SecWiki周刊(第137期)
2016/10/10-2016/10/16
安全资讯
"网络空间安全" 重点专项 2017 年度项目申报指南
http://www.most.gov.cn/mostinfo/xinxifenlei/fgzc/gfxwj/gfxwj2016/201610/t20161013_128183.htm
http://www.most.gov.cn/mostinfo/xinxifenlei/fgzc/gfxwj/gfxwj2016/201610/t20161013_128183.htm
CNCC 人物专访 谭晓生(上)
http://m.leiphone.com/news/201610/nlOvp2QmHI6yOg5e.html%3Ffrom%3Dtimeline%26isappinstalled%3D0%26viewType%3Dweixin
http://m.leiphone.com/news/201610/nlOvp2QmHI6yOg5e.html%3Ffrom%3Dtimeline%26isappinstalled%3D0%26viewType%3Dweixin
CIA Prepping for Possible Cyber Strike Against Russia
http://www.nbcnews.com/news/us-news/cia-prepping-possible-cyber-strike-against-russia-n666636
http://www.nbcnews.com/news/us-news/cia-prepping-possible-cyber-strike-against-russia-n666636
新加坡正式公布国家网络安全策略
http://www.freebuf.com/news/116395.html
http://www.freebuf.com/news/116395.html
HackerOne CEO专访:我们正在打造全球最大的安全人才库
http://www.freebuf.com/articles/neopoints/116064.html
http://www.freebuf.com/articles/neopoints/116064.html
安全技术
ssh-audit:开源SSH服务器审计工具
http://www.mottoin.com/90572.html
http://www.mottoin.com/90572.html
TcpScanner端口存活性检测
http://thief.one/2016/10/14/TcpScanner%E7%AB%AF%E5%8F%A3%E5%AD%98%E6%B4%BB%E6%8E%A2%E6%B5%8B/
http://thief.one/2016/10/14/TcpScanner%E7%AB%AF%E5%8F%A3%E5%AD%98%E6%B4%BB%E6%8E%A2%E6%B5%8B/
windows服务器信息收集工具
http://thief.one/2016/09/04/windows%E6%9C%8D%E5%8A%A1%E5%99%A8%E4%BF%A1%E6%81%AF%E6%94%B6%E9%9B%86%E5%B7%A5%E5%85%B7/
http://thief.one/2016/09/04/windows%E6%9C%8D%E5%8A%A1%E5%99%A8%E4%BF%A1%E6%81%AF%E6%94%B6%E9%9B%86%E5%B7%A5%E5%85%B7/
从甲方的角度谈谈WAF测试方法--part2
http://www.lewisec.com/2016/10/10/%E4%BB%8E%E7%94%B2%E6%96%B9%E7%9A%84%E8%A7%92%E5%BA%A6%E8%B0%88%E8%B0%88WAF%E6%B5%8B%E8%AF%95%E6%96%B9%E6%B3%95-part2/
http://www.lewisec.com/2016/10/10/%E4%BB%8E%E7%94%B2%E6%96%B9%E7%9A%84%E8%A7%92%E5%BA%A6%E8%B0%88%E8%B0%88WAF%E6%B5%8B%E8%AF%95%E6%96%B9%E6%B3%95-part2/
基于御安全APK加固的游戏反外挂方案
http://yaq.qq.com/blog/11
http://yaq.qq.com/blog/11
起点:如何成为一名黑客?
