SecWiki周刊(第107期)
2016/03/14-2016/03/20
安全资讯
[其它]  你的B计划在哪里?
http://www.ruanyifeng.com/blog/2016/03/plan-b.html
安全技术
[运维安全]  美团风险控制系统综述
http://tech.meituan.com/online-risk-control.html
[数据挖掘]  大数据安全分析常见问题汇总
http://blog.nsfocus.net/big-data-security-analysis-summary-common-problems/
[运维安全]  流量劫持攻击之链路劫持剖析
http://drops.wooyun.org/tips/13661
[Web安全]  OrangeScan: 在线子域名信息收集工具
https://github.com/0xbug/OrangeScan
[设备安全]  浅谈一次针对公网PLC恶意操作行为的简单分析
http://plcscan.org/blog/2016/03/security-analysis-from-siemens-s7-plc-cpubuffer/
[Web安全]  0ctf writeup
http://drops.wooyun.org/tips/13791
[恶意分析]  云、管、端三重失守,大范围挂马攻击分析
http://drops.wooyun.org/papers/13755
[漏洞分析]  pyyaml-tags-parse-to-command-execution
http://blog.knownsec.com/2016/03/pyyaml-tags-parse-to-command-execution/
[恶意分析]  Taiwan Presidential Election: A Case Study on Thematic Targeting
http://pwc.blogs.com/cyber_security_updates/2016/03/taiwant-election-targetting.html
[Web安全]  QQ模拟登录实现之四两拨千斤(基于V8引擎)
http://drops.wooyun.org/tips/13556
[漏洞分析]  vulnerability-in-net-signedxml
https://coding.abel.nu/2016/03/vulnerability-in-net-signedxml/
[恶意分析]  Tracking changes in years-long espionage campaign against Tibetans
https://citizenlab.org/2016/03/shifting-tactics/
[Web安全]  collection of tools for security research, CTFs
https://github.com/eugenekolo/sec-tools
[运维安全]  设备唯一标识的思考
http://www.ylzhu.com/?p=9
-----微信ID:SecWiki-----
SecWiki,12年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com

本期原文地址: SecWiki周刊(第107期)