SecWiki周刊(第140期)
2016/10/31-2016/11/06
安全资讯
《见证》特别奉献 四集纪录片《键盘上的幽灵》
http://tv.cctv.com/lm/jianzheng/2016/jpyl/index.shtml?from=timeline&isappinstalled=0
http://tv.cctv.com/lm/jianzheng/2016/jpyl/index.shtml?from=timeline&isappinstalled=0
Protecting your organisation from ransomware
https://www.ncsc.gov.uk/guidance/protecting-your-organisation-ransomware
https://www.ncsc.gov.uk/guidance/protecting-your-organisation-ransomware
全球网安资讯榜 一周回顾(2016年11月第1周)
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655294560&idx=1&sn=1de7cee29dcce15038fb8a762263e32a&chksm=f02fe82bc758613dfb4b7aab1cade080f3c309512b90173c42fe8e0a52a9af17b57a4f35ac12&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655294560&idx=1&sn=1de7cee29dcce15038fb8a762263e32a&chksm=f02fe82bc758613dfb4b7aab1cade080f3c309512b90173c42fe8e0a52a9af17b57a4f35ac12&scene=0#rd
nominal delivery draft, UNC Charlotte,Prediction and The Future of Cybersecurit
http://geer.tinho.net/geer.uncc.5x16.txt
http://geer.tinho.net/geer.uncc.5x16.txt
骗取天猫7亿积分套现六百万,8人被南通检方指控犯诈骗罪
http://www.thepaper.cn/newsDetail_forward_1552051
http://www.thepaper.cn/newsDetail_forward_1552051
DNC 泄露的数据可视化界面展示
https://clinton.media.mit.edu/
https://clinton.media.mit.edu/
关于公布2016年第一批CNVD技术组成员单位资格的公告
http://www.cnvd.org.cn/webinfo/show/3963
http://www.cnvd.org.cn/webinfo/show/3963
2016 JSRC 安全乌托邦-成都站(附PPT)
http://www.mottoin.com/91285.html
http://www.mottoin.com/91285.html
New DMCA Exemptions Give White Hats License To Hack Cars, Medical Devices
http://www.darkreading.com/vulnerabilities---threats/new-dmca-exemptions-give-white-hats-license-to-hack-cars-medical-devices/d/d-id/1327376
http://www.darkreading.com/vulnerabilities---threats/new-dmca-exemptions-give-white-hats-license-to-hack-cars-medical-devices/d/d-id/1327376
南洋股份并购天融信成功过会,揭秘新三板最大“跨板”并购案
http://mp.weixin.qq.com/s?__biz=MjM5MDk0NTA0OA==&mid=2650048551&idx=1&sn=5a33b4bb9874d74a77e069f4d4d3567d&chksm=bebd325089cabb46a2bae7eed126ae49c1981863bbe0cc82bd0bfe600883475fecb25f22243e&mpshare=1&scene=1&srcid=1104WSfNzjCqecfzeOu3DZ1z#rd
http://mp.weixin.qq.com/s?__biz=MjM5MDk0NTA0OA==&mid=2650048551&idx=1&sn=5a33b4bb9874d74a77e069f4d4d3567d&chksm=bebd325089cabb46a2bae7eed126ae49c1981863bbe0cc82bd0bfe600883475fecb25f22243e&mpshare=1&scene=1&srcid=1104WSfNzjCqecfzeOu3DZ1z#rd
全球25家最值得关注的新兴安全厂商
http://www.freebuf.com/articles/security-management/118083.html
http://www.freebuf.com/articles/security-management/118083.html
数据造假黑产技术帖:如何给微信公众号、微博大V、直播网红刷量
http://mp.weixin.qq.com/s?__biz=MTQzMjE1NjQwMQ==&mid=2655537335&idx=1&sn=63991e18f69eed0dfcee4795ab6c5acf&chksm=66dfe72951a86e3f4bb01a23cba5fbe142b3533ad7fbde576045d40229abbd84f3ee037fb5c0&mpshare=1&scene=1&srcid=1101Y97ZFri81p8M5O9t6qDc#rd
http://mp.weixin.qq.com/s?__biz=MTQzMjE1NjQwMQ==&mid=2655537335&idx=1&sn=63991e18f69eed0dfcee4795ab6c5acf&chksm=66dfe72951a86e3f4bb01a23cba5fbe142b3533ad7fbde576045d40229abbd84f3ee037fb5c0&mpshare=1&scene=1&srcid=1101Y97ZFri81p8M5O9t6qDc#rd
黑客小说 杀手(第八章 秘密 下)
http://www.jianshu.com/p/a30d2d0309b0
http://www.jianshu.com/p/a30d2d0309b0
公民实验室逆向工程中国直播软件的关键词名单
http://www.solidot.org/story?sid=50214
http://www.solidot.org/story?sid=50214
黑客小说:杀手 (第七章 秘密 上)
http://www.jianshu.com/p/50c74c598ed9
http://www.jianshu.com/p/50c74c598ed9
安全技术
用户行为分析(UBA)实战:如何为每个用户绘制准确的画像
