SecWiki周刊(第147期)
2016/12/19-2016/12/25
      安全资讯
    
互联网安全志愿者联盟:配合执法部门打击网络灰黑产业链
http://tv.cctv.com/2016/12/24/VIDEvKOS1muC2zyhFgaBJY9m161224.shtml
http://tv.cctv.com/2016/12/24/VIDEvKOS1muC2zyhFgaBJY9m161224.shtml
俄罗斯黑客出售美国选举援助委员会网站权限与数据
http://www.mottoin.com/94240.html
http://www.mottoin.com/94240.html
US State Police Have Spent Millions on Israeli Phone Cracking Tech 
http://motherboard.vice.com/read/us-state-police-have-spent-millions-on-israeli-phone-cracking-tech-cellebrite
http://motherboard.vice.com/read/us-state-police-have-spent-millions-on-israeli-phone-cracking-tech-cellebrite
SANS:2016年安全分析调研报告
http://yepeng.blog.51cto.com/3101105/1885339
http://yepeng.blog.51cto.com/3101105/1885339
Shadow Brokers再次兜售NSA黑客工具包
http://bobao.360.cn/news/detail/3857.html
http://bobao.360.cn/news/detail/3857.html
纽约金融监管机构推迟安全规则
http://www.cnbc.com/2016/12/21/ny-financial-regulator-to-delay-cybersecurity-rules.html
http://www.cnbc.com/2016/12/21/ny-financial-regulator-to-delay-cybersecurity-rules.html
偷情网站 Ashley Madison 因数据泄露被罚160万美元
http://www.aqniu.com/news-views/21813.html
http://www.aqniu.com/news-views/21813.html
FBI逮捕DDoS僵尸网络的租赁者
http://www.solidot.org/story?sid=50788
http://www.solidot.org/story?sid=50788
美国在抓捕俄罗斯黑客上面临重重困难 
http://www.solidot.org/story?sid=50791
http://www.solidot.org/story?sid=50791
全面透视|老王逐条解读网络安全法
https://www.sec-un.org/4933.html
https://www.sec-un.org/4933.html
迪拜警方开始使用犯罪预测软件
http://www.solidot.org/story?sid=50846
http://www.solidot.org/story?sid=50846
      安全技术
    
从“小白”到“白帽子黑客”的实用指南
http://mp.weixin.qq.com/s?__biz=MzIxNDI0MDAxNg==&mid=100000063&idx=1&sn=6ca03d6092bf79412b2baf5b1b174b08&chksm=17abdf4020dc5656476
http://mp.weixin.qq.com/s?__biz=MzIxNDI0MDAxNg==&mid=100000063&idx=1&sn=6ca03d6092bf79412b2baf5b1b174b08&chksm=17abdf4020dc5656476
基于谷歌SSL透明证书的子域名查询脚本
https://github.com/We5ter/GSDF
https://github.com/We5ter/GSDF
cobaltstrike3.6 破解版
http://evi1cg.me/archives/CobaltStrike_3_6_Cracked.html
http://evi1cg.me/archives/CobaltStrike_3_6_Cracked.html
WeCenter 3.1.9 存储 XSS漏洞分析
http://linux.im/2016/12/22/WeCenter-319-Stored-XSS-Vuln.html
http://linux.im/2016/12/22/WeCenter-319-Stored-XSS-Vuln.html
巡风:企业内网的漏洞快速应急巡航扫描系统(附Docker版本)
http://www.mottoin.com/94253.html
http://www.mottoin.com/94253.html
安全顶会 NDSS 2017 接收论文列表 
http://www.internetsociety.org/events/ndss-symposium/ndss-symposium-2017/ndss-2017-programme
http://www.internetsociety.org/events/ndss-symposium/ndss-symposium-2017/ndss-2017-programme
Splunk大数据分析经验分享:从入门到夺门而逃
http://www.freebuf.com/articles/database/123006.html
http://www.freebuf.com/articles/database/123006.html
DSVW: Damn Small Vulnerable Web(小型靶场一枚)
https://github.com/stamparm/DSVW
https://github.com/stamparm/DSVW
Tengine WAF 实践
http://www.mottoin.com/94365.html
http://www.mottoin.com/94365.html
poseidon: 360公司日志搜索平台「开源」
https://github.com/Qihoo360/poseidon
https://github.com/Qihoo360/poseidon
Docker — 从入门到实践
https://github.com/yeasy/docker_practice
https://github.com/yeasy/docker_practice
Harbor: 基于Docker Distribution的企业级Registry服务
http://vmware.github.io/harbor/index_cn.html
http://vmware.github.io/harbor/index_cn.html
xunfeng: 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统
https://github.com/ysrc/xunfeng
https://github.com/ysrc/xunfeng
FuzzySec:Windows Kernel Exploitation: Integer Overflow 
http://www.fuzzysecurity.com/tutorials/expDev/18.html
http://www.fuzzysecurity.com/tutorials/expDev/18.html
awesome-ml-for-cybersecurity: Machine Learning for Cyber Security
https://github.com/jivoi/awesome-ml-for-cybersecurity#awesome-machine-learning-for-cyber-security-
https://github.com/jivoi/awesome-ml-for-cybersecurity#awesome-machine-learning-for-cyber-security-