http://suip.cc/d/1--
http://suip.cc/d/1--
Black Hat USA 2016 Video
https://www.youtube.com/playlist?list=PLbHqJuIbKd_6jPpl9pnXGUmUj8gtlWony
https://www.youtube.com/playlist?list=PLbHqJuIbKd_6jPpl9pnXGUmUj8gtlWony
Android安全之WebViewUXSS漏洞
http://yaq.qq.com/blog/12
http://yaq.qq.com/blog/12
BurpSuite中的安全测试插件推荐
http://www.mottoin.com/90188.html
http://www.mottoin.com/90188.html
Android安全之Https中间人攻击漏洞
http://yaq.qq.com/blog/13
http://yaq.qq.com/blog/13
OJ/gobuster: Directory/file & DNS busting tool written in Go
https://github.com/OJ/gobuster
https://github.com/OJ/gobuster
SQLMAP源码分析—第一讲:架构篇
http://v.youku.com/v_show/id_XMTc1NDI5NjA0OA==.html?refer=eco-h5-wbtb&tuid=UNTgxMDQzNzI4
http://v.youku.com/v_show/id_XMTc1NDI5NjA0OA==.html?refer=eco-h5-wbtb&tuid=UNTgxMDQzNzI4
基于linux嵌入式固件动态分析-FIRMADYNE
http://www.bincker.net/?p=429
http://www.bincker.net/?p=429
How to perform real time Text Analytics on Twitter streaming data in SAS ESP
http://blogs.sas.com/content/sgf/2016/10/05/how-to-perform-real-time-text-analytics-on-twitter-streaming-data-in-sas-esp/
http://blogs.sas.com/content/sgf/2016/10/05/how-to-perform-real-time-text-analytics-on-twitter-streaming-data-in-sas-esp/
解析Mimikatz日志文件
http://www.mottoin.com/90550.html
http://www.mottoin.com/90550.html
使用随机用户代理进行WAF测试
http://www.mottoin.com/90178.html
http://www.mottoin.com/90178.html
利用python进行识别相似图片(二)
https://segmentfault.com/a/1190000004500523?_ea=630748
https://segmentfault.com/a/1190000004500523?_ea=630748
ShinoBOT – Malware Attack Simulator Framework
http://www.sectechno.com/shinobot-malware-attack-simulator-framework/
http://www.sectechno.com/shinobot-malware-attack-simulator-framework/
【Electronic Warfare Payloads of UAVs】无人机电子战载荷的新发展
http://mp.weixin.qq.com/s?__biz=MzAwMDE3MzgxMQ==&mid=2654113135&idx=1&sn=ca97f2f7a1266217308650abac3ce48d&chksm=812adef3b65d57e5dc69ccade33475fccf45ecc3c20ba44a8d8ffaefd3b263203d98a4c3190c&mpshare=1&scene=1&srcid=1016YGQhMu5mAYVzrC4OnUnv#rd
http://mp.weixin.qq.com/s?__biz=MzAwMDE3MzgxMQ==&mid=2654113135&idx=1&sn=ca97f2f7a1266217308650abac3ce48d&chksm=812adef3b65d57e5dc69ccade33475fccf45ecc3c20ba44a8d8ffaefd3b263203d98a4c3190c&mpshare=1&scene=1&srcid=1016YGQhMu5mAYVzrC4OnUnv#rd
如何利用配置错误的SUID获取root权限并提权
http://www.mottoin.com/90304.html
http://www.mottoin.com/90304.html
BBQSQL:SQL注入利用工具
http://www.mottoin.com/90324.html
http://www.mottoin.com/90324.html
Domain Generation Algorithms
https://blog.opendns.com/2016/10/10/domain-generation-algorithms-effective/
https://blog.opendns.com/2016/10/10/domain-generation-algorithms-effective/
利用python进行识别相似图片(一)
https://segmentfault.com/a/1190000004467183
https://segmentfault.com/a/1190000004467183
Github just censored my research data
http://gwillem.gitlab.io/2016/10/14/github-censored-research-data/
http://gwillem.gitlab.io/2016/10/14/github-censored-research-data/
CVE-2016-4977: RCE in Spring Security Oauth漏洞分析
http://www.mottoin.com/90527.html
http://www.mottoin.com/90527.html
attackercan/regexp-security-cheatsheet
https://github.com/attackercan/regexp-security-cheatsheet
https://github.com/attackercan/regexp-security-cheatsheet
2016绿盟科技网络视频监控系统安全报告
http://blog.nsfocus.net/wp-content/uploads/2016/10/2016_NSFOCUS_Network_Video_Surveillance_System_Security_Report_1014.pdf
http://blog.nsfocus.net/wp-content/uploads/2016/10/2016_NSFOCUS_Network_Video_Surveillance_System_Security_Report_1014.pdf
打造不被检测的Metasploit WAR
http://www.mottoin.com/90302.html
http://www.mottoin.com/90302.html
