SecWiki周刊(第142期)
2016/11/14-2016/11/20
安全资讯
国外网络安全博客Top 50
http://blog.feedspot.com/cyber_security_blogs/
http://blog.feedspot.com/cyber_security_blogs/
NIST 发布大规模物联网安全报告[PDF]
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160.pdf
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160.pdf
Kapustkiy 回归,下一个目标是谁?
http://www.mottoin.com/91952.html
http://www.mottoin.com/91952.html
加拿大政府官网疑似被攻破
http://www.mottoin.com/92296.html
http://www.mottoin.com/92296.html
使用USRP追踪飞机
https://v.qq.com/x/page/e0346ll12xf.html
https://v.qq.com/x/page/e0346ll12xf.html
Hacker Breaks into Italian Government Website, 45,000 Users Exposed
http://news.softpedia.com/news/hacker-breaks-into-italian-government-website-45-000-users-exposed-510332.shtml
http://news.softpedia.com/news/hacker-breaks-into-italian-government-website-45-000-users-exposed-510332.shtml
GitHub 800 万用户信息疑似泄露
http://www.mottoin.com/92180.html
http://www.mottoin.com/92180.html
黑客暴露了AdultFriendFinder的4.12亿账户&& twitter 900W用户名数据
http://www.mottoin.com/91846.html
http://www.mottoin.com/91846.html
全球招聘网站巨头PageGroup被黑,泄露数百万求职者信息
http://www.mottoin.com/91881.html
http://www.mottoin.com/91881.html
周鸿祎帮你一篇文章看懂乌镇互联网大会两大热点:互联网经济下半场、人工智能
http://www.mottoin.com/92166.html
http://www.mottoin.com/92166.html
周鸿祎:IOT时代存在巨大威胁
http://www.mottoin.com/92059.html
http://www.mottoin.com/92059.html
美国成人网站使用WebSocket绕过广告屏蔽插件
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994833&idx=1&sn=1d005c7aab59cb1fb908e84188ebf6a8&chksm=bdbf00c28ac889d47f9e71d8b7b7fc37053a75ae710e7586d09bf99c4561260f9d295e5d8b95&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650994833&idx=1&sn=1d005c7aab59cb1fb908e84188ebf6a8&chksm=bdbf00c28ac889d47f9e71d8b7b7fc37053a75ae710e7586d09bf99c4561260f9d295e5d8b95&scene=0#rd
NIST耗时两年编撰《网络安全工程技术指南》 已正式发布
https://www.easyaq.com/newsdetail/id/1018922002.shtml
https://www.easyaq.com/newsdetail/id/1018922002.shtml
锦行科技出奇•守正-幻云发布会即将重磅开启
http://www.mottoin.com/92201.html
http://www.mottoin.com/92201.html
中国央行招聘区块链专家开发数字货币
http://www.solidot.org/story?sid=50409
http://www.solidot.org/story?sid=50409
Secret Backdoor in Some U.S. Phones Sent Data to China
http://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html?_r=0
http://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html?_r=0
我国网络空间防御技术取得重大突破
http://news.sciencenet.cn/htmlnews/2016/11/360863.shtm
http://news.sciencenet.cn/htmlnews/2016/11/360863.shtm
安全技术
基于centos6.8的Suricata+Barnyard2的Snorby-IDS
http://blog.csdn.net/qq_29277155/article/details/53205582
http://blog.csdn.net/qq_29277155/article/details/53205582
NIST特刊800-160:系统安全工程
https://cdn.easyaq.com/@/20161117/1479369118426090915.pdf
https://cdn.easyaq.com/@/20161117/1479369118426090915.pdf
DeGuard:apk-deguard 在线APK反混淆工具
http://www.apk-deguard.com/
http://www.apk-deguard.com/
Open Source Intelligence Tools and Resources Handbook[PDF]
http://www.i-intelligence.eu/wp-content/uploads/2016/11/2016_November_Open-Source-Intelligence-Tools-and-Resources-Handbook.pdf
http://www.i-intelligence.eu/wp-content/uploads/2016/11/2016_November_Open-Source-Intelligence-Tools-and-Resources-Handbook.pdf
How Can Drones Be Hacked? The updated list of vulnerable drones & attack tools
