Aggregator
CVE-2022-26446 | MediaTek MT8797 CMAS Message assertion (MOLY00867883 / ALPS07274118)
CVE-2022-21778 | Google Android VPU information disclosure (ALPS06382421)
CVE-2025-24054 | Microsoft Windows up to Server 2025 NTLM Hash file inclusion (EDB-52280)
每周高级威胁情报解读(2025.04.25~05.01)
每周高级威胁情报解读(2025.04.25~05.01)
The Myth of the Perfect CISO: A Multitalented Master of All
There were never many 'do everything' CISOs. Today there are even fewer. But with a specialist area, strong overview and ability to channel expertise, CISOs can align with business goals, embrace the business enabler role, demonstrate quick wins, and ensure their organization makes better risk decisions.
Ascension Notifying Patients About Rash of Third-Party Hacks
Catholic hospital chain Ascension Health is notifying hundreds of thousands of individuals across several states of at least four hacking incidents in recent months involving third-parties. Ascension reported one of the breaches this week, another in mid-April and the others in March and February.
Planned CISA Cuts Face Political Delays and Growing Backlash
Top officials at the nation's cyber defense agency want to give President Donald Trump's pick to lead the agency time to assess major restructuring plans - a move that is reportedly delaying the timeline for reductions in force while causing growing concerns for job stability among staffers.
Scattered Spider Linked to Marks & Spencer Hack
British retailer Marks & Spencer was reportedly targeted by financial crime group Scattered Spider, who deployed ransomware on the company's VMware ESXi server. The retailer continues to recover from a cyber incident that disrupted operations in its online and offline stores.
马斯克怒怼特斯拉换帅报道;苹果库克称关税成本暂不转嫁给消费者,但未来难说;游戏科学获五四青年奖章集体 | 极客早知道
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
Linux内核0.11完全注释 编译环境搭建
关于Linux 0.11源代码网上已经有很多不同程度修改的版本了,而且某些还是继续有编译链接问题的,不如站在前人的肩膀上继续”搬砖”。
Linux内核0.11完全注释 在Linix 0.11操作系统里面编译Linux 0.11内核源码
来回折腾,终得其法,之后的系列不会照着章节铺叙了~
Linux内核0.11完全注释 来吧,Minix!
认真学习Minix文件系统!通过一个实例手动分析Minix。具体源码实现由于考虑其他情况将很复杂。
Linux内核0.11完全注释 关于任务睡眠和唤醒的理解
主要理解注释中提到的链表以及缺少几行代码的缘由
Linux内核0.11完全注释 0.11的loader->execve
着重分析操作系统的加载器是如何运行程序的。
fmt_exploit
可参考资料不限于但包括:
0day安全 软件漏洞分析技术
https://zhuanlan.zhihu.com/p/24489276
逆向工程学习平台
http://www.xfocus.net/articles/200103/123.html
http://www.freebuf.com/articles/system/74224.html
http://nullablesecurity.blogspot.co.uk/
Exploit 编写教程
https://github.com/shiyanlou/seedlab/blob/master/formatstring.md
http://staff.ustc.edu.cn/~billzeng/seclab/selab02.pdf
The Shellcoder’s Handbook
r00tk1t init
参考:
http://www.freebuf.com/articles/system/54263.html
https://chirath02.wordpress.com/tag/asmlinkage/
r00tk1t基础实验
https://memset.wordpress.com/2010/12/28/syscall-hijacking-simple-rootkit-kernel-2-6-x/
https://memset.wordpress.com/2011/01/20/syscall-hijacking-dynamically-obtain-syscall-table-address-kernel-2-6-x/
http://www.mallocfree.com/data/compile-linux-kernel-mallocfree.com.pdf
https://ruinedsec.wordpress.com/2013/04/04/modifying-system-calls-dispatching-linux/
端到端加密IM预想
从古代烽火通信到二战电台破译,从ARPANET被研发出来至目前互联网,消息加解密会是永恒的主题。近期Google宣布SHA-1发现碰撞,后斯诺登时代信息泄露事件仍在不断发生。一直想学习相关技术并应用于实践,在此进行大致预想。