SecWiki周刊(第17期)
2014/06/23-2014/06/29
安全资讯
IDC:中国IT安全硬件、软件和服务全景图2014–2018 预测与分析
http://yepeng.blog.51cto.com/3101105/1430943
http://yepeng.blog.51cto.com/3101105/1430943
Gartner:2014年SIEM(安全信息与事件管理)市场分析
http://yepeng.blog.51cto.com/3101105/1431857
http://yepeng.blog.51cto.com/3101105/1431857
TimThumb plugin zero-day found, WordPress websites at risk
http://grahamcluley.com/2014/06/timthumb-plugin-zero-day-vulnerability-discovered-thousands-wordpress-websites-risk/?utm_source=rss&utm_medium=rss&utm_campaign=timthumb-plugin-zero-day-vulnerability-discovered-thousands-wordpress-websites-risk&omhide
http://grahamcluley.com/2014/06/timthumb-plugin-zero-day-vulnerability-discovered-thousands-wordpress-websites-risk/?utm_source=rss&utm_medium=rss&utm_campaign=timthumb-plugin-zero-day-vulnerability-discovered-thousands-wordpress-websites-risk&omhide
CCID: 2013-2014年度中国信息安全产品市场研究年度报告
http://yepeng.blog.51cto.com/3101105/1430933
http://yepeng.blog.51cto.com/3101105/1430933
安全技术
论黑产黑阔如何安全地转移赃款/洗钱?
http://drops.wooyun.org/news/2450
http://drops.wooyun.org/news/2450
XssHtml – 基于白名单的富文本XSS过滤类
http://www.freebuf.com/tools/37106.html
http://www.freebuf.com/tools/37106.html
Charles Web Debugging Proxy
http://www.charlesproxy.com/
http://www.charlesproxy.com/
用Burpsuite 来处理csrf token
http://drops.wooyun.org/tips/2460
http://drops.wooyun.org/tips/2460
CAPTCHA (驗證碼) OCR 前置處理
http://steven5538.hack-stuff.com/2014/06/captcha-ocr-python.html
http://steven5538.hack-stuff.com/2014/06/captcha-ocr-python.html
Spark:一个高效的分布式计算系统
http://tech.uc.cn/?p=2116
http://tech.uc.cn/?p=2116
Interactive Data Visualization for the Web
http://chimera.labs.oreilly.com/books/1230000000345/
http://chimera.labs.oreilly.com/books/1230000000345/
odat:Oracle Database Attacking Tool
https://github.com/quentinhardy/odat
https://github.com/quentinhardy/odat
一个巧妙的sshd后门
http://www.icylife.net/blog/?p=950
http://www.icylife.net/blog/?p=950
baseline_testing:Linux的配置检查工具
https://github.com/smarttang/baseline_testing
https://github.com/smarttang/baseline_testing
mysql新型报错注入(mysql无符号整数溢出)
http://www.jinglingshu.org/?p=7343
http://www.jinglingshu.org/?p=7343
Iscc驱动漏洞题目分析与利用
http://www.91ri.org/9399.html
http://www.91ri.org/9399.html
Mimikatz ON Metasploit
http://drops.wooyun.org/tips/2443
http://drops.wooyun.org/tips/2443
构建一个类timeline系统的架构设计
http://neoremind.net/2014/06/%e6%9e%84%e5%bb%ba%e4%b8%80%e4%b8%aa%e7%b1%bbtimeline%e7%b3%bb%e7%bb%9f%e7%9a%84%e6%9e%b6%e6%9e%84%e8%ae%be%e8%ae%a1/
http://neoremind.net/2014/06/%e6%9e%84%e5%bb%ba%e4%b8%80%e4%b8%aa%e7%b1%bbtimeline%e7%b3%bb%e7%bb%9f%e7%9a%84%e6%9e%b6%e6%9e%84%e8%ae%be%e8%ae%a1/
Attacking Android browsers via intent scheme URLs
http://www.mbsd.jp/Whitepaper/IntentScheme.pdf
http://www.mbsd.jp/Whitepaper/IntentScheme.pdf
Aircrack-ng Suite Cheatsheet
https://evilzone.org/security-tools/aircrack-ng-suite-cheatsheet/
https://evilzone.org/security-tools/aircrack-ng-suite-cheatsheet/
awesome-sysadmin
https://github.com/kahun/awesome-sysadmin
https://github.com/kahun/awesome-sysadmin
malcom:Malware Communications Analyzer
https://github.com/tomchop/malcom
https://github.com/tomchop/malcom
Linux被DDOS&CC攻击解决实例
http://drops.wooyun.org/tips/2457
http://drops.wooyun.org/tips/2457
php 依赖管理工具 composer 中文视频教程
http://www.kittencup.com/composer-%E4%B8%AD%E6%96%87%E8%A7%86%E9%A2%91%E7%9B%AE%E5%BD%95%E5%85%8D%E8%B4%B9%E3%80%81%E8%B6%85%E6%B8%85/
