十一月 | 2018 | xxx | 第 3 页2018年11月 – 第3页 – xxx
菜单

每月的档案:2018年11月

[webapps] PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
XuanwuLab Security Daily News Push – 2018-11-30
Tencent Xuanwu Lab Security Daily News[ Browser ] [...]
[remote] Apache Spark – Unauthenticated Command Execution (Metasploit)
Apache Spark – Unauthenticated Command Execution […]
[dos] VBScript – ‘rtFilter’ Out-of-Bounds Read
VBScript – ‘rtFilter’ Out-of-Bounds R […]
[dos] VBScript – ‘OLEAUT32!VariantClear’ and ‘scrrun!VBADictionary::put_Item’ Use-After-Free
VBScript – ‘OLEAUT32!VariantClear’ an […]
[local] xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege […]
[local] HTML5 Video Player 1.2.5 – Buffer Overflow (Metasploit)
HTML5 Video Player 1.2.5 – Buffer Overflow (Metas […]
[webapps] Synaccess netBooter NP-02x/NP-08x 6.8 – Authentication Bypass
Synaccess netBooter NP-02x/NP-08x 6.8 – Authentic […]
[dos] Linux Kernel 4.8 (Ubuntu 16.04) – Leak sctp Kernel Pointer
Linux Kernel 4.8 (Ubuntu 16.04) – Leak sctp Kerne […]
[webapps] Schneider Electric PLC – Session Calculation Authentication Bypass
Schneider Electric PLC – Session Calculation Auth […]
>APP普遍涉嫌过度收集个人信息 中国重拳出击保护信息安全(附政策) – 游侠安全网
中商情报网讯:当天上午,中消协发布了《100款App个人信息收集与隐私政策测评报告》。报告显示,很多被测评App在隐私政策等文件中,未将其收集的个人信息与其实现的产品功能明确挂钩,其中很多个人信息与消费者通常理解的产品功能之间无明显关联,甚至明显超出合理范围。
Personal info ready for the picking
Data belonging to 32 million customers of SKY Brasil has been exposed online long enough to make their theft very likely, an independent security [...]
解析XP版永恒之蓝中的一个Bug – 安全客,安全资讯平台
 永恒之蓝漏洞刚出来时,我可以顺利搞定Windows 7,但在攻击Windows XP时我一直没有成功。我尝试了各种补丁和Service Pack的组合,但利用程序要么无法成功,要么会导致系统蓝屏。当时我没有深入研究,因为FuzzBunch(NSA泄露工具集)还有待探索许多点。
Enabling Faster, More Capable Robots With Real-Time Motion Planning – IEEE Spectrum
This is a guest post. The views expressed here are solely those of the authors and do not represent positions of IEEE Spectrum or the IEEE.
“基因编辑婴儿”背后:超车时,我们落下了什么?
她最担心的是,一旦这对经基因编辑的双胞胎未来有任何健康问题,很可能会导致民众对基因编辑态度的极大反弹,从而长期抑制该领域的一些更温和的、合理的进展。
加速自动驾驶商业化,通用汽车二号人物入主 Cruise | 雷锋网
对通用汽车来说,2018 年的秋天“寒意”正盛。2008 年世界金融危机中“死”过一次的通用汽车 10 年后又遇到了一个坎。11 月 30 日,“一朝被蛇咬,十年怕井绳”的汽车巨头干脆玩起了壮士断腕,开始走上转型之路。
斯雪明:自然界拟态现象,如何启发理想区块链构建? | 雷锋网
在近日2018中国区块链大会上,中国计算机学会区块链专委会主任、复旦教授斯雪明介绍了一番区块链形式化表示与体系结构演进。
亚马逊CTO宣布无服务器Lambda重大更新,不懂“取悦开发者”的云不是好云?| AWS re:Invent | 雷锋网
距离上次见到亚马逊CTO 沃纳·威格尔(Werner Vogels)正好过去了111天,那还是在8月9日于中国举办的AWS技术峰会上。而这一次,沃纳·威格尔则出现在拉斯维加斯AWS re:Invent大会第4天主题演讲的舞台。
Does Library Bloat Make Your Smartphone App Look Fat? | Hackaday
While earlier smartphones seemed to manage well enough with individual applications that only weighed in at a few megabytes, a perusal of the modern [...]
