Windows域渗透之ACL滥用攻击
【ACL简介】 访问控制列表(ACL)定义了Active Directory对象的安全权限。 【攻击向量】 • GenericAll - 完全控制 • GenericWrite - 写入权限 • WriteOwner - 修改所有者 • WriteDACL - 修改权限 • ForceChangePassword - 强制改密 【工具使用】 1. BloodHound - 可视化ACL关...
专业的安全技术分享平台,汇聚全球黑客智慧
【ACL简介】 访问控制列表(ACL)定义了Active Directory对象的安全权限。 【攻击向量】 • GenericAll - 完全控制 • GenericWrite - 写入权限 • WriteOwner - 修改所有者 • WriteDACL - 修改权限 • ForceChangePassword - 强制改密 【工具使用】 1. BloodHound - 可视化ACL关...
【对抗样本原理】 在输入数据中添加人眼不可见的微小扰动,导致AI模型产生错误分类。 【攻击方法】 • FGSM - 快速梯度符号法 • PGD - 投影梯度下降 • C&W - Carlini & Wagner攻击 • DeepFool - 超平面迭代 【攻击场景】 • 图像分类绕过 • 人脸识别欺骗 • 自动驾驶误导 • 恶意软件检测绕过 【防御技术】 • 对抗训练 • 输入预处理...
The deal aims to accelerate AI adoption, train workers, and develop cybersecurity partnerships — the latest move by a hyperscaler to compete for sovereign AI and data centers. 文章来源: https://www.dark...
Elevation-of-privilege bugs accounted for more than half of the 165 vulnerabilities patched, with two zero-days in that mix. 文章来源: https://www.darkreading.com/vulnerabilities-threats/privilege-eleva...
Stopping EDR killers, which employ bring-your-own-vulnerable-driver (BYOVD) attack techniques, is difficult, but not impossible. 文章来源: https://www.darkreading.com/vulnerabilities-threats/edr-killer-...
In an educational game called "Capture the Narrative," students created bots to sway a fictional election, simulating influence in real-world political scenarios. 文章来源: https://www.darkreading.com/c...
Security teams can't test distributed denial-of-service defenses in a vacuum. They need to test during periods of high demand, such as tax filing deadlines. 文章来源: https://www.darkreading.com/cloud-s...
In a new report from the Cloud Security Alliance (CSA), experts warn of an "AI vulnerability storm" triggered by the introduction of Anthropic's Claude Mythos. 文章来源: https://www.darkreading.com/clou...
An attacker has been using maliciously crafted PDF files to exploit a zero-day in Adobe Acrobat and Reader for at least four months. 文章来源: https://www.darkreading.com/application-security/adobe-patc...
OT asset owners are being asked by regulators to attest to their post-quantum cryptographic readiness without the appropriate tooling, resulting in paperwork dressed up to look like genuine security. ...