腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Android ] Testing Anti-Reversing Defenses on Android: https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md
-
[ iOS ] Pangu 9.0-9.1 iOS Kernel UAF Exploit Explained + Tutorial(video): https://www.youtube.com/watch?v=eABhTnz8YK4&feature=youtu.be
-
[ Mobile ] Nexus S 的底层 NFC 实现研究,来自 RECon 会议: https://recon.cx/2017/montreal/resources/slides/RECON-MTL-2017-Hacking_Cell_Phone_Embedded_Systems.pdf
-
[ Pentest ] Cure53 对 Briar 项目应用与协议的渗透测试报告 : https://briarproject.org/raw/BRP-01-report.pdf
-
[ SecurityProduct ] 我是如何利用一个假的私钥欺骗 Symantec 的: https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html
-
[ Tools ] SmoothCriminal - 从光标移动速度的角度检测沙盒: https://github.com/G4lB1t/SmoothCriminal
-
[ Windows ] 因为兼容性,InitializeProcessForWsWatch 和 GetWsChanges/GetWsChangeEx API 存在 5 年的 Bug: http://www.triplefault.io/2017/07/breaking-backwards-compatibility-5-year.html