SecWiki周刊(第151期)
2017/01/16-2017/01/22
安全资讯
Krebs 找到 Mirai 僵尸网络可能的作者
http://www.solidot.org/story?sid=51153
http://www.solidot.org/story?sid=51153
2017年全球最火爆网络安全大会日程(附:全球信息安全会议 Top 50)
http://www.aqniu.com/industry/22312.html
http://www.aqniu.com/industry/22312.html
黑客特种兵潘少华:如何用人工智能“套路”一个骗子
https://mp.weixin.qq.com/s?__biz=MzA4ODUxNjIwMg==&mid=2654324135&idx=1&sn=876980890a7c8bf50ecdb390f02258d9&chksm=8be996a2bc9e1fb4c0be5646a0d0f48bf6fb373d69c3312c502b8434b5be0220281af15e0c04
https://mp.weixin.qq.com/s?__biz=MzA4ODUxNjIwMg==&mid=2654324135&idx=1&sn=876980890a7c8bf50ecdb390f02258d9&chksm=8be996a2bc9e1fb4c0be5646a0d0f48bf6fb373d69c3312c502b8434b5be0220281af15e0c04
信息通信行业发展规划(2016-2020年)中网络信息安全相关内容摘录
http://yepeng.blog.51cto.com/3101105/1892649
http://yepeng.blog.51cto.com/3101105/1892649
软件和信息技术服务业发展规划 (2016-2020年)信息安全相关内容摘录
http://yepeng.blog.51cto.com/3101105/1892652
http://yepeng.blog.51cto.com/3101105/1892652
《大数据产业发展规划》(2016-2020年)安全相关内容摘录
http://yepeng.blog.51cto.com/3101105/1892661
http://yepeng.blog.51cto.com/3101105/1892661
《信息产业发展指南》2016-2020
http://yepeng.blog.51cto.com/3101105/1892626
http://yepeng.blog.51cto.com/3101105/1892626
《关于促进移动互联网健康有序发展的意见》
http://yepeng.blog.51cto.com/3101105/1892608
http://yepeng.blog.51cto.com/3101105/1892608
张矩:信息安全创业必知手册
http://mp.weixin.qq.com/s/KKLThg2cgYqntb0nrfvLXg
http://mp.weixin.qq.com/s/KKLThg2cgYqntb0nrfvLXg
安全技术
waf自动爆破(绕过)工具
https://github.com/3xp10it/bypass_waf
https://github.com/3xp10it/bypass_waf
绕过安全狗拦截,上传webshell
http://www.freebuf.com/articles/web/125084.html
http://www.freebuf.com/articles/web/125084.html
Firefox 50.0.2 释放后重用漏洞分析(CVE-2016-9899)
http://whereisk0shl.top/firefox-uaf-cve-2016-9899-fck-rop-gadget.html
http://whereisk0shl.top/firefox-uaf-cve-2016-9899-fck-rop-gadget.html
2天打造自己的云爬虫
http://www.infosec-wiki.com/?p=308
http://www.infosec-wiki.com/?p=308
利用符号执行去除控制流平坦化
https://security.tencent.com/index.php/blog/msg/112
https://security.tencent.com/index.php/blog/msg/112
NAXSI: 基于 Nginx的开源、高性能、低规则 WAF 防护模块
https://github.com/nbs-system/naxsi
https://github.com/nbs-system/naxsi
Jenkins CLI Ldap Deser CVE-2016-9299
http://www.mottoin.com/95494.html
http://www.mottoin.com/95494.html
攻击大数据应用(二)
http://www.mottoin.com/95510.html
http://www.mottoin.com/95510.html
BadBookmarklet
http://xlab.tencent.com/cn/2017/01/18/badbookmarklet/
http://xlab.tencent.com/cn/2017/01/18/badbookmarklet/
装了这个主题包,就被拿system shell?
