SecWiki周刊(第138期)
2016/10/17-2016/10/23
安全资讯
点融秋季安全沙龙:10月30日,上海,等你。
http://www.freebuf.com/fevents/117176.html
http://www.freebuf.com/fevents/117176.html
Russia Hackers to Blame for Wikileaks Emails
http://www.esquire.com/news-politics/a49791/russian-dnc-emails-hacked/
http://www.esquire.com/news-politics/a49791/russian-dnc-emails-hacked/
被捕的NSA合同工窃取了50TB的数据
http://www.solidot.org/story?sid=50083
http://www.solidot.org/story?sid=50083
Yahoo Asks DNI to De-Classify Email Scanning Order
https://threatpost.com/yahoo-asks-dni-to-de-classify-email-scanning-order/121416/
https://threatpost.com/yahoo-asks-dni-to-de-classify-email-scanning-order/121416/
安全技术
【代码审计】对Beescms SQL注入漏洞的进一步思考
https://www.ohlinge.cn/php/beescms_login_sql.html
https://www.ohlinge.cn/php/beescms_login_sql.html
phpmyadmin 某版本任意文件包含漏洞(无需登录)分析
https://www.92aq.com/2016/08/23/phpmyadmin-arbitrary-file-include.html
https://www.92aq.com/2016/08/23/phpmyadmin-arbitrary-file-include.html
Kali教程中英文版(离线)
https://github.com/louchaooo/kali-tools-zh
https://github.com/louchaooo/kali-tools-zh
XSS跨站点脚本的介绍和代码防御
http://blog.csdn.net/qq_29277155/article/details/52895135
http://blog.csdn.net/qq_29277155/article/details/52895135
告诉你被盗的iPhone是如何一步步被黑客解锁的
http://bobao.360.cn/news/detail/3670.html
http://bobao.360.cn/news/detail/3670.html
AndroidLinker与SO加壳技术之上篇
http://yaq.qq.com/blog/14
http://yaq.qq.com/blog/14
GourdScanV2: 被动式漏洞扫描系统
https://github.com/ysrc/GourdScanV2
https://github.com/ysrc/GourdScanV2
CVE-2016-6187: Exploiting Linux kernel heap off-by-one
https://cyseclabs.com/blog/cve-2016-6187-heap-off-by-one-exploit
https://cyseclabs.com/blog/cve-2016-6187-heap-off-by-one-exploit
wooyun-wiki: wiki.wooyun.org的部分快照网页
https://github.com/l3m0n/wooyun-wiki
https://github.com/l3m0n/wooyun-wiki
Hacking JasperReports:隐藏的SHELL特征
http://www.mottoin.com/90582.html
http://www.mottoin.com/90582.html
Malicious Outlook Rules
https://silentbreaksecurity.com/malicious-outlook-rules/
https://silentbreaksecurity.com/malicious-outlook-rules/
NSA方程式组织BANANAGLEE工具集分析
http://blog.jowto.com/?p=180
http://blog.jowto.com/?p=180
【ISC 2016视频集锦】HackPwn智能家居机器人破解秀
http://bobao.360.cn/course/detail/171.html
http://bobao.360.cn/course/detail/171.html
Exploit generation and JavaScript analysis automation with WinDBG
http://theevilbit.blogspot.hk/2016/10/exploit-generation-and-javascript.html
http://theevilbit.blogspot.hk/2016/10/exploit-generation-and-javascript.html
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
http://researchcenter.paloaltonetworks.com/2016/10/unit42-palo-alto-networks-discovers-two-adobe-reader-privileged-javascript-zero-days/
http://researchcenter.paloaltonetworks.com/2016/10/unit42-palo-alto-networks-discovers-two-adobe-reader-privileged-javascript-zero-days/
“Dirty COW” Race Condition Privilege Escalation (SUID)
http://www.mottoin.com/90834.html
http://www.mottoin.com/90834.html
Vin.place and Airbag:美国机动车编号与人名查询平台
https://nullsecure.org/introducing-airbag-maltego-transforms-for-vehicles-and-addresses/
https://nullsecure.org/introducing-airbag-maltego-transforms-for-vehicles-and-addresses/
Decoders for 7ev3n ransomware
https://hshrzd.wordpress.com/2016/06/13/decoder-for-7ev3n-ransomware/
https://hshrzd.wordpress.com/2016/06/13/decoder-for-7ev3n-ransomware/
对移动用户人口属性进行预测,吸引近两千支队伍参加的Kaggle竞赛作品解析
