腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] IE 浏览器 textarea text value UAF 漏洞分析以及信息泄露 PoC(CVE-2017-0059): https://redr2e.com/cve-to-poc-cve-2017-0059/
-
[ IoTDevice ] 基于 GNU Radio 和 SDR 的无人机劫持攻击: http://nullcon.net/website/archives/pdf/goa-2017/drone-hijacking-and-other-IoT-hacking.pdf
-
[ Others ] 微软公开了大量的免费电子文档,涵盖 Azure、Office、PowerShell、SQL Server、Windows 等重要组件: https://blogs.msdn.microsoft.com/mssmallbiz/2017/07/11/largest-free-microsoft-ebook-giveaway-im-giving-away-millions-of-free-microsoft-ebooks-again-including-windows-10-office-365-office-2016-power-bi-azure-windows-8-1-office-2013-sharepo/
-
[ Others ] How to find internal subdomains? YQL, Yahoo! and bug bounty: https://medium.com/@woj_ciech/how-to-find-internal-subdomains-yql-yahoo-and-bug-bounty-d7730b374d77
-
[ Windows ] 如何利用 ETERNALROMANCE/SYNERGY 在 Windows Server 2016 上获取 Meterpreter Session: https://www.exploit-db.com/docs/42329.pdf
-
[ WirelessSecurity ] Reverse Engineering a 433MHz Motorised Blind RF Protocol: https://nickwhyte.com/post/2017/reversing-433mhz-raex-motorised-rf-blinds/