SecWiki周刊(第125期)
2016/07/18-2016/07/24
安全资讯
Kickass Torrents站长因购买正版音乐被定位
http://www.solidot.org/story?sid=49023
http://www.solidot.org/story?sid=49023
公安部发布侵犯个人信息网络犯罪案例
http://mp.weixin.qq.com/s?__biz=MzIyNjE0NTQ2OA==&mid=2651229147&idx=1&sn=272dc975d41cddc3db5797434e6647e4
http://mp.weixin.qq.com/s?__biz=MzIyNjE0NTQ2OA==&mid=2651229147&idx=1&sn=272dc975d41cddc3db5797434e6647e4
2016年全球数据泄露成本调研
http://www.aqniu.com/industry/17871.html
http://www.aqniu.com/industry/17871.html
NewSky吴志雄:年过四十他选择在美国创业
https://mp.weixin.qq.com/s?__biz=MzIzMTAzNzUxMQ==&mid=2652874547&idx=1&sn=06f09402c3f2244d0201828bda19a047&scene=1&srcid=0722mfSqm
https://mp.weixin.qq.com/s?__biz=MzIzMTAzNzUxMQ==&mid=2652874547&idx=1&sn=06f09402c3f2244d0201828bda19a047&scene=1&srcid=0722mfSqm
WikiLeaks 公开30万封土耳其政府邮件
http://www.solidot.org/story?sid=49011
http://www.solidot.org/story?sid=49011
安全技术
乌云知识库drops全站博文
http://pan.baidu.com/s/1o7WQT4m
http://pan.baidu.com/s/1o7WQT4m
CVE-2015-3864 Metasploit Module
https://asciinema.org/a/8jlbdq006wsnkqewvcaf05wva
https://asciinema.org/a/8jlbdq006wsnkqewvcaf05wva
干货-信息安全甲方乙方理解和职业群岗位脑图
https://www.hackfun.org/learnrecords/information-security-occupational-group-mind-map.html
https://www.hackfun.org/learnrecords/information-security-occupational-group-mind-map.html
APKiD: Android Application Identifier for Packers, Protectors, Obfuscators
https://github.com/rednaga/APKiD
https://github.com/rednaga/APKiD
CuteMarkEd – 朴素 Markdown 本地编辑器
http://cloose.github.io/CuteMarkEd/
http://cloose.github.io/CuteMarkEd/
Diaphora, a Free and Open Source program diffing tool
https://github.com/joxeankoret/diaphora
https://github.com/joxeankoret/diaphora
Bug Bounty 獎金獵人甘苦談 - 那些年我回報過的漏洞
https://speakerdeck.com/p8361/bug-bounty-jiang-jin-lie-ren-gan-ku-tan-na-xie-nian-wo-hui-bao-guo-de-lou-dong
https://speakerdeck.com/p8361/bug-bounty-jiang-jin-lie-ren-gan-ku-tan-na-xie-nian-wo-hui-bao-guo-de-lou-dong
Hackode Android penetration tester
http://www.kalitut.com/2015/11/hackode-android-penetration-tester.html
http://www.kalitut.com/2015/11/hackode-android-penetration-tester.html
Redis Getshell自动化实践之cron
http://www.cdxy.me/vuln/redis-getshell-cron/
http://www.cdxy.me/vuln/redis-getshell-cron/
Web服务器在外网能裸奔多久?
https://mp.weixin.qq.com/s?__biz=MjM5NzA1MTcyMA==&mid=2651161183&idx=3&sn=3552b18d23f8af71feee0fffe4305ce1
https://mp.weixin.qq.com/s?__biz=MjM5NzA1MTcyMA==&mid=2651161183&idx=3&sn=3552b18d23f8af71feee0fffe4305ce1
ChineseWordSegmentation:无需语料库的中文分词
https://github.com/Moonshile/ChineseWordSegmentation
https://github.com/Moonshile/ChineseWordSegmentation
知名商业软件“喂养”病毒产业链:“Toxik”病毒追踪
http://www.freebuf.com/articles/system/109112.html
http://www.freebuf.com/articles/system/109112.html
WebShell: Web端WebShell管理器
https://github.com/guillotines/WebShell
https://github.com/guillotines/WebShell
scanner: 网站漏洞扫描平台
https://github.com/yinzhixin/scanner
https://github.com/yinzhixin/scanner
advanced-methods-to-detect-advanced-cyber-attacks-series-introduction-and-previe
http://www.novetta.com/2014/10/advanced-methods-to-detect-advanced-cyber-attacks-series-introduction-and-preview/
http://www.novetta.com/2014/10/advanced-methods-to-detect-advanced-cyber-attacks-series-introduction-and-preview/
Zulu: The Zulu fuzzer
https://github.com/nccgroup/Zulu
https://github.com/nccgroup/Zulu
Fuzzing with AFL is an Art
http://moyix.blogspot.jp/2016/07/fuzzing-with-afl-is-an-art.html
http://moyix.blogspot.jp/2016/07/fuzzing-with-afl-is-an-art.html
Redis Getshell自动化实践之SSH key
http://www.cdxy.me/vuln/redis-getshell-ssh-key/
http://www.cdxy.me/vuln/redis-getshell-ssh-key/
Analysis of CVE-2016-4203 - Adobe Acrobat and Reader CoolType Handling
https://blog.fortinet.com/2016/07/20/analysis-of-cve-2016-4203-adobe-acrobat-and-reader-cooltype-handling-heap-overflow-vulnerability
https://blog.fortinet.com/2016/07/20/analysis-of-cve-2016-4203-adobe-acrobat-and-reader-cooltype-handling-heap-overflow-vulnerability
Introduction to Windows shellcode development – Part 3 – Security Café
https://securitycafe.ro/2016/02/15/introduction-to-windows-shellcode-development-part-3/
https://securitycafe.ro/2016/02/15/introduction-to-windows-shellcode-development-part-3/
redis的导入导出需要特别注意的地方
http://sery.blog.51cto.com/10037/1828014
http://sery.blog.51cto.com/10037/1828014
Introduction to Windows shellcode development – Part 1 – Security Café
https://securitycafe.ro/2015/10/30/introduction-to-windows-shellcode-development-part1/
https://securitycafe.ro/2015/10/30/introduction-to-windows-shellcode-development-part1/
Redis Getshell自动化实践之webshell
http://www.cdxy.me/vuln/redis-getshell%e8%87%aa%e5%8a%a8%e5%8c%96%e5%ae%9e%e8%b7%b5%e4%b9%8bwebshell/
http://www.cdxy.me/vuln/redis-getshell%e8%87%aa%e5%8a%a8%e5%8c%96%e5%ae%9e%e8%b7%b5%e4%b9%8bwebshell/
Introduction to Windows shellcode development – Part 2 – Security Café
https://securitycafe.ro/2015/12/14/introduction-to-windows-shellcode-development-part-2/
https://securitycafe.ro/2015/12/14/introduction-to-windows-shellcode-development-part-2/
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第125期)