https://zhuanlan.zhihu.com/p/24983092
https://zhuanlan.zhihu.com/p/24983092
eval长度限制绕过 && PHP5.6新特性
https://www.leavesongs.com/PHP/bypass-eval-length-restrict.html
https://www.leavesongs.com/PHP/bypass-eval-length-restrict.html
lcyscan:Python插件化漏洞扫描器
https://github.com/Lcys/lcyscan
https://github.com/Lcys/lcyscan
HTTPS时代已来,你跟上来么
https://jaq.alibaba.com/community/art/show?articleid=621
https://jaq.alibaba.com/community/art/show?articleid=621
phpcms后台注入至getshell漏洞审计
https://www.secpulse.com/archives/54950.html
https://www.secpulse.com/archives/54950.html
基于Web漏洞扫描的URL及网页框架聚类研究
http://cryin.startblog.cc/Articles/article/37
http://cryin.startblog.cc/Articles/article/37
使用OpenBTS基站测试物联网模块 IoT mode fuzzing with OpenBTS
https://cn0xroot.com/2017/01/10/iot-mode-fuzzing-with-openbt/
https://cn0xroot.com/2017/01/10/iot-mode-fuzzing-with-openbt/
MyToolKit: sqlmap对所有目标及其所有旁站批量自动化sqli
https://github.com/3xp10it/MyToolKit
https://github.com/3xp10it/MyToolKit
Google Project Zero挖洞经验整理
https://www.sec-un.org/google-project-zero%E6%8C%96%E6%B4%9E%E7%BB%8F%E9%AA%8C%E6%95%B4%E7%90%86/?from=timeline
https://www.sec-un.org/google-project-zero%E6%8C%96%E6%B4%9E%E7%BB%8F%E9%AA%8C%E6%95%B4%E7%90%86/?from=timeline
一个安全相关的工具,博客的一个汇总(导航性质)
http://www.itxueke.com/SecNavi/
http://www.itxueke.com/SecNavi/
百度第三代 Spider 背后的万亿量级实时数据处理系统
https://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650995223&idx=1&sn=9c2722a2dcddbc26eefc437a1e82531b&chksm=bdbf02448ac88b52b0037900b3301c9d3b602354e5be2902da743409b5b663d3dc47f94c02e5
https://mp.weixin.qq.com/s?__biz=MjM5MDE0Mjc4MA==&mid=2650995223&idx=1&sn=9c2722a2dcddbc26eefc437a1e82531b&chksm=bdbf02448ac88b52b0037900b3301c9d3b602354e5be2902da743409b5b663d3dc47f94c02e5
前所未有的一次披露 | Dark•Mobile•Bank跟踪分析报告
https://mp.weixin.qq.com/s?__biz=MjM5NTY4NzcyNg==&mid=2650238614&idx=1&sn=234abb265be20f24222ab8c66d75728b&srcid=0428DhSoTlQzT0JaxWL5e8Fz&key=f20c318c778828bf1d5cd5ba121cf57289b8868a9cad6d7a2dcc4f45d687f651e070d9deaa57963aa077286e82eb6fd92d9a73a4076592987e7e2e1388e1bfb7a609da678964347398cd7a52a1c8aa
https://mp.weixin.qq.com/s?__biz=MjM5NTY4NzcyNg==&mid=2650238614&idx=1&sn=234abb265be20f24222ab8c66d75728b&srcid=0428DhSoTlQzT0JaxWL5e8Fz&key=f20c318c778828bf1d5cd5ba121cf57289b8868a9cad6d7a2dcc4f45d687f651e070d9deaa57963aa077286e82eb6fd92d9a73a4076592987e7e2e1388e1bfb7a609da678964347398cd7a52a1c8aa
Docker for Automating Honeypots or Malware Sandboxes
https://dadario.com.br/docker-for-automating-honeypots-or-malware-sandboxes/
https://dadario.com.br/docker-for-automating-honeypots-or-malware-sandboxes/
commix-系统命令注入自动化测试实例
http://www.mottoin.com/95641.html
http://www.mottoin.com/95641.html
Automated install scripts for Cuckoo sandbox 一键安装 Cuckoo
https://github.com/daniel-gallagher/cuckoo-autoinstall
https://github.com/daniel-gallagher/cuckoo-autoinstall
安天发布方程式组织Drug攻击平台初步解析
https://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=2650170273&idx=1&sn=05dc4033547c7ae63834ea959d075409&chksm=beb9c09389ce4985c4064a0c2163bad0cc5215c994f30150353520b52f061f3a25a845a19444