http://mp.weixin.qq.com/s?__biz=MzA5NzkxMzg1Nw==&mid=2653161034&idx=1&sn=ead9f45c2ac9321fce34ded09e9139c7&chksm=8b493b24bc3eb2326f675e2c1d9c538cd254d2bc308b427871890cb76ab0f2e01e0756901876&mpshare=1&scene=1&srcid=1020J0Ptgy5zChZKeSXP6oH7#rd
http://mp.weixin.qq.com/s?__biz=MzA5NzkxMzg1Nw==&mid=2653161034&idx=1&sn=ead9f45c2ac9321fce34ded09e9139c7&chksm=8b493b24bc3eb2326f675e2c1d9c538cd254d2bc308b427871890cb76ab0f2e01e0756901876&mpshare=1&scene=1&srcid=1020J0Ptgy5zChZKeSXP6oH7#rd
由HITCON 2016一道Web聊一聊PHP反序列化漏洞
http://www.freebuf.com/vuls/116705.html
http://www.freebuf.com/vuls/116705.html
Spring Security OAuth RCE (CVE-2016-4977) 漏洞分析
http://paper.seebug.org/70/
http://paper.seebug.org/70/
MBRFilter:Open Source Tool to Protect Against 'Master Boot Record' Malware
http://thehackernews.com/2016/10/protect-mbr-malware.html
http://thehackernews.com/2016/10/protect-mbr-malware.html
BurpSuite插件分享:图形化重算sign和参数加解密插件
http://www.mottoin.com/90666.html
http://www.mottoin.com/90666.html
Errata Security: Some notes on today's DNS DDoS
http://blog.erratasec.com/2016/10/some-notes-on-todays-dns-ddos.html
http://blog.erratasec.com/2016/10/some-notes-on-todays-dns-ddos.html
Dirty COW (CVE-2016-5195) privilege escalation vulnerability in the Linux
https://dirtycow.ninja/
https://dirtycow.ninja/
Python 提取《釜山行》人物关系
http://www.jianshu.com/p/3bd06f8816d7#
http://www.jianshu.com/p/3bd06f8816d7#
使用 XML 内部实体绕过 Chrome 和 IE 的 XSS 过滤器
http://paper.seebug.org/80/
http://paper.seebug.org/80/
Extracting LastPass Site Credentials from Memory
https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory/
https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory/
inficere: Mac OS X rootkit - for learning purposes
https://github.com/enzolovesbacon/inficere
https://github.com/enzolovesbacon/inficere
使用sklearn做单机特征工程
https://www.52ml.net/20145.html
https://www.52ml.net/20145.html
使用sklearn进行数据挖掘
https://www.52ml.net/20158.html
https://www.52ml.net/20158.html
Windows zero-day exploit used in targeted attacks by FruityArmor APT
https://securelist.com/blog/research/76396/windows-zero-day-exploit-used-in-targeted-attacks-by-fruityarmor-apt/
https://securelist.com/blog/research/76396/windows-zero-day-exploit-used-in-targeted-attacks-by-fruityarmor-apt/
SecWiki周刊(第137期)
https://www.sec-wiki.com/weekly/137
https://www.sec-wiki.com/weekly/137
使用Spade Apk后门Hack任意Andorid手机
http://www.mottoin.com/90613.html
http://www.mottoin.com/90613.html
QQ手机浏览器“虫洞漏洞”挖掘分析全过程
http://appscan.360.cn/blog/?p=165
http://appscan.360.cn/blog/?p=165
android_vuln_poc-exp: pocs and exploits for android vulneribilities
https://github.com/jiayy/android_vuln_poc-exp
https://github.com/jiayy/android_vuln_poc-exp
An awesome list of high-quality open datasets
https://github.com/caesar0301/awesome-public-datasets
https://github.com/caesar0301/awesome-public-datasets
Human or malware? Detection of malicious Web requests
https://e-collection.library.ethz.ch/eserv.php?pid=eth:49738&dsID=eth-49738-01.pdf
https://e-collection.library.ethz.ch/eserv.php?pid=eth:49738&dsID=eth-49738-01.pdf
【公益译文】关键基础设施系统攻击的检测、关联与呈现
http://blog.nsfocus.net/detection-association-presentation-critical-infrastructure-system-attacks/
http://blog.nsfocus.net/detection-association-presentation-critical-infrastructure-system-attacks/
大量ZIO ROUTER路由器未授权访问
http://t.tips/?action=show&id=23417
http://t.tips/?action=show&id=23417
Android安全工程师-安全技能
https://www.sec-wiki.com/skill/8
https://www.sec-wiki.com/skill/8
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第138期)
