SecWiki周刊(第10期)
2014/05/05-2014/05/11
安全资讯
一周海外安全事件回顾(20140428-0504)
http://www.freebuf.com/news/special/33727.html
http://www.freebuf.com/news/special/33727.html
翰海源关于Struts2漏洞的统计分析报告
http://blog.vulnhunt.com/index.php/2014/05/05/%e7%bf%b0%e6%b5%b7%e6%ba%90%e5%85%b3%e4%ba%8estruts2%e6%bc%8f%e6%b4%9e%e7%9a%84%e7%bb%9f%e8%ae%a1%e5%88%86%e6%9e%90%e6%8a%a5%e5%91%8a/
http://blog.vulnhunt.com/index.php/2014/05/05/%e7%bf%b0%e6%b5%b7%e6%ba%90%e5%85%b3%e4%ba%8estruts2%e6%bc%8f%e6%b4%9e%e7%9a%84%e7%bb%9f%e8%ae%a1%e5%88%86%e6%9e%90%e6%8a%a5%e5%91%8a/
一周海外安全事件回顾(20140421-0427)
http://www.freebuf.com/news/special/33285.html
http://www.freebuf.com/news/special/33285.html
安全技术
使用Suricata進行IDS/IPS
http://maskray.me/blog/2013-07-26-ids-ips-with-suricata
http://maskray.me/blog/2013-07-26-ids-ips-with-suricata
部分dve技术实现代码
http://weibo.com/p/1001603708954432635204
http://weibo.com/p/1001603708954432635204
Debug Struts2 S2-021的一点心得体会
http://drops.wooyun.org/papers/1778
http://drops.wooyun.org/papers/1778
inception: FireWire physical memory manipulation and hacking tool
https://github.com/carmaa/inception
https://github.com/carmaa/inception
ROPs are for the 99%: A revolutionary bypass technology
http://pastebin.ubuntu.com/7444950/
http://pastebin.ubuntu.com/7444950/
django-xadmin:Bootstrap3.0框架的后台管理系统框架
http://sshwsfc.github.io/django-xadmin/#features
http://sshwsfc.github.io/django-xadmin/#features
编写变态的(非字母数字的)PHP后门
http://www.freebuf.com/articles/web/33824.html
http://www.freebuf.com/articles/web/33824.html
SniffMap: Maps of Five Eyes interception
http://sniffmap.telcomap.org/
http://sniffmap.telcomap.org/
360hackgame writeup
http://drops.wooyun.org/tips/1666
http://drops.wooyun.org/tips/1666
15款最好的 Twitter Bootstrap 开发工具
http://www.cnblogs.com/lhb25/p/15-best-bootstrap-tools-for-designers.html
http://www.cnblogs.com/lhb25/p/15-best-bootstrap-tools-for-designers.html
The Nitty Gritty of Sandbox Evasion
http://www.fireeye.com/blog/corporate/2014/05/live-from-infosecurity-europe-2014-the-nitty-gritty-of-sandbox-evasion.html
http://www.fireeye.com/blog/corporate/2014/05/live-from-infosecurity-europe-2014-the-nitty-gritty-of-sandbox-evasion.html
[CVE-2014-3005]Zabbix 1.8.x-2.2.x Local File Inclusion via XXE Attack | 风井
http://www.pnigos.com/?p=273
http://www.pnigos.com/?p=273
SQL SERVER 2008安全配置
http://drops.wooyun.org/tips/1670
http://drops.wooyun.org/tips/1670
Ghost-Hunting With Anti-Virus
http://www.fireeye.com/blog/corporate/2014/05/ghost-hunting-with-anti-virus.html
http://www.fireeye.com/blog/corporate/2014/05/ghost-hunting-with-anti-virus.html
[投稿]从CVE-2014-0166看高效率EXP的编写
http://www.91ri.org/8871.html
http://www.91ri.org/8871.html
工控系统的安全风险及对策
http://www.i170.com/user/falcon/Article_124070
http://www.i170.com/user/falcon/Article_124070
CVE-2014-1776 的 fun() 函数
http://paste.ubuntu.com/7402258/
http://paste.ubuntu.com/7402258/
QCon北京2014大会
http://www.qconbeijing.com/videoslides.html
http://www.qconbeijing.com/videoslides.html
安全漏洞概念及分类
http://pan.baidu.com/s/1kT9LT4r
http://pan.baidu.com/s/1kT9LT4r
针对近期“博全球眼球的OAuth漏洞”的分析与防范建议
http://www.freebuf.com/vuls/33750.html
http://www.freebuf.com/vuls/33750.html
Egor Homakov: Covert Redirect FAQ
http://homakov.blogspot.com/2014/05/covert-redirect-faq.html
