SecWiki周刊(第170期)
2017/05/29-2017/06/04
安全资讯
国家标准《信息安全技术 数据出境安全评估指南》(草案)
http://www.tc260.org.cn/ueditor/jsp/upload/20170527/87491495878030102.pdf
http://www.tc260.org.cn/ueditor/jsp/upload/20170527/87491495878030102.pdf
2017年上半年重大黑客事件盘点
http://www.freebuf.com/news/135842.html
http://www.freebuf.com/news/135842.html
Announcing Google Capture the Flag 2017
https://security.googleblog.com/2017/06/announcing-google-capture-flag-2017.html
https://security.googleblog.com/2017/06/announcing-google-capture-flag-2017.html
安全技术
自律方能自由,《网络安全法》实施后的白帽子行为参考
https://sosly.me/index.php/2017/06/02/wangluoanquanfa/
https://sosly.me/index.php/2017/06/02/wangluoanquanfa/
A Dissection of the “EsteemAudit” Windows Remote Desktop Exploit
http://researchcenter.paloaltonetworks.com/2017/05/unit42-dissection-esteemaudit-windows-remote-desktop-exploit/
http://researchcenter.paloaltonetworks.com/2017/05/unit42-dissection-esteemaudit-windows-remote-desktop-exploit/
IOC sharing - we are doing it wrong
https://www.slideshare.net/CsabaFitzl/ioc-sharing-we-are-doing-it-wrong
https://www.slideshare.net/CsabaFitzl/ioc-sharing-we-are-doing-it-wrong
新一代数据中心网络安全产品的旁路部署方式探讨
http://blog.nsfocus.net/generation-data-center-product-bypass-deployment/
http://blog.nsfocus.net/generation-data-center-product-bypass-deployment/
Chrome漏洞可致恶意站点在用户在不知情的情况下录制音频和视频
http://www.freebuf.com/news/136015.html
http://www.freebuf.com/news/136015.html
GhostButt - CVE-2017-8291利用分析
http://paper.seebug.org/310/
http://paper.seebug.org/310/
信息安全与对抗技术竞赛(ISCC 2017)WriteUp(详细,通俗易懂)
http://www.freebuf.com/articles/others-articles/135825.html
http://www.freebuf.com/articles/others-articles/135825.html
Alex lonescu在#SyScan360# 上关于Windows Container机制的slide
http://www.alex-ionescu.com/publications/syscan/syscan2017.pdf
http://www.alex-ionescu.com/publications/syscan/syscan2017.pdf
浅谈跨站脚本攻击与防御
http://thief.one/2017/05/31/1/
http://thief.one/2017/05/31/1/
从蜜罐数据到SSH蜜罐的典型攻击分析
http://bobao.360.cn/learning/detail/3929.html
http://bobao.360.cn/learning/detail/3929.html
Pwning the Nexus ™ of Every Pixel ™
https://blog.flanker017.me/wp-content/uploads/2017/06/qmss2017.pdf
https://blog.flanker017.me/wp-content/uploads/2017/06/qmss2017.pdf
基于机器学习的分布式webshell检测系统-项目代码
https://github.com/Lingerhk/fshell
https://github.com/Lingerhk/fshell
安天移动安全2017年Q1移动终端钓鱼网站分析报告
http://www.freebuf.com/articles/terminal/135986.html
http://www.freebuf.com/articles/terminal/135986.html
初见 Chrome Headless Browser
https://lightless.me/archives/first-glance-at-chrome-headless-browser.html
https://lightless.me/archives/first-glance-at-chrome-headless-browser.html
初见 Chrome Headless 第二弹
https://lightless.me/archives/chrome-headless-second.html
https://lightless.me/archives/chrome-headless-second.html
如何保护网页按钮不被XSS自动点击
http://www.freebuf.com/articles/web/135759.html
http://www.freebuf.com/articles/web/135759.html
Python 第三方库安全: 钓鱼实战与数据统计分析
http://blog.fatezero.org/2017/06/01/package-fishing/
http://blog.fatezero.org/2017/06/01/package-fishing/
evilwaf: Web Application Firewall (WAF) Detection Tool
https://github.com/eviltik/evilwaf
https://github.com/eviltik/evilwaf
Linux曝新安全漏洞:用户执行sudo命令可获取root权限
http://www.freebuf.com/vuls/136156.html