MongoDB安全 – PHP注入攻击
http://www.mottoin.com/94341.html
http://www.mottoin.com/94341.html
CloudFlare_enum:使用CloudFlare进行子域名枚举的脚本
http://www.mottoin.com/94481.html
http://www.mottoin.com/94481.html
Dnsteal:一个利用DNS请求传输文件的工具
http://www.mottoin.com/94437.html
http://www.mottoin.com/94437.html
HG533路由器分析教程之找到硬件调试接口
http://drops.wiki/index.php/2016/12/22/hg533/
http://drops.wiki/index.php/2016/12/22/hg533/
使用Hashcat破解外国字符构成的密码的终极指南
http://drops.wiki/index.php/2016/12/21/hashcat/
http://drops.wiki/index.php/2016/12/21/hashcat/
BurpSuite插件分享:基于Python的Web应用Fuzzing插件PyJFuzz
http://www.mottoin.com/94302.html
http://www.mottoin.com/94302.html
MySQL大表优化方案
https://segmentfault.com/a/1190000006158186
https://segmentfault.com/a/1190000006158186
FCN: 一款傻瓜式的一键接入私有网络的工具
https://github.com/boywhp/fcn
https://github.com/boywhp/fcn
F_A_S_T扫描器: 定向全自动化渗透测试
https://github.com/RASSec/pentestEr_Fully-automatic-scanner
https://github.com/RASSec/pentestEr_Fully-automatic-scanner
Writing Burp Extensions (Shodan Scanner)
http://resources.infosecinstitute.com/writing-burp-extensions-shodan-scanner/
http://resources.infosecinstitute.com/writing-burp-extensions-shodan-scanner/
Whitewidow:自动化SQL漏洞扫描器
http://www.mottoin.com/94222.html
http://www.mottoin.com/94222.html
Docker for win10下使用ubuntu安装DVWA-1.9
http://www.mottoin.com/94363.html
http://www.mottoin.com/94363.html
ThreatHunting Project:Hunting for adversaries in your IT environment
http://www.threathunting.net/
http://www.threathunting.net/
RASscan: 内网端口极速扫描器
https://github.com/RASSec/RASscan
https://github.com/RASSec/RASscan
基于文件特征的Android模拟器检测(附实现代码下载)
https://mp.weixin.qq.com/s?__biz=MzI4MzI4MDg1NA==&mid=2247483773&idx=1&sn=d654e17c9c3b5e689f9ac04a45a8f993&chksm=eb8c55c4dcfbdcd2a1bf2d0ef9446684291ee82930b8a0d8e7b55cd9a7178039e0b2559502d4&mpshare=1&scene=1&srcid=12195FpjYzbz2LJMuBkTtvbY
https://mp.weixin.qq.com/s?__biz=MzI4MzI4MDg1NA==&mid=2247483773&idx=1&sn=d654e17c9c3b5e689f9ac04a45a8f993&chksm=eb8c55c4dcfbdcd2a1bf2d0ef9446684291ee82930b8a0d8e7b55cd9a7178039e0b2559502d4&mpshare=1&scene=1&srcid=12195FpjYzbz2LJMuBkTtvbY
秒爆十万字典:奇葩技巧快速枚举“一句话后门”密码
http://www.freebuf.com/sectool/122169.html
http://www.freebuf.com/sectool/122169.html
不一样的HTTP Headers (一)
http://www.mottoin.com/93711.html
http://www.mottoin.com/93711.html
A collection of JavaScript engine CVEs with PoCs
https://github.com/tunz/js-vuln-db
https://github.com/tunz/js-vuln-db
Mimikatz Delivery via ClickOnce with URL Parameters
http://subt0x10.blogspot.com/2016/12/mimikatz-delivery-via-clickonce-with.html
http://subt0x10.blogspot.com/2016/12/mimikatz-delivery-via-clickonce-with.html
谈谈HSTS超级Cookie
http://blog.csdn.net/u011721501/article/details/53849064
http://blog.csdn.net/u011721501/article/details/53849064
IOActive研究员声称可入侵松下机载娱乐系统
http://www.freebuf.com/vuls/123712.html
http://www.freebuf.com/vuls/123712.html
SecWiki周刊(第146期)
https://www.sec-wiki.com/weekly/146
https://www.sec-wiki.com/weekly/146
自动化、安全分析和人工智能,从Gartner预测看网络安全新规则
http://www.freebuf.com/articles/neopoints/123545.html
http://www.freebuf.com/articles/neopoints/123545.html
Android Telephony拒绝服务漏洞(CVE-2016-6763)分析
http://drops.wiki/index.php/2016/12/20/android-telephony/
http://drops.wiki/index.php/2016/12/20/android-telephony/
awesome-windows-exploitation: Windows Exploitation resources
https://github.com/enddo/awesome-windows-exploitation
https://github.com/enddo/awesome-windows-exploitation
Bottle HTTP 头注入漏洞探究
https://www.leavesongs.com/PENETRATION/bottle-crlf-cve-2016-9964.html
https://www.leavesongs.com/PENETRATION/bottle-crlf-cve-2016-9964.html
A Lightweight, Compact, No-Nonsense ATM Malware
http://blog.trendmicro.com/trendlabs-security-intelligence/alice-lightweight-compact-no-nonsense-atm-malware/
