腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Safari 技术预览版 37发布: https://webkit.org/blog/7862/release-notes-for-safari-technology-preview-release-37/
-
[ Forensics ] Linux 取证技术介绍: https://countuponsecurity.com/2017/04/12/intro-to-linux-forensics/
-
[ MalwareAnalysis ] Cerber 勒索软件使用 Magnitude Exploit Kit 的不同利用方式进行传播: https://blog.malwarebytes.com/threat-analysis/2017/08/cerber-ransomware-delivered-format-different-order-magnitude/
-
[ MalwareAnalysis ] Mamba 勒索软件回归,卡巴斯基实验室对此做了简单分析: https://securelist.com/the-return-of-mamba-ransomware/79403/
-
[ MalwareAnalysis ] macOS 系统一款携带有效开发者签名的 Mughthesec 广告软件靠劫持用户浏览器获利: https://threatpost.com/signed-mughthesec-adware-hijacking-macs-for-profit/127333/
-
[ Popular Software ] Acrobat Reader DC - 流对象远程代码执行漏洞细节与POC(CVE-2017-11254): https://blogs.securiteam.com/
-
[ Programming ] 利用 WinDbg 调试器结合 wscript.exe 分析 JavaScript 脚本: http://blog.talosintelligence.com/2017/08/windbg-and-javascript-analysis.html
-
[ Tools ] EggShell - 命令行版的 iOS/macOS 远程管理工具,支持获得系统信息、设备控制、用户交互、定位信息等等: https://github.com/neoneggplant/EggShell
-
[ Tools ] Awesome Lockpicking - 与开锁、锁具安全性有关的资料整理: https://github.com/meitar/awesome-lockpicking
-
[ Tools ] DBC2 - 基于 Dropbox 进行 C&C 通信的模块化后渗透工具: https://github.com/Arno0x/DBC2
-
[ Tools ] Git 秘籍 - 有用的命令、建议及技巧: https://sentheon.com/blog/git-cheat-sheet.html
-
[ Virtualization ] Hyper-V sockets internals: https://xakep.ru/2017/08/09/hyper-v-internals/
-
[ Windows ] Windows ATA 平台威胁检测的逃逸 2:Overpass-the-hash and Golden Ticket: http://www.labofapenetrationtester.com/2017/08/week-of-evading-microsoft-ata-day2.html
-
[ Windows ] 微软昨天修复的漏洞中,有两个很重要:一个是 Windows Search 组件的 RCE 漏洞,另一个是 Hyper-V 的 RCE: http://blog.trendmicro.com/trendlabs-security-intelligence/critical-windows-search-hyper-v-vulnerabilities-tackled-augusts-patch-tuesday/
-
[ Bug Bounty ] 神秘公司将提供 25 万美金漏洞奖励给 VM 逃逸漏洞: https://threatpost.com/mystery-company-offers-250000-bounty-for-vm-escape-vulnerabilities/127343/
-
[ Firmware ] 嵌入式设备的固件一般都是怎么存储的,来自 Context 的 系列文章,今天介绍存储的几种方式,后面会介绍如何提取: https://www.contextis.com//resources/blog/part-i-overview-firmware-storage-options/
-
-
-
[ Popular Software ] Office Persistence on x64 operating system,来自 3gstudent's blog: https://3gstudent.github.io/3gstudent.github.io/Office-Persistence-on-x64-operating-system/
-
-
[ SecurityReport ] 2017上半年移动安全报告 | 猎豹移动与安天移动安全联合发布: https://mp.weixin.qq.com/s/2PGUSAIJ-__W8bPFtmtw8w
-
[ Tools ] Vulnerable OTP Application - 存在漏洞的 OTP(一次一密)和 2FA(双因素认证)Web 应用实现,用于学习的目的: https://github.com/mddanish/Vulnerable-OTP-Application
-
[ Web Security ] 科普 XSS 与 CSRF ,来自 余弦's weibo: http://weibo.com/1652595727/Fgk2z09M4?ref=collection&type=comment#_rnd1502329997985
-
[ Windows ] Windows Server Insider Builds 版本开始集成 Linux 子系统(WSL): https://blogs.windows.com/buildingapps/2017/08/08/windows-subsystem-linux-windows-server/
-
[ Windows ] 今年下半年即将发布的 Windows 10 Fall Creators 中,Windows Defender 的 Exploit Guard (WDEG) 将完全集成之前 EMET 的所有 Exploit 防护功能: https://blogs.technet.microsoft.com/srd/2017/08/09/moving-beyond-emet-ii-windows-defender-exploit-guard/