SecWiki周刊(第216期)
2018/04/16-2018/04/22
安全资讯
黑客袁哥:寻原初之力 秉正义之剑
https://m.mp.oeeee.com/a/BAAFRD00002018041675442.html
https://m.mp.oeeee.com/a/BAAFRD00002018041675442.html
Weblogic反序列化命令执行漏洞_CVE-2018-2628
https://nosec.org/my/threats/1608
https://nosec.org/my/threats/1608
RSA 2018 全球高质量安全产品了解一下
https://www.anquanke.com/post/id/105379
https://www.anquanke.com/post/id/105379
习近平:自主创新推进网络强国建设
http://www.xinhuanet.com/politics/2018-04/18/c_1122704349.htm
http://www.xinhuanet.com/politics/2018-04/18/c_1122704349.htm
全国医院信息化建设标准与规范
http://www.nhfpc.gov.cn/guihuaxxs/s10741/201804/5711872560ad4866a8f500814dcd7ddd.shtml
http://www.nhfpc.gov.cn/guihuaxxs/s10741/201804/5711872560ad4866a8f500814dcd7ddd.shtml
加速推动信息领域核心技术突破
https://mp.weixin.qq.com/s/S_HmemBo4wU22e6RJ_qDxw
https://mp.weixin.qq.com/s/S_HmemBo4wU22e6RJ_qDxw
安全技术
Weblogic反序列化漏洞(CVE-2018-2628)
https://github.com/shengqi158/CVE-2018-2628
https://github.com/shengqi158/CVE-2018-2628
知识星球"灰袍技能" 2017 精华
https://chrislinn.gitbooks.io/greyhame-2017/
https://chrislinn.gitbooks.io/greyhame-2017/
Bypass X-WAF SQL注入防御(多姿势)
https://mp.weixin.qq.com/s/5TQddrOqa8MmtsuHoCRu0Q
https://mp.weixin.qq.com/s/5TQddrOqa8MmtsuHoCRu0Q
CVE-2018-4121 - Safari Wasm Sections POC RCE Exploit
https://github.com/mwrlabs/CVE-2018-4121
https://github.com/mwrlabs/CVE-2018-4121
驭龙hids入侵检测功能初探
http://pirogue.org/2018/04/20/yulong-hids/
http://pirogue.org/2018/04/20/yulong-hids/
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable.
https://github.com/prateek147/DVIA-v2
https://github.com/prateek147/DVIA-v2
The IoT Hacker's Toolkit
https://systemoverlord.com/2018/04/16/the-iot-hackers-toolkit.html
https://systemoverlord.com/2018/04/16/the-iot-hackers-toolkit.html
浅谈如何建立互联网风控系统
http://mp.weixin.qq.com/s/_tTtWv5f-r2ihNysZz0LAw
http://mp.weixin.qq.com/s/_tTtWv5f-r2ihNysZz0LAw
打破基于OpenResty的WEB安全防护(CVE-2018-9230)
https://www.anquanke.com/post/id/103771
https://www.anquanke.com/post/id/103771
weblogger: 针对ctf线下赛流量抓取(php)、真实环境流量抓取分析的工具
https://github.com/wupco/weblogger
https://github.com/wupco/weblogger
Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevatio
https://googleprojectzero.blogspot.in/2018/04/windows-exploitation-tricks-exploiting.html
https://googleprojectzero.blogspot.in/2018/04/windows-exploitation-tricks-exploiting.html
CISSP 2017资料
https://pan.baidu.com/s/1tr4hKWzeLj3bcdmdyJ7Iqw
https://pan.baidu.com/s/1tr4hKWzeLj3bcdmdyJ7Iqw
nebula: "星云"业务风控系统
https://github.com/threathunterX/nebula
https://github.com/threathunterX/nebula
Polymorph: A Real-Time Network Packet Manipulation Framework
https://www.exploit-db.com/docs/english/44457-polymorph-a-real-time-network-packet-manipulation-framework.pdf
https://www.exploit-db.com/docs/english/44457-polymorph-a-real-time-network-packet-manipulation-framework.pdf
Awesome Firmware Security & Other Helpful Documents
https://github.com/PreOS-Security/awesome-firmware-security
https://github.com/PreOS-Security/awesome-firmware-security
WordPress hacked site – forensics report
https://www.glenscott.co.uk/wordpress-hacked-site-forensics-report/
https://www.glenscott.co.uk/wordpress-hacked-site-forensics-report/
shield: 基于Strom的日志实时流量分析主动防御(CCFirewall)系统
https://github.com/gy-games/shield
https://github.com/gy-games/shield
Virtual Machine for Adversary Emulation and Threat Hunting
https://github.com/redhuntlabs/RedHunt-OS/
https://github.com/redhuntlabs/RedHunt-OS/
CVE-2018-2628 简单复现与分析
https://mp.weixin.qq.com/s/nYY4zg2m2xsqT0GXa9pMGA
https://mp.weixin.qq.com/s/nYY4zg2m2xsqT0GXa9pMGA
信息安全从业者入门(入职)指南
