SecWiki周刊(第198期)
2017/12/11-2017/12/17
安全资讯
全国第三届工控系统信息安全攻防竞赛
https://mp.weixin.qq.com/s/QDdcrTw4nWf62-6__kCFuA
https://mp.weixin.qq.com/s/QDdcrTw4nWf62-6__kCFuA
2017年中国网络安全富豪排行榜
https://mp.weixin.qq.com/s/L3t-CAOu7l46TSZdox880g
https://mp.weixin.qq.com/s/L3t-CAOu7l46TSZdox880g
从机器学习到机器创造——访AI安全专家李康
https://mp.weixin.qq.com/s/-YVA3FHXea-FK1MqL3DLSg
https://mp.weixin.qq.com/s/-YVA3FHXea-FK1MqL3DLSg
网络安全产业发展现状与展望
https://mp.weixin.qq.com/s/E7Iuri9G0RYOfv50yVLX_A
https://mp.weixin.qq.com/s/E7Iuri9G0RYOfv50yVLX_A
CB Insights全球最强AI创新公司Top100榜单
http://www.sohu.com/a/210427712_473283
http://www.sohu.com/a/210427712_473283
《2018财年国防授权法案》(NDAA)中的网络安全部分
https://mp.weixin.qq.com/s/kJxKDeMkPnYc-F1EIuc2gA
https://mp.weixin.qq.com/s/kJxKDeMkPnYc-F1EIuc2gA
国家网络安全产业园区建设总体思路介绍
https://mp.weixin.qq.com/s/QBtI7uMuReItCRbliBFwrA
https://mp.weixin.qq.com/s/QBtI7uMuReItCRbliBFwrA
工业和信息化部发布《促进新一代人工智能产业发展三年行动计划(2018-2020年)》
https://mp.weixin.qq.com/s/4CQKqL_kZzMTlu8W4WYrLg
https://mp.weixin.qq.com/s/4CQKqL_kZzMTlu8W4WYrLg
安全技术
NDSS Symposium 2018 Accepted Papers
https://www.ndss-symposium.org/ndss2018/programme/?from=timeline
https://www.ndss-symposium.org/ndss2018/programme/?from=timeline
Lua程序逆向之Luajit字节码与反汇编
https://www.anquanke.com/post/id/90241
https://www.anquanke.com/post/id/90241
常规web渗透测试漏洞描述及修复建议
http://blog.51cto.com/eth10/2049721
http://blog.51cto.com/eth10/2049721
IDA Pro 7.0 绿色版
https://www.52pojie.cn/thread-675251-1-1.html
https://www.52pojie.cn/thread-675251-1-1.html
CODASPY 2018 Accepted Papers
http://www.ycheng.org/codaspy/2018/accepted.html
http://www.ycheng.org/codaspy/2018/accepted.html
Linux下pwn从入门到放弃
https://paper.seebug.org/481/
https://paper.seebug.org/481/
2017湖湘杯网络安全大赛Writeup
http://www.freebuf.com/articles/others-articles/155172.html
http://www.freebuf.com/articles/others-articles/155172.html
Vivotek 摄像头远程栈溢出漏洞分析及利用
https://paper.seebug.org/480/?from=timeline&isappinstalled=0
https://paper.seebug.org/480/?from=timeline&isappinstalled=0
渗透技巧——从Admin权限切换到System权限
https://3gstudent.github.io/3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E4%BB%8EAdmin%E6%9D%83%E9%99%90%E5%88%87%E6%8D%A2%E5%88%B0System%E6%9D%83%E9%99%90/
https://3gstudent.github.io/3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E4%BB%8EAdmin%E6%9D%83%E9%99%90%E5%88%87%E6%8D%A2%E5%88%B0System%E6%9D%83%E9%99%90/
CVE–2017–16943 Exim–UAF漏洞分析
https://cert.360.cn/report/detail?id=9efc77a68170170bc490e876d4087fb2
https://cert.360.cn/report/detail?id=9efc77a68170170bc490e876d4087fb2
通过预测API窃取机器学习模型
http://www.freebuf.com/news/156313.html
http://www.freebuf.com/news/156313.html
xsec-traffic: 恶意流量分析程序
https://github.com/netxfly/xsec-traffic
https://github.com/netxfly/xsec-traffic
去哪儿客户端全业务线用户行为数据ETL介绍
https://mp.weixin.qq.com/s/qn8VAMoIk7rkhDL4BsCfcA
https://mp.weixin.qq.com/s/qn8VAMoIk7rkhDL4BsCfcA
Trip: 协程 Requests 实战,获取免费代理
https://www.v2ex.com/t/414753#reply9
https://www.v2ex.com/t/414753#reply9
如何使用QEMU和Volatility攻击全盘加密的系统
https://zhuanlan.zhihu.com/p/32038343
https://zhuanlan.zhihu.com/p/32038343
SecWiki周刊(第197期)
https://www.sec-wiki.com/weekly/197
https://www.sec-wiki.com/weekly/197
malscan: A fully featured malware scanner for Linux desktops and servers.
