SecWiki周刊(第141期)
2016/11/07-2016/11/13
安全资讯
瑞士电信公司遭黑客攻击泄露瑞士全国30000+基础设施
http://www.mottoin.com/91457.html
http://www.mottoin.com/91457.html
OWASP ModSecurity Core Rule Set Version 3.0.0 Released
https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/2016-November/002265.html
https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/2016-November/002265.html
11月安卓安全补丁风险评估
http://appscan.360.cn/blog/?p=171
http://appscan.360.cn/blog/?p=171
Google阻止一起利用恶意AdSense 广告的攻击
http://www.solidot.org/story?sid=50302
http://www.solidot.org/story?sid=50302
加拿大“ODAC”监控计划曝光 已非法保留十年的元数据
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655294562&idx=1&sn=aebb731a26903372f145da1a39d6f31d&chksm=f02fe829c758613f49b51717075785d72f7f860a8cc15d4f62857ca6177d4647c5e2e68e9785&mpshare=1&scene=1&srcid=11054pakXaFJDsMdVp5MhkFK#rd
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655294562&idx=1&sn=aebb731a26903372f145da1a39d6f31d&chksm=f02fe829c758613f49b51717075785d72f7f860a8cc15d4f62857ca6177d4647c5e2e68e9785&mpshare=1&scene=1&srcid=11054pakXaFJDsMdVp5MhkFK#rd
《工业控制系统信息安全防护指南》解读
http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057656/n3057660/c5346569/content.html?from=timeline&isappinstalled=0
http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057656/n3057660/c5346569/content.html?from=timeline&isappinstalled=0
《网络安全法》草案三次审议稿(全文)
https://www.easyaq.com/newsdetail/id/895852407.shtml
https://www.easyaq.com/newsdetail/id/895852407.shtml
Heimdall Open-Source PHP Ransomware Targets Web Servers
http://www.bleepingcomputer.com/news/security/heimdall-open-source-php-ransomware-targets-web-servers/
http://www.bleepingcomputer.com/news/security/heimdall-open-source-php-ransomware-targets-web-servers/
Russian Intel Bots Are Boosting Infowars Alt-Right Twitter Accounts For Trump
http://heatst.com/world/russian-intel-bots-are-boosting-infowars-alt-right-twitter-accounts-for-trump/
http://heatst.com/world/russian-intel-bots-are-boosting-infowars-alt-right-twitter-accounts-for-trump/
CSS 2016 安全盛会:量子通信、数字空间、认知安全
http://mp.weixin.qq.com/s?__biz=MzIzMTAzNzUxMQ==&mid=2652876120&idx=1&sn=4cbfe9fa0c5bc5c39bad1560ed03b9cd&chksm=f3414270c436cb66d4b9d62b83ef056c74e01dd3c8734d7678cc56046fdfc67d6be9cdf2c9d1&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzIzMTAzNzUxMQ==&mid=2652876120&idx=1&sn=4cbfe9fa0c5bc5c39bad1560ed03b9cd&chksm=f3414270c436cb66d4b9d62b83ef056c74e01dd3c8734d7678cc56046fdfc67d6be9cdf2c9d1&scene=0#rd
阿桑奇惊天指控 希拉莉与IS同一金主
http://dailynews.sina.com/gb/news/int/kwongwah/20161105/22397593710.html
http://dailynews.sina.com/gb/news/int/kwongwah/20161105/22397593710.html
特朗普上台后必须考虑的10大关键网络安全问题
http://www.mottoin.com/91742.html
http://www.mottoin.com/91742.html
DTCC调查显示:网络威胁已经成为全球金融系统排名第一的风险
http://www.mottoin.com/91757.html
http://www.mottoin.com/91757.html
美国联邦调查局是如何在8天内检查完65万封电子邮件的
http://www.mottoin.com/91467.html
http://www.mottoin.com/91467.html
黑客小说 杀手(第九章 恶作剧)
http://www.jianshu.com/p/097d82a208f1
http://www.jianshu.com/p/097d82a208f1
网络安全法来了,对个人和企业有哪些影响
http://news.xinhuanet.com/legal/2016-11/10/c_1119887226.htm
http://news.xinhuanet.com/legal/2016-11/10/c_1119887226.htm
GCHQ wants internet providers to rewrite systems to block hackers
http://www.telegraph.co.uk/technology/2016/11/05/gchq-wants-internet-providers-to-rewrite-systems-to-block-hacker/
http://www.telegraph.co.uk/technology/2016/11/05/gchq-wants-internet-providers-to-rewrite-systems-to-block-hacker/
安全技术
CCS 2016 安全顶级会议视频
https://www.youtube.com/channel/UCUuxpXcE3S0Uu14JIEGn5vA
https://www.youtube.com/channel/UCUuxpXcE3S0Uu14JIEGn5vA
CTF常见php猥琐小段代码审计
https://github.com/louchaooo/louchaooo.github.io/issues/20
https://github.com/louchaooo/louchaooo.github.io/issues/20
F-Scrack: 一款Python编写的轻量级弱口令检测脚本
https://github.com/ysrc/F-Scrack
https://github.com/ysrc/F-Scrack
使用IMA扩展Linux可执行日志记录
http://www.mottoin.com/91717.html
http://www.mottoin.com/91717.html
Android 应用重打包检测的新姿势
