Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
🌓
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
WebAssembly 的问题与前景
projectzero.google
| 博客 |
#research
|
#security
|
#webassembly
|
#project-zero
摘要
可用于编写 WebAssembly 代码的工具不少,而设计者的重要目标之一是让 wasm 二进制默认更安全——本文讨论这一目标的现实与差距。
发布时间
2018-08-16 00:00
收录时间
2026-09-22 23:45
原文 ↗
← 上一篇
OATmeal on the Universal Cereal Bus:经 USB 攻击 Android 手机
下一篇 →
Windows 利用技巧:利用任意对象目录创建
相关内容
博客
·
projectzero.google
Welcome to the new Project Zero Blog
Project Zero 官方公告,介绍全新改版的博客:说明迁移背景、新的版式与功能,并指引读者查阅既往安全研究文章的存档。
博客
·
projectzero.google
The Windows Registry Adventure #7: Attack surface analysis
Windows 注册表历险记第七篇:梳理哪些 Windows 组件会解析注册表数据,划定攻击面并圈定值得深入 fuzzing 与审计的高价值目标。
博客
·
projectzero.google
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
macOS 音频攻击面系列第一篇:通过发送 Mach message 对 CoreAudio 进行模糊测试,介绍攻击面构成、harness 设计与初期成果。
博客
·
projectzero.google
The Windows Registry Adventure #6: Kernel-mode objects
Windows 注册表历险记第六篇:考察内核态注册表对象及其暴露的额外攻击面,并结合实例讨论其对权限提升研究的意义。
博客
·
projectzero.google
The Windows Registry Adventure #5: The regf file format
Windows 注册表历险记第五篇:拆解注册表 hive 底层的 regf 文件格式,解析其结构、解析陷阱,以及它对 fuzzing 工作的意义。
博客
·
projectzero.google
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code
Project Zero 将 Project Naptime 升级为 Big Sleep:利用大语言模型在真实世界软件中发现漏洞,并分享首批成果与观察。
返回