
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] 为什么浏览器一直没有默认启用对 TLS 1.3 的支持: https://blog.cloudflare.com/why-tls-1-3-isnt-in-browsers-yet/
-
[ Browser ] Chrome 61 修复的一个漏洞的详情: Security: V8 JIT escape analysis bug(CVE-2017-5121): https://bugs.chromium.org/p/chromium/issues/detail?id=765433
-
[ Conference ] 第 34 届 CCC(Chaos Communication Congress) 大会议程: https://events.ccc.de/congress/2017/Fahrplan/index.html
-
[ Crypto ] 破解加密的 PDF 文档 Part 1: https://blog.didierstevens.com/2017/12/26/cracking-encrypted-pdfs-part-1/
-
[ Industry News ] Mozilla 修补了 Thunderbird email 客户端中的严重漏洞: https://threatpost.com/mozilla-patches-critical-bug-in-thunderbird/129244/
-
[ Others ] 加固 C / C ++ 程序 Part 1 - 堆栈保护器 : http://www.productive-cpp.com/hardening-cpp-programs-stack-protector/ ; 加固 C / C ++ 程序 Part 2 - 可执行空间保护与 ASLR: http://www.productive-cpp.com/hardening-cpp-programs-executable-space-protection-address-space-layout-randomization-aslr/
-
-
-
[ Tools ] dnscrypt-autoinstall - 自动安装和配置 DNSCrypt 的脚本: https://github.com/simonclausen/dnscrypt-autoinstall
-
[ Tools ] 基于 LLVM 的动态二进制框架: https://github.com/quarkslab/QBDI
-
[ Tools ] gr-satellites - 针对特定卫星的 GNU Radio 解码器集合: https://github.com/daniestevez/gr-satellites
-
[ Tools ] Apktool v2.3.1 发布,新版本支持 Android Oreo (8.1): https://connortumbleson.com/2017/12/26/apktool-v2-3-1-released/
-
[ Tools ] ripr - 将二进制工具打包成 Python 软件包的工具,基于 Binary Ninja 和 Unicorn Engine 实现: https://github.com/pbiernat/ripr
-
[ Tools ] radare2 逆向框架的 wiki 文档整理: https://github.com/securisec/radare2_wiki
-
[ Tools ] 使用 Traceroute 进行故障排除的实用指南: https://www.nanog.org/meetings/nanog45/presentations/Sunday/RAS_traceroute_N45.pdf
-
-
-
[ CyberCrime ] 国内地下网络犯罪揭秘,来自 McAfee : https://securingtomorrow.mcafee.com/mcafee-labs/chinese-cybercriminals-develop-lucrative-hacking-services/#sf177243351
-
-
[ MalwareAnalysis ] 基于浏览器的密码货币挖掘现状概述: https://www.symantec.com/blogs/threat-intelligence/browser-mining-cryptocurrency
-
[ MalwareAnalysis ] Satori僵尸网络事件分析:华为路由器0day漏洞(CVE-2017-17215)曝光: https://zhuanlan.zhihu.com/p/32351258?group_id=928943710797070336
-
[ SecurityProduct ] 金山杀软 kavfm.sys/KWatch3.sys 驱动在处理 IOCTL 0x80030004 时存在本地提权漏洞: https://blogs.securiteam.com/index.php/archives/3597
-
-
[ Tools ] Luna - 一款开源的自动化web漏洞扫描工具,主要用途是实现对漏洞扫描策略的快速验证,验证源来自burpsuite中收集的httplog,扫描策略来自独立的python插件: https://github.com/toyakula/luna
-
[ Web Security ] 如何利用Web漏洞窃取NTLM哈希: https://zhuanlan.zhihu.com/p/32350465?group_id=928937862830059520
-
[ Windows ] Exploiting Eternalblue for shell with Empire & Msfconsole: https://www.hackingtutorials.org/exploit-tutorials/exploiting-eternalblue-for-shell-with-empire-msfconsole/
-
[ Windows ] Microsoft 增强的缓解体验工具包与 Windows Defender Exploit Guard 的对比: https://docs.microsoft.com/en-us/windows/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard