2月16日-每日安全知识热点

http://p2.qhimg.com/t012dfaf746e4fefbe3.jpg

1.PwnPhone :默认密码允许秘密监控你的voip通话

https://paul.reviews/pwnphone-default-passwords-allow-covert-surveillance/

2.如何安全的存储密码

https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016

3.Ubitiquiti’s AirVision摄像头可通过rstp访问绕过登陆认证,直接看视频 

https://medium.com/@neilwillgettoit/ubiquiti-airvision-video-stream-auth-bypass-a321330a3dfd#.s1q48mkgs

4.来自Cisco Live Europe 2016 Wifi 架构的观察

https://www.insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/

5.盲注利用

https://isc.sans.edu/diary/Exploiting+%28pretty%29+blind+SQL+injections/20733

6.使用 DarunGrim 执行 bindiff

https://mattoh.wordpress.com/2014/04/21/

7.iOS (up to) 9.3b3 IOHIDFamily Use-After-Free (incorrect patch for CVE-2015-6974) POC 

https://ghostbin.com/paste/s3tz7

8.Usenix安全会议:利用噪音干扰无人机陀螺仪

http://www.securitytube.net/video/15164?utm_source=HT&utm_medium=twitter&utm_campaign=SM

9.智能建筑面临多个IOT安全风险

http://www.techrepublic.com/article/ibm-x-force-finds-multiple-iot-security-risks-in-smart-buildings/

10.反向工程xbee pro物理层第一部分

http://xn--thibaud-dya.fr/phy_xbee_p1.html

11.mitmproxy发行:支持http/2

http://honeynet.org/node/1290

12.Windows Kerberos 安全功能绕过POC (MS16-014)

https://www.exploit-db.com/exploits/39442/

13.研究人员演示在另一个房间从断网的笔记本中偷取私钥

http://motherboard.vice.com/read/how-white-hat-hackers-stole-crypto-keys-from-an-offline-laptop-in-another-room

14.andorid 应用的网络安全策略配置

https://koz.io/network-security-policy-configuration-for-android-apps/

15.跟踪Andromeda/Gamrue僵尸网络

http://eternal-todo.com/blog/travelling-far-side-andromeda-botconf

16.三星警告用户在使用声控控制smartTV的时候,数据有可能会传给第三方厂商

http://theantimedia.org/samsung-warns-customers-to-think-twice-about-what-they-say-near-smart-tvs/

17.使用bettercap绕过hsts

https://www.bettercap.org/blog/sslstripping-and-hsts-bypass/#.VsHQflQ9TwA.twitter

18.针对一款能清除你android数据的mazar bot分析

https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/

19.揭秘Facebook的群体正在使用的恋童癖者交换色情图片 

https://nakedsecurity.sophos.com/2016/02/15/secret-facebook-groups-being-used-by-pedophiles-to-swap-obscene-images/

20.CVE-2016-1903利用

http://www.libnex.org/blog/exploitingcve-2016-1903memoryreadviagdimagerotateinterpolated

21.硬件设计:FPGA的安全风险 

https://www.nccgroup.trust/globalassets/our-research/uk/whitepapers/2016/01/research-insights_vol-8-hardware-design-fpga-security-riskspdf

免责声明:文章内容不代表本站立场,本站不对其内容的真实性、完整性、准确性给予任何担保、暗示和承诺,仅供读者参考,文章版权归原作者所有。如本文内容影响到您的合法权益(内容、图片等),请及时联系本站,我们会及时删除处理。查看原文

为您推荐