Tencent Security Xuanwu Lab Daily News
• Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond:
https://www.intruder.io/research/practical-http-header-smuggling
・ Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
– Jett
• ARMored CoreSight: Towards Efficient Binary-only Fuzzing:
https://ricercasecurity.blogspot.com/2021/11/armored-coresight-towards-efficient.html
・ 基于 ARM CPU 的 CoreSight 特性,实现对闭源 ARM 二进制程序的 Fuzz
– Jett
• [Vulnerability] Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064:
https://www.randori.com/blog/cve-2021-3064/?i=2
・ Palo Alto Networks GlobalProtect VPN Unauthenticated RCE 漏洞分析(CVE-2021-3064)
– Jett
• Announcing osquery 5: Now with EndpointSecurity on macOS:
https://blog.trailofbits.com/2021/11/10/announcing-osquery-5-now-with-endpointsecurity-on-macos/
・ osquery 发布 5.0 版本,支持在 macOS 平台基于 EndpointSecurity 框架收集事件日志
– Jett
• 从 mimikatz 看 Windows DPAPI 数据解密:
http://paper.seebug.org/1755/
・ 从 mimikatz 看 Windows DPAPI 数据解密.
– lanying37
• [Browser] Oilpan Library:
https://v8.dev/blog/oilpan-library
・ V8 脚本引擎 Trace-based garbage collector – Oilpan 的介绍
– Jett
• [Virtualization] ChaosDB Explained: Azure’s Cosmos DB Vulnerability Walkthrough:
https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough
・ Azure Cosmos DB 内部敏感信息泄漏漏洞分析
– Jett
• PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens:
https://blog.zimperium.com/phonespy-the-app-based-cyberattack-snooping-south-korean-citizens/
・ PhoneSpy Android 间谍 App 监控韩国用户的消息、图片等各类隐私信息
– Jett
• Pun-free Cylance vulnerability, fixed:
https://www.pentestpartners.com/security-blog/pun-free-cylance-vulnerability-fixed/
・ 安全软件 Cylance 被发现多个本地提权漏洞
– Jett
• [PDF] https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf:
https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf
・ 攻击 ETW,逃避 EDR 软件的检测
– Jett
• 浅谈JSP Webshell进阶免杀:
https://tttang.com/archive/1315/
・ 浅谈JSP Webshell进阶免杀.
– lanying37
• 朝鲜APT组织使用带后门IDA软件攻击安全研究人员:
https://mp.weixin.qq.com/s/PGHxVr-RPB8fiMTD35oh1w
・ 据 ESET 报道,朝鲜 APT 组织利用带后门的 IDA Pro 7.5 攻击安全研究人员
– Jett
* 查看或搜索历史推送内容请访问:
https://sec.today
* 新浪微博账号:腾讯玄武实验室
https://weibo.com/xuanwulab
原文始发于微信公众号(腾讯玄武实验室):每日安全动态推送(11-11)