SecWiki周刊(第106期)
2016/03/07-2016/03/13
安全资讯
[会议]  Evolution(进化): 谭晓生的RSAC 2016随笔
http://www.freebuf.com/articles/neopoints/98044.html
安全技术
[Web安全]  antSword 远程命令执行
https://github.com/antoor/antSword/issues/3
[Web安全]  中国菜刀仿冒官网三百万箱子爆菊记
http://drops.wooyun.org/news/13471
[移动安全]  用机器学习检测Android恶意代码
http://drops.wooyun.org/mobile/13428
[设备安全]  KACO 电源逆变器系统 XP100U
http://drops.wooyun.org/tips/13578
[移动安全]  阿里发布2015移动安全漏洞年报
http://www.freebuf.com/vuls/98052.html
[移动安全]  2015移动安全病毒年报
http://jaq.alibaba.com/community/art/show?articleid=193
[Web安全]  富文本存储型XSS的模糊测试之道
http://drops.wooyun.org/web/13124
[运维安全]  A curated list of Awesome Threat Intelligence resources
https://github.com/hslatman/awesome-threat-intelligence
[漏洞分析]  Java 反序列化之 CommonsBeanUtils 分析
http://blog.knownsec.com/2016/03/java-deserialization-commonsbeanutils-pop-chains-analysis/
[移动安全]  drozer模块的编写及模块动态加载问题研究
http://drops.wooyun.org/tips/13239
[设备安全]  工控安全标准发展现状与思考
http://plcscan.org/blog/2016/03/ics-standards-development-and-thoughts/
[设备安全]  工业控制信息安全资源汇总(国内篇)
http://plcscan.org/blog/2016/03/ics-security-resources-overview-1/
[Web安全]  Rails Security (上)
http://drops.wooyun.org/web/12750
[Web安全]  Hacking Magento eCommerce For Fun And 17.000 USD
http://karmainsecurity.com/hacking-magento-ecommerce-for-fun-and-17000-usd
[论文]  Proceedings of the 12th International Conference on Security and Cryptography
http://www.scitepress.org/DigitalLibrary/ProceedingsDetails.aspx?ID=isegUqXGJF8=&t=1
[漏洞分析]  The Problem with Dynamic Program Analysis
http://blog.trailofbits.com/2016/03/09/the-problem-with-dynamic-program-analysis/
[Web安全]  PyYAML 对象类型解析导致的命令执行问题
http://rickgray.me/2016/03/09/pyyaml-tags-parse-to-command-execution.html
-----微信ID:SecWiki-----
SecWiki,12年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com

本期原文地址: SecWiki周刊(第106期)