SecWiki周刊(第175期)
2017/07/03-2017/07/09
安全资讯
C3安全峰会主论坛精华内容一览
http://www.aqniu.com/industry/26476.html
http://www.aqniu.com/industry/26476.html
2017年关于数据泄露成本的研究:全球概览
https://mp.weixin.qq.com/s?__biz=MzI4NzU2NjU4NQ==&mid=2247485064&idx=1&sn=f28525df2576bf24416665356efb08c3&scene=0#wechat_redirect
https://mp.weixin.qq.com/s?__biz=MzI4NzU2NjU4NQ==&mid=2247485064&idx=1&sn=f28525df2576bf24416665356efb08c3&scene=0#wechat_redirect
全球钓鱼网站调查报告:近半恶意注册域名针对国内银行企业
http://www.4hou.com/info/news/6075.html
http://www.4hou.com/info/news/6075.html
反病毒还是留后门?卡巴斯基反病毒服务器被爆多个漏洞
http://www.4hou.com/vulnerable/6093.html
http://www.4hou.com/vulnerable/6093.html
走近比特币:一个故事看懂“区块链”
http://www.4hou.com/info/news/6152.html
http://www.4hou.com/info/news/6152.html
揭秘浙大“黑客战队”:战个痛快
http://weibo.com/ttarticle/p/show?id=2309404126436884647639
http://weibo.com/ttarticle/p/show?id=2309404126436884647639
(ISC)²亚太区信息安全峰会召开(附:信息安全领袖成就奖完整名单)
http://www.aqniu.com/industry/26470.html
http://www.aqniu.com/industry/26470.html
安全技术
Apple官方的安全编码指南
https://developer.apple.com/library/content/documentation/Security/Conceptual/SecureCodingGuide/Introduction.html
https://developer.apple.com/library/content/documentation/Security/Conceptual/SecureCodingGuide/Introduction.html
w8scan 一款模仿bugscan的扫描器
https://github.com/boy-hack/w8scan
https://github.com/boy-hack/w8scan
文档型漏洞攻击研究报告
https://5d07da.lt.yunpan.cn/lk/cbPND6mUgvm7W
https://5d07da.lt.yunpan.cn/lk/cbPND6mUgvm7W
struts2_check: 识别目标网站是否采用Struts2框架
https://github.com/coffeehb/struts2_check
https://github.com/coffeehb/struts2_check
企业要如何防御恶意 bot 流量?
http://www.4hou.com/info/news/6102.html
http://www.4hou.com/info/news/6102.html
利用SSRF漏洞滥用AWS元数据服务
http://www.4hou.com/vulnerable/5767.html
http://www.4hou.com/vulnerable/5767.html
[EXPTECH系列]从boot.img中提取kernel
http://ne2der.com/2017/EXPTECH-Extract-Image-from-bootimg/
http://ne2der.com/2017/EXPTECH-Extract-Image-from-bootimg/
Vulnerability-Exploit-Fuzz-Mitigation 漏洞利用与挖掘思维导图
https://github.com/SilverMoonSecurity/Security-misc
https://github.com/SilverMoonSecurity/Security-misc
盗刷银行卡竟如此简单?10秒复制银行卡原理分享
http://www.freebuf.com/articles/wireless/136991.html
http://www.freebuf.com/articles/wireless/136991.html
Prowler: AWS CIS Benchmark Tool 亚马逊基线检测工具
https://github.com/Alfresco/prowler
https://github.com/Alfresco/prowler
MOSEC-2017: 第三届 MOSEC 移动安全技术峰会 PPT
https://github.com/aozhimin/MOSEC-2017/tree/def4e06f3d1e80115c8066281a1b6261368cc105
https://github.com/aozhimin/MOSEC-2017/tree/def4e06f3d1e80115c8066281a1b6261368cc105
PowerShell攻防进阶篇:nishang工具用法详解
http://www.4hou.com/technology/5962.html
http://www.4hou.com/technology/5962.html
利用一个堆溢出漏洞实现VMware虚拟机逃逸
https://zhuanlan.zhihu.com/p/27733895?from=timeline&isappinstalled=0
