SecWiki周刊(第157期)
2017/02/27-2017/03/05
安全资讯
Palo Alto 1.05 亿美元收购 LightCyber 增加行为攻击检测能力
http://app.myzaker.com/news/article.php?pk=58b649b11bc8e0b562000001
http://app.myzaker.com/news/article.php?pk=58b649b11bc8e0b562000001
腾讯CTF(TCTF)大赛正式启航,国际顶级高手等你来战!
http://mp.weixin.qq.com/s/vTt-KHFwE7hrvnPwLFiEGQ
http://mp.weixin.qq.com/s/vTt-KHFwE7hrvnPwLFiEGQ
波音公司员工泄露了36000名同事的个人信息
http://www.mottoin.com/97371.html
http://www.mottoin.com/97371.html
Seebug漏洞平台2016十大漏洞
http://weibo.com/ttarticle/p/show?id=2309404079780348744123
http://weibo.com/ttarticle/p/show?id=2309404079780348744123
川普已被玩坏:头像被敲诈病毒拿来恶搞
http://www.mottoin.com/97208.html
http://www.mottoin.com/97208.html
黑客小说 杀手(第十四章 暗流)
http://www.jianshu.com/p/6a25f14a42de
http://www.jianshu.com/p/6a25f14a42de
美国国土安全部使用网络杀伤链分析总统大选黑客事件
http://www.aqniu.com/industry/23163.html
http://www.aqniu.com/industry/23163.html
瑞星反诈骗报告:不法分子利用“高额奖金”骗取用户隐私信息
http://www.mottoin.com/97439.html
http://www.mottoin.com/97439.html
Google Summer of Code 2017
https://summerofcode.withgoogle.com/
https://summerofcode.withgoogle.com/
安全技术
NodeJS反序列化RCE漏洞的完美利用
http://www.4hou.com/technology/3457.html
http://www.4hou.com/technology/3457.html
新型Web攻击技术——Web缓存欺骗
http://www.4hou.com/technology/3536.html
http://www.4hou.com/technology/3536.html
Undocumented Backdoor Account in DBLTek GoIP
https://www.trustwave.com/Resources/SpiderLabs-Blog/Undocumented-Backdoor-Account-in-DBLTek-GoIP/
https://www.trustwave.com/Resources/SpiderLabs-Blog/Undocumented-Backdoor-Account-in-DBLTek-GoIP/
JEXBOSS V1.2.0 – JBOSS VERIFY AND EXPLOITATION TOOL
http://seclist.us/jexboss-v1-2-0-jboss-verify-and-exploitation-tool.html?utm_source=feedburner&utm_medium=twitter&utm_campaign=Feed%3A+seclist%2Ffeed+%28Security+List+Network%E2%84%A2%29
http://seclist.us/jexboss-v1-2-0-jboss-verify-and-exploitation-tool.html?utm_source=feedburner&utm_medium=twitter&utm_campaign=Feed%3A+seclist%2Ffeed+%28Security+List+Network%E2%84%A2%29
Web Cache Deception Attack
http://omergil.blogspot.jp/2017/02/web-cache-deception-attack.html
http://omergil.blogspot.jp/2017/02/web-cache-deception-attack.html
解密 RubyEncoder
http://blog.fatezero.org/2017/02/26/decrypt-rubyencoder/
http://blog.fatezero.org/2017/02/26/decrypt-rubyencoder/
Ponemon:优化SIEM时所面临的挑战
http://yepeng.blog.51cto.com/3101105/1903177
http://yepeng.blog.51cto.com/3101105/1903177
DokuWiki fetch.php SSRF漏洞与tok安全验证绕过分析
http://paper.seebug.org/230/
http://paper.seebug.org/230/
Mysql数据库反弹端口连接提权
https://xianzhi.aliyun.com/forum/read/774.html
https://xianzhi.aliyun.com/forum/read/774.html
我眼中的渗透测试信息搜集
http://bbs.ichunqiu.com/thread-16020-1-1.html
http://bbs.ichunqiu.com/thread-16020-1-1.html
对 Parrot SkyController 无人机固件的逆向工程
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282109&idx=1&sn=81a84f51043fbed4c391ab4cc3d9d293&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282109&idx=1&sn=81a84f51043fbed4c391ab4cc3d9d293&scene=0#wechat_redirect
在 Windows 10 的 Linux 子系统(WSL)中运行 Kali
http://www.mottoin.com/97429.html
http://www.mottoin.com/97429.html
隐匿的攻击之-Domain Fronting
https://evi1cg.me/archives/Domain_Fronting.html
https://evi1cg.me/archives/Domain_Fronting.html
BurpSmartBuster:用于收集与发现文件目录和后缀的插件
http://www.mottoin.com/97437.html
http://www.mottoin.com/97437.html
巡风在隔离网络环境下的离线更新方案
http://www.mottoin.com/97143.html
http://www.mottoin.com/97143.html
Termineter – Smart Meter Security Testing Framework
http://www.darknet.org.uk/2017/02/termineter-smart-meter-security-testing-framework/
http://www.darknet.org.uk/2017/02/termineter-smart-meter-security-testing-framework/
cgPwn:用于硬件安全测试(Fuzzing,SymEx,Exploit)的轻量级虚拟机
http://www.mottoin.com/97672.html
http://www.mottoin.com/97672.html
一个有意思的Apple XSS(CVE-2016-7762)的 分析与思考
http://avfisher.win/archives/660