http://securitygossip.com/blog/2016/11/07/2016-11-07/
http://securitygossip.com/blog/2016/11/07/2016-11-07/
IoT Goes Nuclear: Creating a ZigBee Chain Reaction[PDF]
http://iotworm.eyalro.net/iotworm.pdf
http://iotworm.eyalro.net/iotworm.pdf
WiFi-Based IMSI Catcher
https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf
https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf
带你走进维也纳版的CCS2016(现场报告点评一)
http://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652306979&idx=1&sn=c0be042daccf25bde617c0bad4c53594&chksm=8bc563adbcb2eabbb882c08281d9f4fecaa8061dd87a8766d373ad2b7f66a08313befb9cca5a&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652306979&idx=1&sn=c0be042daccf25bde617c0bad4c53594&chksm=8bc563adbcb2eabbb882c08281d9f4fecaa8061dd87a8766d373ad2b7f66a08313befb9cca5a&scene=0#rd
geoip-attack-map:Cyber Security GeoIP Attack Map Visualization
https://github.com/matcmay/geoip-attack-map
https://github.com/matcmay/geoip-attack-map
物联网僵尸Mirai源码分析和沙箱运行演示
http://www.freebuf.com/articles/network/119403.html
http://www.freebuf.com/articles/network/119403.html
云计算Docker虚拟化公益大讲坛
http://list.youku.com/albumlist/show?id=23813235&ascending=1&page=1
http://list.youku.com/albumlist/show?id=23813235&ascending=1&page=1
PhishFinder: Hook, Line and Sinker 自动化分析钓鱼网站
https://blog.opendns.com/2016/11/11/phishfinder-hook-line-sinker/
https://blog.opendns.com/2016/11/11/phishfinder-hook-line-sinker/
【公益译文】威胁情报的定义及使用
http://blog.nsfocus.net/threat-intelligence-definition/
http://blog.nsfocus.net/threat-intelligence-definition/
使用sklearn做单机特征工程
http://www.cnblogs.com/jasonfreak/p/5448385.html
http://www.cnblogs.com/jasonfreak/p/5448385.html
Collective Intelligence Framework
http://csirtgadgets.org/
http://csirtgadgets.org/
urlwatch: A tool for monitoring webpages for updates
https://github.com/thp/urlwatch
https://github.com/thp/urlwatch
Clever Gmail Hack Let Attackers Take Over Accounts
https://threatpost.com/clever-gmail-hack-let-attackers-take-over-accounts/121818/
https://threatpost.com/clever-gmail-hack-let-attackers-take-over-accounts/121818/
spaCy: Industrial-strength Natural Language Processing (NLP) with Python
https://github.com/explosion/spaCy
https://github.com/explosion/spaCy
Bypass Imperva by confusing HTTP Pollution Normalization Engine
http://seclists.org/fulldisclosure/2016/Nov/22?utm_source=feedburner&utm_medium=twitter&utm_campaign=Feed%3A+seclists%2FFullDisclosure+%28Full+Disclosure%29
http://seclists.org/fulldisclosure/2016/Nov/22?utm_source=feedburner&utm_medium=twitter&utm_campaign=Feed%3A+seclists%2FFullDisclosure+%28Full+Disclosure%29
Nathan:Android安全测试模拟器
http://www.mottoin.com/91660.html
http://www.mottoin.com/91660.html
BlackNurse Denial of Service Attack
http://www.netresec.com/?page=Blog&month=2016-11&post=BlackNurse-Denial-of-Service-Attack
http://www.netresec.com/?page=Blog&month=2016-11&post=BlackNurse-Denial-of-Service-Attack
Tplmap:一个自动化的服务端模板注射攻击检测和漏洞利用工具
http://www.mottoin.com/91727.html
http://www.mottoin.com/91727.html
Build Your Own PwnPhone
https://n0where.net/build-your-own-pwnphone/
https://n0where.net/build-your-own-pwnphone/
打造免杀JScript
http://www.mottoin.com/91459.html
http://www.mottoin.com/91459.html
第四届通信网络安全知识技能竞赛心得与部分writeup
http://www.mottoin.com/91586.html
http://www.mottoin.com/91586.html
使用浏览器的计算力,对抗密码破解
https://www.cnblogs.com/index-html/p/frontend_kdf.html
https://www.cnblogs.com/index-html/p/frontend_kdf.html
Gmail帐号劫持漏洞
http://www.mottoin.com/91406.html
http://www.mottoin.com/91406.html
Crawlic: Web recon tool (扫描临时文件、目录和子域名查询)
https://github.com/Ganapati/Crawlic
https://github.com/Ganapati/Crawlic
Cyber security geoip attack map that follows syslog and parses IPs/port numbers
https://github.com/matcmay/geoip-attack-map/
https://github.com/matcmay/geoip-attack-map/
漏洞预警:D-Link路由器远程命令执行
http://www.mottoin.com/91571.html
http://www.mottoin.com/91571.html
Disassembling a Mobile Trojan Attack
