
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] “Hidden Gems of Android O” by @ ianhlake https://medium.com/@ ianhlake/hidden-gems-of-android-o-7def63136629
"从 API Diff 的角度来比较 Android O 版本的一些变化: https://t.co/0SOL1b1h0M"
-
[ Conference ] OPCDE slides + materials will be continuously uploaded on our GitHub repository. https://github.com/comaeio/OPCDE
"OPCDE 2017 大会 Materials : https://t.co/pqeOC2Yv3w"
-
[ Industry News ] Air Force hopes to attract hackers w/ #bugbounty program - http://bit.ly/2q8JuTH https://t.co/fbOFnoTL5P
"美国空军也发布了其漏洞奖励计划: https://t.co/f9nynk14iC "
-
[ Others ] The Art of Subdomain Enumeration https://blog.sweepatic.com/art-of-subdomain-enumeration/
"子域名收集的艺术: https://t.co/ug7peIE3fx"
-
[ Popular Software ] More LastPass flaws: researcher pokes holes in 2FA http://feedproxy.google.com/~r/nakedsecurity/~3/Nq6GTdTXtyg/
"研究人员在 LastPass 的双因素认证上发现了问题: https://t.co/UTYoVnhdLW"
-
[ Protocol ] NOMX deep dive https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/ < A pretty fun read :)
" nomx - 一个安全的通信协议介绍: https://t.co/3yiwp7dXaF"
-
[ SecurityProduct ] UXSS in McAfee Endpoint Security, http://www.mcafee.com and some extra goodies... : http://blog.malerisch.net/2017/04/uxss-mcafee-endpoint-security-and-site-advisor-cve-2016-8011.html cc @ malerisch
" McAfee Endpoint Security 的 UXSS 漏洞分析: https://t.co/q4AHlaYZKi "
-
[ Tools ] Wordlists sorted by probability originally created for password generation and testing https://github.com/berzerk0/Probable-Wordlists
"用于生成密码表的单词库,大约有 24GB: https://t.co/fjJNohFzq5 "
-
[ Tools ] VirtualDrone: Virtual Sensing, Actuation, and Communication for Attack-Resilient Unmanned Aerial Systems https://t.co/wFy2xfWPex
"VirtualDrone - 这篇 Paper 提出了一个框架,尝试以虚拟化的思路解决无人机自身的安全问题,将传感器、驱动器和通信信道虚拟化,在虚拟系统中检测系统的安全状态,在可信系统中做决策: https://t.co/wFy2xfWPex"
-
[ Vulnerability ] Imgur RCE (GraphicsMagick) $5,000 https://hackerone.com/reports/212696
" Imgur 相册站点被发现存在一个 GraphicsMagick 带来的命令行注入漏洞,来自 HackerOne,该漏洞被奖励 5000 刀: https://t.co/GQAKtskwUA"
-
[ Windows ] Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability http://blog.talosintelligence.com/2017/04/vulnerability-spotlight-irfanview.html
" Windows 系统的一款图片浏览器 IrfanView 的 jpeg2000 插件存在一个整数溢出漏洞(CVE-2017-2813): https://t.co/GrpMKzeo6f"
-
[ MalwareAnalysis ] 【木马分析】谍影追踪:全球首例UEFI_BIOS木马分析: http://m.bobao.360.cn/learning/appdetail/3779.html?from=timeline&isappinstalled=0
-
[ Protocol ] Fastcgi协议分析 && PHP-FPM未授权访问漏洞 && Exp编写: https://www.leavesongs.com/PENETRATION/fastcgi-and-php-fpm.html