进行黑盒分析来检测 Android 应用隐私泄露的工具 ︰ https://t.co/KMb8IpqeZw ; PDF: https://t.co/GZXq208JZ4"
-
[ Vulnerability ] Arb. code execution in Visual Studio @code (Workspace settings) - because winword macros shouldn't have all the fun. https://t.co/GgcLt5b5Lm
" VSCode 在加载 Workspace 配置文件时存在一个任意命令执行漏洞 : https://t.co/GgcLt5b5Lm"
-
[ Vulnerability ] I found a MitM attack against OpenBSD: A logical vulnerability in the WPA1/WPA2 protocol implementation. https://t.co/o88hHICaPf
" OpenBSD 无线网络栈存在中间人攻击漏洞: https://t.co/o88hHICaPf"
-
[ Vulnerability ] Cisco Warns of High Severity Bug in NetFlow Appliance: https://threatpost.com/cisco-warns-of-high-severity-bug-in-netflow-appliance/124053/ via @ threatpost
" Cisco NetFlow Generation Appliance 存在拒绝服务漏洞: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170301-nga"
-
[ Windows ] 0patching a 0-day : Windows gdi32.dll memory disclosure (CVE-2017-0038) : https://0patch.blogspot.in/2017/02/0patching-0-day-windows-gdi32dll-memory.html
" CVE-2017-0038: Windows gdi32.dll 内存泄露漏洞分析 : https://t.co/iFmLynuVzp"
-
[ WirelessSecurity ] Summary of my experience with cloning RFID: http://xakcop.com/post/cloning-rfid/
"克隆 RFID 卡的经验总结︰ https://t.co/jgH3nvyeVb"
-
[ WirelessSecurity ] Universal Radio Hacker:通用型无线黑客工具箱教程视频: https://www.youtube.com/channel/UCqIWuCQfX00XHFiwTENI79A
Xuanwu Spider via 0xroot 's weibo