SecWiki周刊(第158期)
2017/03/06-2017/03/12
安全资讯
【漏洞预警】Struts 2 被爆远程命令执行漏洞 S2-045
http://www.mottoin.com/97954.html
http://www.mottoin.com/97954.html
深圳公司生产的物联网设备被发现后门
http://www.solidot.org/story?sid=51580
http://www.solidot.org/story?sid=51580
RootedCON 史上第一位中国演讲者的西班牙安全之旅
http://bobao.360.cn/news/detail/4036.html
http://bobao.360.cn/news/detail/4036.html
Hacker Selling Over 1 Million Decrypted Gmail and Yahoo Passwords On Dark Web
http://thehackernews.com/2017/03/gmail-yahoo-password-hack.html
http://thehackernews.com/2017/03/gmail-yahoo-password-hack.html
CIA黑电脑黑手机,哭泣天使秘密基地肉身攻击
http://mp.weixin.qq.com/s?__biz=MjM5NjAwNzI0MA==&mid=2651948229&idx=1&sn=e5b98d4f78fff701adf82ca4888f4a0a&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MjM5NjAwNzI0MA==&mid=2651948229&idx=1&sn=e5b98d4f78fff701adf82ca4888f4a0a&scene=0#wechat_redirect
垃圾邮件运营商泄漏了 13.7 亿电子邮件地址
http://www.solidot.org/story?sid=51597
http://www.solidot.org/story?sid=51597
每周安全资讯(2017.02.27—2017.03.05)
http://www.mottoin.com/97801.html
http://www.mottoin.com/97801.html
2017RSA大会参展心得分享会#之安博通CEO苏长君深度文稿分享
https://mp.weixin.qq.com/s?__biz=MzI0NjU3ODk1Nw==&mid=2247484894&idx=1&sn=841ef6bdfe405da88ff16d27acf1e3fe&scene=0#wechat_redirect
https://mp.weixin.qq.com/s?__biz=MzI0NjU3ODk1Nw==&mid=2247484894&idx=1&sn=841ef6bdfe405da88ff16d27acf1e3fe&scene=0#wechat_redirect
安全技术
Struts2 S2-045 漏洞检测利用工具 Exp GUI 版
https://github.com/Flyteas/Struts2-045-Exp
https://github.com/Flyteas/Struts2-045-Exp
DOM 型 XSS 解析
http://mp.weixin.qq.com/s/ia2itmIPdBwbVi57GAAeuw
http://mp.weixin.qq.com/s/ia2itmIPdBwbVi57GAAeuw
Struts2_045 Poc
http://thief.one/2017/03/07/Struts2-045%E6%BC%8F%E6%B4%9E/
http://thief.one/2017/03/07/Struts2-045%E6%BC%8F%E6%B4%9E/
【王者荣耀】C#与C++互相调用实现原理分析报告
http://gslab.qq.com/article-257-1.html
http://gslab.qq.com/article-257-1.html
【漏洞预警】CVE-2017-2636:linux 内核n_hdlc驱动模块 本地提权漏洞
http://bobao.360.cn/learning/detail/3586.html
http://bobao.360.cn/learning/detail/3586.html
金融行业企业安全运营之路2016.10.28
https://pan.baidu.com/s/1ch4ugI
https://pan.baidu.com/s/1ch4ugI
WEB端一句话管理系统
https://github.com/boy-hack/WebshellManager
https://github.com/boy-hack/WebshellManager
社会工程学密码分析
https://blog.yesfree.pw/?post=152
https://blog.yesfree.pw/?post=152
双尾蝎组织(APT-C-23)分析报告
https://ti.360.com/upload/report/file/APTSWXLVJ8fnjoxck.pdf
https://ti.360.com/upload/report/file/APTSWXLVJ8fnjoxck.pdf
DOTA2 NtHack外挂分析报告
http://gslab.qq.com/article-255-1.html
http://gslab.qq.com/article-255-1.html
bcrpscan: 智能备份文件扫描工具
https://github.com/secfree/bcrpscan
https://github.com/secfree/bcrpscan
外卖订单爬虫:美团,饿了么,百度
https://github.com/mudiyouyou/waimai-crawler
https://github.com/mudiyouyou/waimai-crawler
域渗透基础简单信息收集(基础篇)
https://xianzhi.aliyun.com/forum/read/805.html
https://xianzhi.aliyun.com/forum/read/805.html
Building a Sysmon Dashboard with an ELK Stack
https://cyberwardog.blogspot.com/2017/03/building-sysmon-dashboard-with-elk-stack.html
https://cyberwardog.blogspot.com/2017/03/building-sysmon-dashboard-with-elk-stack.html
movies-for-hackers: 黑客电影汇集
https://github.com/k4m4/movies-for-hackers
https://github.com/k4m4/movies-for-hackers
phptrace:跟踪PHP在运行时的函数调用、请求信息、执行流程
https://github.com/Qihoo360/phptrace
https://github.com/Qihoo360/phptrace
五步七招,开启最强DDoS攻防战!