https://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&mid=2650170273&idx=1&sn=05dc4033547c7ae63834ea959d075409&chksm=beb9c09389ce4985c4064a0c2163bad0cc5215c994f30150353520b52f061f3a25a845a19444
HaboMalHunter: 哈勃Linux 恶意文件分析系统
https://github.com/Tencent/HaboMalHunter
https://github.com/Tencent/HaboMalHunter
通过Shodan api提供的数据进行漏洞检测
http://www.mottoin.com/95525.html
http://www.mottoin.com/95525.html
新晋漏洞攻击套件Sundown Exploit Kits分析
http://www.freebuf.com/vuls/125168.html
http://www.freebuf.com/vuls/125168.html
Use DNS Rebinding to Bypass IP Restriction
https://ricterz.me/posts/Use%20DNS%20Rebinding%20to%20Bypass%20IP%20Restriction
https://ricterz.me/posts/Use%20DNS%20Rebinding%20to%20Bypass%20IP%20Restriction
JSONP注入实战
http://www.mottoin.com/95682.html
http://www.mottoin.com/95682.html
SecWiki周刊(第150期)
https://www.sec-wiki.com/weekly/150
https://www.sec-wiki.com/weekly/150
LearnPython: 以撸代码的形式学习Python
https://github.com/xianhu/LearnPython
https://github.com/xianhu/LearnPython
2016网络空间安全态势之工控安全报告
http://t.cn/RMEohuH
http://t.cn/RMEohuH
The Leading Security Assessment Framework for Android.
https://github.com/mwrlabs/drozer/
https://github.com/mwrlabs/drozer/
Web security tool to make fuzzing at HTTP, Beta
https://github.com/CoolerVoid/0d1n/
https://github.com/CoolerVoid/0d1n/
Who is Anna-Senpai, the Mirai Worm Author?
https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/
https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/
xrkmon-基于ImmunityDebugger的api调用监控脚本
http://blog.topsec.com.cn/ad_lab/xrkmon-%e5%9f%ba%e4%ba%8eimmunitydebugger%e7%9a%84api%e8%b0%83%e7%94%a8%e7%9b%91%e6%8e%a7%e8%84%9a%e6%9c%ac/
http://blog.topsec.com.cn/ad_lab/xrkmon-%e5%9f%ba%e4%ba%8eimmunitydebugger%e7%9a%84api%e8%b0%83%e7%94%a8%e7%9b%91%e6%8e%a7%e8%84%9a%e6%9c%ac/
Chromium 内核浏览器下的隐身模式追踪
http://linux.im/2017/01/19/Chromium-incognito-mode-track.html
http://linux.im/2017/01/19/Chromium-incognito-mode-track.html
CES 2017大会上新登场的7种IoT安全产品技术
http://www.aqniu.com/tools-tech/22407.html
http://www.aqniu.com/tools-tech/22407.html
Hacking and Information Security learning platform
https://www.root-me.org/en/Challenges
https://www.root-me.org/en/Challenges
BlackHole重出江湖:一次针对专业军事论坛的“游击式”挂马事件分析报告
http://www.freebuf.com/articles/web/125662.html
http://www.freebuf.com/articles/web/125662.html
A Reverse Engineering Tool for py2exe applications.
https://github.com/4w4k3/rePy2exe
https://github.com/4w4k3/rePy2exe
Pwnhub之深入敌后writeup
http://0x48.pw/2017/01/17/0x2b/
http://0x48.pw/2017/01/17/0x2b/
msafe: 从底层分析PHP执行代码的安全性(混淆/审计)
https://github.com/yongchuan/msafe
https://github.com/yongchuan/msafe
Visual link analysis with Splunk (or SQL) and Maltego using the MDS
http://maltego.blogspot.jp/2017/01/visual-link-analysis-with-splunk-or-sql.html
http://maltego.blogspot.jp/2017/01/visual-link-analysis-with-splunk-or-sql.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第151期)