http://www.freebuf.com/vuls/136156.html
基于机器学习的分布式webshell检测系统-特征工程(1)
http://www.s0nnet.com/archives/fshell-feature-1
http://www.s0nnet.com/archives/fshell-feature-1
CNCERT《2016年中国互联网网络安全报告》电子版
http://www.cert.org.cn/publish/main/upload/File/2016_cncert_report.pdf
http://www.cert.org.cn/publish/main/upload/File/2016_cncert_report.pdf
基于机器学习的分布式Webshell检测系统-绪论篇
http://www.s0nnet.com/archives/fshell
http://www.s0nnet.com/archives/fshell
TerraMaster NAS TOS <= 3.0.30 Unauthenticated RCE as Root
https://www.evilsocket.net/2017/05/30/Terramaster-NAS-Unauthenticated-RCE-as-root/#.WS1gUW36cHI.reddit
https://www.evilsocket.net/2017/05/30/Terramaster-NAS-Unauthenticated-RCE-as-root/#.WS1gUW36cHI.reddit
WAF Bypass at PHDays VII: Results and Answers
http://blog.ptsecurity.com/2017/06/waf-bypass-at-phdays-vii-results-and.html
http://blog.ptsecurity.com/2017/06/waf-bypass-at-phdays-vii-results-and.html
Black Hat USA 2017 兵工厂兵器列表
https://www.blackhat.com/us-17/arsenal.html
https://www.blackhat.com/us-17/arsenal.html
学点算法做安全之垃圾邮件识别(上)
http://www.freebuf.com/column/135863.html
http://www.freebuf.com/column/135863.html
分享一种可关闭大多数杀软的技术(对360安全卫士已验证成功)
http://www.freebuf.com/articles/system/135708.html
http://www.freebuf.com/articles/system/135708.html
【Twitter实时技术-2017.6.01】|行业资讯
https://xianzhi.aliyun.com/forum/read/1638.html
https://xianzhi.aliyun.com/forum/read/1638.html
Pentest BOX安装和使用
http://www.jianshu.com/p/022b0090d640
http://www.jianshu.com/p/022b0090d640
How-to-locate-CRED | ne2der
https://ne2der.github.io/2017/How-to-locate-CRED/
https://ne2der.github.io/2017/How-to-locate-CRED/
PR的盛宴之下,不能缺席的是技术的纯真——WannaCry事件之反思|技术讨论
https://xianzhi.aliyun.com/forum/read/1645.html
https://xianzhi.aliyun.com/forum/read/1645.html
HatCloud: Bypass CloudFlare with Ruby 真实 IP 查找
https://github.com/HatBashBR/HatCloud
https://github.com/HatBashBR/HatCloud
说说压力测试工具
https://huoding.com/2017/05/31/620
https://huoding.com/2017/05/31/620
SecWiki周刊(第169期)
https://www.sec-wiki.com/weekly/169
https://www.sec-wiki.com/weekly/169
Feedback on how build SMB Honeypot
http://benkowlab.blogspot.jp/2017/05/feedback-on-how-to-build-smb-honeypot.html
http://benkowlab.blogspot.jp/2017/05/feedback-on-how-to-build-smb-honeypot.html
常见无线DOS攻击
常见无线DOS攻击
常见无线DOS攻击
Study Notes of using BGInfo to bypass Application Whitelisting
https://3gstudent.github.io/3gstudent.github.io/Study-Notes-of-using-BGInfo-to-bypass-Application-Whitelisting/
https://3gstudent.github.io/3gstudent.github.io/Study-Notes-of-using-BGInfo-to-bypass-Application-Whitelisting/
Training: Security of BIOS/UEFI System Firmware from Attacker and Defender
https://github.com/advanced-threat-research/firmware-security-training
https://github.com/advanced-threat-research/firmware-security-training
EPOXY: Shielding Bare-Metal Embedded Systems
https://nebelwelt.net/publications/files/17SyScan360-presentation.pdf
https://nebelwelt.net/publications/files/17SyScan360-presentation.pdf
13th届Syclover承办的ctf比赛题解
https://github.com/SycloverSecurity/ctf/tree/master/13th_cuit_game
https://github.com/SycloverSecurity/ctf/tree/master/13th_cuit_game
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第170期)
