2月8日安全热点 - HotSpot Shield VPN / iPhone 的iboot源码泄露

阅读量236590

发布时间 : 2018-02-08 11:05:14

资讯类

美国司法部门控告了36名网络诈骗嫌疑犯,涉案金额高达5.3亿美元

http://www.zdnet.com/article/justice-department-indictment-february-cybercrime-ring/

 

CISCO第二次发布安全补丁来修复CISCO ASA中的一个严重漏洞

http://securityaffairs.co/wordpress/68826/security/cisco-asa-flaw.html

 

HotSpot Shield VPN客户端的一个漏洞可能会暴露用户的信息

https://threatpost.com/hotspot-shield-vulnerability-could-reveal-juicy-info-about-users-researcher-claims/129817/

 

iPhone 的iboot源码泄露

https://github.com/ZioShiba/iBoot

 

自动化黑客工具Autosploit可能导致大规模利用

http://securityaffairs.co/wordpress/68798/hacking/autosploit-hacking-tool.html

 

在这个危险的数字世界中防止WordPress黑客的9个技巧

9 Tips to Prevent WordPress Hacks in this Dangerous Digital World

 

技术类

是谁悄悄偷走了我的电:利用DNSMon批量发现被挂挖矿代码的域名

http://blog.netlab.360.com/who-is-stealing-my-power-web-mining-domains-measurement-via-dnsmon/

 

MalwareFox反恶意软件(zam64.sys) – 通过不正确的访问控制提权

http://rce4fun.blogspot.hk/2018/02/malwarefox-antimalware-zam64sys.html

https://cxsecurity.com/issue/WLB-2018020102

 

从补丁到漏洞分析 –记一次joomla漏洞应急

https://lorexxar.cn/2018/02/07/joomla3-8-4/

 

针对中东的攻击

http://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html

 

Taking over Facebook accounts using Free Basics partner portal

https://www.josipfranjkovic.com/blog/facebook-partners-portal-account-takeover

 

USN-3559-1:Django漏洞

https://usn.ubuntu.com/usn/usn-3559-1

 

云安全风险(P2):AWS CloudTrail中的CSV注入

https://rhinosecuritylabs.com/aws/cloud-security-csv-injection-aws-cloudtrail/

 

在Linux上使用.NET Core获取LTTng事件的堆栈

http://blogs.microsoft.co.il/sasha/2018/02/06/getting-stacks-for-lttng-events-with-net-core-on-linux

 

新白皮书 – DANDERSPRITZ / PEDDLECHEAP流量分析(第1部分)

https://blogs.forcepoint.com/security-labs/new-whitepaper-danderspritzpeddlecheap-traffic-analysis-part-1-2

 

Dissecting mobile native code packers

https://blog.zimperium.com/dissecting-mobile-native-code-packers-case-study

通过BMC颠覆您的服务器:HPE iLO4案例

https://airbus-seclab.github.io/ilo/RECONBRX2018-Slides-Subverting_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf

 

Java反序列化漏洞-玄铁重剑之CommonsCollection(上)

https://xianzhi.aliyun.com/forum/topic/2028

 

iBoot Source Code Leaked

[Discussion] iBoot Source Code Leaked from jailbreak

 

利用Powershell获取System权限

https://www.secpulse.com/archives/68180.html

 

ReelPhish: 实时双因素钓鱼软件

https://www.fireeye.com/blog/threat-research/2018/02/reelphish-real-time-two-factor-phishing-tool.html

 

星图日志分析工具逆向

https://www.secpulse.com/archives/68199.html

 

镰刀 – shellcode开发工具

https://howucan.gr/scripts-tools/2851-sickle-shellcode-development-tool

 

本文由君莫鞋原创发布

转载,请参考转载声明,注明出处: https://www.anquanke.com/post/id/97840

安全KER - 有思想的安全新媒体

分享到:微信
+10赞
收藏
君莫鞋
分享到:微信

发表评论

Copyright © 北京奇虎科技有限公司 三六零数字安全科技集团有限公司 安全KER All Rights Reserved 京ICP备08010314号-66

\n

 

\n

利用Powershell获取System权限

\n

https://www.secpulse.com/archives/68180.html

\n

 

