SecWiki周刊(第20期)
2014/07/14-2014/07/20
安全资讯
Schneier on Security: GCHQ Catalog of Exploit Tools
https://www.schneier.com/blog/archives/2014/07/gchq_catalog_of.html
https://www.schneier.com/blog/archives/2014/07/gchq_catalog_of.html
Havex:以工控设备为狩猎目标的恶意软件
http://www.freebuf.com/articles/system/38525.html
http://www.freebuf.com/articles/system/38525.html
安全技术
安全科普:SQLi Labs 指南 Part 2
http://www.freebuf.com/articles/web/38315.html
http://www.freebuf.com/articles/web/38315.html
#乌云月爆# wooyun monthly -7
http://pan.baidu.com/s/1c0w5I2c
http://pan.baidu.com/s/1c0w5I2c
TrapX_ZOMBIE_Report_Final
http://www.trapx.com/wp-content/uploads/2014/07/TrapX_ZOMBIE_Report_Final.pdf
http://www.trapx.com/wp-content/uploads/2014/07/TrapX_ZOMBIE_Report_Final.pdf
Isolated Heap & Friends - Object Allocation Hardening in Web Browsers
https://labs.mwrinfosecurity.com/blog/2014/06/20/isolated-heap-friends---object-allocation-hardening-in-web-browsers/
https://labs.mwrinfosecurity.com/blog/2014/06/20/isolated-heap-friends---object-allocation-hardening-in-web-browsers/
Reversing a PHP Script Dynamically and Statically
http://www.kahusecurity.com/2014/reversing-a-php-script-dynamically-and-statically/
http://www.kahusecurity.com/2014/reversing-a-php-script-dynamically-and-statically/
CVE-2014-0321 - Exploiting IE11 on windows 8.1 32bits
http://www.weibo.com/p/1001603732980651659108
http://www.weibo.com/p/1001603732980651659108
Industrial Control Systems Cyber Security Conference
http://www.icscybersecurityconference.com/
http://www.icscybersecurityconference.com/
移动基站是如何被假冒的,发送欺诈广告短信的伪基站如何工作?
http://www.zhihu.com/question/21389742
http://www.zhihu.com/question/21389742
Abusing Oracle’s CREATE DATABASE LINK privilege for fun and profit!
http://www.notsosecure.com/blog/2014/07/08/abusing-oracles-create-database-link-privilege-for-fun-and-profit/
http://www.notsosecure.com/blog/2014/07/08/abusing-oracles-create-database-link-privilege-for-fun-and-profit/
漫谈云上架构和运维的艺术
http://t.cn/RPAmzh8
http://t.cn/RPAmzh8
绿盟科技安全+技术内刊 025期
http://www.nsfocus.com/images/6_about/journal/6_10_025_j.pdf
http://www.nsfocus.com/images/6_about/journal/6_10_025_j.pdf
linux python版webshell智能查杀程序-SeayFindShell
http://www.cnseay.com/3984/
http://www.cnseay.com/3984/
Dump Windows password hashes efficiently
http://bernardodamele.blogspot.hk/2011/12/dump-windows-password-hashes.html
http://bernardodamele.blogspot.hk/2011/12/dump-windows-password-hashes.html
Bypassing AV with Veil-Evasion
https://www.netspi.com/blog/entryid/234/bypassing-av-with-veil-evasion
https://www.netspi.com/blog/entryid/234/bypassing-av-with-veil-evasion
Is use-after-free exploitation dead? The new IE memory protector will tell you
http://blog.fortinet.com/Is-use-after-free-exploitation-dead--The-new-IE-memory-protector-will-tell-you/
http://blog.fortinet.com/Is-use-after-free-exploitation-dead--The-new-IE-memory-protector-will-tell-you/
译言精选-大误:网络安全五大迷思
http://select.yeeyan.org/view/270688/415556
http://select.yeeyan.org/view/270688/415556
Anti-Hacker Tool Kit, 4th Edition
http://pan.baidu.com/s/1rPWPS
http://pan.baidu.com/s/1rPWPS
PunkSPIDER:a global web application vulnerability search engine
http://punkspider.hyperiongray.com/
http://punkspider.hyperiongray.com/
上传文件的陷阱II 纯数字字母的swf是漏洞么
http://drops.wooyun.org/tips/2554
http://drops.wooyun.org/tips/2554
iOS_Backdoors_Attack_Points_Surveillance_Mechanisms
http://t.cn/RPAaSN8
http://t.cn/RPAaSN8
Vulnerability Summary for the Week of July 7, 2014
http://www.us-cert.gov/ncas/bulletins/SB14-195
http://www.us-cert.gov/ncas/bulletins/SB14-195
Flash 0day特性带来的攻击思路杂谈
http://evilcos.me/?p=425
http://evilcos.me/?p=425
Android Security Enhancements
http://androidtamer.com/android-security-enhancements/
http://androidtamer.com/android-security-enhancements/
web.py 使用不当可能造成代码执行
http://lcx.cc/?i=4395
http://lcx.cc/?i=4395
TPLINK渗透实战
http://drops.wooyun.org/tips/2552
http://drops.wooyun.org/tips/2552
学习JavaScript的在线课程和指南
http://blog.jobbole.com/73465/
http://blog.jobbole.com/73465/
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第20期)