http://mp.weixin.qq.com/s?__biz=MzA4NTM4NjUzMw==&mid=2649485392&idx=1&sn=187cea8eeac393224279910ad8dda904&chksm=87c7e41ab0b06d0c7ca7ea3905025f2fbd7595da82bd01c90d5a127e5b175b589b700a494c63&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzA4NTM4NjUzMw==&mid=2649485392&idx=1&sn=187cea8eeac393224279910ad8dda904&chksm=87c7e41ab0b06d0c7ca7ea3905025f2fbd7595da82bd01c90d5a127e5b175b589b700a494c63&scene=0#rd
Lookout released a 42 page technical document explaining Pegasus (3 iOS vulns)
https://info.lookout.com/rs/051-ESQ-475/images/pegasus-exploits-technical-details.pdf
https://info.lookout.com/rs/051-ESQ-475/images/pegasus-exploits-technical-details.pdf
Memcached 命令执行漏洞(CVE-2016-8704、CVE-2016-8705、CVE-2016-8706)
http://paper.seebug.org/95/
http://paper.seebug.org/95/
SSC峰会小刀议题《webshell的进化史》
http://m.youku.com/video/id_XMTc3OTc4ODgzNg==.html?refer=pc-sns-1
http://m.youku.com/video/id_XMTc3OTc4ODgzNg==.html?refer=pc-sns-1
Java反序列化工具 — Java Deserialization Exp Tools
https://www.webshell.cc/6238.html
https://www.webshell.cc/6238.html
AlienVault - Open Threat Exchange
https://otx.alienvault.com/dashboard/new/
https://otx.alienvault.com/dashboard/new/
ProxyBroker: 开源代理抓取及验证程序
http://proxybroker.readthedocs.io/en/latest/
http://proxybroker.readthedocs.io/en/latest/
IoTSeeker: scan a network for specific types of IoT devices
https://github.com/rapid7/IoTSeeker
https://github.com/rapid7/IoTSeeker
Black Hat Europe 2016 Slides
https://www.blackhat.com/eu-16/briefings.html
https://www.blackhat.com/eu-16/briefings.html
Android逆向修改内核绕过反调试
http://www.whitecell-club.org/?p=1442
http://www.whitecell-club.org/?p=1442
同源方法执行漏洞挖掘
http://www.mottoin.com/91299.html
http://www.mottoin.com/91299.html
多工具多用户HTTP代理
http://www.mottoin.com/91204.html
http://www.mottoin.com/91204.html
中国最大的Webshell后门箱子调查,所有公开大马全军覆没
http://www.freebuf.com/news/topnews/118424.html?from=singlemessage&isappinstalled=0#10006-weixin-1-52626-6b3bffd01fdde4900130bc5a2751b6d1
http://www.freebuf.com/news/topnews/118424.html?from=singlemessage&isappinstalled=0#10006-weixin-1-52626-6b3bffd01fdde4900130bc5a2751b6d1
Dirty COW - (CVE-2016-5195) - Docker Container Escape
https://blog.paranoidsoftware.com/dirty-cow-cve-2016-5195-docker-container-escape/
https://blog.paranoidsoftware.com/dirty-cow-cve-2016-5195-docker-container-escape/
Read files on application server, leads to RCE of GitLab
https://hackerone.com/reports/178152
https://hackerone.com/reports/178152
IoT: 物联网安全测试经验总结
http://www.mottoin.com/91246.html
http://www.mottoin.com/91246.html
前端黑魔法:使用JS检测远程用户的杀毒软件
http://www.mottoin.com/91264.html
http://www.mottoin.com/91264.html
Backslash Powered Scanning: Hunting Unknown Vulnerability Classes
http://blog.portswigger.net/2016/11/backslash-powered-scanning-hunting.html
http://blog.portswigger.net/2016/11/backslash-powered-scanning-hunting.html
wix.com的Dom-Basic XSS漏洞
http://www.mottoin.com/91302.html
http://www.mottoin.com/91302.html
Twitter开源DistributedLog,对比Kafka和雅虎Pulsar
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994591&idx=1&sn=7e0d837ab28d27df3a00a388e2f13140&chksm=bdbf0fcc8ac886da65b0aca74b1c4f04eb9c309a70da107fb8091b1788be67784b64a5a33f85&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994591&idx=1&sn=7e0d837ab28d27df3a00a388e2f13140&chksm=bdbf0fcc8ac886da65b0aca74b1c4f04eb9c309a70da107fb8091b1788be67784b64a5a33f85&scene=0#rd
2016最流行的Linux发行版渗透测试系统
http://www.mottoin.com/91202.html
http://www.mottoin.com/91202.html
Rootkit analysis Use case on HideDRV[PDF]
http://www.sekoia.fr/blog/wp-content/uploads/2016/10/Rootkit-analysis-Use-case-on-HIDEDRV-v1.6.pdf
http://www.sekoia.fr/blog/wp-content/uploads/2016/10/Rootkit-analysis-Use-case-on-HIDEDRV-v1.6.pdf
