
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] Researchers Hack Accelerometers with Sound Waves https://www.bleepingcomputer.com/news/hardware/researchers-hack-accelerometers-with-sound-waves/ Technical paper: https://spqr.eecs.umich.edu/papers/trippel-IEEE-oaklawn-walnut-2017.pdf
"来自美国两所高校的安全研究员发现利用声波攻击加速度传感器: https://t.co/4ZZC1VxvHQ paper︰ https://t.co/FQwXL0gz3s"
-
[ Conference ] Presentations of BlueHat IL https://microsoftrnd.co.il/bluehat/Pages/Presentations.aspx
"微软公开了 Blue Hat 2017 会议的 PPT 和视频: https://t.co/B4tRPqC65L"
-
[ Conference ] BSidesCharm 2017 Videos http://www.irongeek.com/i.php?page=videos/bsidescharm2017/mainlist, via @ irongeek_adc
"2017 BSidesCharm 安全会议视频: https://t.co/O2hMK8iWNi"
-
[ Conference ] The call for papers for @ hack_lu 2017 is now open https://2017.hack.lu/blog/Call-for-Papers/ https://2017.hack.lu/cfp/ #callforpapers #infosec #luxembourg
" hack.lu 2017 大会将于 10月 17-19 日期间举行,大会现已开始公开征集议题: https://t.co/kOaDsN5OLB"
-
[ Hardware ] How to Set Up Kali Linux on the New $10 Raspberry Pi Zero W https://null-byte.wonderhowto.com/how-to/set-up-kali-linux-new-10-raspberry-pi-zero-w-0176819/?utm_source=dlvr.it&utm_medium=twitter <--Full Article https://t.co/hpueqkOVKO
"如何在树莓派 Zero W 上安装 kali Linux: https://t.co/2LLhNLMt0F "
-
[ Industry News ] OpenSSH Security Testing Kick-Off: https://blogs.msdn.microsoft.com/powershell/2017/05/01/openssh-security-testing-kick-off/ https://t.co/bfU2KKAgeA
" 微软一直在致力于将 OpenSSH 移植到 Win32 平台,微软昨天宣布开始针对 OpenSSH 的安全测试项目,鼓励大家报告漏洞︰ https://t.co/HJS8V7YRZY https://t.co/bfU2KKAgeA"
-
[ Industry News ] OpenSSH Removes SSHv1 Support : http://undeadly.org/cgi?action=article&sid=20170501005206
"OpenSSH 将不再支持 SSHv1︰ https://t.co/Q7kdfRywGz"
-
[ Industry News ] .@ Apple Revokes Certificate Used By #OSX/Dok Malware: https://threatpost.com/apple-revokes-certificate-used-by-osxdok-malware/125322/ via @ threatpost
"Apple 吊销了被恶意软件 OSX/DoK 所使用的开发者证书 : https://t.co/afpeSTeES8"
-
[ Linux ] new blog post: USENIX/LISA 2016 Linux bcc/BPF Tools http://www.brendangregg.com/blog/2017-04-29/usenix-lisa-2016-bcc-bpf-tools.html https://t.co/nu4L88BypG
"Linux 4.X Tracing Tools: Using BPF Superpowers: http://www.brendangregg.com/blog/2017-04-29/usenix-lisa-2016-bcc-bpf-tools.html "
-
[ MalwareAnalysis ] SMS Scam Investigation in 30 Minutes Or Less – Hunchly – Medium http://bit.ly/2oPafMW
"从短信 goo.gl 短域名链接开始追踪钓鱼站的幕后控制者 : https://t.co/2kz6QD7S8y"
-
[ Others ] Project Zero blog: "Exploiting .NET Managed DCOM" by @ tiraniddo - https://googleprojectzero.blogspot.com/2017/04/exploiting-net-managed-dcom.html
"上周推送过 James Forshaow 发现的 Dolby Audio X2 服务的提权漏洞,这个漏洞的背后原因是用 .NET 实现了跨特权边界的 DCOM,为此他专门写了一篇 Blog 详谈这个问题,《Exploiting .NET Managed DCOM》: https://t.co/yrriYKD5Gd"
-
