SecWiki周刊(第161期)
2017/03/27-2017/04/02
      安全资讯
    
About 90% of Smart TVs Vulnerable to Remote Hacking via Rogue TV Signals
https://www.bleepingcomputer.com/news/security/about-90-percent-of-smart-tvs-vulnerable-to-remote-hacking-via-rogue-tv-signals/
https://www.bleepingcomputer.com/news/security/about-90-percent-of-smart-tvs-vulnerable-to-remote-hacking-via-rogue-tv-signals/
专为安全讯飞输入法联手腾讯御安全提升体验
http://yaq.qq.com/blog/20
http://yaq.qq.com/blog/20
人物-netwind | 十年磨一剑
https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282344&idx=1&sn=5d27119c05fc14b25b4eb862f5fd7a63&scene=0#wechat_redirect
https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458282344&idx=1&sn=5d27119c05fc14b25b4eb862f5fd7a63&scene=0#wechat_redirect
看看Palo Alto Networks下一代安全平台的主要亮点
http://www.aqniu.com/tools-tech/23979.html
http://www.aqniu.com/tools-tech/23979.html
      安全技术
    
 CTF比赛总是输?你还差点Tricks
https://drive.google.com/file/d/0B4uxE69uafD5c0lLbGh1NjNoOGM/view
https://drive.google.com/file/d/0B4uxE69uafD5c0lLbGh1NjNoOGM/view
Docker 容器逃逸案例分析
https://yq.aliyun.com/articles/57803
https://yq.aliyun.com/articles/57803
本屌web漏洞扫描器思路 技巧总结(web爬虫篇-1)
http://weibo.com/ttarticle/p/show?id=2309404089676607652351
http://weibo.com/ttarticle/p/show?id=2309404089676607652351
《Web之困》读书笔记 | Pythoner
http://www.pythoner.com/386.html
http://www.pythoner.com/386.html
Sec-Box(信息安全工具集合)
https://github.com/tengzhangchao/Sec-Box
https://github.com/tengzhangchao/Sec-Box
谈谈 Vim 的几种文件备份
http://www.evilclay.com/2017/03/31/%E8%B0%88%E8%B0%88-Vim-%E7%9A%84%E5%87%A0%E7%A7%8D%E6%96%87%E4%BB%B6%E5%A4%87%E4%BB%BD/
http://www.evilclay.com/2017/03/31/%E8%B0%88%E8%B0%88-Vim-%E7%9A%84%E5%87%A0%E7%A7%8D%E6%96%87%E4%BB%B6%E5%A4%87%E4%BB%BD/
涉嫌入侵雅虎的俄罗斯黑客Alexsey Belan常用渗透手段(TTPs)
http://www.freebuf.com/news/130209.html
http://www.freebuf.com/news/130209.html
猪猪侠历次分享总结
https://github.com/ring04h/papers
https://github.com/ring04h/papers
Docker 镜像加速器
https://yq.aliyun.com/articles/29941
https://yq.aliyun.com/articles/29941
BalCCon2k16(video list)
https://ftp.lugons.org/BalCCon2k16/
https://ftp.lugons.org/BalCCon2k16/
dnsbrute: 域名爆破,基于api接口和字典
https://github.com/chuhades/dnsbrute
https://github.com/chuhades/dnsbrute
大华摄像头敏感信息泄露漏洞事件分析
http://paper.seebug.org/257/
http://paper.seebug.org/257/
Black Hat Asia 2017 PPT 下载
https://www.blackhat.com/asia-17/briefings.html
https://www.blackhat.com/asia-17/briefings.html
FileSensor: 基于爬虫的动态敏感文件探测工具
https://github.com/Xyntax/FileSensor
https://github.com/Xyntax/FileSensor
内网渗透思路整理与工具使用
http://bobao.360.cn/learning/detail/3683.html
http://bobao.360.cn/learning/detail/3683.html
EquationDrug rootkit analysis (mstcp32.sys) 
http://artemonsecurity.blogspot.com/2017/03/equationdrug-rootkit-analysis-mstcp32sys.html
http://artemonsecurity.blogspot.com/2017/03/equationdrug-rootkit-analysis-mstcp32sys.html
ring04h的白帽学习路线--20170325
https://github.com/ring04h/papers/blob/master/%E6%88%91%E7%9A%84%E7%99%BD%E5%B8%BD%E5%AD%A6%E4%B9%A0%E8%B7%AF%E7%BA%BF--20170325.pdf
https://github.com/ring04h/papers/blob/master/%E6%88%91%E7%9A%84%E7%99%BD%E5%B8%BD%E5%AD%A6%E4%B9%A0%E8%B7%AF%E7%BA%BF--20170325.pdf
Secure-Host-Baseline:Windows安全配置基线
https://github.com/iadgov/Secure-Host-Baseline
https://github.com/iadgov/Secure-Host-Baseline
Phantomjs正确打开方式
http://thief.one/2017/03/31/Phantomjs%E6%AD%A3%E7%A1%AE%E6%89%93%E5%BC%80%E6%96%B9%E5%BC%8F/
http://thief.one/2017/03/31/Phantomjs%E6%AD%A3%E7%A1%AE%E6%89%93%E5%BC%80%E6%96%B9%E5%BC%8F/
Shamoon2恶意样本技术分析与检测防护方案 
http://blog.nsfocus.net/shamoon2-malicious-sample-technology-analysis-detection-protection-program/