https://weibo.com/ttarticle/p/show?id=2309404229525654378347
https://weibo.com/ttarticle/p/show?id=2309404229525654378347
Ember: An Open Source Classifier And Dataset
https://github.com/endgameinc/ember
https://github.com/endgameinc/ember
基于机器学习的家用物联网设备DDoS检测
https://xz.aliyun.com/t/2285
https://xz.aliyun.com/t/2285
CVE-2018-0171 Cisco Smart Install远程代码执行漏洞分析
https://www.anquanke.com/post/id/105473
https://www.anquanke.com/post/id/105473
DDCTF 2018 Web Writeup
http://sec2hack.com/ctf/ddctf-2018-web-writeup.html
http://sec2hack.com/ctf/ddctf-2018-web-writeup.html
解析卷积神经网络—深度学习实践手册
http://lamda.nju.edu.cn/weixs/book/CNN_book.html
http://lamda.nju.edu.cn/weixs/book/CNN_book.html
生成式对抗网络GAN的研究进展与展望
https://mp.weixin.qq.com/s/QiIRIHiGv6u-4QfK8awKpw
https://mp.weixin.qq.com/s/QiIRIHiGv6u-4QfK8awKpw
用零宽度字符水印揭露泄密者身份
http://www.freebuf.com/articles/web/167903.html
http://www.freebuf.com/articles/web/167903.html
180页PPT,讲解人工智能技术与产业发展
https://mp.weixin.qq.com/s/s8VLWjXrVCrTt4v2d3MoIQ
https://mp.weixin.qq.com/s/s8VLWjXrVCrTt4v2d3MoIQ
Pam-Python实现SSH的短信双因素认证
http://www.freebuf.com/articles/web/165139.html
http://www.freebuf.com/articles/web/165139.html
AutoFuck: 自动识别cms并且加载相关poc自动攻击
https://github.com/fengxuangit/AutoFuck
https://github.com/fengxuangit/AutoFuck
DDCTF2018 部分writeup
http://phantom0301.cc/2018/04/20/ddctf2018/
http://phantom0301.cc/2018/04/20/ddctf2018/
SecWiki周刊(第215期)
https://www.sec-wiki.com/weekly/215
https://www.sec-wiki.com/weekly/215
Steam新型盗号木马及产业链分析报告
https://cert.360.cn/static/files/Steam%E6%96%B0%E5%9E%8B%E7%9B%97%E5%8F%B7%E6%9C%A8%E9%A9%AC%E5%8F%8A%E4%BA%A7%E4%B8%9A%E9%93%BE%E5%88%86%E6%9E%90.pdf
https://cert.360.cn/static/files/Steam%E6%96%B0%E5%9E%8B%E7%9B%97%E5%8F%B7%E6%9C%A8%E9%A9%AC%E5%8F%8A%E4%BA%A7%E4%B8%9A%E9%93%BE%E5%88%86%E6%9E%90.pdf
A tool for covert execution in Linux.
https://github.com/emptymonkey/mimic
https://github.com/emptymonkey/mimic
Lateral Attacks Between IoT Devices: The Technical Details
http://blog.senr.io/blog/lateral-attacks-between-iot-devices-the-technical-details
http://blog.senr.io/blog/lateral-attacks-between-iot-devices-the-technical-details
Bypass CSP by Abusing XSS Filter in Edge
https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754
https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754
SMB Protocol Bruteforce
https://github.com/m4ll0k/SMBrute
https://github.com/m4ll0k/SMBrute
从0CTF一道题看move_uploaded_file的一个细节问题
https://www.anquanke.com/post/id/103784
https://www.anquanke.com/post/id/103784
XSS in pastebin.com via unsanitized markdown output
https://github.com/Nhoya/PastebinMarkdownXSS
https://github.com/Nhoya/PastebinMarkdownXSS
Drupal 7 - CVE-2018-7600 PoC Writeup
https://ricterz.me/posts/Drupal%207%20-%20CVE-2018-7600%20PoC%20Writeup
https://ricterz.me/posts/Drupal%207%20-%20CVE-2018-7600%20PoC%20Writeup
Automotive Industry Guidelines for Secure Over-the-Air Updates
https://fastr.org/wp-content/uploads/2018/04/FASTR_AutomotiveIndustry_Guidelines_SecureOver-the-Air_Updates_v2.pdf
https://fastr.org/wp-content/uploads/2018/04/FASTR_AutomotiveIndustry_Guidelines_SecureOver-the-Air_Updates_v2.pdf
工作中如何做好技术积累
https://tech.meituan.com/study_vs_work.html
https://tech.meituan.com/study_vs_work.html
Golang for Security Professionals
https://github.com/parsiya/Hacking-with-Go
https://github.com/parsiya/Hacking-with-Go
利用Digital Ocean构建远控基础设施
http://www.4hou.com/technology/11107.html
http://www.4hou.com/technology/11107.html
创新沙盒初探 (2) - RSAC2018之二
https://mp.weixin.qq.com/s/KEF458q-88jzrpRq6JpCUA