https://medium.com/@swalters/how-can-drones-be-hacked-the-updated-list-of-vulnerable-drones-attack-tools-dd2e006d6809#.j11w643iz
https://medium.com/@swalters/how-can-drones-be-hacked-the-updated-list-of-vulnerable-drones-attack-tools-dd2e006d6809#.j11w643iz
Python Data Science Handbook: Python数据分析手册书籍
https://github.com/jakevdp/PythonDataScienceHandbook
https://github.com/jakevdp/PythonDataScienceHandbook
How To Set Up A Drone Vulnerability Testing Lab
https://medium.com/@swalters/how-to-set-up-a-drone-vulnerability-testing-lab-db8f7c762663#.kzi1a0dob
https://medium.com/@swalters/how-to-set-up-a-drone-vulnerability-testing-lab-db8f7c762663#.kzi1a0dob
打造一个手机端的渗透平台
http://www.mottoin.com/92241.html
http://www.mottoin.com/92241.html
滥用NPM库实现敏感数据提取
http://www.mottoin.com/91795.html
http://www.mottoin.com/91795.html
jSQL Injection v0.77 - Java application for automatic SQL database injection
http://www.kitploit.com/2016/11/jsql-injection-v077-java-application.html
http://www.kitploit.com/2016/11/jsql-injection-v077-java-application.html
无线之破解wpa2加密的wifi密码
http://www.mottoin.com/92122.html
http://www.mottoin.com/92122.html
Janus: 盘古团队打造的移动应用安全分析社区化平台
http://demo.appscan.io/web/search-rule.html#type=rule&page=1
http://demo.appscan.io/web/search-rule.html#type=rule&page=1
PHP Hacker代码审计秘籍
http://www.freebuf.com/articles/rookie/119969.html
http://www.freebuf.com/articles/rookie/119969.html
JDong: 京东数据爬虫接口
https://github.com/Chyroc/JDong
https://github.com/Chyroc/JDong
带你走进维也纳版的CCS2016(现场报告点评三)
http://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652307009&idx=1&sn=d6b3302e4a17e12a3bf7046de6c56b37&chksm=8bc563cfbcb2ead9455d5adb9ee6c0efc1e5c8ece6b26f229b225b90cbf2ab31bf5c53bdb97c&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzA4ODYzMjU0NQ==&mid=2652307009&idx=1&sn=d6b3302e4a17e12a3bf7046de6c56b37&chksm=8bc563cfbcb2ead9455d5adb9ee6c0efc1e5c8ece6b26f229b225b90cbf2ab31bf5c53bdb97c&scene=0#rd
自然语言处理工具包spaCy介绍
http://www.52nlp.cn/%e8%87%aa%e7%84%b6%e8%af%ad%e8%a8%80%e5%a4%84%e7%90%86%e5%b7%a5%e5%85%b7%e5%8c%85spacy%e4%bb%8b%e7%bb%8d
http://www.52nlp.cn/%e8%87%aa%e7%84%b6%e8%af%ad%e8%a8%80%e5%a4%84%e7%90%86%e5%b7%a5%e5%85%b7%e5%8c%85spacy%e4%bb%8b%e7%bb%8d
大数据框架对比:Hadoop、Storm、Samza、Spark和Flink
http://www.infoq.com/cn/articles/hadoop-storm-samza-spark-flink
http://www.infoq.com/cn/articles/hadoop-storm-samza-spark-flink
CHM渗透:从入门到“入狱”
http://www.freebuf.com/articles/system/119874.html
http://www.freebuf.com/articles/system/119874.html
终端安全产品的进化:终端安全检测和响应
http://bobao.360.cn/news/detail/3761.html
http://bobao.360.cn/news/detail/3761.html
DDoS黑产调研
http://www.arkteam.net/?p=1340
http://www.arkteam.net/?p=1340
一种新型攻击手法:监听WIFI变化嗅探手机输入
http://www.mottoin.com/91945.html
http://www.mottoin.com/91945.html
needle: IOS的安全测试框架
https://github.com/mwrlabs/needle
https://github.com/mwrlabs/needle
命令执行和绕过的一些小技巧
http://bobao.360.cn/learning/detail/3192.html
http://bobao.360.cn/learning/detail/3192.html
企业级入侵检测系统及实时告警的开源实现
http://bobao.360.cn/learning/detail/3185.html
http://bobao.360.cn/learning/detail/3185.html
数据泄露信息发布网站
http://www.leakedin.com/
http://www.leakedin.com/
OSXCollector: a forensic evidence collection & analysis toolkit for OSX.