https://securelist.com/blog/research/76286/disassembling-a-mobile-trojan-attack/
https://securelist.com/blog/research/76286/disassembling-a-mobile-trojan-attack/
利用服务端请求伪造(SSRF)攻击进入内网
http://www.mottoin.com/91641.html
http://www.mottoin.com/91641.html
PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tan
https://www.volexity.com/blog/2016/11/09/powerduke-post-election-spear-phishing-campaigns-targeting-think-tanks-and-ngos/
https://www.volexity.com/blog/2016/11/09/powerduke-post-election-spear-phishing-campaigns-targeting-think-tanks-and-ngos/
Automated W3AF Scanning with Slack Alerting
http://jerrygamblin.com/2016/11/09/automated-w3af-scanning-with-slack-alerting/
http://jerrygamblin.com/2016/11/09/automated-w3af-scanning-with-slack-alerting/
利用 Python 代码实现 Web 应用的注入
http://www.mottoin.com/91638.html
http://www.mottoin.com/91638.html
MalwareTech绘制Mirai等僵尸网络地图
http://mp.weixin.qq.com/s?__biz=MzI4ODA4MTcxMA==&mid=2649549995&idx=1&sn=dd4bc55b1fc0c073141b109f9652161e&chksm=f3db9eeac4ac17fcf82823c575d65d9e93c0d70fa96dbe2f3bc12dff26fb51144417acd4b41e&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzI4ODA4MTcxMA==&mid=2649549995&idx=1&sn=dd4bc55b1fc0c073141b109f9652161e&chksm=f3db9eeac4ac17fcf82823c575d65d9e93c0d70fa96dbe2f3bc12dff26fb51144417acd4b41e&scene=0#rd
HeadlessBrowsers: Ajax爬虫技术中的无界面浏览器集合
https://github.com/dhamaniasad/HeadlessBrowsers
https://github.com/dhamaniasad/HeadlessBrowsers
产业发展新势能:读《工业控制系统信息安全防护指南》的管窥之见
http://plcscan.org/blog/2016/11/guide-for-information-security-protection-of-industrial-control-systems/?from=timeline&isappinstalled=0
http://plcscan.org/blog/2016/11/guide-for-information-security-protection-of-industrial-control-systems/?from=timeline&isappinstalled=0
漏洞预警:Sophos Web Appliance远程代码执行漏洞
http://www.mottoin.com/91413.html
http://www.mottoin.com/91413.html
Python basic cheatsheet
https://www.pythonsheets.com/notes/python-basic.html
https://www.pythonsheets.com/notes/python-basic.html
DRAKVUF:黑盒二进制分析平台
http://www.mottoin.com/91636.html
http://www.mottoin.com/91636.html
novahot: A webshell framework for penetration testers.
https://github.com/chrisallenlane/novahot
https://github.com/chrisallenlane/novahot
Tumblr XSS Exploit
http://blog.andrewlang.net/post/152805939304/tumblr-xss-exploit
http://blog.andrewlang.net/post/152805939304/tumblr-xss-exploit
kids:知乎日志系统开源
https://zhuanlan.zhihu.com/p/19919584?refer=hackers
https://zhuanlan.zhihu.com/p/19919584?refer=hackers
Mac OSX系统下的渗透利用工具Empyre
http://www.freebuf.com/sectool/118715.html
http://www.freebuf.com/sectool/118715.html
MMeTokenDecrypt:Decrypts and extracts iCloud and MMe authorization tokens
https://github.com/manwhoami/MMeTokenDecrypt
https://github.com/manwhoami/MMeTokenDecrypt
pentest-wiki: 渗透测试分阶段资料库
https://github.com/nixawk/pentest-wiki
https://github.com/nixawk/pentest-wiki
SecWiki周刊(第140期)
https://www.sec-wiki.com/weekly/140
https://www.sec-wiki.com/weekly/140
POINTYFEATHER aka Tar extract pathname bypass
https://sintonen.fi/advisories/tar-extract-pathname-bypass.txt
https://sintonen.fi/advisories/tar-extract-pathname-bypass.txt
TheHive: A Scalable, Open Source and Free Incident Response Platform
https://blog.thehive-project.org/2016/11/07/introducing-thehive/
https://blog.thehive-project.org/2016/11/07/introducing-thehive/
Wukong 反作弊系统缓存的优化
https://zhuanlan.zhihu.com/p/23509238
https://zhuanlan.zhihu.com/p/23509238
Azurite:一款云服务安全审计工具
http://www.mottoin.com/91483.html
http://www.mottoin.com/91483.html
一次XorDDos变种样本的分析实战记录(附工具下载)
http://www.freebuf.com/articles/system/119374.html
http://www.freebuf.com/articles/system/119374.html
Radium-Keylogger:基于Python的多功能键盘记录
http://www.mottoin.com/91644.html
http://www.mottoin.com/91644.html
SQLi, Privilage Escalation, and PowerShell Empire
https://glanfield.co.uk/sqli-privilage-escalation-and-powershell-empire/
https://glanfield.co.uk/sqli-privilage-escalation-and-powershell-empire/
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第141期)
