腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ IoTDevice ] 超过 1700 个可用的 IoT 设备的 Telnet 密码泄露到网上: http://securityaffairs.co/wordpress/62365/iot/iot-devices-credentials-leaked.html
-
[ MalwareAnalysis ] Malwarebytes Labs 对 Kronos 银行木马的深入剖析 - part 1: https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
-
[ OpenSourceProject ] libgcrypt CVE-2017-0379 漏洞的补丁: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b
-
[ Tools ] 恶意软件提取工具 Part 2:弱加密算法: https://vallejo.cc/2017/08/27/tools-for-unpacking-malware-part-2-weak-encryption-algorithms/
-
[ Tools ] udp2raw-tunnel - 将 UDP 流量放入其他协议隧道中传输的工具: https://github.com/wangyu-/udp2raw-tunnel
-
[ Vulnerability ] Intel AMT 认证绕过漏洞的 PoC(CVE-2017-5689): https://github.com/embedi/amt_auth_bypass_poc
-
[ Challenges ] 今年的日本的 Mobile PWN2OWN 将会增加中国的手机平台作为目标: https://twitter.com/dragosr/status/900784341051097088
-
-
[ Fuzzing ] Smarter Peach: Add Eyes to Peach Fuzzer,来自 YIHAN LIAN 和 ZHIBIN HU 在 Rooted CON 2017 会议的演讲(视频): https://www.youtube.com/watch?v=tivSuY6rJVg&index=27&list=PLUOjNfYgonUvu4EZ4m6OxVovCd18M6jTv
-
[ iOS ] Stefan Esser 在 HITB 会议关于私有 iOS 越狱(Private iOS Jailbreak)历史的剖析: http://gsec.hitb.org/materials/sg2017/COMMSEC%20D1%20-%20Stefan%20Esser%20-%20The%20Original%20Elevat0r.pdf
-
-
-
-
[ Windows ] CVE-2017-8625 漏洞详情,UMCI vs Internet: https://posts.specterops.io/umci-vs-internet-explorer-exploring-cve-2017-8625-3946536c6442