2月16日-每日安全知识热点

阅读量117722

|

发布时间 : 2016-02-16 16:51:23

http://p2.qhimg.com/t012dfaf746e4fefbe3.jpg

1.PwnPhone :默认密码允许秘密监控你的voip通话

https://paul.reviews/pwnphone-default-passwords-allow-covert-surveillance/

2.如何安全的存储密码

https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016

3.Ubitiquiti’s AirVision摄像头可通过rstp访问绕过登陆认证,直接看视频 

https://medium.com/@neilwillgettoit/ubiquiti-airvision-video-stream-auth-bypass-a321330a3dfd#.s1q48mkgs

4.来自Cisco Live Europe 2016 Wifi 架构的观察

https://www.insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/

5.盲注利用

https://isc.sans.edu/diary/Exploiting+%28pretty%29+blind+SQL+injections/20733

6.使用 DarunGrim 执行 bindiff

https://mattoh.wordpress.com/2014/04/21/

7.iOS (up to) 9.3b3 IOHIDFamily Use-After-Free (incorrect patch for CVE-2015-6974) POC 

https://ghostbin.com/paste/s3tz7

8.Usenix安全会议:利用噪音干扰无人机陀螺仪

http://www.securitytube.net/video/15164?utm_source=HT&utm_medium=twitter&utm_campaign=SM

9.智能建筑面临多个IOT安全风险

http://www.techrepublic.com/article/ibm-x-force-finds-multiple-iot-security-risks-in-smart-buildings/

10.反向工程xbee pro物理层第一部分

http://xn--thibaud-dya.fr/phy_xbee_p1.html

11.mitmproxy发行:支持http/2

http://honeynet.org/node/1290

12.Windows Kerberos 安全功能绕过POC (MS16-014)

https://www.exploit-db.com/exploits/39442/

13.研究人员演示在另一个房间从断网的笔记本中偷取私钥

http://motherboard.vice.com/read/how-white-hat-hackers-stole-crypto-keys-from-an-offline-laptop-in-another-room

14.andorid 应用的网络安全策略配置

https://koz.io/network-security-policy-configuration-for-android-apps/

15.跟踪Andromeda/Gamrue僵尸网络

http://eternal-todo.com/blog/travelling-far-side-andromeda-botconf

16.三星警告用户在使用声控控制smartTV的时候,数据有可能会传给第三方厂商

http://theantimedia.org/samsung-warns-customers-to-think-twice-about-what-they-say-near-smart-tvs/

17.使用bettercap绕过hsts

https://www.bettercap.org/blog/sslstripping-and-hsts-bypass/#.VsHQflQ9TwA.twitter

18.针对一款能清除你android数据的mazar bot分析

https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/

19.揭秘Facebook的群体正在使用的恋童癖者交换色情图片 

https://nakedsecurity.sophos.com/2016/02/15/secret-facebook-groups-being-used-by-pedophiles-to-swap-obscene-images/

20.CVE-2016-1903利用

http://www.libnex.org/blog/exploitingcve-2016-1903memoryreadviagdimagerotateinterpolated

21.硬件设计:FPGA的安全风险 

https://www.nccgroup.trust/globalassets/our-research/uk/whitepapers/2016/01/research-insights_vol-8-hardware-design-fpga-security-riskspdf

本文由安全客原创发布

转载,请参考转载声明,注明出处: https://www.anquanke.com/post/id/83480

安全KER - 有思想的安全新媒体

分享到:微信
+10赞
收藏
安全客
分享到:微信

发表评论

Copyright © 北京奇虎科技有限公司 三六零数字安全科技集团有限公司 安全KER All Rights Reserved 京ICP备08010314号-66