http://avfisher.win/archives/660
AWS gamified security challenges
http://flaws.cloud/
http://flaws.cloud/
KindEditor开源富文本编辑框架XSS漏洞
http://www.freebuf.com/articles/web/128076.html
http://www.freebuf.com/articles/web/128076.html
基于Jenkins和Kubernetes的CI工作流
http://mp.weixin.qq.com/s?__biz=MzA5OTAyNzQ2OA==&mid=2649693456&idx=1&sn=b36ed8057c23113da2396b77208689f1&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MzA5OTAyNzQ2OA==&mid=2649693456&idx=1&sn=b36ed8057c23113da2396b77208689f1&scene=0#wechat_redirect
Profiling a .NET Core Application on Linux
http://blogs.microsoft.co.il/sasha/2017/02/27/profiling-a-net-core-application-on-linux/
http://blogs.microsoft.co.il/sasha/2017/02/27/profiling-a-net-core-application-on-linux/
CVE-2016-9892 - Remote Code Execution as Root via ESET Endpoint Antivirus 6
http://seclists.org/fulldisclosure/2017/Feb/68
http://seclists.org/fulldisclosure/2017/Feb/68
Phantomjs爬过的那些坑
http://thief.one/2017/03/01/Phantomjs%E7%88%AC%E8%BF%87%E7%9A%84%E9%82%A3%E4%BA%9B%E5%9D%91/
http://thief.one/2017/03/01/Phantomjs%E7%88%AC%E8%BF%87%E7%9A%84%E9%82%A3%E4%BA%9B%E5%9D%91/
保护内网安全之提高Windows AD安全性 (二)
http://www.4hou.com/technology/3455.html
http://www.4hou.com/technology/3455.html
FileSensor:基于爬虫的动态敏感文件探测工具
http://www.mottoin.com/97353.html
http://www.mottoin.com/97353.html
低成本安全硬件(二)——RFID on PN532
http://jia1s.info/rfid-on-rpi/
http://jia1s.info/rfid-on-rpi/
动态IP解决新浪的反爬虫机制
https://github.com/szcf-weiya/SinaSpider
https://github.com/szcf-weiya/SinaSpider
Mobile-Security-Framework-MobSF
https://github.com/MobSF/Mobile-Security-Framework-MobSF
https://github.com/MobSF/Mobile-Security-Framework-MobSF
各种形式隐写工具合集
http://www.mottoin.com/97414.html
http://www.mottoin.com/97414.html
Phishers unleash simple but effective social engineering techniques using PDF at
https://blogs.technet.microsoft.com/mmpc/2017/01/26/phishers-unleash-simple-but-effective-social-engineering-techniques-using-pdf-attachments/?platform=hootsuite
https://blogs.technet.microsoft.com/mmpc/2017/01/26/phishers-unleash-simple-but-effective-social-engineering-techniques-using-pdf-attachments/?platform=hootsuite
Ok Google, Give Me All Your Internal DNS Information!
https://www.rcesecurity.com/2017/03/ok-google-give-me-all-your-internal-dns-information/
https://www.rcesecurity.com/2017/03/ok-google-give-me-all-your-internal-dns-information/
Getting read access on TGI Friday’s online ordering system
https://www.adamlogue.com/getting-read-access-on-tgi-fridays-online-ordering-system-fixed/
https://www.adamlogue.com/getting-read-access-on-tgi-fridays-online-ordering-system-fixed/
nosqlinjection_wordlists: payload to test NoSQL Injections
https://github.com/cr0hn/nosqlinjection_wordlists
https://github.com/cr0hn/nosqlinjection_wordlists
企业安全建设之浅谈数据防泄露
http://mp.weixin.qq.com/s/vbTxrkLXu1ES4mqetNuY_Q
http://mp.weixin.qq.com/s/vbTxrkLXu1ES4mqetNuY_Q
Android 渗透测试学习手册(九)编写渗透测试报告
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282109&idx=2&sn=a31aaf55970d2b58d2231406feccaa12&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282109&idx=2&sn=a31aaf55970d2b58d2231406feccaa12&scene=0#wechat_redirect
全球MySQL数据库沦为新一轮勒索软件攻击目标
http://www.4hou.com/info/news/3523.html
http://www.4hou.com/info/news/3523.html
六种常用的网络流量特征提取工具
http://mp.weixin.qq.com/s/QsteT_86uwViXSFXspJHJQ
http://mp.weixin.qq.com/s/QsteT_86uwViXSFXspJHJQ
SecWiki周刊(第156期)
https://www.sec-wiki.com/weekly/156
https://www.sec-wiki.com/weekly/156
Gathering Email Information Tool
https://github.com/m4ll0k/infoga
https://github.com/m4ll0k/infoga
The Evolution of Mobile Security Through the Years 地址位置 应用 摄像头
https://securingtomorrow.mcafee.com/consumer/mobile-security/mobile-security-evolution/
https://securingtomorrow.mcafee.com/consumer/mobile-security/mobile-security-evolution/