\n

ReelPhish: 实时双因素钓鱼软件

\n

https://www.fireeye.com/blog/threat-research/2018/02/reelphish-real-time-two-factor-phishing-tool.html

\n

 

\n

星图日志分析工具逆向

\n

https://www.secpulse.com/archives/68199.html

\n

 

\n

镰刀 – shellcode开发工具

\n

https://howucan.gr/scripts-tools/2851-sickle-shellcode-development-tool

\n

 

\n\n","index":[{"title":"资讯类","id":"#h2-0","sub":[]},{"title":"技术类","id":"#h2-1","sub":[]}],"success":true},"share":{"title":"2月8日安全热点 - HotSpot Shield VPN / iPhone 的iboot源码泄露","desc":"美国司法部门控告了36名网络诈骗嫌疑犯,涉案金额高达5.3亿美元;CISCO第二次发布安全补丁来修复CISCO ASA中的一个严重漏洞;HotSpot Shield VPN客户端的一个漏洞可能会暴露用户的信息。","imgUrl":"https://p3.ssl.qhimg.com/sdm/160_160_100/t01962d627638962a61.png"},"author":{"nickname":"君莫鞋","user_url":"","id":129441,"avatar":"https://p0.ssl.qhimg.com/t010857340ce46bb672.jpg","banner":"https://p3.ssl.qhimg.com/t014757b72460d855bf.png","location":"","user_label":"official","description":"这个人太懒了,签名都懒得写一个","register_date":"2018-01-08 15:11:28","self":false,"follow":false,"post_count":72,"follower_count":3,"follow_count":1,"comment_count":7},"relevant":[{"id":105806,"title":"4月22日安全热点 - 黑客伪造算力盗取多种数字货币(含简单POC)","date":"2018-04-22 10:34:01"},{"id":102077,"title":"3月23日安全热点 –亚特兰大IT系统被SamSam Ransomware袭击","date":"2018-03-23 09:42:46"},{"id":99195,"title":"2月28日安全热点 - SAML漏洞/利用Memcache Server进行DDoS攻击","date":"2018-02-28 11:05:32"},{"id":99084,"title":"2月27日安全热点 - Cellebrite可解锁所有iPhone/网页矿工威胁","date":"2018-02-27 11:11:49"},{"id":98947,"title":"2月26日安全热点 - 趋势科技邮件加密网关被曝存在多个严重漏洞","date":"2018-02-26 11:06:30"},{"id":98923,"title":"2月25日安全热点 - SamSam再次来袭,科罗拉多交通部遭到重创","date":"2018-02-25 11:13:14"},{"id":98828,"title":"2月24日安全热点 - Drupal修复多个严重漏洞/Chaos 后门再现","date":"2018-02-24 11:00:14"}],"authorPostList":[{"post_id":104275,"title":"CSA报名现已开通, 新一届“4.29首都网络安全日”等你来!","cover":"https://p1.ssl.qhimg.com/sdm/229_160_100/t011dbd93c77708c912.jpg","date":"2018-04-23 17:20:06"},{"post_id":104079,"title":"【Chainge】技术沙龙——区块链技术的安全隐患[厦门]","cover":"https://p3.ssl.qhimg.com/sdm/229_160_100/t01c864469963b4de87.png","date":"2018-04-09 19:04:09"},{"post_id":103772,"title":"4月7日热点 - 芬兰第三大数据泄露案,130000余名用户明文密码泄露","cover":"https://p3.ssl.qhimg.com/sdm/229_160_100/t01962d627638962a61.png","date":"2018-04-07 10:46:54"},{"post_id":103739,"title":"4月5日热点 - 剑桥分析公司拥有8700万的用户数据,不是5000万","cover":"https://p3.ssl.qhimg.com/sdm/229_160_100/t01962d627638962a61.png","date":"2018-04-05 17:14:31"},{"post_id":103568,"title":"4月4日安全热点 - 新的Android恶意软件可以窃取IM客户端的数据","cover":"https://p3.ssl.qhimg.com/sdm/229_160_100/t01962d627638962a61.png","date":"2018-04-04 10:13:34"}],"cookie":[]}}; //published at: 5/3/2025, 4:00:45 AM