AT&T's 5G+ Service Will Only Kinda Sorta Be What We Hope For | WIRED
In January, AT&T said it would launch a 5G wireless network in 2018. On Tuesday, the company said it would meet that target—barely—by launching a 5G [...]
Just discovered! "Farout", the Farthest Object Ever Seen in the Solar System – Universe Today
Universe TodaySpace and astronomy newsAstronomers have discovered a distant body that’s more than 100 times farther from the Sun than Earth is. Its [...]
>【安全帮】戴尔宣称发现安全漏洞 已重置所有账户密码;新西兰以国家安全为由禁止使用华为设备 – 游侠安全网
戴尔宣称发现安全漏洞 [...]
All the good stuff for a proper scam
A huge database with over 114 million records of US citizens and companies has been discovered sitting online unprotected. The number of individuals [...]
Hackaday Podcast: 2018 Year In Review | Hackaday
Did you read all 3000+ articles published on Hackaday this year? We did. And to help catch you up, we preset the Hackaday 2018 Year in Review podcast!
Old Wattmeter Uses Magnetics To Do the Math | Hackaday
Measuring power transfer through a circuit seems a simple task. Measure the current and voltage, do a little math courtesy of [Joule] and [Ohm], and [...]
周观林:耐心做中国布草的带头大哥
本文来源微信公众号:领教工坊(ID: ClecChina),作者:陈统奎周观林:康乃馨家纺董事长,领教工坊1511组组员
电动化潮流下,看各大车企如何在洛杉矶车展“争奇斗艳 ” | 雷锋网
车展一端连着车企,一端连着消费者。很多车企都将车展视为展示新产品、新技术和新战略的重要契机,尤其是具有国际影响力的大型车展,更是各大车企必争之地。
Netflix's ‘Roma’ Rollout Teaches the Company Some Lessons | WIRED
There’s never been a movie quite like Netflix’s Roma, writer-director Alfonso Cuarón’s gorgeous, deeply immersive black-and-white drama about a young [...]
Live回顾:星舆科技,用“网-端-云”精准时空体系打造精准位置感知 | 雷锋网
高精度定位与高精度地图,已被行业定义为自动驾驶刚需。然而全场景、高精度、室内外一体化的精准位置感知仍是当下高精度位置服务领域急需解决的技术难点之一。
Why Founders Fail To Grow Their Business – Starter Story
Hello, Starter Story readers! It is fantastic to be back on this blog for another guest post.In case you have no idea who I am (likely), my name is Lucy [...]
Google Chrome wants to stop back-button hijacking | Ars Technica
Front page layoutSite themeSign up or login to join the discussions! Ron Amadeo - Dec 18, 2018 6:22 pm UTC
VLC is popular among malware distributors
The web site for the popular VLC Media Player - VideoLan.org - is getting a big warning in Bing when users hover their cursor over it. This warning [...]
Anthony Levandowski Returns With a Self-Driving Truck Scheme | WIRED
Anthony Levandowski, the engineer whose alleged theft of trade secrets landed him in the middle of a blockbuster self-driving car legal fight, has stepped [...]
>数据库“裸奔”!个人信息屡遭暗网贩卖,我们该如何保护个人隐私? – 游侠安全网
从互联互通时代到如今的人工智能时代,包括个人信息在内的各种数据变成了最宝贵的财富。然而,大数据、云计算、人工智能等新技术的运用,在充分发挥数据价值的同时,也给个人隐私保护带来严峻挑战,数据产业的发展和个人信息安全之间出现了失衡。
Equivalence of State Machines and Coroutines – 250bpm
In the past I often referred to the equivalence between state machines and coroutines as a kind of obvious fact that doesn't need any additional [...]
