SecWiki周刊(第120期)
2016/06/13-2016/06/19
安全资讯
谁最给力?国内各大应急响应中心奖励分析
http://www.freebuf.com/articles/others-articles/13953.html
http://www.freebuf.com/articles/others-articles/13953.html
安全技术
余弦:自学成才的黑客(安全研究员)是从哪学到那些知识的
http://www.e365.org/?p=7882
http://www.e365.org/?p=7882
内网渗透思路探索 之新思路的探索与验证 | WooYun知识库
http://drops.wooyun.org/tips/16116
http://drops.wooyun.org/tips/16116
Thinkphp 漏洞小结
http://www.webshell.cc/4729.html
http://www.webshell.cc/4729.html
ShowMeCon 2016 Videos
http://www.irongeek.com/i.php?page=videos/showmecon2016/mainlist
http://www.irongeek.com/i.php?page=videos/showmecon2016/mainlist
iOS冰与火之歌 – UAF and Kernel Pwn
http://drops.wooyun.org/tips/16681
http://drops.wooyun.org/tips/16681
Datamaps.co: free and simple platform for creating visualizations with data maps
https://github.com/caspg/datamaps.co
https://github.com/caspg/datamaps.co
域渗透——Dump Clear-Text Password after KB2871997 installed
http://drops.wooyun.org/papers/16818
http://drops.wooyun.org/papers/16818
Dangerous Websites, Adware, Banking Trojans and Surprises
https://blog.gdatasoftware.com/2016/04/28232-dangerous-websites-adware-banking-trojans-and-surprises
https://blog.gdatasoftware.com/2016/04/28232-dangerous-websites-adware-banking-trojans-and-surprises
28th Annual FIRST Conference / Program
https://www.first.org/conference/2016/program
https://www.first.org/conference/2016/program
Struts2多版本一次性检测工具
http://0ke.org/index.php/archives/27/
http://0ke.org/index.php/archives/27/
es_email_intel: Extract IOCs from emails, store them in ElasticSearch
https://github.com/pierre427/es_email_intel
https://github.com/pierre427/es_email_intel
awesome-bug-bounty: Bug Bounty & Disclosure Programs and write-ups
https://github.com/djadmin/awesome-bug-bounty
https://github.com/djadmin/awesome-bug-bounty
DDoS Trojan: A Malicious Concept that Conquered the ELF Format
https://www.virusbulletin.com/virusbulletin/2016/06/vb2015-paper-ddos-trojan-malicious-concept-conquered-elf-format/
https://www.virusbulletin.com/virusbulletin/2016/06/vb2015-paper-ddos-trojan-malicious-concept-conquered-elf-format/
浅谈nginx + lua在安全中的一些应用
https://zhuanlan.zhihu.com/p/21362834
https://zhuanlan.zhihu.com/p/21362834
三个白帽之从pwn me调试到Linux攻防学习
http://drops.wooyun.org/binary/16700
http://drops.wooyun.org/binary/16700
Advisory: HTTP Header Injection in Python urllib
http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html
http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html
针对网络空间关键基础设施情报收集的组织行为分析报告
http://plcscan.org/blog/2016/06/ics-security-research-report-2016-05/
http://plcscan.org/blog/2016/06/ics-security-research-report-2016-05/
CVE-2014-6352漏洞及定向攻击样本分析
http://drops.wooyun.org/papers/16825
http://drops.wooyun.org/papers/16825
Stories of XSS in Google (April – May, 2016)
http://arsiadi.net/2016/06/11/stories-of-xss-in-google-april-may-2016/
http://arsiadi.net/2016/06/11/stories-of-xss-in-google-april-may-2016/
一个简单的聊天或者私信系统设计
http://www.ideawu.net/blog/archives/953.html
http://www.ideawu.net/blog/archives/953.html
Python API for dnsd
https://github.com/PaulSec/API-dnsdumpster.com
https://github.com/PaulSec/API-dnsdumpster.com
Summary of recent Anti-Sandbox Tricks
http://joe4security.blogspot.tw/2016/06/summary-of-recent-anti-sandbox-tricks.html
http://joe4security.blogspot.tw/2016/06/summary-of-recent-anti-sandbox-tricks.html
安全专题
国内安全应急响应中心(src)
https://www.sec-wiki.com/topic/71
https://www.sec-wiki.com/topic/71
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第120期)