[ Others ] just published last blog in "Two Bugs, One Func()" mini series: "part iii: a kernel heap overflow" https://t.co/VTcBGNZYom #kernelbug #macos
"Two Bugs, One Func(),Part 3: a kernel heap overflow: https://t.co/VTcBGNZYom "
-
[ Others ] Adventures in JIT compilation: Part 3 - LLVM http://eli.thegreenplace.net/2017/adventures-in-jit-compilation-part-3-llvm/
"之前推送过从头写一个 JIT 编译器系列文章,这次是 Part 3,作者介绍基于 LLVM 框架构建 JIT 编译器: https://t.co/H04M8agpdr"
-
[ Programming ] Writing Optimized Windows Shellcode : https://dimitrifourny.github.io/2017/04/28/optimized-windows-shellcode/ cc @ DimitriFourny
"Windows Shellcode 编写指引: https://dimitrifourny.github.io/2017/04/28/optimized-windows-shellcode/"
-
[ SecurityReport ] Android Security Bulletin—May 2017 #MobileSecurity #AndroidSecurity https://source.android.com/security/bulletin/2017-05-01
"Android 5月安全公告 : https://t.co/zRRuwz5sr5"
-
[ Tools ] Tool for reverse engineering macOS/OS X https://github.com/steven-michaud/HookCase
"HookCase - macOS 上的一个逆向工具: https://t.co/WxTzTZQW6P "
-
[ Tools ] Ubertooth – Open Source Bluetooth Sniffer https://www.darknet.org.uk/2017/05/ubertooth-open-source-bluetooth-sniffer/
"Ubertooth — — 一款开源的蓝牙嗅探器: https://t.co/ERRRJ7OQQS Github: https://github.com/greatscottgadgets/ubertooth/"
-
[ Tools ] 80 #Linux Monitoring Tools for SysAdmins https://www.serverdensity.com/monitor/linux/how-to/ https://t.co/xb8dfe0GRG
"一份汇集了 80 款 Linux 监控工具的列表: https://t.co/LIPFHwRMwZ "
-
[ Vulnerability ] Intel security advisory SA-00075 / CVE-2017-5689, remote attack on the Management Engine: https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://t.co/61TwShtTdv
"2008 年之后生产的 Intel 平台管理引擎(ME)存在一个远程可以利用的漏洞,成功利用可以获得管理权限: https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/ 受影响的产品列表: https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&;languageid=en-fr "
-
[ Windows ] My @BSidesCharm talk #ActiveDirectory Threat Hunting include tables mapping audit categories to event ids (appendix… https://t.co/F7enmojgLf
"来自 ADSecurity 的研究员在 SparkCon 会议关于活动目录、域、PowerShell、Kerberos 相关安全问题的演讲: https://adsecurity.org/wp-content/uploads/2017/04/2017-SparkCon-CurrentStateofADSecurity-Metcalf-Final.pdf"
-
[ Windows ] DLL Injection Using LoadLibrary in C : https://arvanaghi.com/blog/dll-injection-using-loadlibrary-in-C/ cc @ arvanaghi
"利用 LoadLibrary 进行 Windows DLL 注入: https://t.co/qIXLWkpNJh "
-
[ Windows ] Bypassing Windows Attachment Manager : http://www.rvrsh3ll.net/blog/informational/bypassing-windows-attachment-manager/ cc @ 424f424f
" 从 Windows XP SP2 开始,Windows 引入了 Windows Attachment Manager 保护特性,禁止从网络上下载的某些类型文件直接执行,这篇 Blog 介绍如何 Bypass 这项特性︰ https://t.co/TBoQN2cWXi "
-
[ Vulnerability ] QEMU RTL8139/PCNET 网卡模拟器漏洞的利用及虚拟机的逃逸(CVE-2015-5165/7504): http://www.phrack.org/papers/vm-escape-qemu-case-study.html