Aggregator
创新沙盒评论愈发难写,介绍入围者的文章多到汗牛充栋,读者并不感冒浅尝即止的内容,堆砌华丽词藻更会被嗤之以鼻,亟需找到一些独特的角度才能满足眼界变高的读者们的胃口:抛弃吹捧,透过花哨探究本质,试图不放过产品和业务的弱点。
创新沙盒,由开源商业模式说起 - RSAC2019之一
7 years 5 months ago
创新沙盒评论愈发难写,介绍入围者的文章多到汗牛充栋,读者并不感冒浅尝即止的内容,堆砌华丽词藻更会被嗤之以鼻,亟需找到一些独特的角度才能满足眼界变高的读者们的胃口:抛弃吹捧,透过花哨探究本质,试图不放过产品和业务的弱点。
创新沙盒,由开源商业模式说起 - RSAC2019之一
7 years 5 months ago
创新沙盒评论愈发难写,介绍入围者的文章多到汗牛充栋,读者并不感冒浅尝即止的内容,堆砌华丽词藻更会被嗤之以鼻,亟需找到一些独特的角度才能满足眼界变高的读者们的胃口:抛弃吹捧,透过花哨探究本质,试图不放过产品和业务的弱点。
创新沙盒,由开源商业模式说起 - RSAC2019之一
7 years 5 months ago
创新沙盒评论愈发难写,介绍入围者的文章多到汗牛充栋,读者并不感冒浅尝即止的内容,堆砌华丽词藻更会被嗤之以鼻,亟需找到一些独特的角度才能满足眼界变高的读者们的胃口:抛弃吹捧,透过花哨探究本质,试图不放过产品和业务的弱点。
CVE-2019-1002100
7 years 5 months ago
json-patch requests can exhaust apiserver resources
ConQuest DICOM Server 1.4.17d 远程代码执行漏洞
7 years 5 months ago
作者:k0shl 转载请注明出处:https://whereisk0shl.top
system call analysis: mount
7 years 5 months ago
Terenceli
现代化网站的渗透测试
7 years 5 months ago
对现代化网站的渗透测试的思考 前言 首先定义本文所说的现代化网站. 现代化网站是指符合以下多个特征的对外服务. 储存,数据库,网站程序等服务器高度分
WinRAR漏洞复现过程
7 years 5 months ago
0x01 漏洞描述
近日Check Point团队爆出了一个关于WinRAR存在19年的漏洞,用它来可以获得受害者计算机的控制。攻击者只需利用此漏洞构造恶意的压缩文件,当受害者使用WinRAR解压该恶意文件时便会触发漏洞。
浮萍
Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in January 2019
7 years 5 months ago
January threat actor activity focused heavily on exploiting a ThinkPHP remote code execution vulnerability and infecting vulnerable Oracle WebLogic systems with a Mirai variant.
Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in January 2019
7 years 5 months ago
January threat actor activity focused heavily on exploiting a ThinkPHP remote code execution vulnerability and infecting vulnerable Oracle WebLogic systems with a Mirai variant.
Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in January 2019
7 years 5 months ago
January threat actor activity focused heavily on exploiting a ThinkPHP remote code execution vulnerability and infecting vulnerable Oracle WebLogic systems with a Mirai variant.
TTPs & IOCs & 痛苦金字塔
7 years 5 months ago
之前介绍了 Richard Bejtlich 和 Robert M. Lee 就 hunting 术语定义进行的博客辩论。这次讨论还衍生出关于 TTPs 和 IOCs 的问题。今天的分享将围绕这个话题。
Padding Oracle + CBC 字节翻转学习
7 years 5 months ago
DNS Rebind 在 SSRF 中的作用
7 years 5 months ago
这几天沉迷 hgame, 题目质量还是不错的, 其中有一题用到了 DNS rebind, 这里重新记一下笔记. 因为我估计也没多少人看我博客 233, 就直接写了, 不等比赛结束了.
安卓APP测试之双向证书认证
7 years 5 months ago
0x01 前言
在《安卓APP测试之HOOK大法-Frida篇》文章中有一个双向证书认证没详细说明,经过孔已己的提示,现在补充一下。
浮萍
Opening statement to the Intelligence and Security Committee 20 February 2019
7 years 5 months ago
Speaking Notes for the Opening Statement to the Intelligence & Security Committee by Andrew Hampton, Director-General, Government Communications Security Bureau.
MWC 2019: The Key to Establishing Digital Trust with Intelligent Connectivity
7 years 5 months ago
These days, it’s rare to walk into a home that doesn’t have a smart device in use. From voice assistants,...
The post MWC 2019: The Key to Establishing Digital Trust with Intelligent Connectivity appeared first on McAfee Blog.
McAfee
Are security questions leaving a gap in your security?
7 years 5 months ago
Even the best authentication can't help you if there is an easy way to bypass it.
AI safety needs social scientists
7 years 5 months ago
We’ve written a paper arguing that long-term AI safety research needs social scientists to ensure AI alignment algorithms succeed when actual humans are involved. Properly aligning advanced AI systems with human values requires resolving many uncertainties related to the psychology of human rationality, emotion, and biases. The aim of this paper is to spark further collaboration between machine learning and social science researchers, and we plan to hire social scientists to work on this full time at OpenAI.