通过Win10PE SE ISO或WIM实现持久化后门
http://www.mottoin.com/90351.html
http://www.mottoin.com/90351.html
System Security Circus v2.0
http://s3.eurecom.fr/~balzarot/notes/top4/
http://s3.eurecom.fr/~balzarot/notes/top4/
玩一场漏洞游戏:网易开源Pomelo游戏服务端框架远程命令执行
http://www.mottoin.com/90444.html
http://www.mottoin.com/90444.html
PostScript语言安全研究(一)ImageMagick新漏洞分析
http://drops.wiki/index.php/2016/10/15/postscript/
http://drops.wiki/index.php/2016/10/15/postscript/
基于Python的WebServer
http://thief.one/2016/09/14/%E5%9F%BA%E4%BA%8EPython%E7%9A%84WebServer/
http://thief.one/2016/09/14/%E5%9F%BA%E4%BA%8EPython%E7%9A%84WebServer/
黑帽SEO之网页劫持
http://thief.one/2016/10/12/%E9%BB%91%E5%B8%BDSEO%E4%B9%8B%E7%BD%91%E9%A1%B5%E5%8A%AB%E6%8C%81/
http://thief.one/2016/10/12/%E9%BB%91%E5%B8%BDSEO%E4%B9%8B%E7%BD%91%E9%A1%B5%E5%8A%AB%E6%8C%81/
从活动目录中Dump NTDS.dit文件
http://www.mottoin.com/90278.html
http://www.mottoin.com/90278.html
基于浏览器的指纹识别: 影响和缓解措施
http://paper.seebug.org/64/
http://paper.seebug.org/64/
细数那些鲜为人知的后缀名隐藏技巧
http://www.mottoin.com/90109.html
http://www.mottoin.com/90109.html
2016CCF大数据与计算智能大赛
http://www.wid.org.cn/data/science/activity/ccf2016/index.html
http://www.wid.org.cn/data/science/activity/ccf2016/index.html
黑产白皮书 DDoS 篇——乌云笼罩下的产业百态
http://www.freebuf.com/articles/network/116340.html
http://www.freebuf.com/articles/network/116340.html
使用Python实现指定Twitter用户Followers收集
http://www.mottoin.com/90327.html
http://www.mottoin.com/90327.html
a series tutorial for linux exploit development to newbie
https://github.com/hardenedlinux/linux-exploit-development-tutorial
https://github.com/hardenedlinux/linux-exploit-development-tutorial
逆向智能咖啡机协议实现终端控制
http://www.mottoin.com/90168.html
http://www.mottoin.com/90168.html
DMA attacking over USB-C and Thunderbolt 3
http://blog.frizk.net/2016/10/dma-attacking-over-usb-c-and.html
http://blog.frizk.net/2016/10/dma-attacking-over-usb-c-and.html
HITCON 2016 Web 总结
http://0x48.pw/2016/10/14/0x24/
http://0x48.pw/2016/10/14/0x24/
PHP Code Injection Analysis
http://www.mottoin.com/90370.html
http://www.mottoin.com/90370.html
PyCmd 加密隐形木马
http://thief.one/2016/09/18/PyCmd-%E5%8A%A0%E5%AF%86%E9%9A%90%E5%BD%A2%E6%9C%A8%E9%A9%AC/
http://thief.one/2016/09/18/PyCmd-%E5%8A%A0%E5%AF%86%E9%9A%90%E5%BD%A2%E6%9C%A8%E9%A9%AC/
谈一谈SQLite Load_Extension的妙用
http://www.mottoin.com/90266.html
http://www.mottoin.com/90266.html
spade: APK backdoor embedder
https://github.com/suraj-root/spade
https://github.com/suraj-root/spade
Teaching Machines Security: Identifying Botnet Panels
https://blog.cylance.com/teaching-machines-security-identifying-botnet-panels
https://blog.cylance.com/teaching-machines-security-identifying-botnet-panels
通过远程资源注入的xss利用分析
http://www.mottoin.com/90126.html
http://www.mottoin.com/90126.html
Django CSRF 防护绕过漏洞分析
https://virusdefender.net/index.php/archives/753/
https://virusdefender.net/index.php/archives/753/
orangetw: Collection of CTF Web challenges
https://github.com/orangetw/My-CTF-Web-Challenges
https://github.com/orangetw/My-CTF-Web-Challenges
从老漏洞到新漏洞—iMessage 0day(CVE-2016-1843)挖掘实录
http://blog.knownsec.com/2016/10/imessage-0day_cve-2016-1843/
http://blog.knownsec.com/2016/10/imessage-0day_cve-2016-1843/
使用Nginx+uWSGI+Supervisor部署Flask应用
http://www.bibodeng.com/?post=190
http://www.bibodeng.com/?post=190
SecWiki周刊(第136期)
https://www.sec-wiki.com/weekly/136
https://www.sec-wiki.com/weekly/136
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第137期)