http://blog.trendmicro.com/trendlabs-security-intelligence/alice-lightweight-compact-no-nonsense-atm-malware/
The Kings In Your Castle Part 5: APT correlation and do-it-yourself threat resea
https://cyber.wtf/2016/12/15/the-kings-in-your-castle-part-5-apt-correlation-and-do-it-yourself-threat-research/
https://cyber.wtf/2016/12/15/the-kings-in-your-castle-part-5-apt-correlation-and-do-it-yourself-threat-research/
Paper: Spreading techniques used by malware
https://www.virusbulletin.com/blog/2016/december/paper-spreading-techniques-used-malware/
https://www.virusbulletin.com/blog/2016/december/paper-spreading-techniques-used-malware/
Python股市数据分析教程
https://yq.aliyun.com/articles/66878
https://yq.aliyun.com/articles/66878
Oracle酒店管理平台的远程命令执行和持卡人数据泄漏漏洞分析(CVE-2016-5663/4/5)
http://www.mottoin.com/94271.html
http://www.mottoin.com/94271.html
开启TCP BBR拥塞控制算法
https://github.com/iMeiji/shadowsocks_install/wiki/%E5%BC%80%E5%90%AFTCP-BBR%E6%8B%A5%E5%A1%9E%E6%8E%A7%E5%88%B6%E7%AE%97%E6%B3%95
https://github.com/iMeiji/shadowsocks_install/wiki/%E5%BC%80%E5%90%AFTCP-BBR%E6%8B%A5%E5%A1%9E%E6%8E%A7%E5%88%B6%E7%AE%97%E6%B3%95
Engineering Security Through Uber's Custom Email IDS
http://eng.uber.com/custom-email-ids/
http://eng.uber.com/custom-email-ids/
Docker网络隔离初步设想 
http://vipdocker.com/2016/09/14/docker-network-isolation/
http://vipdocker.com/2016/09/14/docker-network-isolation/
Law Enforcement Use of Cell-Site Simulation Technologies: Privacy Concerns and R
https://info.publicintelligence.net/US-CellSiteSimulatorsPrivacy.pdf
https://info.publicintelligence.net/US-CellSiteSimulatorsPrivacy.pdf
2016年Exploit Kits漏洞TOP 10分析 
https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651062549&idx=1&sn=26c4b0a90108a754867e1af4194d7f8f&chksm=bd1f939e8a681a88f863f2b6325a429e83d811d0b724ed69421522be5b13fc854484e0eff2e9&scene=0
https://mp.weixin.qq.com/s?__biz=MjM5NjA0NjgyMA==&mid=2651062549&idx=1&sn=26c4b0a90108a754867e1af4194d7f8f&chksm=bd1f939e8a681a88f863f2b6325a429e83d811d0b724ed69421522be5b13fc854484e0eff2e9&scene=0
Threat model for firmware security
http://media.weibo.cn/article?id=2309404056293743685964&jumpfrom=weibocom&luicode=10000370&from=timeline
http://media.weibo.cn/article?id=2309404056293743685964&jumpfrom=weibocom&luicode=10000370&from=timeline
Learning From A Year of Security Breaches
https://medium.com/starting-up-security/learning-from-a-year-of-security-breaches-ed036ea05d9b#.xobwljx47
https://medium.com/starting-up-security/learning-from-a-year-of-security-breaches-ed036ea05d9b#.xobwljx47
用树莓派搭建小型honeynet
http://www.mottoin.com/94306.html
http://www.mottoin.com/94306.html
利用Python实现knn算法
http://computational-communication.com/python-knn/
http://computational-communication.com/python-knn/
A Good User Interface 好的用户界面设计该如何做
http://goodui.org/
http://goodui.org/
如何通过TensorFlow实现深度学习算法并运用到企业实践中 
http://dataunion.org/26671.html
http://dataunion.org/26671.html
dns recon & research, find & lookup dns records
https://dnsdumpster.com/
https://dnsdumpster.com/
Disclosing the Primary Email address for each Facebook user
http://www.dawgyg.com/2016/12/21/disclosing-the-primary-email-address-for-each-facebook-user/
http://www.dawgyg.com/2016/12/21/disclosing-the-primary-email-address-for-each-facebook-user/
Learning From A Year of Security Breaches – Starting Up Security
https://medium.com/starting-up-security/learning-from-a-year-of-security-breaches-ed036ea05d9b#.23b72hmck
https://medium.com/starting-up-security/learning-from-a-year-of-security-breaches-ed036ea05d9b#.23b72hmck
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
    本期原文地址: SecWiki周刊(第147期)