第三届XCTF——郑州站ZCTF第一名战队Writeup
http://bobao.360.cn/ctf/detail/186.html
http://bobao.360.cn/ctf/detail/186.html
通过双重跳板漫游隔离内网
https://xianzhi.aliyun.com/forum/read/768.html
https://xianzhi.aliyun.com/forum/read/768.html
MySQL Sniffer :基于 MySQL 协议的抓包工具
https://github.com/Qihoo360/mysql-sniffer/blob/master/README_CN.md
https://github.com/Qihoo360/mysql-sniffer/blob/master/README_CN.md
注意,你注册的假1024可能就是它
http://weibo.com/ttarticle/p/show?id=2309404080137598567962
http://weibo.com/ttarticle/p/show?id=2309404080137598567962
实战NTP放大攻击防御方案
https://dev.21ds.cn/article/41.html
https://dev.21ds.cn/article/41.html
Detecting and Preventing Spear Pishing Attacks Using DNS
https://n0where.net/domain-name-typosquatting-crazyparser/
https://n0where.net/domain-name-typosquatting-crazyparser/
Bypassing User Account Control (UAC) using TpmInit.exe
http://uacmeltdown.blogspot.jp/
http://uacmeltdown.blogspot.jp/
Android 渗透测试学习手册(八)ARM 利用
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282106&idx=1&sn=5e9e02864dfedfd3d8a69e8a693ce18e&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282106&idx=1&sn=5e9e02864dfedfd3d8a69e8a693ce18e&scene=0#wechat_redirect
FB Event Map API
https://github.com/mromnia/fb_event_map
https://github.com/mromnia/fb_event_map
Two new Mac backdoors discovered
https://blog.malwarebytes.com/cybercrime/2017/03/two-new-mac-backdoors-discovered/
https://blog.malwarebytes.com/cybercrime/2017/03/two-new-mac-backdoors-discovered/
百度旗下网站暗藏恶意代码——劫持用户电脑疯狂“收割”流量
http://www.4hou.com/technology/3546.html
http://www.4hou.com/technology/3546.html
Mobile malware evolution 2016 移动恶意分析总结
https://securelist.com/analysis/kaspersky-security-bulletin/77681/mobile-malware-evolution-2016/
https://securelist.com/analysis/kaspersky-security-bulletin/77681/mobile-malware-evolution-2016/
Android 渗透测试学习手册(七)不太知名的 Android 漏洞
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282104&idx=1&sn=00918a40555200377ec83a20b6f86101&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282104&idx=1&sn=00918a40555200377ec83a20b6f86101&scene=0#wechat_redirect
Flask的url_for重定向问题和相应源码分析
http://jiayi.space/post/flaskde-url_forzhong-ding-xiang-wen-ti-he-xiang-ying-yuan-ma-fen-xi
http://jiayi.space/post/flaskde-url_forzhong-ding-xiang-wen-ti-he-xiang-ying-yuan-ma-fen-xi
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
https://labs.detectify.com/2017/02/28/hacking-slack-using-postmessage-and-websocket-reconnect-to-steal-your-precious-token/
https://labs.detectify.com/2017/02/28/hacking-slack-using-postmessage-and-websocket-reconnect-to-steal-your-precious-token/
An advanced fuzzing framework designed to find vulnerabilities in C/C++ code
https://github.com/oxagast/ansvif
https://github.com/oxagast/ansvif
subdomain3:a simple and fast tool for bruting subdomains
https://github.com/yanxiu0614/subdomain3
https://github.com/yanxiu0614/subdomain3
Xpath Automated SQL Injection
https://github.com/r0oth3x49/Xpath
https://github.com/r0oth3x49/Xpath
Useful Windows Command Line Tricks
http://blog.kulshitsky.com/2017/02/useful-windows-command-line-tricks.html?m=1
http://blog.kulshitsky.com/2017/02/useful-windows-command-line-tricks.html?m=1
SQL Injection Vulnerability in NextGEN Gallery for WordPress
https://blog.sucuri.net/2017/02/sql-injection-vulnerability-nextgen-gallery-wordpress.html
https://blog.sucuri.net/2017/02/sql-injection-vulnerability-nextgen-gallery-wordpress.html
机器人也饱受安全漏洞折磨
http://mp.weixin.qq.com/s/4DWp9K8GsJm_6ymiiAlerQ
http://mp.weixin.qq.com/s/4DWp9K8GsJm_6ymiiAlerQ
Password History Analysis
https://blog.didierstevens.com/2017/02/28/password-history-analysis/
https://blog.didierstevens.com/2017/02/28/password-history-analysis/
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第157期)