https://zhuanlan.zhihu.com/p/27733895?from=timeline&isappinstalled=0
渗透技巧——Windows日志的删除与绕过
https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E6%97%A5%E5%BF%97%E7%9A%84%E5%88%A0%E9%99%A4%E4%B8%8E%E7%BB%95%E8%BF%87/
https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E6%97%A5%E5%BF%97%E7%9A%84%E5%88%A0%E9%99%A4%E4%B8%8E%E7%BB%95%E8%BF%87/
2017云盾先知 PPT #密码: ns3x
https://pan.baidu.com/s/1bp6HUm7#list/path=%2F
https://pan.baidu.com/s/1bp6HUm7#list/path=%2F
[漏洞分析] Struts2高危漏洞S2-048分析
http://bobao.360.cn/learning/detail/4078.html
http://bobao.360.cn/learning/detail/4078.html
基于Elasticsearch构建千亿流量日志搜索平台实战
https://mp.weixin.qq.com/s?__biz=MzAwMDU1MTE1OQ==&mid=2653548856&idx=1&sn=eda083752319e317c6903017c84d849d&scene=0#wechat_redirect
https://mp.weixin.qq.com/s?__biz=MzAwMDU1MTE1OQ==&mid=2653548856&idx=1&sn=eda083752319e317c6903017c84d849d&scene=0#wechat_redirect
都说打印机不安全,那究竟有多少种黑掉它的姿势呢?
http://www.4hou.com/info/industry/5489.html
http://www.4hou.com/info/industry/5489.html
从形式化方法、程序分析到数据分析--二进制漏洞检测实例
http://www.edu.cn/xxh/spkt/aq/201707/t20170706_1538333.shtml
http://www.edu.cn/xxh/spkt/aq/201707/t20170706_1538333.shtml
面向全流量的网络APT智能检测方法
http://www.edu.cn/xxh/spkt/aq/201705/t20170512_1515501.shtml
http://www.edu.cn/xxh/spkt/aq/201705/t20170512_1515501.shtml
Windows 日志攻防之攻击篇
http://www.4hou.com/system/6036.html
http://www.4hou.com/system/6036.html
ExPetr会是BlackEnergy的变异体吗?
http://www.4hou.com/typ/6017.html
http://www.4hou.com/typ/6017.html
Struts2再爆远程命令执行漏洞!Struts2-048 Poc Shell及防御修复方案抢先看
https://bbs.ichunqiu.com/thread-24504-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-24504-1-1.html?from=sec
一封伪造邮件引发的“探索”(涉及钓鱼邮件、SPF和DKIM等)
http://www.freebuf.com/articles/web/138764.html
http://www.freebuf.com/articles/web/138764.html
老听别人说加密算法,现在给你个机会深入了解下
http://www.freebuf.com/articles/database/138734.html
http://www.freebuf.com/articles/database/138734.html
Struts(S2-048)远程命令执行漏洞分析
http://blog.topsec.com.cn/ad_lab/strutss2-048%e8%bf%9c%e7%a8%8b%e5%91%bd%e4%bb%a4%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e%e5%88%86%e6%9e%90/
http://blog.topsec.com.cn/ad_lab/strutss2-048%e8%bf%9c%e7%a8%8b%e5%91%bd%e4%bb%a4%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e%e5%88%86%e6%9e%90/
《安天365安全研究》-2017-06
https://pan.baidu.com/s/1hscLrb2
https://pan.baidu.com/s/1hscLrb2
通过样本分析之三CVE-2011-0104
https://xianzhi.aliyun.com/forum/read/1811.html
https://xianzhi.aliyun.com/forum/read/1811.html
专为渗透测试人员设计的Python工具大合集
http://www.freebuf.com/sectool/138779.html
http://www.freebuf.com/sectool/138779.html
ThinkPHP5 SQL注入漏洞 && PDO真/伪预处理分析
https://www.leavesongs.com/PENETRATION/thinkphp5-in-sqlinjection.html
https://www.leavesongs.com/PENETRATION/thinkphp5-in-sqlinjection.html
如何判断微信聊天记录被删除过?
