腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] Mozilla Firefox < 45.0 - 'nsHtml5TreeBuilder' UAF 漏洞利用 (可绕过 EMET 5.52): https://www.exploit-db.com/exploits/42484
-
[ IoTDevice ] Honeywell Tuxedo 家用安保系统的逆向分析: https://markclayton.github.io/reverse-engineering-my-home-security-system-decompiling-firmware-updates.html
-
[ Malware ] CryptoMix 勒索软件变体出现,加密文件以.ERROR 作扩展名: https://www.bleepingcomputer.com/news/security/new-error-cryptomix-ransomware-variant-released/
-
[ MalwareAnalysis ] Malwarebytes 实验室对 Kronos 恶意软件的详细分析 Part 1: https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
-
[ Tools ] sniffMK - macOS 上的鼠标与键盘事件嗅探工具: https://github.com/objective-see/sniffMK
-
[ Tools ] DR. CHECKER - USENIX 2017 会议上公开的一个 Linux 内核漏洞挖掘工具,基于程序静态分析的方法实现: https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-machiry.pdf
-
[ Tools ] vulscan - Nmap 的漏洞探测脚本,根据版本信息判断是否存在漏洞: https://github.com/scipag/vulscan