https://mp.weixin.qq.com/s/KEF458q-88jzrpRq6JpCUA
毕业设计之php RASP(一) hook函数
http://www.cnblogs.com/iamstudy/articles/php_code_rasp_1.html
http://www.cnblogs.com/iamstudy/articles/php_code_rasp_1.html
Whatsapp user’s IP disclosure with Link Preview feature
https://medium.com/@kankrale.rahul/whatsapp-users-ip-disclosure-with-link-preview-feature-39a477f54fba
https://medium.com/@kankrale.rahul/whatsapp-users-ip-disclosure-with-link-preview-feature-39a477f54fba
Python反序列化漏洞的花式利用
https://xz.aliyun.com/t/2289
https://xz.aliyun.com/t/2289
狗子的XSS学习之旅
https://xz.aliyun.com/t/2296
https://xz.aliyun.com/t/2296
Vultr Domain Hijacking
https://vincentyiu.co.uk/vultr-domain-hijacking/
https://vincentyiu.co.uk/vultr-domain-hijacking/
APT Trends report Q1 2018
https://securelist.com/apt-trends-report-q1-2018/85280/
https://securelist.com/apt-trends-report-q1-2018/85280/
Abusing Linux's firewall: the hack that allowed us to build Spectrum
https://blog.cloudflare.com/how-we-built-spectrum/
https://blog.cloudflare.com/how-we-built-spectrum/
记一次渗透测试过程中的Zabbix命令执行利用
http://www.freebuf.com/articles/web/168819.html
http://www.freebuf.com/articles/web/168819.html
WebExtension security - Part 1
http://leucosite.com/WebExtension-Security/
http://leucosite.com/WebExtension-Security/
Windows: WLDP CLSID policy .NET COM Instantiation UMCI Bypass
https://bugs.chromium.org/p/project-zero/issues/detail?id=1514
https://bugs.chromium.org/p/project-zero/issues/detail?id=1514
Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer
https://github.com/Jsitech/JShielder
https://github.com/Jsitech/JShielder
吃鸡辅助远控木马分析
https://www.anquanke.com/post/id/105670
https://www.anquanke.com/post/id/105670
从一次溯源窥探地下YY直播洗号产业链
https://www.anquanke.com/post/id/105043
https://www.anquanke.com/post/id/105043
检测攻击的基础日志服务器 Part2:日志聚合
https://www.anquanke.com/post/id/103348
https://www.anquanke.com/post/id/103348
how-to-become-a-cyber-forensics-expert
https://www.peerlyst.com/posts/how-to-become-a-cyber-forensics-expert-abhinav-singh
https://www.peerlyst.com/posts/how-to-become-a-cyber-forensics-expert-abhinav-singh
$5k Service dependencies
https://sites.google.com/site/testsitehacking/-5k-service-dependencies
https://sites.google.com/site/testsitehacking/-5k-service-dependencies
写在“软件基因技术”分论坛之后(一)
https://mp.weixin.qq.com/s/qpVmvTuq6cIl2rQFclX4Yw
https://mp.weixin.qq.com/s/qpVmvTuq6cIl2rQFclX4Yw
MYSQL新特性secure_file_priv对读写文件的影响
https://xz.aliyun.com/t/2293
https://xz.aliyun.com/t/2293
Go AST Scanner:Inspects source code for security problems
https://github.com/GoASTScanner/gas
https://github.com/GoASTScanner/gas
Firefox 56.0 302 Redirect URL Spoofing Vulnerability
http://rm-rf.gg/2018/04/19/Firefox_302_Redirect_URL_Spoofing_Vulnerability.html
http://rm-rf.gg/2018/04/19/Firefox_302_Redirect_URL_Spoofing_Vulnerability.html
写在“软件基因分论”之后(二)
https://mp.weixin.qq.com/s/_cStfXSfXII8m5ary4fzWg
https://mp.weixin.qq.com/s/_cStfXSfXII8m5ary4fzWg
Source code about machine learning and security.
https://github.com/13o-bbr-bbq/machine_learning_security
https://github.com/13o-bbr-bbq/machine_learning_security
bug-monitor: Seebug、structs、cve漏洞实时监控推送系统
https://github.com/FortuneC00kie/bug-monitor
https://github.com/FortuneC00kie/bug-monitor
An Empirical Analysis of Traceability in the Monero Blockchain
https://www.andrew.cmu.edu/user/nicolasc/publications/Moeser-PETS18.pdf
https://www.andrew.cmu.edu/user/nicolasc/publications/Moeser-PETS18.pdf
-----微信ID:SecWiki-----
SecWiki,13年来一直专注安全技术资讯分析!
SecWiki:https://www.sec-wiki.com
本期原文地址: SecWiki周刊(第216期)