MySQL-Maria-Percona-PrivEscRace-CVE-2016-6663-5616-Exploit
http://legalhackers.com/advisories/MySQL-Maria-Percona-PrivEscRace-CVE-2016-6663-5616-Exploit.html
http://legalhackers.com/advisories/MySQL-Maria-Percona-PrivEscRace-CVE-2016-6663-5616-Exploit.html
En Route with Sednit Part 1: Approaching the Target[PDF]
http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf
http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf
BadUSB小尝试
http://www.mottoin.com/91187.html
http://www.mottoin.com/91187.html
安天独家深度曝光分析方程式组织多平台恶意代码武器
http://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=2650170101&idx=1&sn=714546c757db8291d52b6a4332c364a4&chksm=beb9c1c789ce48d1d6a96ed51b2506feab47c344b50461e7a4f72b19d89879dc113669d47a33&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=2650170101&idx=1&sn=714546c757db8291d52b6a4332c364a4&chksm=beb9c1c789ce48d1d6a96ed51b2506feab47c344b50461e7a4f72b19d89879dc113669d47a33&scene=0#wechat_redirect
Spark 在反作弊聚类场景的实践
https://zhuanlan.zhihu.com/p/23385044
https://zhuanlan.zhihu.com/p/23385044
威胁情报2012-2016会议笔记
http://www.tanjiti.top/threatIntelligenceNote.html
http://www.tanjiti.top/threatIntelligenceNote.html
Joomla!用户特权提升漏洞影响范围分析:涉及全球超15000网站(含POC)
http://mp.weixin.qq.com/s?__biz=MzIwMDk0MjcwNA==&mid=2247483896&idx=1&sn=9fb542fc93d90560015993f542af7aa4&chksm=96f434e7a183bdf1e284730647d2dc8979867fcf751cec9e9aae424f363ad68e5ea9e292c74f&mpshare=1&scene=2&srcid=1101dMyuOo6GwVpH6j5YwSke&from=timeline#rd
http://mp.weixin.qq.com/s?__biz=MzIwMDk0MjcwNA==&mid=2247483896&idx=1&sn=9fb542fc93d90560015993f542af7aa4&chksm=96f434e7a183bdf1e284730647d2dc8979867fcf751cec9e9aae424f363ad68e5ea9e292c74f&mpshare=1&scene=2&srcid=1101dMyuOo6GwVpH6j5YwSke&from=timeline#rd
U.S. Army Commanders Guide to Human Intelligence (HUMINT)
https://info.publicintelligence.net/CALL-CommandersGuideHUMINT.pdf
https://info.publicintelligence.net/CALL-CommandersGuideHUMINT.pdf
GitLab application server 文件读取导致命令执行漏洞
http://www.mottoin.com/91325.html
http://www.mottoin.com/91325.html
Spark Streaming + Elasticsearch构建App异常监控平台
http://tech.meituan.com/spark-streaming-es.html
http://tech.meituan.com/spark-streaming-es.html
IPS Community Suite PHP远程代码执行漏洞分析
http://blog.nsfocus.net/ips-community-autoloaded-php-code-injection-vulnerability/
http://blog.nsfocus.net/ips-community-autoloaded-php-code-injection-vulnerability/
Appie:便携式Android渗透测试工具包
http://www.mottoin.com/91363.html
http://www.mottoin.com/91363.html
如何利用Rowhammer漏洞Root Android手机(含演示视频+Exploit源码)
http://www.freebuf.com/news/118163.html
http://www.freebuf.com/news/118163.html
Fireeye 2016 Flare-On Challenge Solutions(竞赛题目分析及答案)
https://www.fireeye.com/blog/threat-research/2016/11/2016_flare-on_challe.html
https://www.fireeye.com/blog/threat-research/2016/11/2016_flare-on_challe.html
anti-XSS: An open source XSS vulnerability scanner
https://github.com/lewangbtcc/anti-XSS
https://github.com/lewangbtcc/anti-XSS
企业需要解决的安全问题
http://www.bincker.net/?p=452
http://www.bincker.net/?p=452
关于Code Review,你必须了解的一些关键点
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994555&idx=1&sn=b196e2dfb293ec7829523011316a7e06&chksm=bdbf0f288ac8863e014eae215469f4bbc0b8e88fa286c3cd38b467348466c663415ffed0e4ca&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994555&idx=1&sn=b196e2dfb293ec7829523011316a7e06&chksm=bdbf0f288ac8863e014eae215469f4bbc0b8e88fa286c3cd38b467348466c663415ffed0e4ca&scene=0#rd
Pwn A Camera Step by Step (Web ver.)