http://blog.nsfocus.net/shamoon2-malicious-sample-technology-analysis-detection-protection-program/
端点保护的那些事儿:盘点国外流行EDR产品
http://www.freebuf.com/articles/terminal/131024.html
http://www.freebuf.com/articles/terminal/131024.html
通过DNS日志来检测Java反序列化漏洞
http://gosecure.net/2017/03/22/detecting-deserialization-bugs-with-dns-exfiltration/
http://gosecure.net/2017/03/22/detecting-deserialization-bugs-with-dns-exfiltration/
APT29 Domain Fronting With TOR
https://www.fireeye.com/blog/threat-research/2017/03/apt29_domain_frontin.html
https://www.fireeye.com/blog/threat-research/2017/03/apt29_domain_frontin.html
白帽子Gr36手把手教你挖漏洞|漏洞研究
https://xianzhi.aliyun.com/forum/read/1427.html
https://xianzhi.aliyun.com/forum/read/1427.html
IIS6.0远程命令执行漏洞(CVE-2017-7269)
http://thief.one/2017/03/29/IIS6-0%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2017-7269/
http://thief.one/2017/03/29/IIS6-0%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2017-7269/
201703_BSidesCBR-ZXSecurity_Practical_GPS_Spoofing
https://zxsecurity.co.nz/presentations/201703_BSidesCBR-ZXSecurity_Practical_GPS_Spoofing.pdf
https://zxsecurity.co.nz/presentations/201703_BSidesCBR-ZXSecurity_Practical_GPS_Spoofing.pdf
八百元八核的服务器?二手服务器搭建指南
http://www.freebuf.com/geek/130366.html
http://www.freebuf.com/geek/130366.html
渗透测试中的Application Verifier(DoubleAgent利用介绍)
http://www.4hou.com/uncategorized/reverse/4005.html
http://www.4hou.com/uncategorized/reverse/4005.html
企业安全建设之使用开源软件建设大规模WAF集群
http://www.freebuf.com/special/127713.html
http://www.freebuf.com/special/127713.html
Hashview:Hashcat 密码破解的 Web 可视化和管理平台
http://www.mottoin.com/99205.html
http://www.mottoin.com/99205.html
intel_collection_tools: 多个威胁情报分析的脚本文件
https://github.com/wolfpack1/intel_collection_tools
https://github.com/wolfpack1/intel_collection_tools
另类追踪之——被“策反”的安全机制 
http://www.arkteam.net/?p=1646
http://www.arkteam.net/?p=1646
ANOMALI STAXX威胁情报订阅分析系统把玩 
http://phantom0301.cc/2017/03/27/staxx/
http://phantom0301.cc/2017/03/27/staxx/
学点算法搞安全之apriori
https://mp.weixin.qq.com/s/fPUaQLFAcM6dstoROnf3iA
https://mp.weixin.qq.com/s/fPUaQLFAcM6dstoROnf3iA
2017年6款最值得推荐的免费Linux防火墙
http://www.4hou.com/info/news/4018.html
http://www.4hou.com/info/news/4018.html
勾陈安全实验室每周技术分享材料
http://www.polaris-lab.com/index.php/share.html
http://www.polaris-lab.com/index.php/share.html
IIS 6.0 远程代码执行
https://github.com/edwardz246003/IIS_exploit/
https://github.com/edwardz246003/IIS_exploit/
某种流量劫持攻击的原理简述和演示
http://mp.weixin.qq.com/s/cq-Hg7iNB4FP06JKWS7Rjg
http://mp.weixin.qq.com/s/cq-Hg7iNB4FP06JKWS7Rjg
Referrer spoofing with iframe injection
http://paper.seebug.org/258/
http://paper.seebug.org/258/
Pwnbox: A Docker Container For Reverse Engineering & Exploitation!
https://github.com/superkojiman/pwnbox
https://github.com/superkojiman/pwnbox
SecWiki周刊(第160期)
https://www.sec-wiki.com/weekly/160
https://www.sec-wiki.com/weekly/160
Threat Landscape for Industrial Automation Systems in the second half of 2016 
https://ics-cert.kaspersky.com/reports/2017/03/28/threat-landscape-for-industrial-automation-systems-in-the-second-half-of-2016/
https://ics-cert.kaspersky.com/reports/2017/03/28/threat-landscape-for-industrial-automation-systems-in-the-second-half-of-2016/
基于MitM的RDP降级攻击
https://xianzhi.aliyun.com/forum/read/1434.html
https://xianzhi.aliyun.com/forum/read/1434.html
IoT设备程序开发及编译环境搭建初体验
http://www.freebuf.com/sectool/130091.html
http://www.freebuf.com/sectool/130091.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
    本期原文地址: SecWiki周刊(第161期)