https://github.com/jgrancell/malscan
https://github.com/jgrancell/malscan
漏洞根源在于人——业务技巧篇
https://bbs.ichunqiu.com/thread-30137-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-30137-1-1.html?from=sec
Anubis: Subdomain enumeration and information gathering tool
https://github.com/jonluca/Anubis
https://github.com/jonluca/Anubis
一个电信劫持案例的简要分析
https://www.92ez.com/?action=show&id=23464
https://www.92ez.com/?action=show&id=23464
XPath注入:攻击与防御技术
http://mp.weixin.qq.com/s/iaOIweU_Oom-sZWfVjNp1Q
http://mp.weixin.qq.com/s/iaOIweU_Oom-sZWfVjNp1Q
SECCON 2017 Web Write Up
http://www.melodia.pw/?p=929
http://www.melodia.pw/?p=929
Mirai IoT Botnet Co-Authors Plead Guilty
https://krebsonsecurity.com/2017/12/mirai-iot-botnet-co-authors-plead-guilty/
https://krebsonsecurity.com/2017/12/mirai-iot-botnet-co-authors-plead-guilty/
JBOOS反序列化漏洞复现
http://mp.weixin.qq.com/s/PAwsAvSdVBIzpsGMmeSqmA
http://mp.weixin.qq.com/s/PAwsAvSdVBIzpsGMmeSqmA
SQL和NoSQL注入原理剖析(上)
https://mp.weixin.qq.com/s/LsqQo_04ROuf2_wLrBRRZQ
https://mp.weixin.qq.com/s/LsqQo_04ROuf2_wLrBRRZQ
scikit-learn: 中文文档
http://sklearn.apachecn.org/cn/0.19.0/index.html
http://sklearn.apachecn.org/cn/0.19.0/index.html
巡风源码浅析之 Vulscan 分析篇
http://www.myh0st.cn/index.php/archives/903/
http://www.myh0st.cn/index.php/archives/903/
A Year in Review: Ransomware
http://www.cyberdefensemagazine.com/a-year-in-review-ransomware/
http://www.cyberdefensemagazine.com/a-year-in-review-ransomware/
Avast open-sources its machine-code decompiler
https://blog.avast.com/avast-open-sources-its-machine-code-decompiler
https://blog.avast.com/avast-open-sources-its-machine-code-decompiler
Monitoring for Windows Event Logs and the Untold Story of proper ELK Integration
http://www.ubersec.com/2017/12/03/monitoring-for-windows-event-logs-and-the-untold-story-of-proper-elk-integration/
http://www.ubersec.com/2017/12/03/monitoring-for-windows-event-logs-and-the-untold-story-of-proper-elk-integration/
机器学习和web安全交叉的一些脑洞
https://zhuanlan.zhihu.com/p/31963829?group_id=924219934821687296
https://zhuanlan.zhihu.com/p/31963829?group_id=924219934821687296
美国中情局是如何做风投的?
https://mp.weixin.qq.com/s/XpymxwqqVPZZDRvY2CGSpg
https://mp.weixin.qq.com/s/XpymxwqqVPZZDRvY2CGSpg
Web Exploit-Framework
https://github.com/WangYihang/Exploit-Framework
https://github.com/WangYihang/Exploit-Framework
Decrypt php VoiceStar encryption extension
http://blog.th3s3v3n.xyz/2017/12/12/web/Decrypt_php_VoiceStar_encryption_extension/
http://blog.th3s3v3n.xyz/2017/12/12/web/Decrypt_php_VoiceStar_encryption_extension/
游戏安全系列教程-植物大战僵尸
https://bbs.ichunqiu.com/thread-30298-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-30298-1-1.html?from=sec
阿里旺旺ActiveX控件imageMan.dll栈溢出漏洞研究
https://bbs.ichunqiu.com/thread-30357-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-30357-1-1.html?from=sec
Tracking Newly Registered Domains
https://isc.sans.edu/forums/diary/Tracking+Newly+Registered+Domains/23127/
https://isc.sans.edu/forums/diary/Tracking+Newly+Registered+Domains/23127/
层层抽丝——GlobeImposter勒索病毒分析
https://bbs.ichunqiu.com/thread-30152-1-1.html?from=sec
https://bbs.ichunqiu.com/thread-30152-1-1.html?from=sec
XDiFF: Extended Differential Fuzzing Framework
https://github.com/IOActive/XDiFF
https://github.com/IOActive/XDiFF
Exploiting Word: CVE-2017-11826
https://www.tarlogic.com/en/blog/exploiting-word-cve-2017-11826/
https://www.tarlogic.com/en/blog/exploiting-word-cve-2017-11826/
CVE监控之Python代码实现
https://mp.weixin.qq.com/s/u6ANBF45fOv3CqJOdkNAQA
https://mp.weixin.qq.com/s/u6ANBF45fOv3CqJOdkNAQA
对Gaza网络犯罪组织2018年新动向的分析
http://www.freebuf.com/articles/network/156740.html
http://www.freebuf.com/articles/network/156740.html
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第198期)