>你所不知道的阿里开源那些事儿 – IT资讯 – 红黑联盟
云原生技术正席卷全球,云原生基金会在去年 KubeCon +CloudNativeCon NA 的现场宣布:
抓住新一轮科技革命产业变革机遇 人工智能改变未来-中共中央网络安全和信息化委员会办公室
  如果说以蒸汽技术驱动的第一次工业革命延伸了人的肢体,拓展了人类的力量,那么,以新一代人工智能技术为驱动的新一轮科技革命和产业变革将拓展人类的智能,极大提升人类智力所能创造的价值。
>针对马拉维(MALAWI)国民银行的网络攻击样本分析报告-网络安全-黑吧安全网
1、概述 近日,安天CERT(安全研究与应急处理中心)在梳理相关安全事件时发现多例对马拉维国民银行(National Bank of Malawi)的钓鱼邮件攻击样本。马拉维共和国(Republic of [...]
Thread Carefully: An Introduction To Concurrent Python | Hackaday
The ability to execute code in parallel is crucial in a wide variety of scenarios. Concurrent programming is a key asset for web servers, producer/consumer [...]
小米说,要开源 | 雷锋网
雷军曾表示,小米创立的原因之一,在于安卓的开源。现在,小米已经有自己的开源团队,成为开源的倡导者和支持者,开源贯穿了小米整个CBA路线。
出门问问CEO李志飞:明年,To B业务营收占比将达25%以上 | 雷锋网
11月28日,AI语音赛道独角兽公司出门问问举办了一场媒体沟通会,发布了旗下智能手表TicWatch Pro 4G版新品,阐述了出门问问的战略布局、最新进展以及对行业的思考。
AI技术赋能行业升级 WOT2018全球人工智能技术峰会驱动智能未来 – 51CTO.COM
[...]
Kroger-owned grocery store begins fully driverless deliveries | Ars Technica
Front page layoutSite themeSign up or login to join the discussions! Timothy B. Lee - Dec 18, 2018 6:18 pm UTC
Cybercriminals Use Malicious Memes that Communicate with Malware – TrendLabs Security Intelligence Blog
By Aliakbar ZahraviSteganography, or the method used to conceal a malicious payload inside an image to evade security solutions, has long been used by [...]
Blaming the responsible party
A data breach notification from the City of York has gone awry as new details shed light over the incident, revealing a completely inappropriate response [...]
Java Eclipse Code Refactoring Shortcuts and Tips – DZone Java
{{node.type}} · {{ node.urlSource.name }} · by {{node.authors[0].realName }}
>三星手机自燃案一审宣判:三星不构成欺诈 – IT资讯 – 红黑联盟
备受关注的三星 note7 炸机机主回先生诉三星案在广州越秀区人民法院一审宣判,法院仅支持原告回先生诉求中,原价赔偿烧坏的笔记本电脑一项,驳回了回先生其他诉讼请求,认定被告三星中国公司不存在欺诈的故意。
>XLoader与FakeSpy的关联以及与Yanbian Gang的关系-WEB安全-黑吧安全网
[...]
>上海消保委测试18款App,涉及个人信息权限的测评结果 – 游侠安全网
11月28日的发布会上,这三家企业仍然没有到场,超功能的权限设置也没有改变。
中国义乌国际智能装备博览会开幕 多项炫酷科技产品集中亮相-中共中央网络安全和信息化委员会办公室
智能调酒机器人 奚金燕 摄    11月29日,2018中国义乌国际智能装备博览会(以下简称装博会)在浙江义乌开幕,来自全国13个省(区、市)以及美国、德国、日本、新加坡、意大利等9个国家和地区的471家企业参展,智能跟随旅行箱、智能调酒机器人、智能擦窗机器人等多项炫酷“黑科技”亮相,吸睛十足。

Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51