http://mt.sohu.com/20170215/n480734620.shtml
http://mt.sohu.com/20170215/n480734620.shtml
Reverse Engineering Samsung S6 SBOOT
http://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-i.html
http://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-i.html
kali下安装Openvas
http://0cx.cc/Install_openvas_on_kali.jspx
http://0cx.cc/Install_openvas_on_kali.jspx
初创公司如何实现 Ansible 多机房自动部署发布
http://www.4hou.com/special/3701.html
http://www.4hou.com/special/3701.html
如何快速利用s02-45漏洞获取服务器权限
http://simeon.blog.51cto.com/18680/1904351
http://simeon.blog.51cto.com/18680/1904351
镇守最后一道防线:三种逃逸沙盒技术分析
http://www.4hou.com/technology/3665.html
http://www.4hou.com/technology/3665.html
webshell样本集合 (2011-2017)
https://www.secsilo.com/silo/view?id=8e6c876e8fa2d0c5379b0df5afed362b
https://www.secsilo.com/silo/view?id=8e6c876e8fa2d0c5379b0df5afed362b
中情局数千份机密文档泄露:各种0day工具、恶意程序应有尽有
http://www.freebuf.com/news/128802.html
http://www.freebuf.com/news/128802.html
Wordpress Username Enumeration 漏洞分析(CVE-2017-5487)
http://paper.seebug.org/239/
http://paper.seebug.org/239/
物联网设备Telnet口令快速扫描工具
http://www.freebuf.com/sectool/128661.html
http://www.freebuf.com/sectool/128661.html
hacking-guatemalas-dns-spying-on-active-directory-users-by-exploiting-a-tld-misc
https://thehackerblog.com/hacking-guatemalas-dns-spying-on-active-directory-users-by-exploiting-a-tld-misconfiguration/
https://thehackerblog.com/hacking-guatemalas-dns-spying-on-active-directory-users-by-exploiting-a-tld-misconfiguration/
Exploit kits: Winter 2017 review 恶意利用包概述
https://blog.malwarebytes.com/threat-analysis/2017/03/exploit-kits-winter-2017-review/
https://blog.malwarebytes.com/threat-analysis/2017/03/exploit-kits-winter-2017-review/
说说OSP在OpenVAS扫描体系内的担当
http://www.mottoin.com/98347.html
http://www.mottoin.com/98347.html
Drupal 7.X服务模块从反序列化到远程命令执行
http://www.mottoin.com/98140.html
http://www.mottoin.com/98140.html
#PCSA成员单位2017RSA大会参展心得分享会#深度文稿分享
http://mp.weixin.qq.com/s?__biz=MzI0NjU3ODk1Nw==&mid=2247484796&idx=1&sn=902d107f4ce6cba227bfe08f8b2ea289&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MzI0NjU3ODk1Nw==&mid=2247484796&idx=1&sn=902d107f4ce6cba227bfe08f8b2ea289&scene=0#wechat_redirect
intrigue-core: 基于扫描和接口的域名信息收集平台
https://github.com/intrigueio/intrigue-core
https://github.com/intrigueio/intrigue-core
NativePayload_DNS:通过DNS传输的后门Payload和绕过反病毒的项目
http://www.mottoin.com/98026.html
http://www.mottoin.com/98026.html
基于CMS插件的扫描器
https://github.com/droope/droopescan
https://github.com/droope/droopescan
【独家】我的企业安全推动方法
https://xianzhi.aliyun.com/forum/read/793.html
https://xianzhi.aliyun.com/forum/read/793.html
Ponemon Institute的《威胁情报的价值:北美和英国公司的研究报告》
http://mp.weixin.qq.com/s?__biz=MzI4NzU2NjU4NQ==&mid=2247484109&idx=1&sn=56b5d16517082096e982d7d823b87c8e&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MzI4NzU2NjU4NQ==&mid=2247484109&idx=1&sn=56b5d16517082096e982d7d823b87c8e&scene=0#wechat_redirect
隐匿的攻击之-Tor Fronting
http://www.4hou.com/technology/3516.html
http://www.4hou.com/technology/3516.html
S2-045 原理初步分析(CVE-2017-5638)
http://paper.seebug.org/241/
http://paper.seebug.org/241/
修改路由器的DNS后我做了什么?
