Android 消息应用:距离完整利用链还差几个 bug
摘要
一年半前对 Android 消息与邮件客户端的研究:找到了一批 bug,但距离完整攻击链还差几步。
- 发布时间
- 收录时间
相关内容
研究 ·
projectzero.google
利用 NVMAP 逃逸 Chrome 沙箱 - CVE-2014-5332
Google Project Zero 文章,利用 NVIDIA NVMAP 驱动漏洞 CVE-2014-5332 逃逸 Chrome for Android 沙箱。
博客 ·
projectzero.google
Welcome to the new Project Zero Blog
Project Zero 官方公告,介绍全新改版的博客:说明迁移背景、新的版式与功能,并指引读者查阅既往安全研究文章的存档。
博客 ·
projectzero.google
The Windows Registry Adventure #7: Attack surface analysis
Windows 注册表历险记第七篇:梳理哪些 Windows 组件会解析注册表数据,划定攻击面并圈定值得深入 fuzzing 与审计的高价值目标。
博客 ·
projectzero.google
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
macOS 音频攻击面系列第一篇:通过发送 Mach message 对 CoreAudio 进行模糊测试,介绍攻击面构成、harness 设计与初期成果。
博客 ·
projectzero.google
The Windows Registry Adventure #6: Kernel-mode objects
Windows 注册表历险记第六篇:考察内核态注册表对象及其暴露的额外攻击面,并结合实例讨论其对权限提升研究的意义。
博客 ·
projectzero.google
The Windows Registry Adventure #5: The regf file format
Windows 注册表历险记第五篇:拆解注册表 hive 底层的 regf 文件格式,解析其结构、解析陷阱,以及它对 fuzzing 工作的意义。
Skip to content