https://mp.weixin.qq.com/s?__biz=MzI3Mjc0MjkwMQ==&mid=2247483675&idx=1&sn=669c2fe44425310e86b003c6ac41acb7&scene=0#wechat_redirect
https://mp.weixin.qq.com/s?__biz=MzI3Mjc0MjkwMQ==&mid=2247483675&idx=1&sn=669c2fe44425310e86b003c6ac41acb7&scene=0#wechat_redirect
ENETRATION TESTING AWS STORAGE: KICKING THE S3 BUCKET
https://rhinosecuritylabs.com/penetration-testing/penetration-testing-aws-storage/
https://rhinosecuritylabs.com/penetration-testing/penetration-testing-aws-storage/
USBLogView — 查看USB端口插过的相关硬件设备
http://www.nirsoft.net/utils/usb_log_view.html
http://www.nirsoft.net/utils/usb_log_view.html
DropboxC2C: Dropbox Infrastructure for command and control operations
https://github.com/0x09AL/DropboxC2C
https://github.com/0x09AL/DropboxC2C
Petya最新进展之利用M.E.Doc后门
http://www.4hou.com/technology/6111.html
http://www.4hou.com/technology/6111.html
Thinkphp5X设计缺陷导致泄漏数据库账户密码
https://xianzhi.aliyun.com/forum/read/1813.html
https://xianzhi.aliyun.com/forum/read/1813.html
The Stack Clash Exploit
https://www.qualys.com/research/security-advisories/
https://www.qualys.com/research/security-advisories/
新型物联网蠕虫 “鲸鲨蠕虫”深度分析报告
http://paper.seebug.org/349/
http://paper.seebug.org/349/
SecWiki周刊(第174期)
https://www.sec-wiki.com/weekly/174
https://www.sec-wiki.com/weekly/174
Deep Learning 中文翻译
https://github.com/exacity/deeplearningbook-chinese
https://github.com/exacity/deeplearningbook-chinese
filewatcher: macOS上的文件监控工具
https://github.com/m3liot/filewatcher
https://github.com/m3liot/filewatcher
St2-048 Remote Code Execution Vulnerability 测试 POC
https://github.com/jas502n/st2-048
https://github.com/jas502n/st2-048
如何把NMAP扫描结果同步到Elasticsearch?
http://www.4hou.com/tools/6040.html
http://www.4hou.com/tools/6040.html
炒鸡棒的模糊测试技术
http://www.4hou.com/mobile/6015.html
http://www.4hou.com/mobile/6015.html
shellMonitor: Linux 下基于 Bash 的文件和数据库监控及备份工具,微信报警
https://github.com/zsenliao/shellMonitor
https://github.com/zsenliao/shellMonitor
卡巴斯基开源数字取证工具Bitscout
https://github.com/vitaly-kamluk/bitscout
https://github.com/vitaly-kamluk/bitscout
NE(Network Embedding)论文小览
http://blog.csdn.net/Dark_Scope/article/details/74279582#0-tsina-1-3919-397232819ff9a47a7b7e80a40613cfe1
http://blog.csdn.net/Dark_Scope/article/details/74279582#0-tsina-1-3919-397232819ff9a47a7b7e80a40613cfe1
WordPress统计插件Statistics SQL注入漏洞分析
http://ecma.io/755.html
http://ecma.io/755.html
自动量化浏览器扩展的“指纹性”
http://www.arkteam.net/?p=1978
http://www.arkteam.net/?p=1978
iOS 项目开发过程中用到的高级调试技巧
https://github.com/aozhimin/iOS-Debug-Hacks
https://github.com/aozhimin/iOS-Debug-Hacks
初学Windows内核漏洞利用(三):窃取访问凭证
https://mp.weixin.qq.com/s/QxdlOop86Z6rOaRkLMkJlg
https://mp.weixin.qq.com/s/QxdlOop86Z6rOaRkLMkJlg
了解macOS上的恶意木马--OSX/Dok
http://bobao.360.cn/learning/detail/4071.html
http://bobao.360.cn/learning/detail/4071.html
OSRFramework: Open Sources Research Intelligence Framework
https://github.com/i3visio/osrframework
https://github.com/i3visio/osrframework
Zeus: AWS Auditing & Hardening Tool
https://github.com/DenizParlak/Zeus
https://github.com/DenizParlak/Zeus
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第175期)