http://yelp.github.io/osxcollector/
http://yelp.github.io/osxcollector/
lightbulb-framework: 一款WAF审计工具
https://github.com/lightbulb-framework/lightbulb-framework
https://github.com/lightbulb-framework/lightbulb-framework
poisontap:在锁定的计算中植入后门
https://github.com/samyk/poisontap
https://github.com/samyk/poisontap
CVE-2016-0176漏洞及利用详解
http://keenlab.tencent.com/zh/2016/11/18/A-Link-to-System-Privilege/
http://keenlab.tencent.com/zh/2016/11/18/A-Link-to-System-Privilege/
iRET:IOS 逆向渗透测试工具套件
http://www.mottoin.com/91857.html
http://www.mottoin.com/91857.html
CVE-2016-5007 Spring Security / MVC Path Matching Inconsistency
http://www.mottoin.com/92079.html
http://www.mottoin.com/92079.html
中文:使用Raspberry Pi Zero在锁定的计算机中安装后门
http://www.mottoin.com/92104.html
http://www.mottoin.com/92104.html
使用nmap和自定义子域名文件发现目标子域
http://www.mottoin.com/92113.html
http://www.mottoin.com/92113.html
SHELLING - an offensive approach to the anatomy of improperly written OS command
https://github.com/ewilded/shelling
https://github.com/ewilded/shelling
国内几大cdn ip地址段
http://www.cmsky.com/cn-cdn-ip
http://www.cmsky.com/cn-cdn-ip
在SQLite中实现命令执行
http://www.mottoin.com/91908.html
http://www.mottoin.com/91908.html
大众点评订单系统分库分表实践 -
http://tech.meituan.com/dianping_order_db_sharding.html
http://tech.meituan.com/dianping_order_db_sharding.html
a tool to perform static analysis of known vulnerabilities in docker
https://github.com/eliasgranderubio/check_docker_image
https://github.com/eliasgranderubio/check_docker_image
PowerShell Reverse HTTPs Shell
https://github.com/subTee/PoshRat
https://github.com/subTee/PoshRat
OWASP Directory Access scanner
https://github.com/stanislav-web/OpenDoor
https://github.com/stanislav-web/OpenDoor
验证码的前世今生(前世篇)
https://zhuanlan.zhihu.com/p/23326828
https://zhuanlan.zhihu.com/p/23326828
从Nginx Access日志中挖掘有价值的漏洞
http://mp.weixin.qq.com/s?__biz=MzI5ODE0ODA5MQ==&mid=2652277631&idx=1&sn=49f5aa92ba552df0aa43804c191a90fa&chksm=f74862ebc03febfd5b5866dfb1785319cf1a79cc026322624c0803cb65986ec6f2a2e9bc45b9&scene=0#rd
http://mp.weixin.qq.com/s?__biz=MzI5ODE0ODA5MQ==&mid=2652277631&idx=1&sn=49f5aa92ba552df0aa43804c191a90fa&chksm=f74862ebc03febfd5b5866dfb1785319cf1a79cc026322624c0803cb65986ec6f2a2e9bc45b9&scene=0#rd
Google's tamper detection for Android 移动端威胁情报检测/风控SDK
https://koz.io/inside-safetynet/
https://koz.io/inside-safetynet/
New Hack: How to Bypass iPhone Passcode to Access Photos and Messages Wednesday
http://thehackernews.com/2016/11/iphone-hacking.html
http://thehackernews.com/2016/11/iphone-hacking.html
PowerShell Empire Web:基于web接口管理Empire
http://www.mottoin.com/91966.html
http://www.mottoin.com/91966.html
dorothy2:开源的恶意软件/僵尸网络分析框架
http://www.mottoin.com/92101.html
http://www.mottoin.com/92101.html
NoSQLAttack: Python编写的开源的mongoDB攻击工具
https://github.com/youngyangyang04/NoSQLAttack
https://github.com/youngyangyang04/NoSQLAttack
A Better Login System: PHP编程实现基于ACL认证过程
https://code.tutsplus.com/tutorials/a-better-login-system--net-3461
https://code.tutsplus.com/tutorials/a-better-login-system--net-3461
使用USRP探索无线世界 Part 1:USRP从入门到追踪飞机飞行轨迹
http://www.freebuf.com/articles/wireless/119950.html
http://www.freebuf.com/articles/wireless/119950.html
浅谈如何利用IP数据来辅助风控和安全系统
http://www.freebuf.com/special/120041.html
http://www.freebuf.com/special/120041.html
awesome-iot-hacks: A Collection of Hacks in IoT Space
https://github.com/nebgnahz/awesome-iot-hacks
https://github.com/nebgnahz/awesome-iot-hacks
绕过Ebay xss保护
http://www.mottoin.com/92305.html
http://www.mottoin.com/92305.html
使用Commix绕过安全防护利用命令执行漏洞
http://www.mottoin.com/91806.html
http://www.mottoin.com/91806.html
从XSS到RCE2.5 - Black Hat Europe Arsenal 2016
https://github.com/Varbaek/xsser
https://github.com/Varbaek/xsser
为何我暂停了维护 Python 社区的志愿者工作
https://www.oschina.net/news/79150/why-i-took-october-off-from-oss-volunteering
https://www.oschina.net/news/79150/why-i-took-october-off-from-oss-volunteering
HackingTeam back for your Androids, now extra insecure!
http://rednaga.io/2016/11/14/hackingteam_back_for_your_androids/
http://rednaga.io/2016/11/14/hackingteam_back_for_your_androids/
AndroidLinker与SO加壳技术之下篇
http://yaq.qq.com/blog/15
http://yaq.qq.com/blog/15
VBulletin 核心插件 forumrunner SQL注入(CVE-2016-6195)漏洞分析
http://paper.seebug.org/116/
http://paper.seebug.org/116/
Pwning Your Java Messaging With Deserialization Vulnerabilities[PDF]
https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities.pdf
https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities.pdf
Bypassing Two-Factor Authentication on OWA & Office365 Portals
http://www.blackhillsinfosec.com/?p=5396
http://www.blackhillsinfosec.com/?p=5396
SecWiki周刊(第141期)
https://www.sec-wiki.com/weekly/141
https://www.sec-wiki.com/weekly/141
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第142期)