http://t.tips/?action=show&id=23440
http://t.tips/?action=show&id=23440
金融企业安全建设探索之天眼系统
http://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247483712&idx=1&sn=19cefe91aa204505ad87a5150e011659&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&mid=2247483712&idx=1&sn=19cefe91aa204505ad87a5150e011659&scene=0#wechat_redirect
Content-Type: Malicious - New Apache Struts2 0-day Under Attack
http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html?m=1
http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html?m=1
一张图看懂CIA:攻击能力强是有原因的
http://www.4hou.com/info/3757.html
http://www.4hou.com/info/3757.html
CIA malware and hacking tools
https://news.ycombinator.com/item?id=13810015&from=timeline
https://news.ycombinator.com/item?id=13810015&from=timeline
程序员路上用到的各种优秀资料、神器及框架
https://github.com/stanzhai/be-a-professional-programmer
https://github.com/stanzhai/be-a-professional-programmer
看我如何发现Facebook注册用户手机号码
http://www.freebuf.com/vuls/128456.html
http://www.freebuf.com/vuls/128456.html
Spammers expose their entire operation through bad backups
http://www.csoonline.com/article/3176433/security/spammers-expose-their-entire-operation-through-bad-backups.html
http://www.csoonline.com/article/3176433/security/spammers-expose-their-entire-operation-through-bad-backups.html
隐私泄露:查开房网站的背后
http://www.freebuf.com/news/128317.html
http://www.freebuf.com/news/128317.html
近20万WiFi监控摄像头存在远程代码执行漏洞,可随意组建僵尸网络
http://www.4hou.com/info/news/3778.html
http://www.4hou.com/info/news/3778.html
SecWiki周刊(第157期)
https://www.sec-wiki.com/weekly/157
https://www.sec-wiki.com/weekly/157
如何打造一个能有效抵御“羊毛党”攻击的系统?
http://www.4hou.com/info/news/3714.html
http://www.4hou.com/info/news/3714.html
美情报系统身陷破窗效应:维基解密再曝CIA惊天内幕【附下载】
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655295027&idx=1&sn=82d6f63084d9409c588a27b447d62012&scene=0#wechat_redirect
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655295027&idx=1&sn=82d6f63084d9409c588a27b447d62012&scene=0#wechat_redirect
Top Exploit Kit Activity Roundup - Winter 2017 活跃漏洞利用包
https://www.zscaler.com/blogs/research/top-exploit-kit-activity-roundup-winter-2017
https://www.zscaler.com/blogs/research/top-exploit-kit-activity-roundup-winter-2017
APP安全在线检测系统汇总
http://www.jianshu.com/p/946bdea18f49
http://www.jianshu.com/p/946bdea18f49
Crypt0l0cker (TorrentLocker): Old Dog, New Tricks
http://blog.talosintelligence.com/2017/03/crypt0l0cker-torrentlocker-old-dog-new.html
http://blog.talosintelligence.com/2017/03/crypt0l0cker-torrentlocker-old-dog-new.html
Spammergate: The Fall of an Empire 14亿?
https://mackeeper.com/blog/post/339-spammergate-the-fall-of-an-empire
https://mackeeper.com/blog/post/339-spammergate-the-fall-of-an-empire
How I found a $5,000 Google Maps XSS (by fiddling with Protobuf) [fq]
https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff#.qd4siqiac
https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff#.qd4siqiac
Kerberoast攻击的另一种姿势
http://www.4hou.com/technology/3640.html
http://www.4hou.com/technology/3640.html
保护内网安全之提高Windows AD安全性(三)
http://www.4hou.com/technology/3456.html
http://www.4hou.com/technology/3456.html
2016年安天移动安全年报:威胁的全面迁徙
http://blog.avlsec.com/2017/03/4474/2016-security-report/
http://blog.avlsec.com/2017/03/4474/2016-security-report/
针对Neutrino僵尸程序新增加的保护层进行分析
http://www.4hou.com/technology/3740.html
http://www.4hou.com/technology/3740.html
7 ways to Exploit RFI Vulnerability
http://www.hackingarticles.in/7-ways-exploit-rfi-vulnerability/
http://www.hackingarticles.in/7-ways-exploit-rfi-vulnerability/
.NET逆向工程 (一)
http://www.4hou.com/technology/3641.html
http://www.4hou.com/technology/3641.html
intrigue-core:发现新的攻击面
http://www.mottoin.com/98263.html
http://www.mottoin.com/98263.html
The WikiLeaks CIA Dump Shows Hacking Secrets of Spies
https://www.wired.com/2017/03/cia-can-hack-phone-pc-tv-says-wikileaks/
https://www.wired.com/2017/03/cia-can-hack-phone-pc-tv-says-wikileaks/
EXIF分析与利用(上)
http://www.mottoin.com/97860.html
http://www.mottoin.com/97860.html
无线IP摄像机WIFICAM的OEM版本漏洞影响1250多个型号
http://www.mottoin.com/98152.html
http://www.mottoin.com/98152.html
WordPress Hacks: functions.php Backdoors
https://www.polaris64.net/blog/cyber-security/2017/wordpress-hacks-functions-php-backdoors
https://www.polaris64.net/blog/cyber-security/2017/wordpress-hacks-functions-php-backdoors
Development of an anomaly based web application firewall
https://github.com/matthiasmaes/AnomalyWebApplicationFirewall
https://github.com/matthiasmaes/AnomalyWebApplicationFirewall
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第158期)