http://www.kittencup.com/composer-%E4%B8%AD%E6%96%87%E8%A7%86%E9%A2%91%E7%9B%AE%E5%BD%95%E5%85%8D%E8%B4%B9%E3%80%81%E8%B6%85%E6%B8%85/
drozer- security and attack framework for Android
http://www.sectechno.com/2014/06/22/drozer-security-and-attack-framework-for-android/
http://www.sectechno.com/2014/06/22/drozer-security-and-attack-framework-for-android/
C99.PHP webshell 绕过登陆密码漏洞
http://www.5luyu.cn/archives/69/
http://www.5luyu.cn/archives/69/
一套标准的安卓挂马代码
http://weibo.com/p/1001603724694418249344
http://weibo.com/p/1001603724694418249344
Hacking with Android Part 2: Network Spoofer (HD)
https://www.youtube.com/watch?v=sm-llBJA8EA
https://www.youtube.com/watch?v=sm-llBJA8EA
Evil HTTP Compression - Compression Bombs
http://www.cyberis.co.uk/downloads/Cyberis%20Whitepaper%20-%20Evil%20HTTP%20Compression.pdf
http://www.cyberis.co.uk/downloads/Cyberis%20Whitepaper%20-%20Evil%20HTTP%20Compression.pdf
Linux 通配符可能产生的问题
http://drops.wooyun.org/papers/2448
http://drops.wooyun.org/papers/2448
MalwareResourceScanner
https://github.com/edix/MalwareResourceScanner
https://github.com/edix/MalwareResourceScanner
Bypassing Windows 8.1 Mitigations using Unsafe COM Objects
http://www.contextis.com/blog/windows-mitigaton-bypass/
http://www.contextis.com/blog/windows-mitigaton-bypass/
VRT: Exceptional behavior: the Windows 8.1 X64 SEH Implementation
http://vrt-blog.snort.org/2014/06/exceptional-behavior-windows-81-x64-seh.html
http://vrt-blog.snort.org/2014/06/exceptional-behavior-windows-81-x64-seh.html
Detecting Keyloggers on Dynamic Analysis Systems
http://labs.lastline.com/detecting-keyloggers-on-dynamic-analysis-systems
http://labs.lastline.com/detecting-keyloggers-on-dynamic-analysis-systems
CS161 Syllabus
http://inst.eecs.berkeley.edu/~cs161/fa08/syllabus.html
http://inst.eecs.berkeley.edu/~cs161/fa08/syllabus.html
Ubuntu 安装使用 DNSCrypt
http://www.slblog.net/2014/06/install-dnscrypt-on-ubuntu/
http://www.slblog.net/2014/06/install-dnscrypt-on-ubuntu/
prowler:Base Code for P2P Network Crawlers
https://github.com/tillmannw/prowler
https://github.com/tillmannw/prowler
Searchcode: 源代码搜索利器
https://searchcode.com/
https://searchcode.com/
基于AngularJS的企业软件前端架构
http://www.infoq.com/cn/presentations/frontend-architecture-based-on-angularjs
http://www.infoq.com/cn/presentations/frontend-architecture-based-on-angularjs
Android渗透测试工具大合集
http://www.freebuf.com/tools/36880.html
http://www.freebuf.com/tools/36880.html
主流APT解决方案对比分析
http://safe.zol.com.cn/463/4635852.html
http://safe.zol.com.cn/463/4635852.html
fullPage.js:jQuery全屏滚动插件
https://github.com/alvarotrigo/fullPage.js
https://github.com/alvarotrigo/fullPage.js
Offensive Computer Security Home Page
http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/lectures.html
http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/lectures.html
Beta Version of VMRay Analyzer
http://www.vmray.com/beta-version-of-vmray-analyzer/
http://www.vmray.com/beta-version-of-vmray-analyzer/
CUIT 2014 Writeup
http://www.91ri.org/9482.html
http://www.91ri.org/9482.html
Visualizing Algorithms
http://bost.ocks.org/mike/algorithms/
http://bost.ocks.org/mike/algorithms/
跟python有关的东西
http://iteches.com/archives/63840
http://iteches.com/archives/63840
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第17期)
