首页
社区
课程
招聘
[分享]国外最新安全推文整理(第25期)
发表于: 2018-8-5 16:39 5166

[分享]国外最新安全推文整理(第25期)

2018-8-5 16:39
5166

Automatically test and explore the capabilities of generic AV engines(反病毒引擎测试框架)

https://github.com/necst/crave


Virtual Machine for Intermediate Representation(解析执行 WebAssembly 和 LLVM Bitcode)

https://github.com/andoma/vmir


The Windows Library for Intel Process Trace(Intel PT 库)

https://github.com/ionescu007/winipt


A research purpose hypervisor for Windows on AMD processors(基于 AMD-V 的 hypervisor)

https://github.com/tandasat/SimpleSvmHook


Perform a MitM attack and extract clear text credentials from RDP connections(RDP 中间人)

https://github.com/SySS-Research/Seth


ISSISP 2018 Slides

https://cs.anu.edu.au/cybersec/issisp2018/schedule.html


Usenix Security 2018 Schedule

https://www.usenix.org/conference/usenixsecurity18/technical-sessions


Precision Issues in Graphic Libraries(图形库中的精确度问题)

https://googleprojectzero.blogspot.com/2018/07/drawing-outside-box-precision-issues-in.html


CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime(Safari WebKit CVE-2017-2446 漏洞)

https://doar-e.github.io/blog/2018/07/14/cve-2017-2446-or-jscjsglobalobjectishavingabadtime/


Cracking the Walls of the Safari Sandbox(Safari 沙箱逃逸)

http://blog.ret2.io/2018/07/25/pwn2own-2018-safari-sandbox/


VirtualBox 3D acceleration considered harmful(VirtualBox 3D 加速的漏洞)

https://phoenhex.re/2018-07-27/better-slow-than-sorry


Taking apart a double zero-day sample discovered in joint hunt with ESET(更多有关 CVE-2018-4990 & CVE-2018-8120 的细节)

https://cloudblogs.microsoft.com/microsoftsecure/2018/07/02/taking-apart-a-double-zero-day-sample-discovered-in-joint-hunt-with-eset/


Delving deep into VBScript Internals(深入 VBScript 解析器)

https://securelist.com/delving-deep-into-vbscript-analysis-of-cve-2018-8174-exploitation/86333/


Localhost Network Isolation and Edge(Edge 浏览器网络隔离特性)

https://tyranidslair.blogspot.com/2018/07/uwp-localhost-network-isolation-and-edge.html


System call dispatching on Windows ARM64(ARM 架构下的 Windows 系统调用)

https://gracefulbits.com/2018/07/26/system-call-dispatching-for-windows-on-arm64/


Detecting Hypervisor Presence on Windows 10(Hypervisor 的检测)

https://revers.engineering/detecting-hypervisor-presence-on-windows-10/


Overview of Intel SGX(Intel SGX 技术概览)

https://blog.quarkslab.com/overview-of-intel-sgx-part-1-sgx-internals.html

https://blog.quarkslab.com/overview-of-intel-sgx-part-2-sgx-externals.html


Solving the Atredis BlackHat 2018 CTF Challenge(题目 Atredis 的 writeup,BlackHat CTF)

http://www.msreverseengineering.com/blog/2018/7/24/the-atredis-blackhat-2018-ctf-challenge


Exploiting a Windows 10 PagedPool off-by-one overflow(题目 Searchme 的 writeup,wctf)

https://j00ru.vexillium.org/2018/07/exploiting-a-windows-10-pagedpool-off-by-one/


"Evil Maid" Firmware Attacks Using USB Debug(借助 USB 调试进行攻击)

https://blog.eclypsium.com/2018/07/23/evil-mai%EF%BB%BFd-firmware-attacks-using-usb-debug/


Dangerous Reality Inside of VR headset: HTC Vive(VR 设备的安全)

https://embedi.com/blog/dangerous-reality-inside-of-vr-headset-htc-vive/


Build a Mini Mass Deauther Using bettercap and a Raspberry Pi Zero W(WiFi 干扰器)

https://www.evilsocket.net/2018/07/28/Project-PITA-Writeup-build-a-mini-mass-deauther-using-bettercap-and-a-Raspberry-Pi-Zero-W/


Advanced Mobile Malware Campaign in India uses Malicious MDM(借助恶意 iOS MDM 的攻击)

https://blog.talosintelligence.com/2018/07/Mobile-Malware-Campaign-uses-Malicious-MDM.html


iOS/macOS kernel double free(iOS/macOS 内核漏洞相关)

https://bugs.chromium.org/p/project-zero/issues/detail?id=1417


A Story About Three Bluetooth Vulnerabilities in Android(Android 蓝牙漏洞)

https://blog.quarkslab.com/a-story-about-three-bluetooth-vulnerabilities-in-android.html



[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!

收藏
免费 0
支持
分享
打赏 + 1.00雪花
打赏次数 1 雪花 + 1.00
 
赞赏  junkboy   +1.00 2018/08/07
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//