http://homakov.blogspot.com/2014/05/covert-redirect-faq.html
Python gdb Disassembly Extension 1.20
http://www.thegreycorner.com/2014/05/python-gdb-disassembly-extension-120.html
http://www.thegreycorner.com/2014/05/python-gdb-disassembly-extension-120.html
走进科学: 无线安全需要了解的芯片选型、扫描器使用知识
http://www.freebuf.com/articles/wireless/33524.html
http://www.freebuf.com/articles/wireless/33524.html
Double-Dip: Using the latest IE 0-day to get RCE and an ASLR Bypass
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Double-Dip-Using-the-latest-IE-0-day-to-get-RCE-and-an-ASLR/ba-p/6466280#.U2mpkihlIbx
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Double-Dip-Using-the-latest-IE-0-day-to-get-RCE-and-an-ASLR/ba-p/6466280#.U2mpkihlIbx
Windows平台下的堆溢出利用技术(二)(上篇)
http://drops.wooyun.org/papers/1714
http://drops.wooyun.org/papers/1714
LIONsolver: the Learning and Intelligent OptimizatioN solver
http://www.lionsolver.com/LIONbook/
http://www.lionsolver.com/LIONbook/
Prolexic_Q12014_Global_Attack_Report_US_041614
http://vdisk.weibo.com/s/C72IDYVyeiWsd/1399302056
http://vdisk.weibo.com/s/C72IDYVyeiWsd/1399302056
Spring MVC xml绑定pojo造成的XXE
http://drops.wooyun.org/papers/1911
http://drops.wooyun.org/papers/1911
动态调试 Android so库函数的方法
http://riusksk.blogbus.com/logs/271566148.html
http://riusksk.blogbus.com/logs/271566148.html
New Paper: Advanced Endpoint and Server Protection
https://securosis.com/blog/new-paper-advanced-endpoint-and-server-protection
https://securosis.com/blog/new-paper-advanced-endpoint-and-server-protection
《How to Read an Engineering Research Paper》笔记
http://liusihao.com/post/85169957748/how-to-read-an-engineering-research-paper
http://liusihao.com/post/85169957748/how-to-read-an-engineering-research-paper
HII_The_Non-Advanced_Persistent_Threat
http://vdisk.weibo.com/s/C72IDYVyeiYWJ/1399389089
http://vdisk.weibo.com/s/C72IDYVyeiYWJ/1399389089
MSSQL注射知识库 v 1.0
http://drops.wooyun.org/tips/1620
http://drops.wooyun.org/tips/1620
2014-annual-ddos-attacks-and-impact-report
http://vdisk.weibo.com/s/C72IDYVyeiWt0/1399301885
http://vdisk.weibo.com/s/C72IDYVyeiWt0/1399301885
有关网络攻击的世界地图是怎么开发的
http://www.zhihu.com/question/23624209
http://www.zhihu.com/question/23624209
http://www.exploit-db.com/download_pdf/33196/
Windows Heap Overflow Exploitation
Windows Heap Overflow Exploitation
Exploit Kit Roundup: Best of Obfuscation Techniques
http://blog.spiderlabs.com/2014/05/exploit-kit-roundup-best-of-obfuscation-techniques.html
http://blog.spiderlabs.com/2014/05/exploit-kit-roundup-best-of-obfuscation-techniques.html
Assembly Language Tutorial
https://wiki.skullsecurity.org/Assembly
https://wiki.skullsecurity.org/Assembly
我读《大型网站技术架构》笔记
http://iamzhongyong.iteye.com/blog/2063481
http://iamzhongyong.iteye.com/blog/2063481
Open Flash Charts File Upload Attacks
http://blog.spiderlabs.com/2014/05/honeypot-alert-open-flash-charts-file-upload-attacks.html
http://blog.spiderlabs.com/2014/05/honeypot-alert-open-flash-charts-file-upload-attacks.html
SQL Injection in Insert, Update and Delete Statements
http://www.exploit-db.com/download_pdf/33253
http://www.exploit-db.com/download_pdf/33253
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第10期)
