360-CERT每日安全简报
Daily Security Briefing
2020-11-13 星期五
<<Previous
Next>>
漏洞
Vulnerability
CVE-2020-25705:SAD DNS 新型的DNS缓存中毒攻击
https://www.cs.ucr.edu/~zhiyunq/SADDNS.html
CVE-2020-17083:Microsoft Exchange Server ExportExchangeCertificate WriteCertiricate文件写入远程代码执行漏洞及验证PoC
https://srcincite.io/advisories/src-2020-0025/
Ubuntu gdm3本地提取漏洞
https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE
安全研究
Security Research
firefox漏洞研究(一)
https://blog.exodusintel.com/2020/10/20/firefox-vulnerability-research/
firefox漏洞研究(二)
https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
如何从PyPI上寻找恶意软件包
https://jordan-wright.com/blog/post/2020-11-12-hunting-for-malicious-packages-on-pypi/
有趣的openssh会话解密
https://blog.fox-it.com/2020/11/11/decrypting-openssh-sessions-for-fun-and-profit/
如何使用MVSC编译器生成XFG函数原型哈希
https://blog.quarkslab.com/how-the-mvsc-compiler-generates-xfg-function-prototype-hashes.html
哥斯达黎加行动:外包黑客组织的间谍活动
https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced
介绍和利用打印机C2
https://labs.f-secure.com/blog/print-c2/
<<Previous
Next>>