https://ricterz.me/posts/Pwn%20A%20Camera%20Step%20by%20Step%20%28Web%20ver.%29?_=1478056015650
https://ricterz.me/posts/Pwn%20A%20Camera%20Step%20by%20Step%20%28Web%20ver.%29?_=1478056015650
Ability to access all user authentication tokens, leads to RCE of gitlab
https://hackerone.com/reports/158330
https://hackerone.com/reports/158330
An Experiment Shows How Quickly The Internet Of Things Can Be Hacked
http://www.npr.org/sections/alltechconsidered/2016/11/01/500253637/an-experiment-shows-how-quickly-the-internet-of-things-can-be-hacked
http://www.npr.org/sections/alltechconsidered/2016/11/01/500253637/an-experiment-shows-how-quickly-the-internet-of-things-can-be-hacked
Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communicatio
https://arxiv.org/pdf/1510.07563.pdf
https://arxiv.org/pdf/1510.07563.pdf
Packet Capture Generator for IDS and Regular Expression Evaluation
http://www.kitploit.com/2016/11/sniffles-packet-capture-generator-for.html?utm_source=dlvr.it&utm_medium=twitter
http://www.kitploit.com/2016/11/sniffles-packet-capture-generator-for.html?utm_source=dlvr.it&utm_medium=twitter
乌克兰电网攻击分析20161101
http://blog.nsfocus.net/wp-content/uploads/2016/11/%E4%B9%8C%E5%85%8B%E5%85%B0%E7%94%B5%E7%BD%91%E6%94%BB%E5%87%BB%E5%88%86%E6%9E%9020161101.pdf
http://blog.nsfocus.net/wp-content/uploads/2016/11/%E4%B9%8C%E5%85%8B%E5%85%B0%E7%94%B5%E7%BD%91%E6%94%BB%E5%87%BB%E5%88%86%E6%9E%9020161101.pdf
文档化身商业木马,对“盗神”的分析与溯源
http://www.freebuf.com/news/117354.html
http://www.freebuf.com/news/117354.html
OpenDoor: OWASP Directory Access scanner
https://github.com/stanislav-web/OpenDoor/
https://github.com/stanislav-web/OpenDoor/
《WebUSB API》Under Editor's Draft
https://wicg.github.io/webusb/
https://wicg.github.io/webusb/
SecWiki周刊(第139期)
https://www.sec-wiki.com/weekly/139
https://www.sec-wiki.com/weekly/139
Bypassing antivirus with a sharp syringe
https://www.exploit-db.com/docs/20420.pdf
https://www.exploit-db.com/docs/20420.pdf
Pornhub Bypasses Ad Blockers With WebSockets
http://blog.bugreplay.com/post/152579164219/pornhubdodgesadblockersusingwebsockets
http://blog.bugreplay.com/post/152579164219/pornhubdodgesadblockersusingwebsockets
awesome-adb: ADB Usage Complete / ADB 用法大全
https://github.com/mzlogin/awesome-adb
https://github.com/mzlogin/awesome-adb
The HookAds Malvertising Campaign
https://blog.malwarebytes.com/cybercrime/exploits/2016/11/the-hookads-malvertising-campaign/
https://blog.malwarebytes.com/cybercrime/exploits/2016/11/the-hookads-malvertising-campaign/
awesome-static-analysis: A curated list of static analysis tools
https://github.com/mre/awesome-static-analysis#python
https://github.com/mre/awesome-static-analysis#python
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第140期)
